Live data from Hacker News

A billion medical images are exposed online

techcrunch.com

111–120 of 201 posts

Re: A billion medical images are exposed online

#113
post #105

Earlier quoted context omitted.

I'm sympathetic to this, and in other threads I would usually be the first person coming to the defense of doctors and harping on how complex and terrible EMR and other medical software is. But that's not what I'm talking about. I'm not talking about complex software. I'm not talking about instances where doctors are asked to learn an entirely new records management or scheduling system. I'm not talking about the typ…

> Except in one instance we had delays rolling out SSO not because the system was complicated to use, but because doctors complained that they didn't like the color of the SSO UI. They insisted it be blue rather than yellow and wanted to scrap the entire project because of it. That's the type of resistance I'm talking about. Is it really the hill you want to die on? Just change the damn widget color if it is so impor…

Ha, I agree! We were willing, able, (and did) change the color relatively easily. I'm just using it as an example of the type of pushback I've gotten. The doctors were the ones willing to die on that hill; they wanted to cancel the entire project and their reasoning was the color, and they didn't even care to hear that it could easily be changed. In that case it really did feel like resistance for resistance's sake.

Re: A billion medical images are exposed online

#114

Earlier quoted context omitted.

Indeed, other hospital chains do as well, which is why we viewed it as a good option and went down that path to begin with. In the case I'm referring to, everyone at the hospital already had badges and the thought was that removing password requirements and using the badges that everyone already had as a login would work well. It didn't work, not because of technical issues, but because we didn't anticipate the high…

Physicians sporadically not having badges sounds like an accreditation-threatening problem, for what it’s worth. (It depends on the institution’s self-stated standards, however.)

I'm not surprised to hear that. When I rolled off that project, the login system project was slowed down/put on hold while solving the badge situation was being prioritized. We definitely opened up a can of worms when we reported to leadership that the project was delayed because people weren't carrying their badges with them.

Re: A billion medical images are exposed online

#115
post #88

Earlier quoted context omitted.

Yes, I’m sure they have their reasons and their own priorities and constraints. Just like the doctors who decline to use basic authentication. See my point? Hospitals are notorious for passing the buck around. As it happens there is a single web property for accessing a remote desktop, not multiple systems, and the hospital down the road funded by the same entity has implemented TOTP authentication.

Curious, why would a doctor decline to use basic password auth?

I have had a doctor tell me that his time was too important to waste it typing passwords. I had another one tell me, quite dramatically, "someone could die" while he was typing in a password. It's a profession where many have an "interesting" perspective on information protection. I have tons of tragicomic security stories from dealing with health care providers.

Re: A billion medical images are exposed online

#116

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

On the other hand(and I'm really not trying to excuse this behaviour) some doctors are almost daily in situations where "if I had a little bit more time or did this thing a day earlier maybe the patient would still be alive". If you run into those kinds of situations frequently, then obviously any slowdown(like having to remember or type in a password) is obviously stupid. And only they understand it, no IT employee ever would.

Re: A billion medical images are exposed online

#117
post #95

Earlier quoted context omitted.

It may seem so, but I’ve done security consulting work for 10+ of the largest hospital chains and insurance providers in the country and I can assure you it isn’t an exception. Doctors don’t care about HIPAA (“that’s legal’s job”). They don’t care about the company’s finances (unless it’s a small private practice, “that’s the accountant’s job”). Some of the complexity is caused by the software itself being complex, y…

Sounds like someone has it in for doctors. I worked in healthcare IT for years, before than going to medical school, and now in residency. My experience really does not match yours. As mentioned earlier in the thread, I will agree that doctors in general are quite resistant to technology because they have been fucked over by implementations that are more concerned with billing and regulatory than either better patien…

Also in security for a long time, spending a lot of that with hospitals and healthcare organizations. My experience matches the parents. Your points are very valid but doctors can definitely be dicks as well.

Re: A billion medical images are exposed online

#118
post #67

Earlier quoted context omitted.

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

It goes both ways. I keep telling the IT people at my hospital to stop using SMS 2-factor and they blow me off and treat me like an idiot. Anyway, ‘Doctors’ are a pretty diverse bunch, and most of them aren’t arrogant porn-fiends.

Porn fiends? Doctors don't have the time. But you must admit that the profession brings out some very arrogant traits. They usually express the pointof view that they learned everything they needed to at med school and any new outside information is suspect and not important including IT security.

Re: A billion medical images are exposed online

#119
post #70

Earlier quoted context omitted.

Yep. Never blame users for raging at the system until you understand the system as well as they do. Techies have it easy: they only have one job and that’s all they ever do. It looks very different from the other side. (Protip: The key to delivering successful software is not to learn programming, it is to learn your users.) (Oh, and good luck with your medical studies; world needs good Renaissance [Wo]Men now more t…

> (Oh, and good luck with your medical studies; world needs good Renaissance [Wo]Men now more than ever.) Why now more than ever?

Growing complexity. Struggling scalability. Overspecialization. Balkanization. Failures of accountability.

OP’s firsthand observation on the awful state of programmer-produced medical software, the original linked article, and notoriously lethal software disasters such as Therac-25 provide frightening cases in point. These things are not accidents. Programmers who only know how to program are as much use as managers who only know how to manage. And this world has far too many of both.

Look, any idiot can hack teh codez. Learning the problem domain; that’s the hard part. It is also the critical core of the job. Because if you don’t/won’t/can’t understand the problem, how do you possibly expect to solve it?

Especially when that problem space is something as vast, complicated, and utterly unforgiving as millions of people’s healthcare.

Re: A billion medical images are exposed online

#120
post #118
post #67

Earlier quoted context omitted.

It goes both ways. I keep telling the IT people at my hospital to stop using SMS 2-factor and they blow me off and treat me like an idiot. Anyway, ‘Doctors’ are a pretty diverse bunch, and most of them aren’t arrogant porn-fiends.

Porn fiends? Doctors don't have the time. But you must admit that the profession brings out some very arrogant traits. They usually express the pointof view that they learned everything they needed to at med school and any new outside information is suspect and not important including IT security.

“But you must admit that the profession brings out some very arrogant traits.”

Which one? You know we’re also talking about programmers, right?

Post reply on HN