Live data from Hacker News

FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

krebsonsecurity.com

321–330 of 357 posts

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#321
post #10

Bad health IT is a public health issue. Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.

The regulatory environment in the Heath Care industry is based on the premise that any change risks patient safety. Changing a single line of CSS literally takes 6 months to test, validate, document and get approval for, so everyone's afraid to change a thing. You can't automate anything because the current process survived 7 audits and regulatory is afraid changing it might raise an alarm. You'd be stunned at the nu…

> The regulatory environment in the Heath Care industry is based on the premise that any change risks patient safety.

I understand your point, but surely, simply REPORTING the current OS patch level is not, in and of itself, a change risk?

“Sunlight is the best disinfectant”, and all that.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#322
InsurTechnix's founders experienced the effects of cyber attacks on multiple hospitals at our previous start up. That's one of the reasons we founded InsurTechnix.

Here's an introduction to our ransomware report: https://youtu.be/2yDqp34JN9k

If any hospital CISO and/or IT admin would like a three month free trial - even just to get through the current attacks - please reach out.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#323

Earlier quoted context omitted.

To fix medical service affordability we need to bring down the cost of the services instead of expecting significantly more efficient insurance plans. We can’t insure away high costs. They just pass through the costs via premium and deductible increases. Even if health insurers were nonprofits that would only directly save us 5%. High deductibles encouraging shopping around but price discovery is very limited as even…

Step 1. Ban private equity and investment firms from owning healthcare providers.

From my experience, the doctors that own the providers and private equity have the same motivations and resulting actions.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#324
post #308

Earlier quoted context omitted.

I registered an account to comment because this made me laugh. One does not simply export images from medical systems. It takes a ton of effort and clicking to get patient images out of most PACS systems IF YOU ARE LUCKY. DICOM images are often high bit-depth JPEG2000 and are hard to get access to because of the way PACS systems and medical devices store data. Screen scraping DICOMs would take ages as each DICOM can…

That sounds challenging to deal with. What you are describing reminds me of proprietary backend banking, military systems and most internet-of-things that have custom firmware. Maybe I was hoping too much for hospitals to have pushed for more compatible standards. Do you have a theory as to why they have not evolved? Lack of vendor competition due to certification costs?

In my experience when I worked for a medical image analysis startup some major vendors such as Philips, Siemens, and GE are developing analysis tools in house as value adds for their existing customer channels and there is no reason for them to open themselves up to competition by increasing interoperability. Hospitals are happy with waiting for your next startup idea to become a feature in their next MRI purchase from the same vendor they have had a relationship with for years.

One way I can think of to disrupt this process is partnering with a new medical device company which is accelerating sales to hospitals. Last time I had this conversation the promising ones were all Chinese, wanted investment solely for development of algorithms under Chinese jurisdiction as part of terms of investment, and carried all the usual IP theft and legal risks you can imagine. Israel has some med tech startups too but they wanted to source talent from within their country and their due diligence seemed to be more of an intelligence gathering operation.

I moved on to working in finance. I don't know what ended up happening to that startup. I left after the paychecks stopped coming.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#325

Earlier quoted context omitted.

Because of the confusion, death and fear it creates. It's a hospital, remember?

Perhaps you should remember your own argument, or at least decide what it is, before continuing with the condescending attitude. First it was terrorism because it's deliberate; now it's terrorism because it creates confusion, death and fear. Here's just one example that checks all those boxes and is, of course, not terrorism: https://en.wikipedia.org/wiki/Mercy_Hospital_shooting

Is this just pedantry? I'm making room for an interpretation, that's all. Hospitals are a special case. No reason to read any attitude into it. And no reason for a deliberately argumentative response.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#326
Mikko Hypponen and F-Secure will get revenge.

> Public message to ransomware gangs: Stay the f away from medical organizations. If you target hospital computer systems during the pandemic, we will use all of our resources to hunt you down.

https://nitter.net/mikko/status/1240225603565105152?lang=en

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#327

Earlier quoted context omitted.

You're talking about the mass murder of easily 20 million people.

I don't condone it. I'm saying it's been discussed.

Oh! I'm really sorry about that, my mistake.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#328
post #141

Earlier quoted context omitted.

That’s a naive position to take. Hospitals employ actual people who need to access information from mobile devices, home, etc. They should, however, require those devices are locked down and connected via secure means.

If you're putting the words "secure" and "computer" in the same sentence, you've already lost. There is no such thing as computer security.

@coldpie: ‘If you're putting the words "secure" and "computer" in the same sentence, you've already lost. There is no such thing as computer security.’

We should borrow an idea from nature and not create a monoculture. That way when a ‘computer virus’ comes along, it won't run rampant through the ecosystem.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#329
post #324

Earlier quoted context omitted.

That sounds challenging to deal with. What you are describing reminds me of proprietary backend banking, military systems and most internet-of-things that have custom firmware. Maybe I was hoping too much for hospitals to have pushed for more compatible standards. Do you have a theory as to why they have not evolved? Lack of vendor competition due to certification costs?

In my experience when I worked for a medical image analysis startup some major vendors such as Philips, Siemens, and GE are developing analysis tools in house as value adds for their existing customer channels and there is no reason for them to open themselves up to competition by increasing interoperability. Hospitals are happy with waiting for your next startup idea to become a feature in their next MRI purchase fr…

Thankyou for that explanation. I suppose that none of this should surprise me.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#330

Earlier quoted context omitted.

Perhaps you should remember your own argument, or at least decide what it is, before continuing with the condescending attitude. First it was terrorism because it's deliberate; now it's terrorism because it creates confusion, death and fear. Here's just one example that checks all those boxes and is, of course, not terrorism: https://en.wikipedia.org/wiki/Mercy_Hospital_shooting

Is this just pedantry? I'm making room for an interpretation, that's all. Hospitals are a special case. No reason to read any attitude into it. And no reason for a deliberately argumentative response.

Come on. I already posted a link showing that hospitals are not a special case, remember? That's so obvious to not merit discussion.
Post reply on HN