Live data from Hacker News

Hospitals are a weak spot in U.S. cybersecurity

axios.com

101–110 of 166 posts

Re: Hospitals are a weak spot in U.S. cybersecurity

#101
post #95
post #47

Healthcare CIO here. This is true. Healthcare is still using paper fax. It has a 30 year old data interchange format that no one really supports because it's more profitable to lock in customers to your EMR. Healthcare is HORRIBLE about upgrading anything, at changing processes, and technological progress in general. Healthcare is VERY backwards from a tech standpoint. Another problem is that EVERYTHING is custom, we…

I've never understood hating on mumps. 66 vs 72 (c language) It's just shitting on the language for being old without a way to impact it.

It's so much more niche than something more widely used like C that it makes me very suspect.

Re: Hospitals are a weak spot in U.S. cybersecurity

#102
post #71

Earlier quoted context omitted.

Fax is odd, it was a fantastic thing when it first came about, and it has some desirable properties. - It's direct point to point communication (over a network) - The transport network is dedicated and not open to anyone and covered by quite strong laws in many countries - It's easy to see the history of communications - It's easy to see if the other end successfully received something - It's relatively standardized…

- It's easy to see if the other end successfully received something I think this is a biggie. It means your workflow doesn't need to include going back later and checking to see if your document was received, and then trying to send it some different way. You don't have to guess which way the recipient is capable of receiving a message. It's the original e-mail. ;-)

somewhat ironically, the fax will be captured in digital form, some "middle" person will read it, then work out who it is for, then email it to those concerned / attach it to a patient record.

Re: Hospitals are a weak spot in U.S. cybersecurity

#103

Earlier quoted context omitted.

Does Epic use MUMPS? I know a lot of professional nurses and the rancor around Epic is off the charts.

Backend is all MUMPS. Frontend was for a long time coded in Visual Basic 6. VB6/MUMPS stack is... not ergonomic to code in. Epic is easy to hate (it's everywhere), and for good reason. However, the alternatives are not obviously better unless there's been some radical innovation. There are definitely systems designed for a particular piece of a hospital (ex, ER, or labs, etc) that are probably better than Epic is, bu…

> The main problem is that the customer is not the nurses, it's the legal/financial/administrative side.

This. The reason my medical staff like me is that I fight for usability for them, and push back against legal when they make requests that aren't backed up by the regulations. Legal hates me for the same reason, I know the regs and I'm willing to fight them on it.

Re: Hospitals are a weak spot in U.S. cybersecurity

#104
I’m an IT guy; I cringe almost every time I interact with the healthcare system.

I could pile on; all I want for now is encrypted and signed email with my doctors. I have an S/MIME certificate; can’t see why the IT staff at the hospitals I deal with can’t make sure my doctors have the same.

Re: Hospitals are a weak spot in U.S. cybersecurity

#105
post #47

Healthcare CIO here. This is true. Healthcare is still using paper fax. It has a 30 year old data interchange format that no one really supports because it's more profitable to lock in customers to your EMR. Healthcare is HORRIBLE about upgrading anything, at changing processes, and technological progress in general. Healthcare is VERY backwards from a tech standpoint. Another problem is that EVERYTHING is custom, we…

How much end to end efficiency do you think a proper/average IT healthcare system would bring ?

> How much end to end efficiency do you think a proper/average IT healthcare system would bring ?

I have a long history in proper IT, and I'm very legally/regulationally knowledgeable, and in my two healthcare gigs I've made friends of the medical staff for improving responsiveness in IT and making things easier to use, while also reducing security problems by having both of those worlds of knowledge. Usually top IT management isn't technically knowledgeable, and frequently they're not even that good with regulatory knowledge. That makes it hard on the rank and file to be efficient. Not to pay my own back too much, but being well versed in both regs and tech helps a LOT in user satisfaction.

Re: Hospitals are a weak spot in U.S. cybersecurity

#106

Earlier quoted context omitted.

it has nothing to do with security. Nurses like fax machines because it gets them a break. I've seen them print e-refferals just to fax to each other.

That's not even the same thing. People mess around with just about anything they can get their hands on- so what if the nurses send messages to each other and have fun? I'd be willing to give the people who take care of me a ream of paper if it meant they were in a good mood.

It has nothing to do with fun or messing around. It is about people being incentivized to avoid the tooling. I worked in US and Canadian health IT, my perspective is completely different from patient's. This may not have huge impact in high-end American hospitals, but in Canada where hospitals are underfunded and drowning in beuracracy it is a disaster

Re: Hospitals are a weak spot in U.S. cybersecurity

#107

I’m an IT guy; I cringe almost every time I interact with the healthcare system. I could pile on; all I want for now is encrypted and signed email with my doctors. I have an S/MIME certificate; can’t see why the IT staff at the hospitals I deal with can’t make sure my doctors have the same.

Because doctors are spoiled children. Were rolling out keyfobs for 2FA for our e-prescribe solution, but I'm keeping the fobs because I KNOW the docs will forget them/lose them. Docs only get soft-tokens on their phones because they never forget their phones.

Re: Hospitals are a weak spot in U.S. cybersecurity

#109
post #105

Earlier quoted context omitted.

How much end to end efficiency do you think a proper/average IT healthcare system would bring ?

> How much end to end efficiency do you think a proper/average IT healthcare system would bring ? I have a long history in proper IT, and I'm very legally/regulationally knowledgeable, and in my two healthcare gigs I've made friends of the medical staff for improving responsiveness in IT and making things easier to use, while also reducing security problems by having both of those worlds of knowledge. Usually top IT…

What were you able to make easier to use?

Re: Hospitals are a weak spot in U.S. cybersecurity

#110
post #86

Earlier quoted context omitted.

I'd wish hard to have a peek in these projects.

One of the reasons change is so slow in the industry is because there are many must-be-coordinated changes, with various independent parties. E.g. if I update my system, you need to update your system From what I saw, one of the biggest motivators would be carving out legal protections for trialing some smaller % of total workflow under new systems. E.g. If you moved By decreasing that first burden of migration, you…

> E.g. if I update my system, you need to update your system

I see you’ve played InternetExplorer X vs X+1 before.

Post reply on HN