Live data from Hacker News

A billion medical images are exposed online

techcrunch.com

71–80 of 201 posts

Re: A billion medical images are exposed online

#71

Earlier quoted context omitted.

I work in health, and I sometimes have to interact with the federal database of doctors. It's amazing the things you see in there. There are doctors who don't know their own addresses. Can't spell the name of their town. Don't know their ZIP Code. Don't know the difference between a mailing address and a physical address. Don't keep their information current. Or sometimes don't even know what town they're in, putting…

Not smart at computers, but maybe they are smart about computers. Everyone thinks old people can’t use tech but what if they don’t want to and that resistance is a manifestation of wisdom that’s incomprehensible to those without the same wisdom. To believe doctors as a class of people are less intelligent than average is silly and probably ego defensive. As a group doctors are of above average intelligence and certai…

There are different types of intelligence. Both fields require totally different talent, interests and skills. One is solving very abstract problems, the other is talking to people and learning a huge amount of information about how humans work.

I am good with abstract stuff, but in no way I could remember that amount of information about people as doctors too. I still have no idea what most of my bones or other things within me are named and I have zero interest in it. I can imagine one could be also the other way around. Have huge amount of interest in people, but despise techy knowledge.

In the end both doctors and it workers are so different from each other that they have so much trouble understanding one another. Remember doctors never asked for all this abstract shit. Also as you age you will get more set in the field you choose. That is just the way people work. Not an excuse or why one should not keep improving themselves.

Re: A billion medical images are exposed online

#72
post #50
post #47

Earlier quoted context omitted.

>doctors that insist that they shouldn’t be forced to use passwords (not even complicated passwords; ANY passwords). well, it is a clear voice of customer. And it has good reason behind it - time and effort that the customer would like to avoid wasting. Instead of disparaging the customers and their needs how about listening to it and trying to really solve the issues. May be doctors for example would be more happy w…

Doctors are not customers, patients with their expectation of privacy are. This is similar to doctors resisting keeping checklists [1] of what goes in and out of patients during operations. Doctors are service providers and the service is lacking. [1] https://hbr.org/2019/05/how-one-health-system-overcame-resis...

> This is similar to doctors resisting keeping checklists

Or how they refused to wash their hands between morgue and delivery after Semmelweiss' discoveries.

Doctors see themselves as demigods. Not without reason, since other employees treat them as demigods, society and culture at large sees them as demigods as well.

Re: A billion medical images are exposed online

#73
post #67

Earlier quoted context omitted.

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

It goes both ways. I keep telling the IT people at my hospital to stop using SMS 2-factor and they blow me off and treat me like an idiot. Anyway, ‘Doctors’ are a pretty diverse bunch, and most of them aren’t arrogant porn-fiends.

From experience, users who come to IT and simply demand we do something because 'reasons' usually aren't prioritized for follow up.

Managers who come to IT and demand we do something and show us how it affects their work/department and perhaps the rest of the business and offer to be part of the solution making process often get first class attention.

Could it be IT is blowing you off because of how you're delivering your complaint about SMS 2FA without regard for their existing workload?

They likely have more than enough on their plates as it is to simply do something because someone from a department said something about it, and IT doesn't exactly pivot on lithium battery, especially in hospitals. That doesn't mean they don't care about your issue or request, but like every other department they have objectives and goals that were likely set well before your 2FA conversation even began.

Re: A billion medical images are exposed online

#74
post #73
post #67

Earlier quoted context omitted.

It goes both ways. I keep telling the IT people at my hospital to stop using SMS 2-factor and they blow me off and treat me like an idiot. Anyway, ‘Doctors’ are a pretty diverse bunch, and most of them aren’t arrogant porn-fiends.

From experience, users who come to IT and simply demand we do something because 'reasons' usually aren't prioritized for follow up. Managers who come to IT and demand we do something and show us how it affects their work/department and perhaps the rest of the business and offer to be part of the solution making process often get first class attention. Could it be IT is blowing you off because of how you're delivering…

You realise what you just did there right, without a hint of irony?

Re: A billion medical images are exposed online

#75

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

This is why in starting up my own little IT services company I'm planning on not serving medical clients.

"HIPAA? I'm sure we're just fine, and no you can't take away my Windows 7 PCs."

Re: A billion medical images are exposed online

#76
post #67

Earlier quoted context omitted.

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

It goes both ways. I keep telling the IT people at my hospital to stop using SMS 2-factor and they blow me off and treat me like an idiot. Anyway, ‘Doctors’ are a pretty diverse bunch, and most of them aren’t arrogant porn-fiends.

I hear you and I’m sure it’s frustrating, but I’d be curious to know if the security team has any reasons for sticking with SMS 2FA. I’d be willing to bet money that the reason they blow you off is because it’s a sore spot for them. They probably have tried to implement other MFA methods but were reprimanded by the medical staff because anything other than SMS is too complicated (I’m harping on doctors a lot, but I legitimately do cringe at the thought of even asking a typical MD to download an MFA app or carry around a physical token).

Re: A billion medical images are exposed online

#78
post #25

Earlier quoted context omitted.

I completely agree. I have friends in the medical field, and they hate their computer systems. One of them spends almost as much time on data entry as he does with his patients. He has to double and sometimes triple enter data. He’s probably going to end up hiring someone to do that full time, which is so obviously a totally broken system.

> One of them spends almost as much time on data entry as he does with patients ...then he’s one of the lucky ones! One study found that for every hour a physician spends with a patient, she spends two on processing health records. https://www.jwatch.org/fw111995/2016/09/06/half-physician-ti...

I mean, for every hour I spend writing production code - I spend an hour in agile meetings, and 2 hours chasing down obscure bugs in javascript libraries. Not that many professions are "do visible part of work 100%".

Heck, I hear bricklayers need to spend some time mixing cement and getting bricks off the truck, not just scooping mud and sticking bricks.

Health records ARE a big part of the product of a doctor. Keeping a good chart and finding trends over time is a bit part of the service you need.

Re: A billion medical images are exposed online

#79
post #67

Earlier quoted context omitted.

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

It goes both ways. I keep telling the IT people at my hospital to stop using SMS 2-factor and they blow me off and treat me like an idiot. Anyway, ‘Doctors’ are a pretty diverse bunch, and most of them aren’t arrogant porn-fiends.

SMS for 2FA isn't good, but it's still better than no 2FA at all.

Depending on how many systems they have it integrated with that could end up being a huge undertaking for them and they've probably been cut to the point where another huge undertaking may not be in the cards right now. If they're like a lot of large enterprises they may also still be trying to get rid of Windows 7 and Server 2008R2.

Edit: for example, are you full on Microsoft 365 Enterprise with Azure AD? I believe that has ties in with Microsoft's Authenticator app. If you're strictly onsite traditional AD I think you'd need to look at Duo for 2fa that integrates nicely with AD, then also see what else you need to integrate it with that uses its own separate non - SSO authentication.

And while it's not huge, the question of "who's paying for the $3/6/9 monthly per user charges (contact sales if you have > 500 users)?" will come up, particularly if there are hundreds or thousands of external medical office users able to sign in through a portal system as well. (this is based on pricing from the Duo website)

Re: A billion medical images are exposed online

#80

Earlier quoted context omitted.

A brand new account posting scathing anti-government anti-regulation content? HIPAA and HITECH and the other legislation that you're likely referring to pushed a stagnant industry in the right direction. Yes there is pain with growth but patients are far better off for it, which is what the end goal was.

At my annual physical, as my doctor was typing away at data entry on a laptop in the exam room, I asked him whether he felt the new electronic systems had freed up his time to spend more time on patients, or whether they had taken time away from patients. He felt the later. I realize that anecdote is not data, and I'm not sure what metric of 'better' you're using, but I wouldn't be too hasty to claim technology as an…

Thing is, people will overlook the elements that are faster and focus on the slower.

Lab results for any patient at a click or two? Ignored.

Changing a med order to be stopped in 27 hours? Guaranteed to be flagged to the nurse at the exact right time.

As much as I complain about Google’s changes (stop ignoring my double quotes!), it’s probably improved overall despite its constant attacks.

Post reply on HN