30 ms·
Hospitals are a weak spot in U.S. cybersecurity
- rolph 7y agowaiting rooms are a gaping hole. nobody seems to see a problem with blabbing out your final 4 and first,last name when thier at a desk in a room full of whoever walked in and sat down. un protected desktops are another issue, there is a tide of duties and an attacker can pattern the staff and get a good idea when they will have time to do an inside job of some sort.
- Scoundreller 7y agoAs with most environments, there’s a lot of trust based in a hospital running successfully. At least they have their own on-site security that’s experienced in taking people down. I continue to believe the real threats are actual insiders and remote attacks. Dunno how far someone will get with a USB key versus sending everyone a plausible email.
- ohithereyou 7y ago>Dunno how far someone will get with a USB key versus sending everyone a plausible email. Insiders still can be threats. There was a machine that was deployed in a hospital for clinical imaging that some rad tech who guessed the administrator password put folding@home on without telling anyone which crippled that machine's ability to perform its function.
- wutbrodo 7y ago> some rad tech who guessed the administrator password put folding@home on without telling anyone which crippled that machine's ability to perform its function. How incredibly bizarre to do something that dumb for no personal benefit.
- Scoundreller 7y agoF@H had value!!! I do remember an IT admin day that said he ran SETI@Home at a low priority on all machines because detect any problems with a machine (e.g. spyware, crashing, heat problems, etc.) But 2002 thinking wouldn’t fly in 2019.
- Bnshsysjab 7y agoBTC miners occur more than F@H these days, but they happen plenty.
- ohithereyou 7y agoThis incident occurred before crypto mining was a thing many knew about. He thought that since the machine was unused overnight that someone should get some benefit from it.
- newnewpdro 7y agoThese aren't mutually exclusive vectors of attack, they all need to be addressed.
- pharrington 7y agoYou plug in the USB key, then you pull out the USB key. The physical security layer at alot of hospitals is almost entirely absent, sadly.
- Scoundreller 7y agoWhat I meant was that sending everyone an email will get you further with less time/effort than actually going.
- rolph 7y agoor you swap keyboards with a special keyboard [maybe a pineapple?] , or you can swap ethernet patches around.
- Scoundreller 7y agoGiven how terrible a lot of low-end Dell keyboards get after years and years, most people would cheer :) With the main apps being virtualized, workstations are refreshed less often than they used to be.
- chapium 7y agoUSB keys are blocked mostly these days. There are other huge vulnerabilities if you have physical access and are motivated.
- Bnshsysjab 7y agoFrom experience in plenty of industries, your statement is incorrect. Most places suck at security and blocking removable storage, but likewise suck at far more important controls (eg application whitelisting) for it to really mitigate much in the first place
- JBlue42 7y agoIn my org's environment, not very far with USB key. Email = very much yes. We had one user who called after filling in every email address she had into a very plausible looking O365 login page. She admitted she initially distrusted the email/link that led her to this page and had replied saying so. The hackers on the other end told her to go ahead and do so. I mean, who she to question when it's coming directly from the hospital's lawyer?
- ta999999171 7y agoSpecialist I went to attempted to collect a photograph in the waiting room, as well - "please hold still a second while I take your picture for the doctor", with a webcam sitting atop the counter between us.
- rolph 7y agothese are times when i say no thankyou thats not medically necessary, and obsruct the cam or turn around if its unobstructable.
- ta999999171 7y ago> attempted :)
- nitwit005 7y agoThe big threat used to be the paperwork (and still is sometimes due to fax machines). There were people who broke in after hours, and stole boxes of paperwork to use for medical billing fraud.
- cmurf 7y agoWe're past time for simple challenge response for this, if not something better. Computer picks two digits, maybe they are part of your SSN sequence, or not, you have to parse that and say true or false. Then last three of your SSN. The current strategy is b.s.
- weka 7y agoSame thing for picking up prescription at CVS/Walgreens. They make you verify your phone number and address. Every. Single. Time. In public. It's a shame how silly it all is.
- Avamander 7y agoI actually feel kinda sad for you, seems so cumbersome, yet I can't relate at all. Really bizarre to me as an Estonian, I've only had to show my ID-card to the pharmacist and get my prescription, because my doctor has entered it into the e-prescription[1] system. Reading this thread definitely made me appreciate it a lot more. [1]: https://www.eesti.ee/eng/services/citizen/tervis_ja_tervisekaitse/retseptid_1 https://www.eesti.ee/eng/services/citizen/tervis_ja_tervisek...
- tyingq 7y agoThe central IT function in a US hospital also usually has little organizational power and funding. Admissions, radiology, etc, buy whatever hardware and software they want, and the underfunded IT department has to figure it out.
- ohithereyou 7y agoNot to mention that network security necessarily means limiting access, and getting that wrong in a hospital context can lead to wasted minutes and hours that can cause harm to somebody.
- oneepic 7y agoThis may vary by hospital, but in general many hospital IT staff tend not to be very good with computers, from my experience. Many are more focused on business/bureaucracy, or maybe they're just unskilled. I don't mean to attack their character, but instead to make the point that some very unqualified people are in charge of very important systems. (Edit: My first job was hospital IT for a few months, and my boss was actually a pretty skilled programmer with a good grasp on security. So there are definitely exceptions.) I imagine not many hospitals hire security talent either, or that they do much security beyond the "change your password" email every 6 months. Oh, and doctors/nurses/etc tend to ignore those emails.
- sidlls 7y agoAgreed with this. IT in hospitals is perpetually underfunded and basically a playground for creatures of corporate politics. Between administrative staff who think their medical credentials qualify them to micromanage IT decisions and perpetually under-funded departments I'm actually shocked that their systems aren't regularly crippled or destroyed by malicious entities. Don't assume your medical data is secure. Systems that conform to HIPAA regulations are just one part of their computing infrastructure, and it's trivial to maliciously access a huge surface area outside of those specific pieces of hardware and software--and once a malicious actor has that access, it's not too hard to cross the gap.
- nitwit005 7y ago
- aasasd 7y agoPossibly in one part because I see people on freelancer marketplaces making software for hospitals, with job budgets of a couple hundred bucks. I'm ok with freelancers in general, but I feel that integrating code from disparate small jobs while keeping security in mind isn't gonna be so simple.
- keiferski 7y agoI feel like Mr. Robot may have highlighted this fact (along with others) to the general population rather effectively. https://www.youtube.com/watch?v=g6gG-6Co_v4 https://www.youtube.com/watch?v=g6gG-6Co_v4
- williesleg 7y agoToo many do the needful h1b's But that's the plan to destabilize from the inside out. Whoops, cat's out of the bag.
- Thriptic 7y agoIt's really tough. You have a function which is viewed purely as a cost center; you have a totally porous environment where you're required to admit tons of minimally-verified people into confidential spaces; staff and affiliates need different levels of access from all over the world; there are critical availability demands where temporary denial of service for security reasons is unacceptable; device development is optimized for safety and fault tolerance as opposed to security which isn't ever really tested for; patients need to be able to submit tons of data in myriad forms; there are few central clearing houses for transmitting data so people are all calling each other with minimal validation; etc
- ethbro 7y agoOh, and you're ultimately sourcing truth from people who are minimally trained on (and have minimal time for training on) the system. Because they've spent the last couple decades focused on medical training.
- Scoundreller 7y agoAnd patients that lie / dirty input. Sure, use cousin x’s coverage. Nobody will freak out when your blood type doesn’t match the records...
- jtdev 7y agoIt seems that hospitals are overly focused on bullshit security frameworks and box-checking, i.e., HITRUST, which in my experience results in many dollars going to consultants with essentially zero tangible improvement in information security. Worse yet, the false sense of security within these hospitals due to having a HITRUST audit report with a bunch of meaninglessness check marks prevents them from actually doing the work of securing information properly. Have worked in health-tech for a number of years.
- tristor 7y agoOn the flip side, I’ve long preached that compliance is not security. HITRUST CSF is a huge improvement over the previous state of healthcare IT, because HIPAA is not prescriptive
- dmix 7y agoThe famous critique on HITRUST by a healthcare security guy that went viral, calling it "Cumbersome, Expensive, and Arbitrary": https://www.linkedin.com/pulse/open-letter-hitrust-alliance-kamal-govindaswamy-cissp-cipp-us-ccsp https://www.linkedin.com/pulse/open-letter-hitrust-alliance-...
- tristor 7y agoYep, and yet I’ve been able to successfully implement it in a 1 year project in a prior org (as part of a team obviously). HITRUST isn’t that bad, and it’s better than the alternative, which is HIPAA directly. I would best describe HIPAA as Vague, Fruitless, Bureaucratic, and Arbitrary. HITRUST is a huge improvement even if it’s not perfect.
- dmix 7y agoWasnt HIPAA not intended for security or privacy when it was originally developed? Merely as a standardized approach so various vendors could integrate easier. I could be mis-remembering this though.
- deleted 7y ago[deleted]
- crispyambulance 7y agoGiven the state of cybersecurity right now, is there any organization or domain AT ALL which is strong and model-worthy when it comes to cybersecurity?
- cm2012 7y agoBig tech. Google, especially.
- Doodood 7y agoHow so?
- dodobirdlord 7y agoIn the wake of discovery of attacks by China[0] and the NSA[1] Google has adopted a nation-state actor threat model and a siege mentality around data access and encryption. [0] https://en.wikipedia.org/wiki/Operation_Aurora https://en.wikipedia.org/wiki/Operation_Aurora [1] https://www.washingtonpost.com/world/national-security/nsa-infiltrates-links-to-yahoo-google-data-centers-worldwide-snowden-documents-say/2013/10/30/e51d661e-4166-11e3-8b74-d89d714ca4dd_story.html https://www.washingtonpost.com/world/national-security/nsa-i...
- deleted 7y ago[deleted]
- dredmorbius 7y agoAny idea if that siege mentality is part of the reason for sunsetting its social projects?
- xyst 7y agoTo be honest, Google is the last company I want handling my health data. If you don't check the right boxes, it could end up being "anonymized", and sold off.
- bagacrap 7y agoIt seems the biggest reason they're a weak spot is that the data they store make them a target. Retailers are also weak on security -- really, I wouldn't trust any company that wasn't a specialist in the space, i.e. finance and tech -- but most entities don't know so much about their clientele. Retailers don't need to keep as much info as they do (aside from profit motives), but hospitals probably do, so I can see this being a vulnerability that's never closed.
- chapium 7y agoHonestly I have to completely disagree. Security is simply bad. Hospital IT depts are pulled between many competing interests which lead up to this.
- sidlls 7y agoThe data they have are sensitive, but that's just the reason they're a target. They're a weak spot because of poor security practices, which is due to poorly managed IT organizations, which is due largely to the egos of administrative management and poor funding.
- Classicaldj34 7y agoHow do they store their data? Why don't they use private clouds? -Duple? https://www.duple.io/en/ https://www.duple.io/en/ -Nextcloud? https://nextcloud.com/ https://nextcloud.com/
- chapium 7y agoIBM,Cerner,Dell
- Mountain_Skies 7y agoRecently saw an ad for an IT support position at a hospital. The list of potential hazards in the work environment listed in the ad likely scares off many who have plenty of other employment opportunities. And most hospitals can't jack up the pay to compensate so attracting good talent is going to be a problem.
- save_ferris 7y agoWhat were the hazards that you saw? Just curious
- Mountain_Skies 7y agoIt's been over a year but I seem to recall potential exposure to radiation, infectious disease, and chemicals being on the list. It was quite long. I'm guessing the legal department added it for all positions in the hospital.
- delfinom 7y agoYea that's just lawyer cya speak.
- vkou 7y ago> And most hospitals can't jack up the pay to compensate I find that hard to believe in an age of $100 saline bags, $20,000 childbirths, and 15-minute-long $500 specialist visits.
- braindeath 7y agoYou’re downvoted likely because the high expenses of hospitalization speak more to inefficiencies in healthcare supply chain and the economics of insurance and really has nothing much to do with how much hospitals can afford on IT. Some hospital systems are rich... but they’re not that rich. That said I agree (based on 1st hand experience) that the larger healthcare multibillion dollar systems in the US can afford to pay more for better IT/engineering. There is simply little incentive to do so. And further it’s more than just hiring a few engineers with FAANG pay... these institutions are organizationally not suited to engineering. Changing this would not be easy for them...and no, we don’t need a hospital run like Facebook or Uber. Then there are the tons of smaller systems in the US.. they cannot afford high priced engineers regardless of the pre-insurance line charge for a bag of saline.
- einpoklum 7y ago"Sky is blue, news at 11:00"... Of course hospitals are a security weak spot: They're full of sensitive patient health data shared over computer systems whose users and procurers are not very security-literate, and often absent-minded about such issues due to the grinding, stressful work.
- dang 7y agoA different hospital/security thread from a couple days ago: https://news.ycombinator.com/item?id=21483337 https://news.ycombinator.com/item?id=21483337
- burnte 7y agoHealthcare CIO here. This is true. Healthcare is still using paper fax. It has a 30 year old data interchange format that no one really supports because it's more profitable to lock in customers to your EMR. Healthcare is HORRIBLE about upgrading anything, at changing processes, and technological progress in general. Healthcare is VERY backwards from a tech standpoint. Another problem is that EVERYTHING is custom, we use very, very few off the shelf solutions. Need an EMR? Let's build it in MUMPS, a 51 year old language that originated on the PDP7 and call it a state of the art system like Epic or GE Healthcare. Don't like the terminal interface? Let's slap a GUI on the front that still interacts via TTY on the back end. SQL? Nah. C, C++, or any more modern language with more robust features and way more programmers? Nope. Now, there are some EMRs and other healthcare-centric apps that are better written, but they're also terrible. Healthcare is a relatively small market, you'll never sell a million units of your app, so you charge out the wazoo for it, get a few health systems on it, and allow they to go crazy with customization to help lock them in. And then you try to add on modern security features on to a system that's been growing for 50 years and it's a nightmare. It's INCREDIBLY common for nurses and doctors to need to have administrator access on their Windows desktops for various apps. I was about to leave IT in general when a healthcare gig landed on me, and I'm glad it did. I find it very refreshing to be in an industry where it's so far behind that there are mountains of problems to tackle, even if half of them are so stupid it makes me want to cry.
- dpflan 7y agoRegarding legacy EMRs, are specifications/standards like HL7's FHIR actually gaining any traction and making data interoperability more feasible?
- EuphoricEmu 7y agoNot OP but I can tell you that due to the object size limitations of FHIR objects, document exchange is just not feasible. Using FHIR to register a patient is pretty pointless currently as every older and larger hospital sends HL7v2. RHIOs building gateways for 3rd party apps is very much the future of FHIR. But they’ll still be interacting with that crufty legacy system. Just my own two cents.
- swader999 7y agoSo are vet hospitals. At this very moment there's a chance you'll walk into one that has fallen back to paper records and billing due to a continent wide ransom ware attack. https://www.reddit.com/r/msp/comments/dnd7aq/ransomware_attack_against_national_veterinary https://www.reddit.com/r/msp/comments/dnd7aq/ransomware_atta... From that thread: Avimark is an old style load the EXE from a share program with a flat file structure for the data. Most clinics are not in a domain, just workgroup, and the share is read/write access for Everyone. So, yeah.
- heartbreak 7y agoIt's worse than that thread reveals. NVA was hit by a ransomware attack in May. They're now in a second attack that began in late October (ongoing). The latest one was described by CIO Joe Leggio as a "coordinated and sophisticated" attack in an internal email. He said it was designed to breach the NVA system specifically and that the attackers had three separate entry points. Only this week did NVA deploy endpoint security software to every computer in their 500+ veterinary practices. Note: Avimark itself is not at fault here. The Avimark issue that the practices are having is related to NVA not having a solid DR plan with working backups. Part of the problem there is that because of Avimark's architecture, most practices have an on-prem server that each workstation RDPs into for using Avimark. Because this equates to 500 or so Avimark SQL Server instances spread around the United States, it's perhaps not surprising that NVA's unsophisticated IT department did not have working backups for each instance.
- adamnemecek 7y agoEverything in US is targetable. The main problem is that say the power/health/<fundamental infrastructure> are all managed by 1000 different companies who are all at different wavelength as far as OPSEC.
- z3ugma 7y agoFor those interested, I wrote a primer on M aka MUMPS at https://learnxinyminutes.com/docs/m/ https://learnxinyminutes.com/docs/m/
- alwillis 7y agoI’m an IT guy; I cringe almost every time I interact with the healthcare system. I could pile on; all I want for now is encrypted and signed email with my doctors. I have an S/MIME certificate; can’t see why the IT staff at the hospitals I deal with can’t make sure my doctors have the same.
- burnte 7y agoBecause doctors are spoiled children. Were rolling out keyfobs for 2FA for our e-prescribe solution, but I'm keeping the fobs because I KNOW the docs will forget them/lose them. Docs only get soft-tokens on their phones because they never forget their phones.
- deleted 7y ago[deleted]
- gen220 7y agoI work in health tech (full stack insurance), and sit next to security and IT, so this is a frequent topic of conversation for us. :) For some context, this is one of our favorite websites/datasets: https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf. It is a structured archive of all reported health data breaches, major or minor, over the last 15 years or so, as reported by the breached entities. They’re required to report breaches as part of HIPPA compliance, or something related to it. It’s a fascinating quilt of stories, with patches for phishing, accidental email attachments forwarded, and rogue admins. Fun reading. You can also load it into sqlite and find some interesting results (leakiest companies, states with most breaches reported, etc). Hospitals might be a weak spot, but at least their weaknesses are ruthlessly well documented! As opposed to, say, financial infrastructure which IME is a similar horror show of monkey patched sftp servers. Solving this collective technical debt is a massive coordination problem. It’ll be interesting to see if we ever get there. My suspicion is that the changes will be driven by monopolistic insurers, if ever, since that’s where all the money comes from (if you go to doctor at hospital X, your coinsurance will be Y instead of Z, because doing business with X is more/less risky due to their documented data practices). But it’s just a suspicion, this kind of thing might not be solved in our lifetimes.