Live data from Hacker News

Workarounds to Computer Access in Healthcare: Password or a Dead Patient? (2015)

cs.dartmouth.edu

31–40 of 61 posts

Re: Workarounds to Computer Access in Healthcare: Password or a Dead Patient? (2015)

#31
post #6

It really seems to me that at least for healthcare the solution is just to go back to paper and then just take the paper and do data entry on it after it's out of the workflow on a daily or bidaily basis or something. Honestly I'm also going to go out on a limb and guess that if most of the EHR portals screens were replaced with flat org files things would also work better.

I thought the whole promise of electronic records was to avoid transcription errors -- if the doctor enters it into the record himself, there's less chance of someone misreading or mistyping his notes later.

Promise yes.

Reality on the ground is that there were governmental subsidies to implement them, so everyone got them.

How much they actually help vs create problems is still an open research problem

Re: Workarounds to Computer Access in Healthcare: Password or a Dead Patient? (2015)

#32
post #28
post #23

All healthcare employees have badges they carry everywhere. Just get new ones with chips in them and an associated pin. Add the card scanner dongles for the computers. Access to rooms and supplies that don't need tight security is simply a card tap. Require the pin as well for more important stuff (computer login). Require a biometric as well for really important stuff. Make sure employees know they must report lost/…

Now you’ll have a bunch of scanners with the cards permanently on top, doors with a card hanging from the handle, and somehow all your staff is fired. Mission accomplished?

When something goes wrong, they will collectively cover each other. When something goes catastrophically wrong, the public will learn about it and say "how it could function like that?!". Alternatively they will use the opportunity to get rid of someone unwanted. Healthcare professionals are awfully slimy and corrupted.

Re: Workarounds to Computer Access in Healthcare: Password or a Dead Patient? (2015)

#33
I've spent a lot of time working as an academic in / out of hospitals. There's a big difference between an academic research centre (where you have, comparatively speaking, a lot of time to sit and think) and the "coal face" of clinical medicine (where the opposite is true).

Literally every high-level doctor I have ever worked with:

– Knows the passwords of their juniors and shares their password with them

– Has a lot of mutual bottom-covering going on

– Finds hospital computers intolerably slow, incredibly locked down, and designed by "muppets" who don't have to use them

– Keeps the issued smart-card for accessing patient records required as part of a 2FA scheme to themselves on their lanyard because they're all functionally identical

– Keeps their "badges" of lanyards mostly on their neck but occasionally asked for mine / borrowed mine to open random doors

All of this comes from precisely the mindset of putting patient care above security theatre. They all share passwords all the time because, well, it's hard to type on a keyboard and order a drug or a kit if you're in the middle of doing a transoesophageal echo, say, yet it's incredibly apparent that it's needed quickly. We all get yelled at periodically never to do this. If I was the person with the cardiac complaint, I'd much rather get my drugs quickly. A lot of the examples in the article ring very, very true. Most places I have worked let every doctor look up the medical records of every patient, but keep an audit of who does so (and occasionally make a fuss if someone does something inappropriate). I did once have an awful conversation with hospital security refusing me access to the door I was on the secure side of, when I was in scrubs and had a human liver on a perfusion rig (along with colleagues), however, as it was after hours and my badge hadn't been given permissions to open the door in the middle of the night, and needed to get something on the other side of it. That was "fun". (We wedged the door open when they were gone).

Re: Workarounds to Computer Access in Healthcare: Password or a Dead Patient? (2015)

#34

I've spent a lot of time working as an academic in / out of hospitals. There's a big difference between an academic research centre (where you have, comparatively speaking, a lot of time to sit and think) and the "coal face" of clinical medicine (where the opposite is true). Literally every high-level doctor I have ever worked with: – Knows the passwords of their juniors and shares their password with them – Has a lo…

Imagine that your embarrassingly slow software literally costs people's health (and maybe even lives in the long run). But we will still pretend like everything is fine, because "the DEveLopEr eXPeRiEncE", and "jUsT buY beTTeR hArDWaRe". And sure, hospital issued PCs aren't fast, but if they are anything from past decades, they still have processors running billions operations per second. And such managing software isn't something demanding either. The fact that it takes any thing longer then your IO bounded critical path is pathetic. It's just tragic how little we actually care today for end user experience, despite all the pretending.

Re: Workarounds to Computer Access in Healthcare: Password or a Dead Patient? (2015)

#35

Have had some level of security farce, like described in this paper, in every org I've ever been in. The root cause is failing to hold security staff to a dual mandate: keeping the bad guys out AND keeping the good guys in. Because they don't get held to account for obstructing everyone else's work, they naturally do every ass-covering piece of security theatre they can - they don't suffer any consequences. The momen…

Only tangentially related but my wife used to work at a private institute research lab which was affiliated with a large university, and therefore used computing resources.

The University IT security staff did a great job enabling 2FA across the entire network.. big job, well done. They didn’t do the slightest bit of requirements analysis of those people using the network such as affiliated research labs. One day my wife went to use the computer _in the PC3 lab_ and couldn’t without 2FA. Even logistically getting a computer in - that computer can then never leave the lab. PC3 labs don’t allow you to bring in a phone or anything really.. you’re double gowned, double gloved, goggles etc… hilarious.

Took them about a week to explain themselves sufficiently for IT security to fix it.

Re: Workarounds to Computer Access in Healthcare: Password or a Dead Patient? (2015)

#36
post #34

I've spent a lot of time working as an academic in / out of hospitals. There's a big difference between an academic research centre (where you have, comparatively speaking, a lot of time to sit and think) and the "coal face" of clinical medicine (where the opposite is true). Literally every high-level doctor I have ever worked with: – Knows the passwords of their juniors and shares their password with them – Has a lo…

Imagine that your embarrassingly slow software literally costs people's health (and maybe even lives in the long run). But we will still pretend like everything is fine, because "the DEveLopEr eXPeRiEncE", and "jUsT buY beTTeR hArDWaRe". And sure, hospital issued PCs aren't fast, but if they are anything from past decades, they still have processors running billions operations per second. And such managing software i…

> It's just tragic how little we actually care today for end user experience, despite all the pretending.

Most modern frameworks, languages, and concepts are developed and owned by ad companies. Then we take these and build critical stuff with it. Then they use it as a leverage to expand into industries where their stuff is used. There are some UX folks here and there but they're more happy to work on something "engaging" and "addicting".

Re: Workarounds to Computer Access in Healthcare: Password or a Dead Patient? (2015)

#37

Have had some level of security farce, like described in this paper, in every org I've ever been in. The root cause is failing to hold security staff to a dual mandate: keeping the bad guys out AND keeping the good guys in. Because they don't get held to account for obstructing everyone else's work, they naturally do every ass-covering piece of security theatre they can - they don't suffer any consequences. The momen…

"The moment they're under carrot-and-stick for not interfering with productivity, as well as preventing intrusions, you get more acceptable outcomes."

Suggestions on how to do this?

Re: Workarounds to Computer Access in Healthcare: Password or a Dead Patient? (2015)

#38

I'm not in healthcare, but I've evaded annoying/inconvenient security crap. One method I used for evading VPNs and using SSH was to have an script running inside the protected network, making an active connection to a SSH server on my machine at home, and set up a tunnel. Then I could use remote desktop through the tunnel. I use the following TXR Lisp program to defeat screen timeouts on Windows: (typedef UINT uint)…

This is pretty cool! I’ll have to try it out

Re: Workarounds to Computer Access in Healthcare: Password or a Dead Patient? (2015)

#39

I'm not in healthcare, but I've evaded annoying/inconvenient security crap. One method I used for evading VPNs and using SSH was to have an script running inside the protected network, making an active connection to a SSH server on my machine at home, and set up a tunnel. Then I could use remote desktop through the tunnel. I use the following TXR Lisp program to defeat screen timeouts on Windows: (typedef UINT uint)…

You are likely compromising your employer with this.

This is a reverse connection trojan basically and have been around since 2000+.

It's weird you haven't been caught yet.

Re: Workarounds to Computer Access in Healthcare: Password or a Dead Patient? (2015)

#40

Have had some level of security farce, like described in this paper, in every org I've ever been in. The root cause is failing to hold security staff to a dual mandate: keeping the bad guys out AND keeping the good guys in. Because they don't get held to account for obstructing everyone else's work, they naturally do every ass-covering piece of security theatre they can - they don't suffer any consequences. The momen…

At the exec level, the Chief Information Officer (CIO) is primarily responsible for maintaining availability of the network systems and data, but the Chief Information Security Officer (CISO) is responsible for securing systems and data. Sometimes they are same-level positions and compete for authority + resources. Sometimes CISO is subordinate to CIO. CIO supports profit centers, whereas CISO is entire a cost center and is focused on preventing losses.

The problem is that the competing interests aren’t exactly comparable apples-to-apples. Should every system get OS patches ASAP? Yes if you want to minimize the security surface area. No if the upgrade creates some adverse affect on employee/system. Testing can reveal the latter, but it takes time, which is the enemy of unpatched systems.

Low level IT workers are given instructions and incentives to follow established security procedures (including overseeing patching). Their supervisors are the ones who must make the call when it comes to how much testing is sufficient before forcing those patches.

Post reply on HN