Live data from Hacker News

Hospitals are a weak spot in U.S. cybersecurity

axios.com

1–10 of 166 posts

Re: Hospitals are a weak spot in U.S. cybersecurity

#2
waiting rooms are a gaping hole. nobody seems to see a problem with blabbing out your final 4 and first,last name when thier at a desk in a room full of whoever walked in and sat down.

un protected desktops are another issue, there is a tide of duties and an attacker can pattern the staff and get a good idea when they will have time to do an inside job of some sort.

Re: Hospitals are a weak spot in U.S. cybersecurity

#4
post #2

waiting rooms are a gaping hole. nobody seems to see a problem with blabbing out your final 4 and first,last name when thier at a desk in a room full of whoever walked in and sat down. un protected desktops are another issue, there is a tide of duties and an attacker can pattern the staff and get a good idea when they will have time to do an inside job of some sort.

As with most environments, there’s a lot of trust based in a hospital running successfully.

At least they have their own on-site security that’s experienced in taking people down.

I continue to believe the real threats are actual insiders and remote attacks.

Dunno how far someone will get with a USB key versus sending everyone a plausible email.

Re: Hospitals are a weak spot in U.S. cybersecurity

#5
post #3

The central IT function in a US hospital also usually has little organizational power and funding. Admissions, radiology, etc, buy whatever hardware and software they want, and the underfunded IT department has to figure it out.

Not to mention that network security necessarily means limiting access, and getting that wrong in a hospital context can lead to wasted minutes and hours that can cause harm to somebody.

Re: Hospitals are a weak spot in U.S. cybersecurity

#6
post #2

waiting rooms are a gaping hole. nobody seems to see a problem with blabbing out your final 4 and first,last name when thier at a desk in a room full of whoever walked in and sat down. un protected desktops are another issue, there is a tide of duties and an attacker can pattern the staff and get a good idea when they will have time to do an inside job of some sort.

As with most environments, there’s a lot of trust based in a hospital running successfully. At least they have their own on-site security that’s experienced in taking people down. I continue to believe the real threats are actual insiders and remote attacks. Dunno how far someone will get with a USB key versus sending everyone a plausible email.

>Dunno how far someone will get with a USB key versus sending everyone a plausible email.

Insiders still can be threats. There was a machine that was deployed in a hospital for clinical imaging that some rad tech who guessed the administrator password put folding@home on without telling anyone which crippled that machine's ability to perform its function.

Re: Hospitals are a weak spot in U.S. cybersecurity

#7
post #2

waiting rooms are a gaping hole. nobody seems to see a problem with blabbing out your final 4 and first,last name when thier at a desk in a room full of whoever walked in and sat down. un protected desktops are another issue, there is a tide of duties and an attacker can pattern the staff and get a good idea when they will have time to do an inside job of some sort.

As with most environments, there’s a lot of trust based in a hospital running successfully. At least they have their own on-site security that’s experienced in taking people down. I continue to believe the real threats are actual insiders and remote attacks. Dunno how far someone will get with a USB key versus sending everyone a plausible email.

These aren't mutually exclusive vectors of attack, they all need to be addressed.

Re: Hospitals are a weak spot in U.S. cybersecurity

#8
Possibly in one part because I see people on freelancer marketplaces making software for hospitals, with job budgets of a couple hundred bucks. I'm ok with freelancers in general, but I feel that integrating code from disparate small jobs while keeping security in mind isn't gonna be so simple.

Re: Hospitals are a weak spot in U.S. cybersecurity

#9
post #3

The central IT function in a US hospital also usually has little organizational power and funding. Admissions, radiology, etc, buy whatever hardware and software they want, and the underfunded IT department has to figure it out.

This may vary by hospital, but in general many hospital IT staff tend not to be very good with computers, from my experience. Many are more focused on business/bureaucracy, or maybe they're just unskilled. I don't mean to attack their character, but instead to make the point that some very unqualified people are in charge of very important systems.

(Edit: My first job was hospital IT for a few months, and my boss was actually a pretty skilled programmer with a good grasp on security. So there are definitely exceptions.)

I imagine not many hospitals hire security talent either, or that they do much security beyond the "change your password" email every 6 months. Oh, and doctors/nurses/etc tend to ignore those emails.

Post reply on HN