Live data from Hacker News

A billion medical images are exposed online

techcrunch.com

61–70 of 201 posts

Re: A billion medical images are exposed online

#61
Fun experiment: use google maps API to search a major US metro area for medical practices. Pick out any websites that don't use TLS. Crawl them for HTML forms that include common PHI keywords. You'll find a lot. Those same practices are usually going to have a whole mess of more serious HIPAA issues.

Re: A billion medical images are exposed online

#62

Earlier quoted context omitted.

Theoretically, there would/should be a unified system and standards applied. Realistically, it'll probably still be first attempted through vendors with exclusive contracts, which is basically the current system but with extra steps.

Theoretically, there would/should be a unified system and standards applied. So, a nice convenient one stop shop for hackers. I'd rather a thief had to break into a thousand homes than one great big home.

One stop shop? Even with an assumed "unified system" there is absolutely no way that even an incompetent group of IT engineers would be able to construct a single unified network with a single doorway into it to make a "one stop shop experience." It would still be "breaking into a thousand homes", but at least the difference is -- given a unified set of controls -- that reconciliation of a breach could be automated.

Re: A billion medical images are exposed online

#63

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

A brand new account posting scathing anti-government anti-regulation content? HIPAA and HITECH and the other legislation that you're likely referring to pushed a stagnant industry in the right direction. Yes there is pain with growth but patients are far better off for it, which is what the end goal was.

Yes, because I am a lurker that was moved to post by the degree to which I disagreed with the article. Please restrict yourself to actually arguing with the content of my posts, and not going ad hominem. It's both against the rules of HN, and just shitty.

You say "pushed a stagnant industry", I say "hostility to small practices." Large hospitals were already moving onto EMR to better handle the volume of their data, if not already having done so. It's small practices that couldn't afford things like EPIC, and were forced to move onto free, ad-revenue-driven crap like PracticeFusion that just made everything slower and worse, without improving shit for patients.

Are some patients better off for it? I think so. I appreciate web portals, which wouldn't have existed otherwise. I don't appreciate the death of small practices, the majority of whom are now selling out at cost to large hospital chains.

Re: A billion medical images are exposed online

#64

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

> no real ROI to be seen from it.

I just did a brief Google, and the situation seems to be the same as always - there isn’t a clear win financially when a PACS is installed. They are expensive to buy, to run and to maintain and the gains are often hard to measure financially. Having a minimum wage worker sort old films and carry them to where they are needed was cheap compared to the wages and hardware a large hospital needs to pay for when a large PACS goes in.

The number of people who miss hard copy film must be very small however, that world was archaic.

Re: A billion medical images are exposed online

#65

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

People are constantly targeting every aspect of the physician workflow, from CMS and private payors constantly changing their documentation requirements (which differ between payors and CMS, and results in hospitals trying to teach their docs to document everything to meet everyone's requirements - which are made intentionally lengthy and obtuse so as to justify denials of payment), quality improvement people and vendors populating the EMR with shit-tons of Alerts! meant to prevent medical errors (but, due to specific medical contexts justifying deviations from the textbook standard, the false positives vastly outweigh true positives, to the point where the alerts as a whole are utterly ignored), etc.

It's easy to complain doctors resist (this particular workflow change), which is SO important because it affects PATIENT LIVES (because it's in the healthcare setting, so EVERYTHING DOES) damn entitled doctors. Then recall that every single time a doctor asks a nurse to do something that nurse will say "oh, just enter a communication order." And because your security set up your RFID to only work on a computer where you've already logged in earlier, and you're running around the hospital constantly, those badges aren't worth shit >half the time.

It's easy to complain about doctors' resistance to various evolutions of their digital workflow, until you realize that nearly every evolution adds complexity and time-burden to their workload in a way that does not directly improve patient care, but slows down their work, increases complexity (which does adversely impact patient care), and lengthens their workday (because their patient workload isn't reduced in the slightest by this.) I don't know a single doc that doesn't do significant unpaid after-hours work catching up to their digital bullshit; you also would resist non-mission-critical additions to your unpaid workload.

It's easy to treat physicians as entitled and resisting "just to resist", rather than understanding that the physician workflow is constantly changing, from every possible angle, and most often for reasons wildly unrelated to the immediate task of "taking care of the patient in front of me". You'd resist under those circumstances, too.

There's a reason about half of physicians nationwide (https://www.medscape.com/slideshow/2019-lifestyle-burnout-de...) are burned out. HALF. That's what happens when your ability to do your job is constantly fucked with. Perhaps you should consider what that means, and how that relates to what you're saying, rather than asserting doctors are just too damn self-important to change.

Re: A billion medical images are exposed online

#66

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

Inasmuch as “Caveat Emptor” is the Latin to live by, physicians and hospitals are indeed responsible for making sure what they’ve just bought is safe and fit for purpose. Especially with HIPAA et al already breathing down their necks.

The big problem is that tech grifters, just like AltMed scamsters, are just way quicker and better at burying all their shit than surgeons and scientists are at digging it out again. And, to be fair, doctors do already have far more pressing things to be digging out: wood spales, fence railings, guinea worms, and so on. Hence the need to hire in [ostensible] specialists in the first place.

Still, be consoled that us countries with socialized heathcare are just as adept at Medical IT disasters as yours are. :/

--

“A lie can travel halfway around the world before the truth can get its boots on.” Of course, this was before we invented the networked computer.

Re: A billion medical images are exposed online

#67

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

It goes both ways. I keep telling the IT people at my hospital to stop using SMS 2-factor and they blow me off and treat me like an idiot.

Anyway, ‘Doctors’ are a pretty diverse bunch, and most of them aren’t arrogant porn-fiends.

Re: A billion medical images are exposed online

#68

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

This was my immediate thought at the headline, doctors-who-what-now? This feels informed from the technology side, and profoundly ignorant of how health care IT actually works (especially in the United States).

When it comes to healthcare, everything is always the doctor's fault. It's convenient to have a single target to blame for everything that goes wrong in the industry. Never mind that most physicians are just employees, with plenty of layers of management, in massive organizations, with extremely heavy regulatory oversight.

If an organization that runs three hospitals can't put together the IT to secure their PACS system with a decent password, that's the fault of the physician about as much as it's the fault of the nurse, the janitor, the cafeteria chef, etc.

WTF is with people blaming doctors for literally everything related to healthcare? Do they not understanding we haven't been in charge of anything for a couple of decades now? Since the combined rise of HMOs and Medicare/Medicaid, and the massive hospital M&A splurge, we're just line workers. We try to do our best by patients, but we ain't in charge of anything.

Re: A billion medical images are exposed online

#69

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

You're right, this is a very irritating take.

From what I understand these DICOM-devices are insecure by default, you can just connect to them and download data, and they expect their users to make them secure with network separation etc. That's not a realistic expectation if your customers aren't IT security professionals. And there's no reason to create such a flawed design, a simple password would be a huge improvement.

In such a case the blame should fully go to the vendor.

Re: A billion medical images are exposed online

#70

Earlier quoted context omitted.

This seems like a caricature or an exception. Doctors are very aware of HIPAA (and the equivalent in every other country), and the professional and monetary costs of non-compliance. Doctors didn't set up these systems. Doctors didn't expose them to the internet. As the other post said, vendors did. If those vendors couldn't properly communicate the needs, that's their problem. What I think is a more rational explanat…

I'm a student doctor with a CS undergrad. I'm constantly gobsmacked by how horrible the computer systems doctors are forced to use are. They're pretty much abusive to use. The hours and hours of physician time that are thrown away into mindless box-ticking, copy-pasting, button-pushing, and general head-banging is astounding. If doctors are resistant to new IT hurdles it is, at least in part, because they're already…

Yep. Never blame users for raging at the system until you understand the system as well as they do. Techies have it easy: they only have one job and that’s all they ever do. It looks very different from the other side.

(Protip: The key to delivering successful software is not to learn programming, it is to learn your users.)

(Oh, and good luck with your medical studies; world needs good Renaissance [Wo]Men now more than ever.)

Post reply on HN