Live data from Hacker News

Hospitals are a weak spot in U.S. cybersecurity

axios.com

111–120 of 166 posts

Re: Hospitals are a weak spot in U.S. cybersecurity

#111
post #47

Healthcare CIO here. This is true. Healthcare is still using paper fax. It has a 30 year old data interchange format that no one really supports because it's more profitable to lock in customers to your EMR. Healthcare is HORRIBLE about upgrading anything, at changing processes, and technological progress in general. Healthcare is VERY backwards from a tech standpoint. Another problem is that EVERYTHING is custom, we…

From my perpective, part of the problem is that any system is chosen based on political connections and/or bribes. And once any system is in place, there is zero reason to replace it until someone else puts down enough bribe money to convince a poltician to make another move.

Government promises, and thus government kills. A monopoly enforced by guns and prisons.

Re: Hospitals are a weak spot in U.S. cybersecurity

#112
post #77

It's really tough. You have a function which is viewed purely as a cost center; you have a totally porous environment where you're required to admit tons of minimally-verified people into confidential spaces; staff and affiliates need different levels of access from all over the world; there are critical availability demands where temporary denial of service for security reasons is unacceptable; device development is…

Oh, and you're ultimately sourcing truth from people who are minimally trained on (and have minimal time for training on) the system. Because they've spent the last couple decades focused on medical training.

And patients that lie / dirty input.

Sure, use cousin x’s coverage. Nobody will freak out when your blood type doesn’t match the records...

Re: Hospitals are a weak spot in U.S. cybersecurity

#113
post #71

Earlier quoted context omitted.

People need to stop hating on fax. Hospitals still use fax because it is a much more punishable crime to tap phone lines which requires physical access, as opposed to a server that could be infected from a hacker halfway across the world.

Fax is odd, it was a fantastic thing when it first came about, and it has some desirable properties. - It's direct point to point communication (over a network) - The transport network is dedicated and not open to anyone and covered by quite strong laws in many countries - It's easy to see the history of communications - It's easy to see if the other end successfully received something - It's relatively standardized…

Some points seem contradictory. How do faxes have history that's easy to see, and if the other end successfully received, but it doesn't have delivery receipt like email?

Re: Hospitals are a weak spot in U.S. cybersecurity

#114
post #47

Healthcare CIO here. This is true. Healthcare is still using paper fax. It has a 30 year old data interchange format that no one really supports because it's more profitable to lock in customers to your EMR. Healthcare is HORRIBLE about upgrading anything, at changing processes, and technological progress in general. Healthcare is VERY backwards from a tech standpoint. Another problem is that EVERYTHING is custom, we…

> Don't like the terminal interface? Let's slap a GUI on the front that still interacts via TTY on the back end.

This made me smile, because this is exactly what I did when working for a major health insurer...

Re: Hospitals are a weak spot in U.S. cybersecurity

#115
post #71

Earlier quoted context omitted.

People need to stop hating on fax. Hospitals still use fax because it is a much more punishable crime to tap phone lines which requires physical access, as opposed to a server that could be infected from a hacker halfway across the world.

Fax is odd, it was a fantastic thing when it first came about, and it has some desirable properties. - It's direct point to point communication (over a network) - The transport network is dedicated and not open to anyone and covered by quite strong laws in many countries - It's easy to see the history of communications - It's easy to see if the other end successfully received something - It's relatively standardized…

>- The transport network is dedicated and not open to anyone and covered by quite strong laws in many countries

is it? what if the hospital is using a VOIP solution?

Re: Hospitals are a weak spot in U.S. cybersecurity

#116
post #61
post #2

waiting rooms are a gaping hole. nobody seems to see a problem with blabbing out your final 4 and first,last name when thier at a desk in a room full of whoever walked in and sat down. un protected desktops are another issue, there is a tide of duties and an attacker can pattern the staff and get a good idea when they will have time to do an inside job of some sort.

Same thing for picking up prescription at CVS/Walgreens. They make you verify your phone number and address. Every. Single. Time. In public. It's a shame how silly it all is.

I actually feel kinda sad for you, seems so cumbersome, yet I can't relate at all. Really bizarre to me as an Estonian, I've only had to show my ID-card to the pharmacist and get my prescription, because my doctor has entered it into the e-prescription[1] system. Reading this thread definitely made me appreciate it a lot more.

[1]: https://www.eesti.ee/eng/services/citizen/tervis_ja_tervisek...

Re: Hospitals are a weak spot in U.S. cybersecurity

#117
post #38

Earlier quoted context omitted.

> And most hospitals can't jack up the pay to compensate I find that hard to believe in an age of $100 saline bags, $20,000 childbirths, and 15-minute-long $500 specialist visits.

Earlier in my career I interviewed for a health IT job that was basically a director level position. The pay ended up being less than I was making as a government employee for a smaller scoped job. The government gig was probably less than an intern makes at a FAANG. In medicine, doctors are king. Everyone else is a peon.

Doctors don't feel like they are kings--while they make very good money there are massive amounts of red tape, filling out Epic...

It's the bureaucrats who are kings.

Re: Hospitals are a weak spot in U.S. cybersecurity

#118
post #47

Healthcare CIO here. This is true. Healthcare is still using paper fax. It has a 30 year old data interchange format that no one really supports because it's more profitable to lock in customers to your EMR. Healthcare is HORRIBLE about upgrading anything, at changing processes, and technological progress in general. Healthcare is VERY backwards from a tech standpoint. Another problem is that EVERYTHING is custom, we…

People need to stop hating on fax. Hospitals still use fax because it is a much more punishable crime to tap phone lines which requires physical access, as opposed to a server that could be infected from a hacker halfway across the world.

No Hospitals use fax because it's too hard to change, most information traveling through fax is sent via automated fax servers so it is the worst of both worlds, hack-able server and unencrypted transmission protocol.

Re: Hospitals are a weak spot in U.S. cybersecurity

#119
post #63
post #36

Earlier quoted context omitted.

Big tech. Google, especially.

To be honest, Google is the last company I want handling my health data. If you don't check the right boxes, it could end up being "anonymized", and sold off.

Google is very good at precisely controlling what happens to the data. You never hear about some huge leak where 1B google accounts had their whole data taken.

Re: Hospitals are a weak spot in U.S. cybersecurity

#120
post #39
post #35

Earlier quoted context omitted.

On the flip side, I’ve long preached that compliance is not security. HITRUST CSF is a huge improvement over the previous state of healthcare IT, because HIPAA is not prescriptive

The famous critique on HITRUST by a healthcare security guy that went viral, calling it "Cumbersome, Expensive, and Arbitrary": https://www.linkedin.com/pulse/open-letter-hitrust-alliance-...

Yep, and yet I’ve been able to successfully implement it in a 1 year project in a prior org (as part of a team obviously). HITRUST isn’t that bad, and it’s better than the alternative, which is HIPAA directly. I would best describe HIPAA as Vague, Fruitless, Bureaucratic, and Arbitrary. HITRUST is a huge improvement even if it’s not perfect.
Post reply on HN