Live data from Hacker News

A billion medical images are exposed online

techcrunch.com

91–100 of 201 posts

Re: A billion medical images are exposed online

#91

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

I am horrified... at how plausible this sounds.

Like many IT people, I google the heck out of a medical condition when I see doctors. Once I must have asked enough pertinent pointed questions that the doctor asked with a mix of sincerity AND condescension, “have you ever worked in a medical field?” No but like any curious individual I utilize the systems accumulating all human knowledge at our fingertips to inform myself... Doesn’t mean I can’t ultimately rely on your professional judgment, Sir

Re: A billion medical images are exposed online

#92
post #88

Earlier quoted context omitted.

SMS for 2FA isn't good, but it's still better than no 2FA at all. Depending on how many systems they have it integrated with that could end up being a huge undertaking for them and they've probably been cut to the point where another huge undertaking may not be in the cards right now. If they're like a lot of large enterprises they may also still be trying to get rid of Windows 7 and Server 2008R2. Edit: for example,…

Yes, I’m sure they have their reasons and their own priorities and constraints. Just like the doctors who decline to use basic authentication. See my point? Hospitals are notorious for passing the buck around. As it happens there is a single web property for accessing a remote desktop, not multiple systems, and the hospital down the road funded by the same entity has implemented TOTP authentication.

Curious, why would a doctor decline to use basic password auth?

Re: A billion medical images are exposed online

#93

Earlier quoted context omitted.

This is why in starting up my own little IT services company I'm planning on not serving medical clients. "HIPAA? I'm sure we're just fine, and no you can't take away my Windows 7 PCs."

I get the feeling big law is just as bad.

I never worked for big law, but medium law is terrible. Partners can just order the IT department to do anything. We had a new head of IT that tried to implement some common sense changes for an organization that handles sensitive data. Basic stuff: Block websites that tend to be malware vectors, don't let users be admins on their own machines, restrict USB storage to certain users, etc. We were forced to override it on the partners machines almost immediately.

Re: A billion medical images are exposed online

#94

Earlier quoted context omitted.

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

People are constantly targeting every aspect of the physician workflow, from CMS and private payors constantly changing their documentation requirements (which differ between payors and CMS, and results in hospitals trying to teach their docs to document everything to meet everyone's requirements - which are made intentionally lengthy and obtuse so as to justify denials of payment), quality improvement people and ven…

I'm sympathetic to this, and in other threads I would usually be the first person coming to the defense of doctors and harping on how complex and terrible EMR and other medical software is. But that's not what I'm talking about.

I'm not talking about complex software. I'm not talking about instances where doctors are asked to learn an entirely new records management or scheduling system. I'm not talking about the type of systems where you have to interrupt your day with an extra training session on how to navigate the interface.

I'm talking about the most basic, bare minimum interactions with security systems that every other person in every other industry has absolutely no issue with, but for some reason doctors refuse to accept. I'm talking about stuff as simple as swiping your ID badge on a reader to gain access to restricted areas. I'm talking about not using work computers to look at porn. I'm talking about basic awareness when it comes to not disclosing sensitive information to a random person in the hallway.

Another commenter brought up the number of passwords as a complaint. Again, I'm sympathetic to this. This is why one of my major areas of focus is implementing SSO solutions to cut down on the number of passwords that users have to remember. Except in one instance we had delays rolling out SSO not because the system was complicated to use, but because doctors complained that they didn't like the color of the SSO UI. They insisted it be blue rather than yellow and wanted to scrap the entire project because of it. That's the type of resistance I'm talking about.

These aren't difficult or complex things. We are talking about highly educated, highly paid individuals handling highly sensitive information. They should be held to higher standards, not treated like children just because they work long hours.

Speaking of working long hours, the second half of your post is just a minor glimpse of the elitism I'm referring to. Are you under the impression that medicine is the only profession in which people experience burnout? Do you think that only doctors have to deal with constantly changing work environments and the never-ending cycle of evolving technology?

Every profession deals with these things. Lawyers, accountants, bankers, social workers, police officers, and educators are just examples of professions that have similar or higher burnout rates than doctors. Every single one of these also has to deal with immense amounts of bureaucratic processes, regulations, and inefficient software that is constantly changing and affecting their daily workflow. And yet in my years of consulting I have never met a group that was as egotistically opposed to the use of technology as doctors are. Even investment bankers, which tend to be the most egotistical assholes with an attitude of "I make millions of dollars a day for this company, I don't have to listen to you puny IT people", still don't hold a candle to the willful ludditism of doctor's I've worked with.

Re: A billion medical images are exposed online

#95

Earlier quoted context omitted.

This seems like a caricature or an exception. Doctors are very aware of HIPAA (and the equivalent in every other country), and the professional and monetary costs of non-compliance. Doctors didn't set up these systems. Doctors didn't expose them to the internet. As the other post said, vendors did. If those vendors couldn't properly communicate the needs, that's their problem. What I think is a more rational explanat…

It may seem so, but I’ve done security consulting work for 10+ of the largest hospital chains and insurance providers in the country and I can assure you it isn’t an exception. Doctors don’t care about HIPAA (“that’s legal’s job”). They don’t care about the company’s finances (unless it’s a small private practice, “that’s the accountant’s job”). Some of the complexity is caused by the software itself being complex, y…

Sounds like someone has it in for doctors.

I worked in healthcare IT for years, before than going to medical school, and now in residency. My experience really does not match yours.

As mentioned earlier in the thread, I will agree that doctors in general are quite resistant to technology because they have been fucked over by implementations that are more concerned with billing and regulatory than either better patient care or improving physician quality of life/workload.

Most medical facilities use badges for access. I think what you’re calling resistance is increased scrutiny, something you might not be used to dealing with in other fields.

Based on your sweeping generalizations tinged with bitterness I can only imagine most doctors that have to work with you professionally are going to be a bit on edge. The reaction you’re getting from all these physicians you’re working with is probably related to what I can only imagine is a shitty attitude.

Re: A billion medical images are exposed online

#96

Could this data be anonymized and open-sourced for training diagnostic algorithms? It’s hard to put the genie back in the bottle so why not at least make some use of the images?

In theory, yes. I was working on doing this (for internal data) at a large healthcare system some time ago.

The de-id part was actually really easy since DICOM is a very standardized format and this hospital system had good practices in place to only input certain information about each patient.

Re: A billion medical images are exposed online

#97

Earlier quoted context omitted.

It really applies to every industry -- people push back against things that they see as impediments to their work. Many/most HN visitors are software developers, and if you've worked in a Fortune 500 virtually all of us have gone to war with IT. "Don't they understand that we're special and we need special rights and privileges" etc. And often we have legitimate grievances because often arbitrary, counter-productive,…

Have you worked with doctor's? When I did I'd routinely sit in a room with 10-25 people and wait for hours on a doctor to show up to a meeting they'd schedule onlu to be told by a secretary he was busy. Everyone I know who has worked with doctor's has similar stories. This hasn't happened to me with any other position in any other organization, including vice presidents of Fortune 500 companies.

I'm not claiming that doctors are interchangeable with other careers. Doctors often have higher priorities that can absolutely intrude at any time: An emergent medical situation is far more important than a meeting about document retention, for instance. For that VP, or CEO for that matter, those meetings are a major priority of their job.

Instead I was pointing out that there are many fields where people resist IT-style policies, and many special snowflakes that believe (often rightly) that they are a unique situation.

Often in tales like this the worst scenarios arise because some people aren't equipped at managing expectations and communicating reasons and benefits. If yet another vendor comes in with yet another system and yet another set of demands and obligations, to someone who sees it as a hindrance to their work product there will be resistance. Understanding and communicating in a way that, to use lame corporate speak, aligns goals makes things go much smoother.

Re: A billion medical images are exposed online

#98

Earlier quoted context omitted.

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

I am horrified... at how plausible this sounds. Like many IT people, I google the heck out of a medical condition when I see doctors. Once I must have asked enough pertinent pointed questions that the doctor asked with a mix of sincerity AND condescension, “have you ever worked in a medical field?” No but like any curious individual I utilize the systems accumulating all human knowledge at our fingertips to inform my…

99% of the time doctors are annoyed by anyone who has researched and informed themselves on what their medical problems might be. The notable exception is when the doctor has repeatedly failed to accurately determine what's wrong. Then you're "allowed" to bring up your own ideas. I can't wait until the majority of work done by doctors is replaced with a small shell script. They will fight VERY hard to stop that from happening, and they're rich. So it will be a tough fight.

Re: A billion medical images are exposed online

#99

Earlier quoted context omitted.

In another company, we tried rolling out RFID badges that could be scanned at any workstation to log doctors in rather than passwords. This proved to be too inconvenient for doctors as well, and the system had to be rolled back within a month because doctors kept forgetting to keep their badge with them and would then throw a hissy fit because they wanted to go back to the old system where all workstations were perma…

In contrast to your experience, all VA physicians are obligated to use an ID card with a chip in order to login.

Indeed, other hospital chains do as well, which is why we viewed it as a good option and went down that path to begin with. In the case I'm referring to, everyone at the hospital already had badges and the thought was that removing password requirements and using the badges that everyone already had as a login would work well.

It didn't work, not because of technical issues, but because we didn't anticipate the high number of doctors that apparently had lost their badges and had never faced consequences for it (the culture at this hospital was "oh you forgot your badge? no worries, I'll just open the door for you"). When we then asked the medical staff to keep better track of their badges (not just for the login system but also because of general campus security) we received incredible pushback, and that's when we had to roll back the program.

IME, and as evidenced by the VA using a similar system as you mentioned, doctors are perfectly competent enough and able to use these systems and do just fine once they get used to the system. The issue is that they put up a fight more than anyone else when introducing something new, and oftentimes IME the new system never gets a chance before it's shot down.

Re: A billion medical images are exposed online

#100
post #4

Earlier quoted context omitted.

NHS has plenty of data breaches.

"anyone with an internet connection and free-to-download software to access over 1 billion medical images of patients across the world." Breaches on that scale?

images != people. NHS had a 150k patients breach not long ago. And many other of smaller scale in the thousands. It's definitely not an organization renowned for being good handling patient data.

On top of that, they made recently a deal to share with Amazon and Google. They clearly don't care.

Also, it's a monopoly. You can't chose something else. And never mind the politics of both the administration (who chose them to be in power?) and political pressure from whatever party is in control of funding. Pass.

Post reply on HN