Live data from Hacker News

Hospitals are a weak spot in U.S. cybersecurity

axios.com

61–70 of 166 posts

Re: Hospitals are a weak spot in U.S. cybersecurity

#61
post #2

waiting rooms are a gaping hole. nobody seems to see a problem with blabbing out your final 4 and first,last name when thier at a desk in a room full of whoever walked in and sat down. un protected desktops are another issue, there is a tide of duties and an attacker can pattern the staff and get a good idea when they will have time to do an inside job of some sort.

Same thing for picking up prescription at CVS/Walgreens.

They make you verify your phone number and address. Every. Single. Time. In public.

It's a shame how silly it all is.

Re: Hospitals are a weak spot in U.S. cybersecurity

#62
post #47

Healthcare CIO here. This is true. Healthcare is still using paper fax. It has a 30 year old data interchange format that no one really supports because it's more profitable to lock in customers to your EMR. Healthcare is HORRIBLE about upgrading anything, at changing processes, and technological progress in general. Healthcare is VERY backwards from a tech standpoint. Another problem is that EVERYTHING is custom, we…

There are new data exchange protocols/formats which help to exchange between parties. They have been defined 2000+ so they are quite modern.

The only problem is that is such a diverse way the healthcare providers are implementing it. So you end up having provider specific code :)

Re: Hospitals are a weak spot in U.S. cybersecurity

#63
post #36

Given the state of cybersecurity right now, is there any organization or domain AT ALL which is strong and model-worthy when it comes to cybersecurity?

Big tech. Google, especially.

To be honest, Google is the last company I want handling my health data. If you don't check the right boxes, it could end up being "anonymized", and sold off.

Re: Hospitals are a weak spot in U.S. cybersecurity

#64
So are vet hospitals. At this very moment there's a chance you'll walk into one that has fallen back to paper records and billing due to a continent wide ransom ware attack.

https://www.reddit.com/r/msp/comments/dnd7aq/ransomware_atta...

From that thread: Avimark is an old style load the EXE from a share program with a flat file structure for the data. Most clinics are not in a domain, just workgroup, and the share is read/write access for Everyone. So, yeah.

Re: Hospitals are a weak spot in U.S. cybersecurity

#65
post #63
post #36

Earlier quoted context omitted.

Big tech. Google, especially.

To be honest, Google is the last company I want handling my health data. If you don't check the right boxes, it could end up being "anonymized", and sold off.

Privacy is not security

Re: Hospitals are a weak spot in U.S. cybersecurity

#66
post #47

Healthcare CIO here. This is true. Healthcare is still using paper fax. It has a 30 year old data interchange format that no one really supports because it's more profitable to lock in customers to your EMR. Healthcare is HORRIBLE about upgrading anything, at changing processes, and technological progress in general. Healthcare is VERY backwards from a tech standpoint. Another problem is that EVERYTHING is custom, we…

Does Epic use MUMPS? I know a lot of professional nurses and the rancor around Epic is off the charts.

Re: Hospitals are a weak spot in U.S. cybersecurity

#67
post #20

It seems that hospitals are overly focused on bullshit security frameworks and box-checking, i.e., HITRUST, which in my experience results in many dollars going to consultants with essentially zero tangible improvement in information security. Worse yet, the false sense of security within these hospitals due to having a HITRUST audit report with a bunch of meaninglessness check marks prevents them from actually doing…

Cyber security standards are in place to make the process easier to understand for the non-technical executives, who approve the budgets. Without the standards the executives don’t know who they should believe, and invariably they believe the guy who sounds and acts like themselves, which means he knows as much about cyber security as the executives. If you know what you are doing regarding cyber security, AND you ar…

I think they are intended to be helpful, but they are adopted as CYA that have the side benefit of improving security.

Re: Hospitals are a weak spot in U.S. cybersecurity

#68
post #47

Healthcare CIO here. This is true. Healthcare is still using paper fax. It has a 30 year old data interchange format that no one really supports because it's more profitable to lock in customers to your EMR. Healthcare is HORRIBLE about upgrading anything, at changing processes, and technological progress in general. Healthcare is VERY backwards from a tech standpoint. Another problem is that EVERYTHING is custom, we…

People need to stop hating on fax. Hospitals still use fax because it is a much more punishable crime to tap phone lines which requires physical access, as opposed to a server that could be infected from a hacker halfway across the world.

I’m willing to bet that most digital PBXs out there could be infected by a hacker from halfway across the world too.

Re: Hospitals are a weak spot in U.S. cybersecurity

#69

So are vet hospitals. At this very moment there's a chance you'll walk into one that has fallen back to paper records and billing due to a continent wide ransom ware attack. https://www.reddit.com/r/msp/comments/dnd7aq/ransomware_atta... From that thread: Avimark is an old style load the EXE from a share program with a flat file structure for the data. Most clinics are not in a domain, just workgroup, and the share i…

It's worse than that thread reveals. NVA was hit by a ransomware attack in May. They're now in a second attack that began in late October (ongoing). The latest one was described by CIO Joe Leggio as a "coordinated and sophisticated" attack in an internal email. He said it was designed to breach the NVA system specifically and that the attackers had three separate entry points. Only this week did NVA deploy endpoint security software to every computer in their 500+ veterinary practices.

Note: Avimark itself is not at fault here. The Avimark issue that the practices are having is related to NVA not having a solid DR plan with working backups. Part of the problem there is that because of Avimark's architecture, most practices have an on-prem server that each workstation RDPs into for using Avimark. Because this equates to 500 or so Avimark SQL Server instances spread around the United States, it's perhaps not surprising that NVA's unsophisticated IT department did not have working backups for each instance.

Post reply on HN