Live data from Hacker News

A billion medical images are exposed online

techcrunch.com

151–160 of 201 posts

Re: A billion medical images are exposed online

#151
post #150
post #128

Earlier quoted context omitted.

Its the IT job to provide security without having to inconvenience the user. you can't just add extra layer of inconvenience for the sake of security. Your ultimate goal should be to provide security without adding additional inconvenience to the user or without having the user to notice it at all.

> Its the IT job to provide security without having to inconvenience the user. you can't just add extra layer of inconvenience for the sake of security. Your ultimate goal should be to provide security without adding additional inconvenience to the user or without having the user to notice it at all. We trade convenience for security every single day. Ever get locked out of your house because you forgot your keys? Wh…

>We trade convenience for security every single day

Which is totally sucks.

>Ever get locked out of your house because you forgot your keys? Why is that level of inconvenience (requiring keys on doors) okay

I would not say that is okay, that is sucks too

Re: A billion medical images are exposed online

#152
Knock. Knock. The average human body is rather boring. especially for the 3/4ths that outside the young adult age range of 15-35.

As to insurance company exposure, almost all of these imaging procedures were paid by health insurance companies and already know all your ailments.

Re: A billion medical images are exposed online

#153
post #149
post #148

Earlier quoted context omitted.

Hey, thanks for the condescension. You know what else our job as "security personel" (sic) is? Other than literacy, it's matching controls to risk. The guy who talked about "people dying" was a urologist; I can assure you the no one was going to die in his office because of passwords. So, yes, we should reduce friction where it's appropriate, but unless you understand the actual risk model, maybe you should keep your…

"people dying" might be exaggerated but nonetheless because of the password he is inconvenienced. So you have to come up with different method. For the security personal, Dr is the customer, customer is king.

The doctor is not the customer. The doctor and security personnel are coworkers in a business where the customer is the patient who is being treated and who's sensitive data is being stored.

It is indeed the shared responsibility of the security team to keep in mind that the customer requires quality medical care, and security should not interfere with that. Similarly, it is also the shared responsibility of the doctor to keep in mind that the customer also requires that their data remain secure, and their ludditism should not interfere with that, either.

Re: A billion medical images are exposed online

#154
post #115

Earlier quoted context omitted.

I have had a doctor tell me that his time was too important to waste it typing passwords. I had another one tell me, quite dramatically, "someone could die" while he was typing in a password. It's a profession where many have an "interesting" perspective on information protection. I have tons of tragicomic security stories from dealing with health care providers.

And they are right. Passwords are probably the wrong thing. Give the doctors a hardware token, a smartcard (and fit smartcard readers to everything doctors might expect to use) or use biometrics. Might some doctors leave the smartcard in the reader for a PC they often use, then walk away? Yes, yes they might, and that is a behaviour you can start fighting with peer pressure, but doctors are right to think passwords a…

>And they are right. Passwords are probably the wrong thing. Give the doctors a hardware token, a smartcard (and fit smartcard readers to everything doctors might expect to use) or use biometrics.

This is spot on and in most cases this is the way most hospitals are moving, particularly by using the already-assigned ID badges as RFID tokens. But as I mentioned in a couple of other comments farther down, I have experienced situations in which even this is something that doctors refuse (in one case, because they were upset that we were asking them to keep their ID badge with them, which they apparently had a problem with doing).

It's the most frictionless solution I've seen in widespread adoption and probably the least prone to pushback, but that doesn't mean there's no pushback, which is the unfortunate point of my original comment at the top of the thread.

Re: A billion medical images are exposed online

#155
post #149

Earlier quoted context omitted.

"people dying" might be exaggerated but nonetheless because of the password he is inconvenienced. So you have to come up with different method. For the security personal, Dr is the customer, customer is king.

The doctor is not the customer. The doctor and security personnel are coworkers in a business where the customer is the patient who is being treated and who's sensitive data is being stored. It is indeed the shared responsibility of the security team to keep in mind that the customer requires quality medical care, and security should not interfere with that. Similarly, it is also the shared responsibility of the doct…

Said much better than I could.

Re: A billion medical images are exposed online

#156

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

> patient safety is more important than security

Ultimately these are linked; imagine ransomware blocking a medical device necessary to save lives, or tampering with settings of an x-ray machine.

Re: A billion medical images are exposed online

#157
post #149

Earlier quoted context omitted.

"people dying" might be exaggerated but nonetheless because of the password he is inconvenienced. So you have to come up with different method. For the security personal, Dr is the customer, customer is king.

The doctor is not the customer. The doctor and security personnel are coworkers in a business where the customer is the patient who is being treated and who's sensitive data is being stored. It is indeed the shared responsibility of the security team to keep in mind that the customer requires quality medical care, and security should not interfere with that. Similarly, it is also the shared responsibility of the doct…

So the doctor has to ensure security in addition of treating patient? Why do we need security professional then ?

Re: A billion medical images are exposed online

#158
post #157

Earlier quoted context omitted.

The doctor is not the customer. The doctor and security personnel are coworkers in a business where the customer is the patient who is being treated and who's sensitive data is being stored. It is indeed the shared responsibility of the security team to keep in mind that the customer requires quality medical care, and security should not interfere with that. Similarly, it is also the shared responsibility of the doct…

So the doctor has to ensure security in addition of treating patient? Why do we need security professional then ?

[deleted]

Re: A billion medical images are exposed online

#159
post #157

Earlier quoted context omitted.

The doctor is not the customer. The doctor and security personnel are coworkers in a business where the customer is the patient who is being treated and who's sensitive data is being stored. It is indeed the shared responsibility of the security team to keep in mind that the customer requires quality medical care, and security should not interfere with that. Similarly, it is also the shared responsibility of the doct…

So the doctor has to ensure security in addition of treating patient? Why do we need security professional then ?

Yes, everyone has to participate in ensuring security; how completely divorced from reality do you have to be to think otherwise. And we need security professionals to remind everyone that security is important and we all have to be part of ensuring it.

Re: A billion medical images are exposed online

#160

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

Physician here (neuroradiologist) and after working at several hospitals in the US and abroad, let me be really clear about this:

1) I have never seen a health care organization ANYWHERE where the physicians determine the IT policy (including and especially the IT security policy).

2) Universally, healthcare organizations use the bloated garbage that gets passed off as EMRs and affiliated garbage software. None of this is up to physicians. It's up to the administrative and bureaucratic parasites that have infested healthcare at every level and based largely (I assume) on crony relationships, because it's certainly not based on competence.

3)Healthcare IT is the most abysmal software anyone anywhere has ever devised to perform any task. Systems like EPIC are bloated, barely functional trash that systems have wasted billions of dollars on. The various components of departmental IT do not co-ordinate with one another, crash on a daily basis, are not fit for purpose and would embarrass engineers in any other industry.

It comes as no surprise that security for these systems is piss-poor, just like everything else about these systems. Blaming doctors for this administrative mess, whilst not unexpected, is disingenuous at best (of course this is what healthcare administration excel at - making a mess and blaming physicians).

Post reply on HN