Healthcare CIO here. This is true. Healthcare is still using paper fax. It has a 30 year old data interchange format that no one really supports because it's more profitable to lock in customers to your EMR. Healthcare is HORRIBLE about upgrading anything, at changing processes, and technological progress in general. Healthcare is VERY backwards from a tech standpoint. Another problem is that EVERYTHING is custom, we…
So true. Also healthcare software companies are shipping shit quality products and charging a fortune. Hospital CEOs are buying from mates. Fancy pants doctors are demanding exceptions. Shift staff are sharing passwords. Medical systems are not even capable of automating proper user access controls. The volume of data, especially medical imaging is growing at a crazy rate. Network links are under invested in. They sw…
Hospitals are a weak spot in U.S. cybersecurity
161–166 of 166 posts
Re: Hospitals are a weak spot in U.S. cybersecurity
#162The central IT function in a US hospital also usually has little organizational power and funding. Admissions, radiology, etc, buy whatever hardware and software they want, and the underfunded IT department has to figure it out.
Upper level IT management doesn't communicate with the team when large changes are made, and pretty much treat them disrespectfully, even though they have their fingers on the pulse of what's going wrong from the medical staff. There's also a lot of waste from poorly implemented/delayed projects (there are more PMs than IT staff to implement the projects). Definitely a frustrating and bureaucratic area to be in.
Re: Hospitals are a weak spot in U.S. cybersecurity
#163Earlier quoted context omitted.
Earlier in my career I interviewed for a health IT job that was basically a director level position. The pay ended up being less than I was making as a government employee for a smaller scoped job. The government gig was probably less than an intern makes at a FAANG. In medicine, doctors are king. Everyone else is a peon.
Doctors don't feel like they are kings--while they make very good money there are massive amounts of red tape, filling out Epic... It's the bureaucrats who are kings.
Re: Hospitals are a weak spot in U.S. cybersecurity
#164waiting rooms are a gaping hole. nobody seems to see a problem with blabbing out your final 4 and first,last name when thier at a desk in a room full of whoever walked in and sat down. un protected desktops are another issue, there is a tide of duties and an attacker can pattern the staff and get a good idea when they will have time to do an inside job of some sort.
As with most environments, there’s a lot of trust based in a hospital running successfully. At least they have their own on-site security that’s experienced in taking people down. I continue to believe the real threats are actual insiders and remote attacks. Dunno how far someone will get with a USB key versus sending everyone a plausible email.
We had one user who called after filling in every email address she had into a very plausible looking O365 login page. She admitted she initially distrusted the email/link that led her to this page and had replied saying so. The hackers on the other end told her to go ahead and do so. I mean, who she to question when it's coming directly from the hospital's lawyer?
Re: Hospitals are a weak spot in U.S. cybersecurity
#165Healthcare CIO here. This is true. Healthcare is still using paper fax. It has a 30 year old data interchange format that no one really supports because it's more profitable to lock in customers to your EMR. Healthcare is HORRIBLE about upgrading anything, at changing processes, and technological progress in general. Healthcare is VERY backwards from a tech standpoint. Another problem is that EVERYTHING is custom, we…
People need to stop hating on fax. Hospitals still use fax because it is a much more punishable crime to tap phone lines which requires physical access, as opposed to a server that could be infected from a hacker halfway across the world.
Re: Hospitals are a weak spot in U.S. cybersecurity
#166Earlier quoted context omitted.
People need to stop hating on fax. Hospitals still use fax because it is a much more punishable crime to tap phone lines which requires physical access, as opposed to a server that could be infected from a hacker halfway across the world.
Fax is odd, it was a fantastic thing when it first came about, and it has some desirable properties. - It's direct point to point communication (over a network) - The transport network is dedicated and not open to anyone and covered by quite strong laws in many countries - It's easy to see the history of communications - It's easy to see if the other end successfully received something - It's relatively standardized…
This was not the case when I worked in healthcare. It was a constant back and fourth of "did you receive it?" over the phone.