Live data from Hacker News

A billion medical images are exposed online

techcrunch.com

181–190 of 201 posts

Re: A billion medical images are exposed online

#181
post #163

Earlier quoted context omitted.

Sure but if it become annoying then most people, including me will choose convinience over security every time. That's where I critize security professional. They often disregard this end user pain. You have to find frictionless solution and shouldn't impact their productivity.

As recently as maybe 20 years ago we learned a lot patient infection in hospital was caused by patient-to-doctor-to-patient transfer. Things like disposable gloves and hand cleaning stations at every bed were resisted by doctors initially as being over the top. Now they are ubiquitous once the benefits were proven. Maybe the same approach for IT as for germ security can be demonstrated, and that everyone needs to par…

Or maybe make it easier, less annoying to use.

Re: A billion medical images are exposed online

#182

Earlier quoted context omitted.

This is why in starting up my own little IT services company I'm planning on not serving medical clients. "HIPAA? I'm sure we're just fine, and no you can't take away my Windows 7 PCs."

I get the feeling big law is just as bad.

In my experience with biglaw (a single top 10 firm), their IT and in particular information security was top notch. Having a lot of available capital to work with probably helps.

Re: A billion medical images are exposed online

#183
post #88

Earlier quoted context omitted.

Yes, I’m sure they have their reasons and their own priorities and constraints. Just like the doctors who decline to use basic authentication. See my point? Hospitals are notorious for passing the buck around. As it happens there is a single web property for accessing a remote desktop, not multiple systems, and the hospital down the road funded by the same entity has implemented TOTP authentication.

Curious, why would a doctor decline to use basic password auth?

> Curious, why would a doctor decline to use basic password auth?

I'm not a (medical) doctor and I decline to use password authentication as well. Give me public key access or fuck off.

Re: A billion medical images are exposed online

#184

Earlier quoted context omitted.

That is why plenty of medical systems have an override in place for emergency situations allowing you to bypass all but the most basic authentication and segmentation. You will usually need to explain your override afterwards.

I'm not talking about emergencies - I'm talking about situations where someone comes in for a "routine" blood test, but it shows they have cancer, and you as a doctor end up blaming yourself for not spending 10 minutes more to look at the test the day before, and the most obvious thing to blame for not having those 10 extra minutes is anything in IT that slows you down and takes those 10 minutes away. Even if it's ir…

This. I don't know enough about the econo-political situation gp mentions, but the idea that doctors are somehow irresponsible for not wanting to enter passwords is a perfect example of a usability fail. It's too easy to gloss over - "it's only a password". But think of your own situation: ever been a bit frustrated when your desktop/laptop times out and locks, just as you were about to start typing again? Objectively it takes seconds to enter your password again. Subjectively it's broken your flow. Convenience has a non-linear decay curve. Now take that out of your work environment, where your normal context is sitting/standing at a desk. And put it in a hospital where a doctor is mobile by default: on their rounds/attending to patients/whatever.

The answer isn't "make the doctors change and accept the inconvenience". The answer is "find a solution that actually helps them rather than hindering".

Yes, there will always be recalcitrant users who stubbornly refuse to use systems irrespective of usability and/or utility. But I'd wager most aren't in this category. Most will be only too ready to use something that actually helps them.

If passwords are a barrier to use, find a better solution.

Re: A billion medical images are exposed online

#185

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

If a physicians office installed something like this on their own I'd be horrified.

Re: A billion medical images are exposed online

#186

Earlier quoted context omitted.

I'm not talking about emergencies - I'm talking about situations where someone comes in for a "routine" blood test, but it shows they have cancer, and you as a doctor end up blaming yourself for not spending 10 minutes more to look at the test the day before, and the most obvious thing to blame for not having those 10 extra minutes is anything in IT that slows you down and takes those 10 minutes away. Even if it's ir…

This. I don't know enough about the econo-political situation gp mentions, but the idea that doctors are somehow irresponsible for not wanting to enter passwords is a perfect example of a usability fail. It's too easy to gloss over - "it's only a password". But think of your own situation: ever been a bit frustrated when your desktop/laptop times out and locks, just as you were about to start typing again? Objectivel…

The computing industry is quite unique in that we are so arrogant that we tend to tell everybody else how they should be doing their job, and then add insult to injury by blaming the users for the systems shortcomings.

Re: A billion medical images are exposed online

#187
post #157

Earlier quoted context omitted.

The doctor is not the customer. The doctor and security personnel are coworkers in a business where the customer is the patient who is being treated and who's sensitive data is being stored. It is indeed the shared responsibility of the security team to keep in mind that the customer requires quality medical care, and security should not interfere with that. Similarly, it is also the shared responsibility of the doct…

So the doctor has to ensure security in addition of treating patient? Why do we need security professional then ?

If people are supposed to look after their own health, why do they need doctors?

Re: A billion medical images are exposed online

#188

Earlier quoted context omitted.

I get the feeling big law is just as bad.

In my experience with biglaw (a single top 10 firm), their IT and in particular information security was top notch. Having a lot of available capital to work with probably helps.

Which firm?

Re: A billion medical images are exposed online

#189

Earlier quoted context omitted.

Just curious, but why are you using "-L"? Without it just doing -o to an .html opens fine in the browser for reading. I feel like I'm missing something here.

From the man page -L, --location (HTTP) If the server reports that the requested page has moved to a different location (indicated with a Location: header and a 3XX response code), this option will make curl redo the request on the new place. If used together with -i, --include or -I, --head, headers from all requested pages will be shown. When authentication is used, curl only sends its credentials to the initial ho…

I read the man page and I understand what -L does, but I still don't understand why the -L is needed in this particular case when the request works ok without it.

Is the user only wanting to curl from the original page and any redirects are considered bad?, etc.

Re: A billion medical images are exposed online

#190
I've contracted for some medical orgs and I can tell you there is plenty of blame to go around, and most of it belongs on the heads of administration (C-levels), who let doctors get away with things they shouldn't while at the same time underfund and generally shit on their IT departments. IT directors without the backbone or knowledge to speak boardroom and convince the C-levels to have their back are failing, doctors are failing, and administrations are failing when it comes to IT, add all that to a complex regulatory scheme in which some vendors are basically immune to being dropped, overworked doctors and nurses because congress keeps them artificially scarce, and it's a recipe for disaster.

To those making excuses for doctors, you should be ashamed of yourselves. There is enough blame for everyone in this case.

Post reply on HN