Live data from Hacker News

Hospitals are a weak spot in U.S. cybersecurity

axios.com

11–20 of 166 posts

Re: Hospitals are a weak spot in U.S. cybersecurity

#11
post #2

waiting rooms are a gaping hole. nobody seems to see a problem with blabbing out your final 4 and first,last name when thier at a desk in a room full of whoever walked in and sat down. un protected desktops are another issue, there is a tide of duties and an attacker can pattern the staff and get a good idea when they will have time to do an inside job of some sort.

As with most environments, there’s a lot of trust based in a hospital running successfully. At least they have their own on-site security that’s experienced in taking people down. I continue to believe the real threats are actual insiders and remote attacks. Dunno how far someone will get with a USB key versus sending everyone a plausible email.

You plug in the USB key, then you pull out the USB key.

The physical security layer at alot of hospitals is almost entirely absent, sadly.

Re: Hospitals are a weak spot in U.S. cybersecurity

#13
post #9
post #3

The central IT function in a US hospital also usually has little organizational power and funding. Admissions, radiology, etc, buy whatever hardware and software they want, and the underfunded IT department has to figure it out.

This may vary by hospital, but in general many hospital IT staff tend not to be very good with computers, from my experience. Many are more focused on business/bureaucracy, or maybe they're just unskilled. I don't mean to attack their character, but instead to make the point that some very unqualified people are in charge of very important systems. (Edit: My first job was hospital IT for a few months, and my boss was…

Agreed with this. IT in hospitals is perpetually underfunded and basically a playground for creatures of corporate politics. Between administrative staff who think their medical credentials qualify them to micromanage IT decisions and perpetually under-funded departments I'm actually shocked that their systems aren't regularly crippled or destroyed by malicious entities.

Don't assume your medical data is secure. Systems that conform to HIPAA regulations are just one part of their computing infrastructure, and it's trivial to maliciously access a huge surface area outside of those specific pieces of hardware and software--and once a malicious actor has that access, it's not too hard to cross the gap.

Re: Hospitals are a weak spot in U.S. cybersecurity

#14

Earlier quoted context omitted.

As with most environments, there’s a lot of trust based in a hospital running successfully. At least they have their own on-site security that’s experienced in taking people down. I continue to believe the real threats are actual insiders and remote attacks. Dunno how far someone will get with a USB key versus sending everyone a plausible email.

You plug in the USB key, then you pull out the USB key. The physical security layer at alot of hospitals is almost entirely absent, sadly.

What I meant was that sending everyone an email will get you further with less time/effort than actually going.

Re: Hospitals are a weak spot in U.S. cybersecurity

#15

Earlier quoted context omitted.

As with most environments, there’s a lot of trust based in a hospital running successfully. At least they have their own on-site security that’s experienced in taking people down. I continue to believe the real threats are actual insiders and remote attacks. Dunno how far someone will get with a USB key versus sending everyone a plausible email.

You plug in the USB key, then you pull out the USB key. The physical security layer at alot of hospitals is almost entirely absent, sadly.

or you swap keyboards with a special keyboard [maybe a pineapple?] , or you can swap ethernet patches around.

Re: Hospitals are a weak spot in U.S. cybersecurity

#16

Earlier quoted context omitted.

As with most environments, there’s a lot of trust based in a hospital running successfully. At least they have their own on-site security that’s experienced in taking people down. I continue to believe the real threats are actual insiders and remote attacks. Dunno how far someone will get with a USB key versus sending everyone a plausible email.

>Dunno how far someone will get with a USB key versus sending everyone a plausible email. Insiders still can be threats. There was a machine that was deployed in a hospital for clinical imaging that some rad tech who guessed the administrator password put folding@home on without telling anyone which crippled that machine's ability to perform its function.

> some rad tech who guessed the administrator password put folding@home on without telling anyone which crippled that machine's ability to perform its function.

How incredibly bizarre to do something that dumb for no personal benefit.

Re: Hospitals are a weak spot in U.S. cybersecurity

#17
It's really tough. You have a function which is viewed purely as a cost center; you have a totally porous environment where you're required to admit tons of minimally-verified people into confidential spaces; staff and affiliates need different levels of access from all over the world; there are critical availability demands where temporary denial of service for security reasons is unacceptable; device development is optimized for safety and fault tolerance as opposed to security which isn't ever really tested for; patients need to be able to submit tons of data in myriad forms; there are few central clearing houses for transmitting data so people are all calling each other with minimal validation; etc

Re: Hospitals are a weak spot in U.S. cybersecurity

#18
post #2

waiting rooms are a gaping hole. nobody seems to see a problem with blabbing out your final 4 and first,last name when thier at a desk in a room full of whoever walked in and sat down. un protected desktops are another issue, there is a tide of duties and an attacker can pattern the staff and get a good idea when they will have time to do an inside job of some sort.

Specialist I went to attempted to collect a photograph in the waiting room, as well - "please hold still a second while I take your picture for the doctor", with a webcam sitting atop the counter between us.

Re: Hospitals are a weak spot in U.S. cybersecurity

#19

Earlier quoted context omitted.

>Dunno how far someone will get with a USB key versus sending everyone a plausible email. Insiders still can be threats. There was a machine that was deployed in a hospital for clinical imaging that some rad tech who guessed the administrator password put folding@home on without telling anyone which crippled that machine's ability to perform its function.

> some rad tech who guessed the administrator password put folding@home on without telling anyone which crippled that machine's ability to perform its function. How incredibly bizarre to do something that dumb for no personal benefit.

F@H had value!!!

I do remember an IT admin day that said he ran SETI@Home at a low priority on all machines because detect any problems with a machine (e.g. spyware, crashing, heat problems, etc.)

But 2002 thinking wouldn’t fly in 2019.

Re: Hospitals are a weak spot in U.S. cybersecurity

#20
It seems that hospitals are overly focused on bullshit security frameworks and box-checking, i.e., HITRUST, which in my experience results in many dollars going to consultants with essentially zero tangible improvement in information security. Worse yet, the false sense of security within these hospitals due to having a HITRUST audit report with a bunch of meaninglessness check marks prevents them from actually doing the work of securing information properly. Have worked in health-tech for a number of years.
Post reply on HN