Live data from Hacker News

FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

krebsonsecurity.com

91–100 of 357 posts

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#91
post #82
post #77

Earlier quoted context omitted.

If US citizens die due to this, I am 100% down with bringing the full might of our military down on the state/group that did this. No mercy.

what if the state actor who did this has nuclear weapons?

Who? I don’t think Russia is killing off senior citizens. North Korea? Nuke the shit out of them.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#92
As diabolical as this is, you wouldn't really need state level actions to take down hospitals.

Anyone who has been to one in the last year, pre-covid even, understands the ferris wheel of nurses and doctors that churn through the butter of what goes on there.

These weren't exactly hardened targets to begin with.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#93
post #83

Earlier quoted context omitted.

Health insurance premiums are just total healthcare costs for the insured lives plus x% for operations of the health insurance company. If all hospitals have to raise prices to meet IT costs, then presumably the total cost of healthcare for the insured lives goes up, and hence the health insurance premium has to go up. So yes, typically if your vendor's suppliers increase price, then your vendor will increase their p…

> health insurance is already a low margin business I’d like to know much, much more about this statement.

[deleted]

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#94
post #83

Earlier quoted context omitted.

> health insurance is already a low margin business I’d like to know much, much more about this statement.

By the ACA law health insurance companies have to pay out at least 80% of premiums on claims. The cost of running the company and any profit has to come out of the other 20%. 5% of billions of dollars is huge in absolute figures but as a percentage falls in line with other industries.

To fix medical service affordability we need to bring down the cost of the services instead of expecting significantly more efficient insurance plans. We can’t insure away high costs. They just pass through the costs via premium and deductible increases. Even if health insurers were nonprofits that would only directly save us 5%. High deductibles encouraging shopping around but price discovery is very limited as even doctors don’t know how much a service costs. Focusing on price alone is an issue as people don’t know medicine and are unable to evaluate quality so they end up giving five stars for having a private room or suck up staff. What ends up happening is the not well off or frugal avoid care until there’s an undeniable problem. Others consider consuming medical services a dignity not a price and will never give up their low co-pay plans.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#95

Earlier quoted context omitted.

Do you blame the dev? Do you blame the HR system that hired them? How about the manager that pushed them too much? What about his manager? Is it the VP of IT's fault, even if he didn't know the technical specifics? Nothing is any one person's fault. Blame is a stupid waste of time.

At some point we will sit down and recognize that calling programmers "engineers" was a mistake. True engineers make guarantees within clearly specified limits and take on liability for those guarantees. Modern technology companies claim many things while owning little, if any, responsibility.

I agree, although I also think civil engineers who miss things (Elliot Lake mall collapse, for example) are mostly just scapegoats and don't deserve to shoulder so much of the blame.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#96
post #10

Bad health IT is a public health issue. Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.

My hospital offline for a whole week because they got hit by a ransomware attack, and they use Epic. I asked someone I knew at Epic what she knew about it, and confirmed that my hospital was up-to-date on the latest version of their software and following most of their security protocols. My initial thought was they had weak IT security and now I’m not so sure.

Epic is an on-premise dumpster fire, so I'm not surprised. Plus there are many attack vectors besides the EHR. I assume they probably had access to services cut off rather than having patient data held up for ransom.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#97

Is the US ransom-ware-ing Russia? Or anything similar?

Several years ago the Obama admin took down the entire financial and banking sector of Russia after the iirc early signs of election tampering were shown in 2016

But Ryuk is not the Russian government anyways

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#98
post #83

Earlier quoted context omitted.

> health insurance is already a low margin business I’d like to know much, much more about this statement.

By the ACA law health insurance companies have to pay out at least 80% of premiums on claims. The cost of running the company and any profit has to come out of the other 20%. 5% of billions of dollars is huge in absolute figures but as a percentage falls in line with other industries.

It also means that the easiest way to earn more profit is for healthcare costs (the 80%) to be higher. Kind of a perverse incentive in the long run.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#100
post #75

If this attack results in actual loss of life, I firmly believe the US should ensure that there are real-world physical consequences for these criminals. They cannot be described as anything less than the worst humanity has to offer. A failure to respond with meaningful and severe consequences for those responsible (assuming this is attack can be confidently attributed to a particular threat actor) opens the floodgat…

Floodgates... TGD

You're talking about the mass murder of easily 20 million people.
Post reply on HN