An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…
I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…
A billion medical images are exposed online
51–60 of 201 posts
Re: A billion medical images are exposed online
#52An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…
Re: A billion medical images are exposed online
#53Earlier quoted context omitted.
I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…
This seems like a caricature or an exception. Doctors are very aware of HIPAA (and the equivalent in every other country), and the professional and monetary costs of non-compliance. Doctors didn't set up these systems. Doctors didn't expose them to the internet. As the other post said, vendors did. If those vendors couldn't properly communicate the needs, that's their problem. What I think is a more rational explanat…
The hours and hours of physician time that are thrown away into mindless box-ticking, copy-pasting, button-pushing, and general head-banging is astounding.
If doctors are resistant to new IT hurdles it is, at least in part, because they're already faced with a decathlon-esque ritual to achieve their basic day's work.
Re: A billion medical images are exposed online
#54"We’re not naming the affected organizations to limit the risk of exposing patient data."
However, a google inurl:dicom search sure shows up the affected organizations on the first page (and plenty pages after that).
And the sites are still fully open. Absolutely zero hacking required.
A lot of organizations had better get to work fast on this.
(edit: no images were viewed in the making of this post)
Re: A billion medical images are exposed online
#55Earlier quoted context omitted.
>doctors that insist that they shouldn’t be forced to use passwords (not even complicated passwords; ANY passwords). well, it is a clear voice of customer. And it has good reason behind it - time and effort that the customer would like to avoid wasting. Instead of disparaging the customers and their needs how about listening to it and trying to really solve the issues. May be doctors for example would be more happy w…
Doctors are not customers, patients with their expectation of privacy are. This is similar to doctors resisting keeping checklists [1] of what goes in and out of patients during operations. Doctors are service providers and the service is lacking. [1] https://hbr.org/2019/05/how-one-health-system-overcame-resis...
In the US system, is the patient the customer, or the insurance company?
I work in healthcare outside the US and I’d argue that the system I’m in is also quite skewed. In private healthcare where I am, the patient is the person who turns up and pays, but their doctor holds the power to send their patients elsewhere, and so must be kept happy too.
Re: A billion medical images are exposed online
#56Earlier quoted context omitted.
I work in health, and I sometimes have to interact with the federal database of doctors. It's amazing the things you see in there. There are doctors who don't know their own addresses. Can't spell the name of their town. Don't know their ZIP Code. Don't know the difference between a mailing address and a physical address. Don't keep their information current. Or sometimes don't even know what town they're in, putting…
You're really blaming the subjects of a database for errors in that database? There are many reasons for errors that have nothing to do with anything a physician might or might not have done.
Re: A billion medical images are exposed online
#57DICOM is a standard that does too much. They should scrub everything related to networking and focus solely on encoding/decoding medical images.
Re: A billion medical images are exposed online
#58The key takeaway from that article, for me, is that the government body that is supposed to monitor, enforce, and penalize organizations who fail to follow the HIPAA rules is basically doing nothing. So with no consequence to these massive lapses, why would these companies care?
The article states pretty clearly from the interview with Senator Mark Warner:
> “To my knowledge, Health and Human Services has done nothing about it,” Warner told TechCrunch. “As Health and Human Services aggressively pushes to permit a wider range of parties to have access to the sensitive health information of American patients without traditional privacy protections attached to that information, HHS’s inattention to this particular incident becomes even more troubling,” he added.
It's not that they're doing nothing, they're supposedly making it worse.
They're also underfunded. OCR budget dropped to 10% of its previous budget between 2017 and 2018:
https://www.hhs.gov/about/budget/fy2018/budget-in-brief/ocr/...
So, when you ask "why would these companies care?", I think the current federal government is trying to say "these companies _should not_ care."
Re: A billion medical images are exposed online
#59Earlier quoted context omitted.
I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…
This is a little off-topic, but I work in a school and sometimes get the same feeling from teachers. I imagine CEOs of companies that get breached because of stupid preventable reasons are also similar. My point is that I don't think this mindset is limited to doctors, though doctors may take it to another level.
And I'm sure on some IT admin board they talk about all of those entitled developers and this one time this one developer did something really stupid, ergo all developers are god-complex dummies.
Re: A billion medical images are exposed online
#60The key takeaway from that article, for me, is that the government body that is supposed to monitor, enforce, and penalize organizations who fail to follow the HIPAA rules is basically doing nothing. So with no consequence to these massive lapses, why would these companies care?