An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…
A brand new account posting scathing anti-government anti-regulation content? HIPAA and HITECH and the other legislation that you're likely referring to pushed a stagnant industry in the right direction. Yes there is pain with growth but patients are far better off for it, which is what the end goal was.
A billion medical images are exposed online
81–90 of 201 posts
Re: A billion medical images are exposed online
#82Re: A billion medical images are exposed online
#83Earlier quoted context omitted.
I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…
This is why in starting up my own little IT services company I'm planning on not serving medical clients. "HIPAA? I'm sure we're just fine, and no you can't take away my Windows 7 PCs."
Re: A billion medical images are exposed online
#84Earlier quoted context omitted.
>doctors that insist that they shouldn’t be forced to use passwords (not even complicated passwords; ANY passwords). well, it is a clear voice of customer. And it has good reason behind it - time and effort that the customer would like to avoid wasting. Instead of disparaging the customers and their needs how about listening to it and trying to really solve the issues. May be doctors for example would be more happy w…
In another company, we tried rolling out RFID badges that could be scanned at any workstation to log doctors in rather than passwords. This proved to be too inconvenient for doctors as well, and the system had to be rolled back within a month because doctors kept forgetting to keep their badge with them and would then throw a hissy fit because they wanted to go back to the old system where all workstations were perma…
Re: A billion medical images are exposed online
#85Earlier quoted context omitted.
This seems like a caricature or an exception. Doctors are very aware of HIPAA (and the equivalent in every other country), and the professional and monetary costs of non-compliance. Doctors didn't set up these systems. Doctors didn't expose them to the internet. As the other post said, vendors did. If those vendors couldn't properly communicate the needs, that's their problem. What I think is a more rational explanat…
I'm a student doctor with a CS undergrad. I'm constantly gobsmacked by how horrible the computer systems doctors are forced to use are. They're pretty much abusive to use. The hours and hours of physician time that are thrown away into mindless box-ticking, copy-pasting, button-pushing, and general head-banging is astounding. If doctors are resistant to new IT hurdles it is, at least in part, because they're already…
Likely at go-live/vendor selection, nobody wanted to revolutionize things in a way that could only be done on computer.
The successful vendor will be the one that can « make all of your paper stuff look/function/feel the same way on a computer ».
This minimizes training, development and changing the workflow you used for 20 years. Which checks every department’s checkboxes.
So you end up with the worst aspects of paper, with few of the benefits of technology.
Re: A billion medical images are exposed online
#86Earlier quoted context omitted.
It goes both ways. I keep telling the IT people at my hospital to stop using SMS 2-factor and they blow me off and treat me like an idiot. Anyway, ‘Doctors’ are a pretty diverse bunch, and most of them aren’t arrogant porn-fiends.
I hear you and I’m sure it’s frustrating, but I’d be curious to know if the security team has any reasons for sticking with SMS 2FA. I’d be willing to bet money that the reason they blow you off is because it’s a sore spot for them. They probably have tried to implement other MFA methods but were reprimanded by the medical staff because anything other than SMS is too complicated (I’m harping on doctors a lot, but I l…
Re: A billion medical images are exposed online
#87Earlier quoted context omitted.
I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…
People are constantly targeting every aspect of the physician workflow, from CMS and private payors constantly changing their documentation requirements (which differ between payors and CMS, and results in hospitals trying to teach their docs to document everything to meet everyone's requirements - which are made intentionally lengthy and obtuse so as to justify denials of payment), quality improvement people and ven…
Paywalled, but nonetheless, I wonder how that rate compares to other industries. And how much has to do with physicians usually being unable to switch industries without a massive pay cut.
Dunno if doctors are particularly too self-important to change than anyone else, but if someone was, I could see that inability itself leading to burnout when things even slightly change around you.
Re: A billion medical images are exposed online
#88Earlier quoted context omitted.
It goes both ways. I keep telling the IT people at my hospital to stop using SMS 2-factor and they blow me off and treat me like an idiot. Anyway, ‘Doctors’ are a pretty diverse bunch, and most of them aren’t arrogant porn-fiends.
SMS for 2FA isn't good, but it's still better than no 2FA at all. Depending on how many systems they have it integrated with that could end up being a huge undertaking for them and they've probably been cut to the point where another huge undertaking may not be in the cards right now. If they're like a lot of large enterprises they may also still be trying to get rid of Windows 7 and Server 2008R2. Edit: for example,…
As it happens there is a single web property for accessing a remote desktop, not multiple systems, and the hospital down the road funded by the same entity has implemented TOTP authentication.
Re: A billion medical images are exposed online
#89Earlier quoted context omitted.
I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…
This is a little off-topic, but I work in a school and sometimes get the same feeling from teachers. I imagine CEOs of companies that get breached because of stupid preventable reasons are also similar. My point is that I don't think this mindset is limited to doctors, though doctors may take it to another level.
Re: A billion medical images are exposed online
#90Earlier quoted context omitted.
This is a little off-topic, but I work in a school and sometimes get the same feeling from teachers. I imagine CEOs of companies that get breached because of stupid preventable reasons are also similar. My point is that I don't think this mindset is limited to doctors, though doctors may take it to another level.
It really applies to every industry -- people push back against things that they see as impediments to their work. Many/most HN visitors are software developers, and if you've worked in a Fortune 500 virtually all of us have gone to war with IT. "Don't they understand that we're special and we need special rights and privileges" etc. And often we have legitimate grievances because often arbitrary, counter-productive,…
This hasn't happened to me with any other position in any other organization, including vice presidents of Fortune 500 companies.