Live data from Hacker News

Hospitals are a weak spot in U.S. cybersecurity

axios.com

21–30 of 166 posts

Re: Hospitals are a weak spot in U.S. cybersecurity

#22
post #3

The central IT function in a US hospital also usually has little organizational power and funding. Admissions, radiology, etc, buy whatever hardware and software they want, and the underfunded IT department has to figure it out.

Radiology has gotten somewhat better. They do might buy whatever they want, but the files tend to end up in a vendor neutral archive with proper access controls.

Re: Hospitals are a weak spot in U.S. cybersecurity

#24
It seems the biggest reason they're a weak spot is that the data they store make them a target. Retailers are also weak on security -- really, I wouldn't trust any company that wasn't a specialist in the space, i.e. finance and tech -- but most entities don't know so much about their clientele. Retailers don't need to keep as much info as they do (aside from profit motives), but hospitals probably do, so I can see this being a vulnerability that's never closed.

Re: Hospitals are a weak spot in U.S. cybersecurity

#26

Earlier quoted context omitted.

>Dunno how far someone will get with a USB key versus sending everyone a plausible email. Insiders still can be threats. There was a machine that was deployed in a hospital for clinical imaging that some rad tech who guessed the administrator password put folding@home on without telling anyone which crippled that machine's ability to perform its function.

> some rad tech who guessed the administrator password put folding@home on without telling anyone which crippled that machine's ability to perform its function. How incredibly bizarre to do something that dumb for no personal benefit.

BTC miners occur more than F@H these days, but they happen plenty.

Re: Hospitals are a weak spot in U.S. cybersecurity

#27
post #2

waiting rooms are a gaping hole. nobody seems to see a problem with blabbing out your final 4 and first,last name when thier at a desk in a room full of whoever walked in and sat down. un protected desktops are another issue, there is a tide of duties and an attacker can pattern the staff and get a good idea when they will have time to do an inside job of some sort.

Specialist I went to attempted to collect a photograph in the waiting room, as well - "please hold still a second while I take your picture for the doctor", with a webcam sitting atop the counter between us.

these are times when i say no thankyou thats not medically necessary, and obsruct the cam or turn around if its unobstructable.

Re: Hospitals are a weak spot in U.S. cybersecurity

#28
post #2

waiting rooms are a gaping hole. nobody seems to see a problem with blabbing out your final 4 and first,last name when thier at a desk in a room full of whoever walked in and sat down. un protected desktops are another issue, there is a tide of duties and an attacker can pattern the staff and get a good idea when they will have time to do an inside job of some sort.

The big threat used to be the paperwork (and still is sometimes due to fax machines). There were people who broke in after hours, and stole boxes of paperwork to use for medical billing fraud.

Re: Hospitals are a weak spot in U.S. cybersecurity

#29
Recently saw an ad for an IT support position at a hospital. The list of potential hazards in the work environment listed in the ad likely scares off many who have plenty of other employment opportunities. And most hospitals can't jack up the pay to compensate so attracting good talent is going to be a problem.

Re: Hospitals are a weak spot in U.S. cybersecurity

#30

It seems the biggest reason they're a weak spot is that the data they store make them a target. Retailers are also weak on security -- really, I wouldn't trust any company that wasn't a specialist in the space, i.e. finance and tech -- but most entities don't know so much about their clientele. Retailers don't need to keep as much info as they do (aside from profit motives), but hospitals probably do, so I can see th…

Honestly I have to completely disagree. Security is simply bad.

Hospital IT depts are pulled between many competing interests which lead up to this.

Post reply on HN