Of course hospitals are a security weak spot: They're full of sensitive patient health data shared over computer systems whose users and procurers are not very security-literate, and often absent-minded about such issues due to the grinding, stressful work.
Hospitals are a weak spot in U.S. cybersecurity
31–40 of 166 posts
Re: Hospitals are a weak spot in U.S. cybersecurity
#32Earlier quoted context omitted.
As with most environments, there’s a lot of trust based in a hospital running successfully. At least they have their own on-site security that’s experienced in taking people down. I continue to believe the real threats are actual insiders and remote attacks. Dunno how far someone will get with a USB key versus sending everyone a plausible email.
You plug in the USB key, then you pull out the USB key. The physical security layer at alot of hospitals is almost entirely absent, sadly.
Re: Hospitals are a weak spot in U.S. cybersecurity
#33How do they store their data? Why don't they use private clouds? -Duple? https://www.duple.io/en/ -Nextcloud? https://nextcloud.com/
Re: Hospitals are a weak spot in U.S. cybersecurity
#34Recently saw an ad for an IT support position at a hospital. The list of potential hazards in the work environment listed in the ad likely scares off many who have plenty of other employment opportunities. And most hospitals can't jack up the pay to compensate so attracting good talent is going to be a problem.
Re: Hospitals are a weak spot in U.S. cybersecurity
#35It seems that hospitals are overly focused on bullshit security frameworks and box-checking, i.e., HITRUST, which in my experience results in many dollars going to consultants with essentially zero tangible improvement in information security. Worse yet, the false sense of security within these hospitals due to having a HITRUST audit report with a bunch of meaninglessness check marks prevents them from actually doing…
Re: Hospitals are a weak spot in U.S. cybersecurity
#36Given the state of cybersecurity right now, is there any organization or domain AT ALL which is strong and model-worthy when it comes to cybersecurity?
Re: Hospitals are a weak spot in U.S. cybersecurity
#37Earlier quoted context omitted.
> some rad tech who guessed the administrator password put folding@home on without telling anyone which crippled that machine's ability to perform its function. How incredibly bizarre to do something that dumb for no personal benefit.
BTC miners occur more than F@H these days, but they happen plenty.
Re: Hospitals are a weak spot in U.S. cybersecurity
#38Recently saw an ad for an IT support position at a hospital. The list of potential hazards in the work environment listed in the ad likely scares off many who have plenty of other employment opportunities. And most hospitals can't jack up the pay to compensate so attracting good talent is going to be a problem.
I find that hard to believe in an age of $100 saline bags, $20,000 childbirths, and 15-minute-long $500 specialist visits.
Re: Hospitals are a weak spot in U.S. cybersecurity
#39It seems that hospitals are overly focused on bullshit security frameworks and box-checking, i.e., HITRUST, which in my experience results in many dollars going to consultants with essentially zero tangible improvement in information security. Worse yet, the false sense of security within these hospitals due to having a HITRUST audit report with a bunch of meaninglessness check marks prevents them from actually doing…
On the flip side, I’ve long preached that compliance is not security. HITRUST CSF is a huge improvement over the previous state of healthcare IT, because HIPAA is not prescriptive
https://www.linkedin.com/pulse/open-letter-hitrust-alliance-...
Re: Hospitals are a weak spot in U.S. cybersecurity
#40Recently saw an ad for an IT support position at a hospital. The list of potential hazards in the work environment listed in the ad likely scares off many who have plenty of other employment opportunities. And most hospitals can't jack up the pay to compensate so attracting good talent is going to be a problem.
> And most hospitals can't jack up the pay to compensate I find that hard to believe in an age of $100 saline bags, $20,000 childbirths, and 15-minute-long $500 specialist visits.
That said I agree (based on 1st hand experience) that the larger healthcare multibillion dollar systems in the US can afford to pay more for better IT/engineering. There is simply little incentive to do so. And further it’s more than just hiring a few engineers with FAANG pay... these institutions are organizationally not suited to engineering. Changing this would not be easy for them...and no, we don’t need a hospital run like Facebook or Uber.
Then there are the tons of smaller systems in the US.. they cannot afford high priced engineers regardless of the pre-insurance line charge for a bag of saline.