Live data from Hacker News

Hospitals are a weak spot in U.S. cybersecurity

axios.com

151–160 of 166 posts

Re: Hospitals are a weak spot in U.S. cybersecurity

#151
post #45

Earlier quoted context omitted.

How so?

In the wake of discovery of attacks by China[0] and the NSA[1] Google has adopted a nation-state actor threat model and a siege mentality around data access and encryption. [0] https://en.wikipedia.org/wiki/Operation_Aurora [1] https://www.washingtonpost.com/world/national-security/nsa-i...

Any idea if that siege mentality is part of the reason for sunsetting its social projects?

Re: Hospitals are a weak spot in U.S. cybersecurity

#152

So are vet hospitals. At this very moment there's a chance you'll walk into one that has fallen back to paper records and billing due to a continent wide ransom ware attack. https://www.reddit.com/r/msp/comments/dnd7aq/ransomware_atta... From that thread: Avimark is an old style load the EXE from a share program with a flat file structure for the data. Most clinics are not in a domain, just workgroup, and the share i…

It's worse than that thread reveals. NVA was hit by a ransomware attack in May. They're now in a second attack that began in late October (ongoing). The latest one was described by CIO Joe Leggio as a "coordinated and sophisticated" attack in an internal email. He said it was designed to breach the NVA system specifically and that the attackers had three separate entry points. Only this week did NVA deploy endpoint s…

Hello. I'm a reporter at the Wall Street Journal and I've been looking into this second attack for two weeks now. Some users from that Reddit thread have passed along some internal emails to me, and some customers have reached out with complaints as well and I've been looking to corroborate some details. Would you be willing to chat with me via Signal?

Re: Hospitals are a weak spot in U.S. cybersecurity

#153
post #47

Healthcare CIO here. This is true. Healthcare is still using paper fax. It has a 30 year old data interchange format that no one really supports because it's more profitable to lock in customers to your EMR. Healthcare is HORRIBLE about upgrading anything, at changing processes, and technological progress in general. Healthcare is VERY backwards from a tech standpoint. Another problem is that EVERYTHING is custom, we…

People need to stop hating on fax. Hospitals still use fax because it is a much more punishable crime to tap phone lines which requires physical access, as opposed to a server that could be infected from a hacker halfway across the world.

That is not why they use them. Doctors like scribbling, and hate being told what to do, that's why.

Re: Hospitals are a weak spot in U.S. cybersecurity

#154
post #71

Earlier quoted context omitted.

People need to stop hating on fax. Hospitals still use fax because it is a much more punishable crime to tap phone lines which requires physical access, as opposed to a server that could be infected from a hacker halfway across the world.

Fax is odd, it was a fantastic thing when it first came about, and it has some desirable properties. - It's direct point to point communication (over a network) - The transport network is dedicated and not open to anyone and covered by quite strong laws in many countries - It's easy to see the history of communications - It's easy to see if the other end successfully received something - It's relatively standardized…

No quite, many fax system are just modems, image conversion to pdf, email. Plenty to go wrong. Paper faxes might be revived by the machine by you have no idea who read it, or who didnt. Fax machine are typically MFP devices, so now you may have some part of a medical record on your photocopier HDD.

Many fax machine can be programmed over the wire, so maybe you have default pins and now your faxes are being forwarded and you don't know.

Re: Hospitals are a weak spot in U.S. cybersecurity

#155
post #47

Healthcare CIO here. This is true. Healthcare is still using paper fax. It has a 30 year old data interchange format that no one really supports because it's more profitable to lock in customers to your EMR. Healthcare is HORRIBLE about upgrading anything, at changing processes, and technological progress in general. Healthcare is VERY backwards from a tech standpoint. Another problem is that EVERYTHING is custom, we…

So true. Also healthcare software companies are shipping shit quality products and charging a fortune. Hospital CEOs are buying from mates. Fancy pants doctors are demanding exceptions. Shift staff are sharing passwords. Medical systems are not even capable of automating proper user access controls. The volume of data, especially medical imaging is growing at a crazy rate. Network links are under invested in. They sweat the assets to the points of lunacy. Ok I'm gonna stop.

Re: Hospitals are a weak spot in U.S. cybersecurity

#156

Earlier quoted context omitted.

People need to stop hating on fax. Hospitals still use fax because it is a much more punishable crime to tap phone lines which requires physical access, as opposed to a server that could be infected from a hacker halfway across the world.

I’m willing to bet that most digital PBXs out there could be infected by a hacker from halfway across the world too.

Saw that happen yesterday. A vendor had insecure remote access setup to an older NEC PBX. Someone attacked it and was making international calls with it.

Re: Hospitals are a weak spot in U.S. cybersecurity

#157
post #32

Earlier quoted context omitted.

You plug in the USB key, then you pull out the USB key. The physical security layer at alot of hospitals is almost entirely absent, sadly.

USB keys are blocked mostly these days. There are other huge vulnerabilities if you have physical access and are motivated.

From experience in plenty of industries, your statement is incorrect. Most places suck at security and blocking removable storage, but likewise suck at far more important controls (eg application whitelisting) for it to really mitigate much in the first place

Re: Hospitals are a weak spot in U.S. cybersecurity

#158

So are vet hospitals. At this very moment there's a chance you'll walk into one that has fallen back to paper records and billing due to a continent wide ransom ware attack. https://www.reddit.com/r/msp/comments/dnd7aq/ransomware_atta... From that thread: Avimark is an old style load the EXE from a share program with a flat file structure for the data. Most clinics are not in a domain, just workgroup, and the share i…

It's worse than that thread reveals. NVA was hit by a ransomware attack in May. They're now in a second attack that began in late October (ongoing). The latest one was described by CIO Joe Leggio as a "coordinated and sophisticated" attack in an internal email. He said it was designed to breach the NVA system specifically and that the attackers had three separate entry points. Only this week did NVA deploy endpoint s…

AVImark does not use SQL in general. They did an experiment with SQL a few years ago but abandoned it. They have a flat file database written in Delphi.

Re: Hospitals are a weak spot in U.S. cybersecurity

#159

So are vet hospitals. At this very moment there's a chance you'll walk into one that has fallen back to paper records and billing due to a continent wide ransom ware attack. https://www.reddit.com/r/msp/comments/dnd7aq/ransomware_atta... From that thread: Avimark is an old style load the EXE from a share program with a flat file structure for the data. Most clinics are not in a domain, just workgroup, and the share i…

It's worse than that thread reveals. NVA was hit by a ransomware attack in May. They're now in a second attack that began in late October (ongoing). The latest one was described by CIO Joe Leggio as a "coordinated and sophisticated" attack in an internal email. He said it was designed to breach the NVA system specifically and that the attackers had three separate entry points. Only this week did NVA deploy endpoint s…

AVImark is not SQL. AVImark runs at workstation as a UNC path shortcut and no application is installed on the workstations. Entire program resides on the Server and is much like it's DOS predesessor from the 1980's. Everything it needs to run is installed in it's AVIark folder on the Server. Very few of the 8,000 plus hospitals run it in an RDP mode. Usually those that do have multiple locations with satellite hospitals connected to the main server via Internet back to the central or main hospital. Problem is NVA does not know what they are doing for security and has paid no attention to this problem, and has no well defined distaster recovery plan. They do not allow for outside expert AVImark or IT consultants to help their hospitals.

Dr. Paul DVM and AVImark Consultant and Trainer since 1998.

Re: Hospitals are a weak spot in U.S. cybersecurity

#160

Earlier quoted context omitted.

Does Epic use MUMPS? I know a lot of professional nurses and the rancor around Epic is off the charts.

Backend is all MUMPS. Frontend was for a long time coded in Visual Basic 6. VB6/MUMPS stack is... not ergonomic to code in. Epic is easy to hate (it's everywhere), and for good reason. However, the alternatives are not obviously better unless there's been some radical innovation. There are definitely systems designed for a particular piece of a hospital (ex, ER, or labs, etc) that are probably better than Epic is, bu…

>Epic is easy to hate (it's everywhere), and for good reason. However, the alternatives are not obviously better unless there's been some radical innovation. There are definitely systems designed for a particular piece of a hospital (ex, ER, or labs, etc) that are probably better than Epic is, but when it comes to having one system for the entire hospital, they're all pretty bad.

Yeah, our org is on Cerner and there's excited talk around going to Epic in the future. People don't seem to understand that it's just going to be more of same in dealing with an old, monolithic system.

Post reply on HN