Live data from Hacker News

Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

csoonline.com

1–10 of 50 posts

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#3

so who's gonna serve the HIPAA violation sentence?

Why are you sure there was a HIPAA violation? HIPAA includes disaster recovery plan, which is what they should be doing now.

I guess it wasn't a great plan if it's a week in and they're still dealing with it, but still...

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#4
post #3

so who's gonna serve the HIPAA violation sentence?

Why are you sure there was a HIPAA violation? HIPAA includes disaster recovery plan, which is what they should be doing now. I guess it wasn't a great plan if it's a week in and they're still dealing with it, but still...

Well, there are plenty provisions under the security chapter, funnily enough now that I look at it again (been long time) it seems both 'accountability' (tracking every media in and out) and 'protection from malicious software' are not listed as required. duh.

The emergency mode operation plan is however listed as required, and this place was basically shut for a week.

I remembered it being more stringent that what it really is.

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#5
post #3

Earlier quoted context omitted.

Why are you sure there was a HIPAA violation? HIPAA includes disaster recovery plan, which is what they should be doing now. I guess it wasn't a great plan if it's a week in and they're still dealing with it, but still...

Well, there are plenty provisions under the security chapter, funnily enough now that I look at it again (been long time) it seems both 'accountability' (tracking every media in and out) and 'protection from malicious software' are not listed as required. duh. The emergency mode operation plan is however listed as required, and this place was basically shut for a week. I remembered it being more stringent that what i…

Yes, I'd love for HIPAA to say: if we're talking about a medical centre, you've got to be able to snapshot and reimage within X hours with data loss of less than Y hours. One can dream...

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#9
post #7

Doesn't sound like a major hospital. The major hospital in Hollywood is Cedars-Sinai, IIRC.

And that matters because? Real people needing real treatment are being affected... Major hospital or not.

It gives insight in to the probable investment in, maturity and/or scale of infrastructure. Unlike your emotional rah-rah there.
Post reply on HN