4 ms·
I was also in a govt / enterprise EHR type project. Similar story, but you had a double layer of VPN that only worked with outdate explorer / java etc (AT TIME
by tempnow987 4y ago
I was also in a govt / enterprise EHR type project. Similar story, but you had a double layer of VPN that only worked with outdate explorer / java etc (AT TIME OF DEPLOYMENT - the software was "new" to the govt agency and the poor health staff).
To skip all the sillyness - you basically had to password share, keep systems logged in etc etc to get anything done. Yes, security is important, but if it's 30 minutes to do anything, and then they did something like 30 day double password resets (on both layers of VPN) it's just chaos. Every password had to be written down, because when a patient showed up an clinician couldn't login it was a disaster. The millions they spent without every talking to anyone using this crap was mind blowing. We had in the end separate computers with locked down ancient IE and java to do some stuff on this system (auto or user updates to Java - which would pop up scary warnings given how old things were - would blow the fragile system up).
Then the one person who could create new accounts through a ridiculous process would go on some kind of 2 month union break at a time, and....
- lostlogin 4y agoWhile working in a hospital as a radiographer I met an IT contractor socially who was excited to be implementing a system which sounded like the one you describe ‘to help me work more efficiently’. It takes a special kind of person to confidently explain how a job they have never seen done is being done wrong. I had to walk away.
- userbinator 4y agoThe people who came up with that stuff probably never thought to weigh how much more it obstructs attackers than real workers... or even more scarily, thought treating them the same would be more secure somehow. As the saying goes, a perfectly secure computer is one that no one can use
- tempnow987 4y agoIronically, this system resulted in lots of insecurity. Password resets were so common the govt agency OUTSOURCED them - and you just had to provide your username to get it reset. Literally, you called and said I need a password reset for account X, and they gave you a temp password over the phone. I never complained about how easy this was because this was a CRITICAL feature. Sometimes we didn't even know why a password wasn't working - so after you got done with whatever client came in you called the number and got a new one. So it's really security theatre + the security provided by the massive annoyance of setting up old internet explorer to login and all the other silliness (which really was security, we were not alone in struggles, they kept on having to do paper backup systems when stuff went down). I often thought that a hacker could probably make all our lives easier by figuring out a way around the double VPN. This was a long time ago though (10+ years) and I have to believe better now.
- retcon 4y agoIn healthcare ten years doesn't even cover the original rollout you may be complaining about...
- avgcorrection 4y agoThat’s terrible. And then IT staff was unionized, too?? Well that’s just the icing on the cake, ’innit!