Earlier quoted context omitted.
I think the obvious solution would be to invest in a new open-source end-to-end infrastructure that could be thoroughly audited then implemented by hospitals everywhere. Of course, that would need a sizeable investment of both money and time, but it would almost definitely be more efficient than updating one component at a time.
My armchair analysis of the obvious solution is to airgap all these systems. Perhaps this would require some new infrastructure in hospitals, but it would add a very difficult-to-penetrate layer.
FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
261–270 of 357 posts
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#262Earlier quoted context omitted.
-
> the unlawful use of violence and intimidation, especially against civilians, in the pursuit of political aims. From Oxford dictionary. Terrorism absolute includes the political struggle. The point is that terrorism uses violence and intimidation to further its goals and that it has no legal base for it.
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#263Bad health IT is a public health issue. Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.
The regulatory environment in the Heath Care industry is based on the premise that any change risks patient safety. Changing a single line of CSS literally takes 6 months to test, validate, document and get approval for, so everyone's afraid to change a thing. You can't automate anything because the current process survived 7 audits and regulatory is afraid changing it might raise an alarm. You'd be stunned at the nu…
That being said, most commercial software seems to be way worse. There was the article the other month of a windows 10 machine automatically updating while a patient was being operated on forcing them to be kept under for an extra few hours.
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#264Earlier quoted context omitted.
The regulatory environment in the Heath Care industry is based on the premise that any change risks patient safety. Changing a single line of CSS literally takes 6 months to test, validate, document and get approval for, so everyone's afraid to change a thing. You can't automate anything because the current process survived 7 audits and regulatory is afraid changing it might raise an alarm. You'd be stunned at the nu…
I think the obvious solution would be to invest in a new open-source end-to-end infrastructure that could be thoroughly audited then implemented by hospitals everywhere. Of course, that would need a sizeable investment of both money and time, but it would almost definitely be more efficient than updating one component at a time.
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#265Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#266Earlier quoted context omitted.
If you run your infrastructure on a “computer” directly connected to the Internet such that it puts hospitals and power grids in danger, then maybe you're in the wrong profession.
That’s a naive position to take. Hospitals employ actual people who need to access information from mobile devices, home, etc. They should, however, require those devices are locked down and connected via secure means.
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#267And no networked computers for processing anything important.
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#268I take this opportunity to complain about regulatory capture and the medical cartels. Their constant irresponsibility (opioid epidemic, coronavirus response) affects everyone. Yet they still are paid more than any other industry.
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#269Earlier quoted context omitted.
My armchair analysis of the obvious solution is to airgap all these systems. Perhaps this would require some new infrastructure in hospitals, but it would add a very difficult-to-penetrate layer.
Yes, but now consider how important remote doctor visits are right now... it's a really hard problem.
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#270It is happening: https://www.bloomberg.com/amp/news/articles/2020-10-28/u-s-h... Patients are being turned away: Wyckoff Hospital hit by computer virus https://www.reddit.com/r/nyc/comments/jju0rp/wyckoff_hospita...