Earlier quoted context omitted.
How so?
In the wake of discovery of attacks by China[0] and the NSA[1] Google has adopted a nation-state actor threat model and a siege mentality around data access and encryption. [0] https://en.wikipedia.org/wiki/Operation_Aurora [1] https://www.washingtonpost.com/world/national-security/nsa-i...
Hospitals are a weak spot in U.S. cybersecurity
151–160 of 166 posts
Re: Hospitals are a weak spot in U.S. cybersecurity
#152So are vet hospitals. At this very moment there's a chance you'll walk into one that has fallen back to paper records and billing due to a continent wide ransom ware attack. https://www.reddit.com/r/msp/comments/dnd7aq/ransomware_atta... From that thread: Avimark is an old style load the EXE from a share program with a flat file structure for the data. Most clinics are not in a domain, just workgroup, and the share i…
It's worse than that thread reveals. NVA was hit by a ransomware attack in May. They're now in a second attack that began in late October (ongoing). The latest one was described by CIO Joe Leggio as a "coordinated and sophisticated" attack in an internal email. He said it was designed to breach the NVA system specifically and that the attackers had three separate entry points. Only this week did NVA deploy endpoint s…
Re: Hospitals are a weak spot in U.S. cybersecurity
#153Healthcare CIO here. This is true. Healthcare is still using paper fax. It has a 30 year old data interchange format that no one really supports because it's more profitable to lock in customers to your EMR. Healthcare is HORRIBLE about upgrading anything, at changing processes, and technological progress in general. Healthcare is VERY backwards from a tech standpoint. Another problem is that EVERYTHING is custom, we…
People need to stop hating on fax. Hospitals still use fax because it is a much more punishable crime to tap phone lines which requires physical access, as opposed to a server that could be infected from a hacker halfway across the world.
Re: Hospitals are a weak spot in U.S. cybersecurity
#154Earlier quoted context omitted.
People need to stop hating on fax. Hospitals still use fax because it is a much more punishable crime to tap phone lines which requires physical access, as opposed to a server that could be infected from a hacker halfway across the world.
Fax is odd, it was a fantastic thing when it first came about, and it has some desirable properties. - It's direct point to point communication (over a network) - The transport network is dedicated and not open to anyone and covered by quite strong laws in many countries - It's easy to see the history of communications - It's easy to see if the other end successfully received something - It's relatively standardized…
Many fax machine can be programmed over the wire, so maybe you have default pins and now your faxes are being forwarded and you don't know.
Re: Hospitals are a weak spot in U.S. cybersecurity
#155Healthcare CIO here. This is true. Healthcare is still using paper fax. It has a 30 year old data interchange format that no one really supports because it's more profitable to lock in customers to your EMR. Healthcare is HORRIBLE about upgrading anything, at changing processes, and technological progress in general. Healthcare is VERY backwards from a tech standpoint. Another problem is that EVERYTHING is custom, we…
Re: Hospitals are a weak spot in U.S. cybersecurity
#156Earlier quoted context omitted.
People need to stop hating on fax. Hospitals still use fax because it is a much more punishable crime to tap phone lines which requires physical access, as opposed to a server that could be infected from a hacker halfway across the world.
I’m willing to bet that most digital PBXs out there could be infected by a hacker from halfway across the world too.
Re: Hospitals are a weak spot in U.S. cybersecurity
#157Earlier quoted context omitted.
You plug in the USB key, then you pull out the USB key. The physical security layer at alot of hospitals is almost entirely absent, sadly.
USB keys are blocked mostly these days. There are other huge vulnerabilities if you have physical access and are motivated.
Re: Hospitals are a weak spot in U.S. cybersecurity
#158So are vet hospitals. At this very moment there's a chance you'll walk into one that has fallen back to paper records and billing due to a continent wide ransom ware attack. https://www.reddit.com/r/msp/comments/dnd7aq/ransomware_atta... From that thread: Avimark is an old style load the EXE from a share program with a flat file structure for the data. Most clinics are not in a domain, just workgroup, and the share i…
It's worse than that thread reveals. NVA was hit by a ransomware attack in May. They're now in a second attack that began in late October (ongoing). The latest one was described by CIO Joe Leggio as a "coordinated and sophisticated" attack in an internal email. He said it was designed to breach the NVA system specifically and that the attackers had three separate entry points. Only this week did NVA deploy endpoint s…
Re: Hospitals are a weak spot in U.S. cybersecurity
#159So are vet hospitals. At this very moment there's a chance you'll walk into one that has fallen back to paper records and billing due to a continent wide ransom ware attack. https://www.reddit.com/r/msp/comments/dnd7aq/ransomware_atta... From that thread: Avimark is an old style load the EXE from a share program with a flat file structure for the data. Most clinics are not in a domain, just workgroup, and the share i…
It's worse than that thread reveals. NVA was hit by a ransomware attack in May. They're now in a second attack that began in late October (ongoing). The latest one was described by CIO Joe Leggio as a "coordinated and sophisticated" attack in an internal email. He said it was designed to breach the NVA system specifically and that the attackers had three separate entry points. Only this week did NVA deploy endpoint s…
Dr. Paul DVM and AVImark Consultant and Trainer since 1998.
Re: Hospitals are a weak spot in U.S. cybersecurity
#160Earlier quoted context omitted.
Does Epic use MUMPS? I know a lot of professional nurses and the rancor around Epic is off the charts.
Backend is all MUMPS. Frontend was for a long time coded in Visual Basic 6. VB6/MUMPS stack is... not ergonomic to code in. Epic is easy to hate (it's everywhere), and for good reason. However, the alternatives are not obviously better unless there's been some radical innovation. There are definitely systems designed for a particular piece of a hospital (ex, ER, or labs, etc) that are probably better than Epic is, bu…
Yeah, our org is on Cerner and there's excited talk around going to Epic in the future. People don't seem to understand that it's just going to be more of same in dealing with an old, monolithic system.