Live data from Hacker News

Hospitals are a weak spot in U.S. cybersecurity

axios.com

41–50 of 166 posts

Re: Hospitals are a weak spot in U.S. cybersecurity

#41
post #2

waiting rooms are a gaping hole. nobody seems to see a problem with blabbing out your final 4 and first,last name when thier at a desk in a room full of whoever walked in and sat down. un protected desktops are another issue, there is a tide of duties and an attacker can pattern the staff and get a good idea when they will have time to do an inside job of some sort.

We're past time for simple challenge response for this, if not something better. Computer picks two digits, maybe they are part of your SSN sequence, or not, you have to parse that and say true or false. Then last three of your SSN. The current strategy is b.s.

Re: Hospitals are a weak spot in U.S. cybersecurity

#42
post #20

It seems that hospitals are overly focused on bullshit security frameworks and box-checking, i.e., HITRUST, which in my experience results in many dollars going to consultants with essentially zero tangible improvement in information security. Worse yet, the false sense of security within these hospitals due to having a HITRUST audit report with a bunch of meaninglessness check marks prevents them from actually doing…

Cyber security standards are in place to make the process easier to understand for the non-technical executives, who approve the budgets.

Without the standards the executives don’t know who they should believe, and invariably they believe the guy who sounds and acts like themselves, which means he knows as much about cyber security as the executives.

If you know what you are doing regarding cyber security, AND you are doing all the right things, HITRUST compliance is a cinch.

If you don’t know what you are doing regarding cyber security, HITRUST at least gives you a fighting chance. But then that’s the rub, if you don’t know what you are doing why are you running cyber security.

Re: Hospitals are a weak spot in U.S. cybersecurity

#43
post #38

Recently saw an ad for an IT support position at a hospital. The list of potential hazards in the work environment listed in the ad likely scares off many who have plenty of other employment opportunities. And most hospitals can't jack up the pay to compensate so attracting good talent is going to be a problem.

> And most hospitals can't jack up the pay to compensate I find that hard to believe in an age of $100 saline bags, $20,000 childbirths, and 15-minute-long $500 specialist visits.

Much of that cost has to go to people who cannot pay for healthcare and the massive amounts of bureaucracy managing multiple contradictory medical billing codes by company.

Re: Hospitals are a weak spot in U.S. cybersecurity

#44
post #15

Earlier quoted context omitted.

You plug in the USB key, then you pull out the USB key. The physical security layer at alot of hospitals is almost entirely absent, sadly.

or you swap keyboards with a special keyboard [maybe a pineapple?] , or you can swap ethernet patches around.

Given how terrible a lot of low-end Dell keyboards get after years and years, most people would cheer :)

With the main apps being virtualized, workstations are refreshed less often than they used to be.

Re: Hospitals are a weak spot in U.S. cybersecurity

#47
Healthcare CIO here. This is true. Healthcare is still using paper fax. It has a 30 year old data interchange format that no one really supports because it's more profitable to lock in customers to your EMR. Healthcare is HORRIBLE about upgrading anything, at changing processes, and technological progress in general. Healthcare is VERY backwards from a tech standpoint.

Another problem is that EVERYTHING is custom, we use very, very few off the shelf solutions. Need an EMR? Let's build it in MUMPS, a 51 year old language that originated on the PDP7 and call it a state of the art system like Epic or GE Healthcare. Don't like the terminal interface? Let's slap a GUI on the front that still interacts via TTY on the back end. SQL? Nah. C, C++, or any more modern language with more robust features and way more programmers? Nope.

Now, there are some EMRs and other healthcare-centric apps that are better written, but they're also terrible. Healthcare is a relatively small market, you'll never sell a million units of your app, so you charge out the wazoo for it, get a few health systems on it, and allow they to go crazy with customization to help lock them in. And then you try to add on modern security features on to a system that's been growing for 50 years and it's a nightmare. It's INCREDIBLY common for nurses and doctors to need to have administrator access on their Windows desktops for various apps.

I was about to leave IT in general when a healthcare gig landed on me, and I'm glad it did. I find it very refreshing to be in an industry where it's so far behind that there are mountains of problems to tackle, even if half of them are so stupid it makes me want to cry.

Re: Hospitals are a weak spot in U.S. cybersecurity

#48

It seems the biggest reason they're a weak spot is that the data they store make them a target. Retailers are also weak on security -- really, I wouldn't trust any company that wasn't a specialist in the space, i.e. finance and tech -- but most entities don't know so much about their clientele. Retailers don't need to keep as much info as they do (aside from profit motives), but hospitals probably do, so I can see th…

The data they have are sensitive, but that's just the reason they're a target. They're a weak spot because of poor security practices, which is due to poorly managed IT organizations, which is due largely to the egos of administrative management and poor funding.

Re: Hospitals are a weak spot in U.S. cybersecurity

#49
post #20

It seems that hospitals are overly focused on bullshit security frameworks and box-checking, i.e., HITRUST, which in my experience results in many dollars going to consultants with essentially zero tangible improvement in information security. Worse yet, the false sense of security within these hospitals due to having a HITRUST audit report with a bunch of meaninglessness check marks prevents them from actually doing…

Cyber security standards are in place to make the process easier to understand for the non-technical executives, who approve the budgets. Without the standards the executives don’t know who they should believe, and invariably they believe the guy who sounds and acts like themselves, which means he knows as much about cyber security as the executives. If you know what you are doing regarding cyber security, AND you ar…

And how does this seemingly absurd exercise make hospital information systems more secure? These non-technical executives are also probably not aware of the intricacies of a knee replacements surgery... and shouldn’t be... these execs should be hiring and trusting skilled practitioners both in the operating room and in the information security dept. NOT injecting their ignorance of these disciplines into the process of ensuring good patient outcomes or security of patient information.

Re: Hospitals are a weak spot in U.S. cybersecurity

#50
post #47

Healthcare CIO here. This is true. Healthcare is still using paper fax. It has a 30 year old data interchange format that no one really supports because it's more profitable to lock in customers to your EMR. Healthcare is HORRIBLE about upgrading anything, at changing processes, and technological progress in general. Healthcare is VERY backwards from a tech standpoint. Another problem is that EVERYTHING is custom, we…

Regarding legacy EMRs, are specifications/standards like HL7's FHIR actually gaining any traction and making data interoperability more feasible?
Post reply on HN