Live data from Hacker News

Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

csoonline.com

11–20 of 50 posts

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#12
Exactly what happened? Most hospitals use proprietary electronic medical record systems. These are layered constructs of different networks requiring different passwords and VPNs for their different functions. Is there an actual url that one can visit to verify this? Did the internet archive capture this in a snapshot I can see? Or is this smack that a neighboring hospital is pushing to capture market share in this era of declining reimbursements and increasing regulation?

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#13
post #12

Exactly what happened? Most hospitals use proprietary electronic medical record systems. These are layered constructs of different networks requiring different passwords and VPNs for their different functions. Is there an actual url that one can visit to verify this? Did the internet archive capture this in a snapshot I can see? Or is this smack that a neighboring hospital is pushing to capture market share in this e…

Probably locked down the physical machines at the hospital.

>Most hospitals use proprietary electronic medical record systems. These are layered constructs of different networks requiring different passwords and VPNs for their different functions.

That's idealistic. Usually they're giant pieces of shit.

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#14

so who's gonna serve the HIPAA violation sentence?

HIPAA does require a lot of security. Having been a HIPAA architect, in reality no one in the industry cares since few are ever even accused of anything much less convicted. It's a toothless gums law.

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#16
post #5

Earlier quoted context omitted.

Well, there are plenty provisions under the security chapter, funnily enough now that I look at it again (been long time) it seems both 'accountability' (tracking every media in and out) and 'protection from malicious software' are not listed as required. duh. The emergency mode operation plan is however listed as required, and this place was basically shut for a week. I remembered it being more stringent that what i…

Yes, I'd love for HIPAA to say: if we're talking about a medical centre, you've got to be able to snapshot and reimage within X hours with data loss of less than Y hours. One can dream...

Part of the problem is that HIPAA must be easy for small private practices as well as massive hospitals to follow.

Another standard may be needed for the larger businesses.

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#18
post #11

I'm sure they'll just pass the cost (either of the ransom, or of the missed profits) onto the patients.

..rather than, say, not pay nurses their salaries for a while?

Heaven forbid that top executives ever have to take a pay hit.

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#19
post #16
post #5

Earlier quoted context omitted.

Yes, I'd love for HIPAA to say: if we're talking about a medical centre, you've got to be able to snapshot and reimage within X hours with data loss of less than Y hours. One can dream...

Part of the problem is that HIPAA must be easy for small private practices as well as massive hospitals to follow. Another standard may be needed for the larger businesses.

Totally agree, but in 2016 that doesn't take much: spin up two instances in different AWS datacenters and fail between them and you have Disaster Recovery. Regularly operate in each datacenter and you have Sustained Resiliency. A small business probably won't have staff to maintain such a solution but surely this is a space for a nice niche startup?

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#20

The internet of things... what could possibly go wrong?

Very good point.

It reminds me a comment from the Usenet, a long ago: "if your VCR is still blinking 12:00 then Linux is not for you".

Most people playing with technology don't know what they're doing. Giving them more power means giving them more danger.

Post reply on HN