3 ms·
"Victims can easily spend thousands of dollars and hundreds of hours simply trying to put their life back together." While that may or may not be true, this pa
by jonjlee 9y ago
"Victims can easily spend thousands of dollars and hundreds of hours simply trying to put their life back together."
While that may or may not be true, this particular post certainly is nothing more than a piece of propaganda. For example, HIPAA regulations require PHI to be encrypted in transit and at rest, contrary to what this post tries to scare readers with. In general, healthcare organizations tend towards being extraordinarily conservative when it comes to security and require providers to jump through unnecessary hoops tO access data. Citrix seems to be deployed widely across hospitals, which is a pretty blunt security iinstrument for things like even access to email. It's true that there is tons of work to be done to improve security and access to healthcare data, but for pretty much none of the reasons stated here. Lastly, how exactly is patient data a virtual gold mine? Given the risk of dealing with federally protected data, is there a marketplace for actually selling stolen PHI for a reasonable return?
- nkw 9y ago>"For example, HIPAA regulations require PHI to be encrypted in transit and at rest" Really? What about all those records faxed back and forth between health care providers. >"Lastly, how exactly is patient data a virtual gold mine" Take an antidepressant? Have an STD? Abortion? Treated by a psychiatrist? I would imagine a lot of people would pay a bitcoin or two not to have those issues become public.
- roywiggins 9y agoFaxes are are a special case, and are exempt, I think. Plaintext email, for instance, would not ordinarily be allowed to contain patient health information.
- deleted 9y ago[deleted]
- dragonwriter 9y agoFaxes and phone calls are, generally, explicitly excluded from the definition of electronic media under HIPAA.
- emodendroket 9y agoHIPAA doesn't really make those sorts of specific technical recommendations.
- ch4s3 9y agoI work in the space, and can say for certain that while everyone talk a good game about their encryption, and compliance policies, the reality is often a bit different.
- cnnsucks 9y agoIndeed. If you believe HIPAA has ensured everything is encrypted you've been suckered by the potemkin village that is EHR compliance pencil whipping. The work is farmed out to all sorts of fly-by-night shops that are expert at passing the audits and filling out the applications that make the grant money flow and get the necessary boxes ticked with the feds.
- ch4s3 9y agoIt kind of depends, I think. I work with some really great companies who take this stuff very seriously and do a really good job. There is however a gigantic attack surface. The vulnerability to plain old spear phishing alone is gigantic. Additionally a lot of hospitals have too few, poorly paid and trained IT staff running their in house infrastructure. This is a big mistake, but they think doing it this way is more secure. And, as you suggest, there are some bad actors. Fortunately there's been a lot of consolidation on the EHR side that's wiped out a lot of the fly by night operations. Third party contractors, are of course another story and a mixed bag.
- chapium 9y agoAnyone with exposure to the industry and has an ounce of sense would realize there are a ton of security vulnerabilities. Patchwork implementation of encryption is just one of many ails.
- metaobject 9y agoA few years ago I had my identity stolen by someone from a large hospital on the east coast. They charged about $20K of merchandise, opened about 6-7 credit cards and failed to open a few more before I started getting bills in the mail. It took me dozens of hours and weeks on the phone to get things cleared up. They caught the person on Target surveillance camera and finally arrested and charged them at the federal level. There were ~40 other people who had their info stolen as well. They went to prison and will be there for a few more years. The whole ordeal was a fairly stressful thing to deal with right after having major surgery. I looked into my legal options after I cleared things up, but I couldn't get anyone to seriously listen to my case. I wanted to know whether the hospital was responsible, but I guess I didn't know who to contact (the right lawyer, etc). Everyone I contacted either weren't able to help me or didn't know I should contact.