Live data from Hacker News

Hospitals are a weak spot in U.S. cybersecurity

axios.com

71–80 of 166 posts

Re: Hospitals are a weak spot in U.S. cybersecurity

#71
post #47

Healthcare CIO here. This is true. Healthcare is still using paper fax. It has a 30 year old data interchange format that no one really supports because it's more profitable to lock in customers to your EMR. Healthcare is HORRIBLE about upgrading anything, at changing processes, and technological progress in general. Healthcare is VERY backwards from a tech standpoint. Another problem is that EVERYTHING is custom, we…

People need to stop hating on fax. Hospitals still use fax because it is a much more punishable crime to tap phone lines which requires physical access, as opposed to a server that could be infected from a hacker halfway across the world.

Fax is odd, it was a fantastic thing when it first came about, and it has some desirable properties.

- It's direct point to point communication (over a network)

- The transport network is dedicated and not open to anyone and covered by quite strong laws in many countries

- It's easy to see the history of communications

- It's easy to see if the other end successfully received something

- It's relatively standardized and ubiquitous ( in health )

Email would be the closest thing, but it doesn't have all the advantages, and the extra add ons that would make it better (like encryption, delivery receipt, digital signatures) are not standardized and/or ubiquitous ( and often hotly argued about )

So fax is the lowest common denominator, that, if it was proposed today, would not be accepted for many of its disadvantages, but it's now hard to find a way to replace it.

Re: Hospitals are a weak spot in U.S. cybersecurity

#72
post #38

Recently saw an ad for an IT support position at a hospital. The list of potential hazards in the work environment listed in the ad likely scares off many who have plenty of other employment opportunities. And most hospitals can't jack up the pay to compensate so attracting good talent is going to be a problem.

> And most hospitals can't jack up the pay to compensate I find that hard to believe in an age of $100 saline bags, $20,000 childbirths, and 15-minute-long $500 specialist visits.

Earlier in my career I interviewed for a health IT job that was basically a director level position. The pay ended up being less than I was making as a government employee for a smaller scoped job. The government gig was probably less than an intern makes at a FAANG.

In medicine, doctors are king. Everyone else is a peon.

Re: Hospitals are a weak spot in U.S. cybersecurity

#73
post #47

Healthcare CIO here. This is true. Healthcare is still using paper fax. It has a 30 year old data interchange format that no one really supports because it's more profitable to lock in customers to your EMR. Healthcare is HORRIBLE about upgrading anything, at changing processes, and technological progress in general. Healthcare is VERY backwards from a tech standpoint. Another problem is that EVERYTHING is custom, we…

People need to stop hating on fax. Hospitals still use fax because it is a much more punishable crime to tap phone lines which requires physical access, as opposed to a server that could be infected from a hacker halfway across the world.

Fax machines are just as insecure as that server. Last year taking over a network using just a fax number was demonstrated:

https://research.checkpoint.com/sending-fax-back-to-the-dark...

Re: Hospitals are a weak spot in U.S. cybersecurity

#74

Recently saw an ad for an IT support position at a hospital. The list of potential hazards in the work environment listed in the ad likely scares off many who have plenty of other employment opportunities. And most hospitals can't jack up the pay to compensate so attracting good talent is going to be a problem.

What were the hazards that you saw? Just curious

It's been over a year but I seem to recall potential exposure to radiation, infectious disease, and chemicals being on the list. It was quite long. I'm guessing the legal department added it for all positions in the hospital.

Re: Hospitals are a weak spot in U.S. cybersecurity

#75
post #47

Healthcare CIO here. This is true. Healthcare is still using paper fax. It has a 30 year old data interchange format that no one really supports because it's more profitable to lock in customers to your EMR. Healthcare is HORRIBLE about upgrading anything, at changing processes, and technological progress in general. Healthcare is VERY backwards from a tech standpoint. Another problem is that EVERYTHING is custom, we…

How much end to end efficiency do you think a proper/average IT healthcare system would bring ?

The amount of complexity that it would be necessary to simplify and approximate would make any answer to this question meaningless.

And it's not only an IT systems problem. It's a comprehensive systems problem.

Which includes training, and counterparty expectations, and manual data entry, etc.

Re: Hospitals are a weak spot in U.S. cybersecurity

#76
post #45
post #36

Earlier quoted context omitted.

Big tech. Google, especially.

How so?

In the wake of discovery of attacks by China[0] and the NSA[1] Google has adopted a nation-state actor threat model and a siege mentality around data access and encryption.

[0] https://en.wikipedia.org/wiki/Operation_Aurora

[1] https://www.washingtonpost.com/world/national-security/nsa-i...

Re: Hospitals are a weak spot in U.S. cybersecurity

#77

It's really tough. You have a function which is viewed purely as a cost center; you have a totally porous environment where you're required to admit tons of minimally-verified people into confidential spaces; staff and affiliates need different levels of access from all over the world; there are critical availability demands where temporary denial of service for security reasons is unacceptable; device development is…

Oh, and you're ultimately sourcing truth from people who are minimally trained on (and have minimal time for training on) the system.

Because they've spent the last couple decades focused on medical training.

Re: Hospitals are a weak spot in U.S. cybersecurity

#78
post #75

Earlier quoted context omitted.

How much end to end efficiency do you think a proper/average IT healthcare system would bring ?

The amount of complexity that it would be necessary to simplify and approximate would make any answer to this question meaningless. And it's not only an IT systems problem. It's a comprehensive systems problem. Which includes training, and counterparty expectations, and manual data entry, etc.

I'd wish hard to have a peek in these projects.

Re: Hospitals are a weak spot in U.S. cybersecurity

#79
post #47

Healthcare CIO here. This is true. Healthcare is still using paper fax. It has a 30 year old data interchange format that no one really supports because it's more profitable to lock in customers to your EMR. Healthcare is HORRIBLE about upgrading anything, at changing processes, and technological progress in general. Healthcare is VERY backwards from a tech standpoint. Another problem is that EVERYTHING is custom, we…

Does Epic use MUMPS? I know a lot of professional nurses and the rancor around Epic is off the charts.

Epic uses MUMPS, but a nurse would not typically be interacting with that side of it...

Re: Hospitals are a weak spot in U.S. cybersecurity

#80
post #50
post #47

Healthcare CIO here. This is true. Healthcare is still using paper fax. It has a 30 year old data interchange format that no one really supports because it's more profitable to lock in customers to your EMR. Healthcare is HORRIBLE about upgrading anything, at changing processes, and technological progress in general. Healthcare is VERY backwards from a tech standpoint. Another problem is that EVERYTHING is custom, we…

Regarding legacy EMRs, are specifications/standards like HL7's FHIR actually gaining any traction and making data interoperability more feasible?

In my world they sure are. Want health records on your iPhone? Well that comes via FHIR. You can even see the FHIR resource JSON in the Health app.

But there are many systems in a hospital. And as EuphoricEmu pointed out within the hospital, admits, discharges and movements throughout the hospital are still done via HL7v2 (a delimited and structured format).

Additionally, I would absolutely NOT build a new system on HL7v2 at this point in time. I would only use it to integrate with existing systems.

Also, I do know of EHR systems that use FHIR for their internal data storage format.

Post reply on HN