Bad health IT is a public health issue. Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.
You could just have hospitals be required to meet FedRAMP compliance. It is kind of crazy that hipaa compliance isn’t encompassing enough
FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
111–120 of 357 posts
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#112If this attack results in actual loss of life, I firmly believe the US should ensure that there are real-world physical consequences for these criminals. They cannot be described as anything less than the worst humanity has to offer. A failure to respond with meaningful and severe consequences for those responsible (assuming this is attack can be confidently attributed to a particular threat actor) opens the floodgat…
If US citizens die due to this, I am 100% down with bringing the full might of our military down on the state/group that did this. No mercy.
https://en.wikipedia.org/wiki/United_Nations_Security_Counci...
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#113Bad health IT is a public health issue. Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.
If there's a zero day, there's not a lot you can do. NHS got hit so bad because they were running very old Windows versions. A lot of embedded systems have no upgrade paths (MRIs running embedded XP should probably not be on the network at all). Hospitals need full backup machines and with health care costs already through the roof, that will just add more. Even if you have all your order entry machines setup to not…
No way the operator is copying a 5GB+ dicom file to your record in your EMR manually.
You NEED to have the patient name added via modality worklists to reduce errors (ie. add the pt to the MRI software before the scan, and send the scan to the EMR once it's taken).
The worst thing is, this protocol is old and insecure. They just don't have the IT chops at hospitals to handle this.
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#114It is happening: https://www.bloomberg.com/amp/news/articles/2020-10-28/u-s-h... Patients are being turned away: Wyckoff Hospital hit by computer virus https://www.reddit.com/r/nyc/comments/jju0rp/wyckoff_hospita...
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#115This is not what we need in these final chapters of 2020 with COVID cases spiking. > Charles Carmakal, senior vice president for Mandiant, told Reuters that UNC1878 is one of most brazen, heartless, and disruptive threat actors he’s observed over the course of his career. This is what terrorism looks like in 2020. Horrifying, terrifying, disgusting.
Isn't ransomware profit-motivated? I thought with terrorism the goal was fear rather than profit.
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#116Earlier quoted context omitted.
If US citizens die due to this, I am 100% down with bringing the full might of our military down on the state/group that did this. No mercy.
The problem with this is that other bad players within US can "hack" this attempt to blame a state/group that had nothing to do with this. Has happened in the past.
From having some knowledge of some investigations like these (though not on behalf of any government), the investigators and forensics experts are constantly asking themselves "is this a false flag? is this piece of evidence deliberately planted, or an actual mistake?" Investigators obviously want to get the right people and not get the wrong people. And in the case of nation-states, they also have classified information they can use (like from NSA global spying, etc.).
[1] (I shudder at the term "cyber" as much as anyone else reading this, but that pretty much is the official term the government uses.)
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#117This is not what we need in these final chapters of 2020 with COVID cases spiking. > Charles Carmakal, senior vice president for Mandiant, told Reuters that UNC1878 is one of most brazen, heartless, and disruptive threat actors he’s observed over the course of his career. This is what terrorism looks like in 2020. Horrifying, terrifying, disgusting.
>terrorism Isn't ransomware profit-motivated? I thought with terrorism the goal was fear rather than profit.
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#118Earlier quoted context omitted.
Why the assumption that its terrorist and not a state sanctioned attack?
If we're honest, it's neither. It's 1000% profit-orientated.
https://www.coindesk.com/ban-all-ransomware-payments-bitcoin
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#119Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#120Earlier quoted context omitted.
What about management? What about the sysadmins/developers that left a security hole somewhere? Are they held responsible in some way? It's unacceptable that this keeps happening. If you own a safe and it gets broken into every week, do you blame the safe cracker or who built the safe?
Sometimes analogies can be misleading. It's a lot harder to design a secure hospital IT apparatus than a safe. Also, in the event of a safe getting cracked, you'd likely have no recourse against the safe vendor. Safes are designed to present a firewall against tampering, but with sufficient physical access, no safe will stand for long. So your analogy fails two ways: one is that it trivializes the difficulty of the p…
Yeah I agree there.
I'm curious what the surface area could look like. What is the minimum a hospital could operate with? How locked down could things be? Anyone in healthcare care to comment?