Live data from Hacker News

A billion medical images are exposed online

techcrunch.com

121–130 of 201 posts

Re: A billion medical images are exposed online

#121
post #25

Earlier quoted context omitted.

> One of them spends almost as much time on data entry as he does with patients ...then he’s one of the lucky ones! One study found that for every hour a physician spends with a patient, she spends two on processing health records. https://www.jwatch.org/fw111995/2016/09/06/half-physician-ti...

I mean, for every hour I spend writing production code - I spend an hour in agile meetings, and 2 hours chasing down obscure bugs in javascript libraries. Not that many professions are "do visible part of work 100%". Heck, I hear bricklayers need to spend some time mixing cement and getting bricks off the truck, not just scooping mud and sticking bricks. Health records ARE a big part of the product of a doctor. Keepi…

Your analogies would make more sense if you spent 2 hours on documentation for every hour you spent coding or bug finding.

Re: A billion medical images are exposed online

#122
post #93

Earlier quoted context omitted.

I get the feeling big law is just as bad.

I never worked for big law, but medium law is terrible. Partners can just order the IT department to do anything. We had a new head of IT that tried to implement some common sense changes for an organization that handles sensitive data. Basic stuff: Block websites that tend to be malware vectors, don't let users be admins on their own machines, restrict USB storage to certain users, etc. We were forced to override it…

Restricting partners usb access? Restricting websites and restricting install permissions.

Overkill and probably the opposite of what they envision an IT department doing.

Re: A billion medical images are exposed online

#123
post #118
post #67

Earlier quoted context omitted.

It goes both ways. I keep telling the IT people at my hospital to stop using SMS 2-factor and they blow me off and treat me like an idiot. Anyway, ‘Doctors’ are a pretty diverse bunch, and most of them aren’t arrogant porn-fiends.

Porn fiends? Doctors don't have the time. But you must admit that the profession brings out some very arrogant traits. They usually express the pointof view that they learned everything they needed to at med school and any new outside information is suspect and not important including IT security.

In my experience, you are way off base. Doctors can be very arrogant but I've never met someone from another profession who could point me to research articles regarding their proposed plan of action. Doctors at major hospitals are often either a) residents who are in their nth year of leaning post med school, or b) expected to publish at least case study papers regularly or communicate with those that do.

Re: A billion medical images are exposed online

#124
post #67

Earlier quoted context omitted.

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

It goes both ways. I keep telling the IT people at my hospital to stop using SMS 2-factor and they blow me off and treat me like an idiot. Anyway, ‘Doctors’ are a pretty diverse bunch, and most of them aren’t arrogant porn-fiends.

> I keep telling the IT people at my hospital to stop using SMS 2-factor and they blow me off and treat me like an idiot.

Well... yeah. Nobody is sim swapping hospital staff.

It’s not great, but this isn’t a real threat they’re facing.

Re: A billion medical images are exposed online

#125
post #119

Earlier quoted context omitted.

> (Oh, and good luck with your medical studies; world needs good Renaissance [Wo]Men now more than ever.) Why now more than ever?

Growing complexity. Struggling scalability. Overspecialization. Balkanization. Failures of accountability. OP’s firsthand observation on the awful state of programmer-produced medical software, the original linked article, and notoriously lethal software disasters such as Therac-25 provide frightening cases in point. These things are not accidents. Programmers who only know how to program are as much use as managers…

I've never seen a programmer produced medical system.

Do you realize these systems are designed by respected doctors and product managers? They tell the programmers exactly what to do. When something vague comes up the product manager talks to his stakeholders and decides how to proceed. When the project is done the doctor/project manager group go over everything and make changes.

They decide things like how it looks is not as important as making sure you checkmark this section if you need to.

The priority is on reducing errors never on making the experience better for the computer operator (you).

Re: A billion medical images are exposed online

#126
post #95

Earlier quoted context omitted.

It may seem so, but I’ve done security consulting work for 10+ of the largest hospital chains and insurance providers in the country and I can assure you it isn’t an exception. Doctors don’t care about HIPAA (“that’s legal’s job”). They don’t care about the company’s finances (unless it’s a small private practice, “that’s the accountant’s job”). Some of the complexity is caused by the software itself being complex, y…

Sounds like someone has it in for doctors. I worked in healthcare IT for years, before than going to medical school, and now in residency. My experience really does not match yours. As mentioned earlier in the thread, I will agree that doctors in general are quite resistant to technology because they have been fucked over by implementations that are more concerned with billing and regulatory than either better patien…

Why you are resistant is important but you must follow the rules. Bad things beyond your imagination will happen if you click on that email link. The increased scrutiny allows for better patient tracking and care. That needs to be the priority.

Regulatory paperwork and billing are the reason why you are putting in information into the computer. Without these the medical centre closes. Getting the correct information to that department is part of the role.

Re: A billion medical images are exposed online

#127

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

Most business and schools are the same. Ignorance and self importance prevails over common sense!

Re: A billion medical images are exposed online

#128

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

Its the IT job to provide security without having to inconvenience the user. you can't just add extra layer of inconvenience for the sake of security. Your ultimate goal should be to provide security without adding additional inconvenience to the user or without having the user to notice it at all.

Re: A billion medical images are exposed online

#129
post #128

Earlier quoted context omitted.

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

Its the IT job to provide security without having to inconvenience the user. you can't just add extra layer of inconvenience for the sake of security. Your ultimate goal should be to provide security without adding additional inconvenience to the user or without having the user to notice it at all.

Just curious, are you joking, or are you serious?

Re: A billion medical images are exposed online

#130
In 2009 I was building an enterprise medical imaging SaaS for hospitals, and we would constantly come across hospital IT admins who were adamantly against trusting a cloud vendor with their sensitive healthcare data - even one that's audited, security-checked and whose sole responsibility is to take care of these images.

We always thought it was a joke that these guys questioned us, when we knew how bad their internal security practices were. At some point around 2011-2012 we seized on the idea that holding your images inside of the hospital's four walls was a liability for them, and not a point of pride.

So, not at all surprised about this, nor about the complete lack of security practices at many of these healthcare IT vendors.

Post reply on HN