Live data from Hacker News

Hospitals are a weak spot in U.S. cybersecurity

axios.com

31–40 of 166 posts

Re: Hospitals are a weak spot in U.S. cybersecurity

#31
"Sky is blue, news at 11:00"...

Of course hospitals are a security weak spot: They're full of sensitive patient health data shared over computer systems whose users and procurers are not very security-literate, and often absent-minded about such issues due to the grinding, stressful work.

Re: Hospitals are a weak spot in U.S. cybersecurity

#32

Earlier quoted context omitted.

As with most environments, there’s a lot of trust based in a hospital running successfully. At least they have their own on-site security that’s experienced in taking people down. I continue to believe the real threats are actual insiders and remote attacks. Dunno how far someone will get with a USB key versus sending everyone a plausible email.

You plug in the USB key, then you pull out the USB key. The physical security layer at alot of hospitals is almost entirely absent, sadly.

USB keys are blocked mostly these days. There are other huge vulnerabilities if you have physical access and are motivated.

Re: Hospitals are a weak spot in U.S. cybersecurity

#34

Recently saw an ad for an IT support position at a hospital. The list of potential hazards in the work environment listed in the ad likely scares off many who have plenty of other employment opportunities. And most hospitals can't jack up the pay to compensate so attracting good talent is going to be a problem.

What were the hazards that you saw? Just curious

Re: Hospitals are a weak spot in U.S. cybersecurity

#35
post #20

It seems that hospitals are overly focused on bullshit security frameworks and box-checking, i.e., HITRUST, which in my experience results in many dollars going to consultants with essentially zero tangible improvement in information security. Worse yet, the false sense of security within these hospitals due to having a HITRUST audit report with a bunch of meaninglessness check marks prevents them from actually doing…

On the flip side, I’ve long preached that compliance is not security. HITRUST CSF is a huge improvement over the previous state of healthcare IT, because HIPAA is not prescriptive

Re: Hospitals are a weak spot in U.S. cybersecurity

#37

Earlier quoted context omitted.

> some rad tech who guessed the administrator password put folding@home on without telling anyone which crippled that machine's ability to perform its function. How incredibly bizarre to do something that dumb for no personal benefit.

BTC miners occur more than F@H these days, but they happen plenty.

This incident occurred before crypto mining was a thing many knew about. He thought that since the machine was unused overnight that someone should get some benefit from it.

Re: Hospitals are a weak spot in U.S. cybersecurity

#38

Recently saw an ad for an IT support position at a hospital. The list of potential hazards in the work environment listed in the ad likely scares off many who have plenty of other employment opportunities. And most hospitals can't jack up the pay to compensate so attracting good talent is going to be a problem.

> And most hospitals can't jack up the pay to compensate

I find that hard to believe in an age of $100 saline bags, $20,000 childbirths, and 15-minute-long $500 specialist visits.

Re: Hospitals are a weak spot in U.S. cybersecurity

#39
post #35
post #20

It seems that hospitals are overly focused on bullshit security frameworks and box-checking, i.e., HITRUST, which in my experience results in many dollars going to consultants with essentially zero tangible improvement in information security. Worse yet, the false sense of security within these hospitals due to having a HITRUST audit report with a bunch of meaninglessness check marks prevents them from actually doing…

On the flip side, I’ve long preached that compliance is not security. HITRUST CSF is a huge improvement over the previous state of healthcare IT, because HIPAA is not prescriptive

The famous critique on HITRUST by a healthcare security guy that went viral, calling it "Cumbersome, Expensive, and Arbitrary":

https://www.linkedin.com/pulse/open-letter-hitrust-alliance-...

Re: Hospitals are a weak spot in U.S. cybersecurity

#40
post #38

Recently saw an ad for an IT support position at a hospital. The list of potential hazards in the work environment listed in the ad likely scares off many who have plenty of other employment opportunities. And most hospitals can't jack up the pay to compensate so attracting good talent is going to be a problem.

> And most hospitals can't jack up the pay to compensate I find that hard to believe in an age of $100 saline bags, $20,000 childbirths, and 15-minute-long $500 specialist visits.

You’re downvoted likely because the high expenses of hospitalization speak more to inefficiencies in healthcare supply chain and the economics of insurance and really has nothing much to do with how much hospitals can afford on IT. Some hospital systems are rich... but they’re not that rich.

That said I agree (based on 1st hand experience) that the larger healthcare multibillion dollar systems in the US can afford to pay more for better IT/engineering. There is simply little incentive to do so. And further it’s more than just hiring a few engineers with FAANG pay... these institutions are organizationally not suited to engineering. Changing this would not be easy for them...and no, we don’t need a hospital run like Facebook or Uber.

Then there are the tons of smaller systems in the US.. they cannot afford high priced engineers regardless of the pre-insurance line charge for a bag of saline.

Post reply on HN