Live data from Hacker News

A billion medical images are exposed online

techcrunch.com

51–60 of 201 posts

Re: A billion medical images are exposed online

#51

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

This is a little off-topic, but I work in a school and sometimes get the same feeling from teachers. I imagine CEOs of companies that get breached because of stupid preventable reasons are also similar. My point is that I don't think this mindset is limited to doctors, though doctors may take it to another level.

Re: A billion medical images are exposed online

#52

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

how about those health care professionals not logging out of their sessions, writing up their passwords on the stickit notes and just generally leaving their computers unlocked for anybody to just browse through. Its always easy to blame the "maker" and say Im an idiot, make this idiot proof. Do you really want people to treat you, being in a mindset of an idiot ? If there is one field in all of universe that you cant not blame the tools for your own idiocracy is the health care ! I want you, the doctor, bend backwards to be at the top of your game ALWAYS, not just when you are doing a brain surgery. I want you to be the ONE that i can have 100% trust that you have my interests in mind instead of playing blame games.

Re: A billion medical images are exposed online

#53

Earlier quoted context omitted.

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

This seems like a caricature or an exception. Doctors are very aware of HIPAA (and the equivalent in every other country), and the professional and monetary costs of non-compliance. Doctors didn't set up these systems. Doctors didn't expose them to the internet. As the other post said, vendors did. If those vendors couldn't properly communicate the needs, that's their problem. What I think is a more rational explanat…

I'm a student doctor with a CS undergrad. I'm constantly gobsmacked by how horrible the computer systems doctors are forced to use are. They're pretty much abusive to use.

The hours and hours of physician time that are thrown away into mindless box-ticking, copy-pasting, button-pushing, and general head-banging is astounding.

If doctors are resistant to new IT hurdles it is, at least in part, because they're already faced with a decathlon-esque ritual to achieve their basic day's work.

Re: A billion medical images are exposed online

#54
From the article :

"We’re not naming the affected organizations to limit the risk of exposing patient data."

However, a google inurl:dicom search sure shows up the affected organizations on the first page (and plenty pages after that).

And the sites are still fully open. Absolutely zero hacking required.

A lot of organizations had better get to work fast on this.

(edit: no images were viewed in the making of this post)

Re: A billion medical images are exposed online

#55
post #50
post #47

Earlier quoted context omitted.

>doctors that insist that they shouldn’t be forced to use passwords (not even complicated passwords; ANY passwords). well, it is a clear voice of customer. And it has good reason behind it - time and effort that the customer would like to avoid wasting. Instead of disparaging the customers and their needs how about listening to it and trying to really solve the issues. May be doctors for example would be more happy w…

Doctors are not customers, patients with their expectation of privacy are. This is similar to doctors resisting keeping checklists [1] of what goes in and out of patients during operations. Doctors are service providers and the service is lacking. [1] https://hbr.org/2019/05/how-one-health-system-overcame-resis...

> Doctors are not customers, patients with their expectation of privacy are.

In the US system, is the patient the customer, or the insurance company?

I work in healthcare outside the US and I’d argue that the system I’m in is also quite skewed. In private healthcare where I am, the patient is the person who turns up and pays, but their doctor holds the power to send their patients elsewhere, and so must be kept happy too.

Re: A billion medical images are exposed online

#56

Earlier quoted context omitted.

I work in health, and I sometimes have to interact with the federal database of doctors. It's amazing the things you see in there. There are doctors who don't know their own addresses. Can't spell the name of their town. Don't know their ZIP Code. Don't know the difference between a mailing address and a physical address. Don't keep their information current. Or sometimes don't even know what town they're in, putting…

You're really blaming the subjects of a database for errors in that database? There are many reasons for errors that have nothing to do with anything a physician might or might not have done.

Those subjects fill out the forms that end up in the database. It isn't some faceless government agency reading their minds. The data comes from what the doctors write down.

Re: A billion medical images are exposed online

#57
post #30

DICOM is a standard that does too much. They should scrub everything related to networking and focus solely on encoding/decoding medical images.

> DICOM It’s a great standard compared to HL7 though. That ‘standard’ is the bane of radiology’s existence.

Re: A billion medical images are exposed online

#58
post #3

The key takeaway from that article, for me, is that the government body that is supposed to monitor, enforce, and penalize organizations who fail to follow the HIPAA rules is basically doing nothing. So with no consequence to these massive lapses, why would these companies care?

This is the wrong takeaway.

The article states pretty clearly from the interview with Senator Mark Warner:

> “To my knowledge, Health and Human Services has done nothing about it,” Warner told TechCrunch. “As Health and Human Services aggressively pushes to permit a wider range of parties to have access to the sensitive health information of American patients without traditional privacy protections attached to that information, HHS’s inattention to this particular incident becomes even more troubling,” he added.

It's not that they're doing nothing, they're supposedly making it worse.

They're also underfunded. OCR budget dropped to 10% of its previous budget between 2017 and 2018:

https://www.hhs.gov/about/budget/fy2018/budget-in-brief/ocr/...

So, when you ask "why would these companies care?", I think the current federal government is trying to say "these companies _should not_ care."

Re: A billion medical images are exposed online

#59
post #51

Earlier quoted context omitted.

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

This is a little off-topic, but I work in a school and sometimes get the same feeling from teachers. I imagine CEOs of companies that get breached because of stupid preventable reasons are also similar. My point is that I don't think this mindset is limited to doctors, though doctors may take it to another level.

It really applies to every industry -- people push back against things that they see as impediments to their work. Many/most HN visitors are software developers, and if you've worked in a Fortune 500 virtually all of us have gone to war with IT. "Don't they understand that we're special and we need special rights and privileges" etc. And often we have legitimate grievances because often arbitrary, counter-productive, productivity-sapping restrictions weigh us down. Often they're illusions of security.

And I'm sure on some IT admin board they talk about all of those entitled developers and this one time this one developer did something really stupid, ergo all developers are god-complex dummies.

Re: A billion medical images are exposed online

#60
post #3

The key takeaway from that article, for me, is that the government body that is supposed to monitor, enforce, and penalize organizations who fail to follow the HIPAA rules is basically doing nothing. So with no consequence to these massive lapses, why would these companies care?

[deleted]
Post reply on HN