3 ms·
There's something in this story that doesn't ring true. You knew from the moment you walked into the laboratory that their data handling practices were inadequ
by coldcoldground 7y ago
There's something in this story that doesn't ring true.
You knew from the moment you walked into the laboratory that their data handling practices were inadequate and prone to being hacked/leaked. How?
You tried to explain this to their secretaries and nurses. Why bother when it's obvious they can't/won't do anything about it? Why not contacting their management or IT?
- guessmyname 7y ago> You knew from the moment you walked into the laboratory that their data handling practices were inadequate and prone to being hacked/leaked. How? The laboratory is divided into small rooms where the patient talks with the nurse and/or doctor, each room looks something like this [1] along with a computer that is connected to whatever system LifeLabs uses. When I arrived for my appointment the nurse left me alone in the room for approximately 15 minutes, the computer was on, and the user session (which I believe was created using the doctor’s credentials) was still alive, I could have done a lot with that computer while the nurse was outside checking the other patients. Later, the doctor came to do the initial physical checkup and then left for another 10-15 minutes to talk with another nurse. This gave me more time to “snoop around” and in fact, I took the opportunity to take a picture of the computer screen [1]. Ironically, you can see in the picture that the doctor uses a Post-it Note to cover the webcam, which means they do care about their privacy but not the privacy of their patient’s. You may think “this is not LifeLabs fault but the doctor’s fault” but this is how social engineering works and as people say “A chain is only as strong as its weakest link”. > You tried to explain this to their secretaries and nurses. > Why bother when it's obvious they can't/won't do anything about it? > Why not contacting their management or IT? Yes, good point, but this doesn’t disprove the rest of my anecdote. [1] https://en.wikipedia.org/wiki/Doctor%27s_office https://en.wikipedia.org/wiki/Doctor%27s_office [2] https://i.imgur.com/c0tXTEK.png https://i.imgur.com/c0tXTEK.png
- supercommand 7y agoTo be fair to life labs, at least they don’t dox you aloud to an entire waiting room. I witnessed that happen to a few prominent financiers in Toronto while I was getting some bloodwork done. It was terrifying within about 5 minutes I had all the personal information I’d need to do some seriously nefarious things. This happens on most every occasion I visit a clinic in Canada. Nurses and secretaries do not care.
- lvturner 7y agoI wonder if it's more that they just don't understand - also habits are hard to change. "it's always been this way" Not sure what the solution is.
- rickyc091 7y agoHappens in the US too. As I was waiting for my doctor's appointment, I was just listening to the secretary call up patients to obtain payments. She was just reading out their credit card information out loud. I was honestly tempted to just take one down then call the credit card company to let them know it was compromised.