7 ms·
Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers
- LoSboccacc 11y agoso who's gonna serve the HIPAA violation sentence?
- viraptor 11y agoWhy are you sure there was a HIPAA violation? HIPAA includes disaster recovery plan, which is what they should be doing now. I guess it wasn't a great plan if it's a week in and they're still dealing with it, but still...
- LoSboccacc 11y agoWell, there are plenty provisions under the security chapter, funnily enough now that I look at it again (been long time) it seems both 'accountability' (tracking every media in and out) and 'protection from malicious software' are not listed as required. duh. The emergency mode operation plan is however listed as required, and this place was basically shut for a week. I remembered it being more stringent that what it really is.
- viraptor 11y agoYes, I'd love for HIPAA to say: if we're talking about a medical centre, you've got to be able to snapshot and reimage within X hours with data loss of less than Y hours. One can dream...
- 15155 11y agoPart of the problem is that HIPAA must be easy for small private practices as well as massive hospitals to follow. Another standard may be needed for the larger businesses.
- technofiend 11y agoTotally agree, but in 2016 that doesn't take much: spin up two instances in different AWS datacenters and fail between them and you have Disaster Recovery. Regularly operate in each datacenter and you have Sustained Resiliency. A small business probably won't have staff to maintain such a solution but surely this is a space for a nice niche startup?
- otterley 11y ago> in 2016 that doesn't take much: spin up two instances in different AWS datacenters and fail between them and you have Disaster Recovery Things that look simple on the surface are often not easy to implement in practice - especially when you're not starting with a green field.
- technofiend 11y agoWhy am I not starting with a greenfield? In my example I did mention a niche start up.
- LoSboccacc 11y agoThat won't work you'd need the whole datacwnter to comply with the security restriction you can't just have the data in a place where you don't know whom can access
- viraptor 11y agoThat's not true actually. You can be HIPAA compliant while storing data on AWS. https://aws.amazon.com/compliance/hipaa-compliance/ https://aws.amazon.com/compliance/hipaa-compliance/
- stcredzero 11y agoPart of the problem is that HIPAA must be easy for small private practices as well as massive hospitals to follow. We're at the point where some company could sell a comprehensive software package for small practices that includes disaster recovery.
- coldcode 11y agoHIPAA does require a lot of security. Having been a HIPAA architect, in reality no one in the industry cares since few are ever even accused of anything much less convicted. It's a toothless gums law.
- DKnoll 11y agoAssuming it's CryptoLocker style malware, they're probably one of the few hospitals fully satisfying the encryption requirements of HIPAA at the moment.
- contingencies 11y agoDoesn't sound like a major hospital. The major hospital in Hollywood is Cedars-Sinai, IIRC.
- bkmartin 11y agoAnd that matters because? Real people needing real treatment are being affected... Major hospital or not.
- contingencies 11y agoIt gives insight in to the probable investment in, maturity and/or scale of infrastructure. Unlike your emotional rah-rah there.
- IvyMike 11y agoHollywood Presbyterian Medical Center has 434 beds and around 1500 employees. That's pretty decent. Cedars-Sinai is indeed about twice the size, but that's mostly because Cedars-Sinai is extraordinarily large.
- klunger 11y agoThis was quite low, even for a ransomware attack. What's next, daycare centers?
- noxToken 11y agoHow do you figure? If I'm targeting digital data for ransom, I'm going after the easiest targets. I don't care if it's hospital records, online obituary guestbook, daycare records, a memorial Facebook account - anything that gives me what I'm looking for. This goes doubly so for how notoriously insecure (relatively speaking) hospitals are.
- tzs 11y agoEven criminals tend to have some moral standards. They are not all complete sociopaths. For instance, go to jail for murdering an adult male and you will be accepted and perhaps even respected by other prisoners. Go to jail for murdering a child and you will be despised and quite possibly abused by the other prisoners.
- stcredzero 11y agoEven criminals tend to have some moral standards. They are not all complete sociopaths. I've met a lot of "techie-trash" who even outwardly portray themselves as sociopathic, as if that made them seem smart and cool. Hell, I've been meeting people like that since the 90's! (They are a very slim minority of the tech populace, but their lack of self-awareness makes them tend to be very visible.)
- rogersmith 11y agoThe internet of things... what could possibly go wrong?
- diego_moita 11y agoVery good point. It reminds me a comment from the Usenet, a long ago: "if your VCR is still blinking 12:00 then Linux is not for you". Most people playing with technology don't know what they're doing. Giving them more power means giving them more danger.
- logicrook 11y agoBasically every piece of hardware with a clock in my house is blinking, yet I'm fine with Linux. The problem isn't that it's too hard to set, but usually they will get unplugged at some point, and you have to set the clocks again. It gets boring very fast.
- ne0n 11y agoSomebody should make a simple alarm clock with wifi to sync time via NTP. I guess once you open that can of worms, most alarm clocks add other features, too.
- viraptor 11y agoYou don't need NTP. There are lots of clocks which can synchronise to radio signal, which is much easier and doesn't require internet connection. (https://en.wikipedia.org/wiki/Radio_clock https://en.wikipedia.org/wiki/Radio_clock)
- gaur 11y agoI'm sure they'll just pass the cost (either of the ransom, or of the missed profits) onto the patients.
- kristiandupont 11y ago..rather than, say, not pay nurses their salaries for a while?
- gaur 11y agoHeaven forbid that top executives ever have to take a pay hit.
- at-fates-hands 11y agoI never understood this attitude. Most executives are either life long doctors, or worked their way up the corporate ladder. I don't understand why people who work hard to get to these positions are suddenly vilified as being somehow overpaid? Take for example the CEO at Cedars-Sinai Health System in LA. They guy has held his CEO position for 17 years and worked his way up thought the ranks. He also went to school and got an undergrad and masters degree. He started in 1979 as an assistant admin and took the top job in 1994. So after 15 years of working his way up to CEO, he's should somehow not be paid in accordance with what other Health Care CEO's are getting paid? If you want a villain, look at the system that's broken, or the government regulations, but seriously, get off the executives back for fucks sake. They aren't "gifted" CEO spots, they had to work hard to get there, and most have done amazing things for the industry.
- TACIXAT 11y agoI think the idea is that they can afford to take a hit on their income. A nurse or patient doesn't have as much flexibility.
- qbrass 11y agoIt's Hollywood, option the movie rights. Next summer we'll see how many explosions can be worked into a movie "based on a true story" about cybercrime.
- bawana 11y agoExactly what happened? Most hospitals use proprietary electronic medical record systems. These are layered constructs of different networks requiring different passwords and VPNs for their different functions. Is there an actual url that one can visit to verify this? Did the internet archive capture this in a snapshot I can see? Or is this smack that a neighboring hospital is pushing to capture market share in this era of declining reimbursements and increasing regulation?
- FLUX-YOU 11y agoProbably locked down the physical machines at the hospital. >Most hospitals use proprietary electronic medical record systems. These are layered constructs of different networks requiring different passwords and VPNs for their different functions. That's idealistic. Usually they're giant pieces of shit.
- bawana 11y agoSo really the data is unaffected. Just the OS on the client machines is borked and throwing up a scare screen. If that is the case, they can 'just' reimage the machines from backups. I agree, the EMRs are repurposed shit , but honed to an incredibly complex and fine edge.
- heinrichf 11y agoVery interesting article about the subject from November 2015: It’s Way Too Easy to Hack the Hospital, http://www.bloomberg.com/features/2015-hospital-hack/ http://www.bloomberg.com/features/2015-hospital-hack/
- CaptSpify 11y agoHaving worked in hospitals doing network security: They are terribly insecure. They really are a prime example of bad bureaucracy and proprietary software making everything horrible, despite the best of intentions. YMMV of course.
- enraged_camel 11y agoThis goes beyond network security. Most hospital systems, including hardware and software, are insecure. One of the main reason for this is that hospital staff, especially doctors and nurses, tend to be atrociously bad at technology. One hospital we used to work with had removed passwords on their EMR software for all users because the chief of surgery always forgot his. Their reasoning was that inability to remember passwords slowed people down, and the EMR software was "internal anyway" so what could be the worst case scenario of not having passwords?
- stcredzero 11y agoOne of the main reason for this is that hospital staff, especially doctors and nurses, tend to be atrociously bad at technology. I remember that med students were early adopters of ePocrates in the Palm PDA era. I think it's more that they are atrociously bad at technology, unless it's particularly useful to them. inability to remember passwords slowed people down It would slow people down a lot. Someone needs to sell some sort of zero effort authentication technology for hospitals. (One where a supervising nurse could quickly auth the chief of surgery, because that sort of guy is going to forget his token/device.)
- dawnbreez 11y ago
- maratc 11y agoSo instead of targeting random people in opportunistic attacks, the malware writers had a very clear target here. It's like "spearansomware". I only wonder why it took them so long to get to this idea.
- ianlevesque 11y agoIt didn't, they've been doing this to police departments for nearly a year at least. http://www.darkreading.com/attacks-breaches/police-pay-off-ransomware-operators-again/d/d-id/1319918 http://www.darkreading.com/attacks-breaches/police-pay-off-r...
- newobj 11y agoFrackin' toasters. The old man told us to keep those computers off the network.
- abrkn 11y ago"They're through the fourth firewall!" https://www.youtube.com/watch?v=cZnhzAo2Ozk https://www.youtube.com/watch?v=cZnhzAo2Ozk
- JohnLeTigre 11y agowow, talk about a lack of morals, I wonder how many years he would get if he is caught for endangering so many lives.
- sergers 11y agonot sure if they are being specifically targeted, or hospital networks are easy targets, but i work with a vendor who supports this hospital. this is the 3rd major healthcare org hit with this in like past 3 weeks. last one just got hit last week. RIS/HIS/PACS/EHR/any systems all hit, with like 80-90% of network equipment compromised