Not Paranoid Enough

The Regina Leader-Post Editorial Board echos my concerns over giving the Internet access to patient records. However the editorial focuses mainly on the threat from allowing external access.
By far, the largest threat vector is internal in origin and I’m not just talking about a disgruntled employee. Any employee who brings in their own device, checks email or surfs the web at work, plays facebook games or VPN’s in from home are all potential points of vulnerability.
This just happened.

A hospital in Los Angeles has been operating without access to email or electronic health records for more than a week, after hackers took over its computer systems and demanded millions of dollars in ransom to return it.

Based on the article it looks like the hospital was hit with a version of Cryptolocker software. That means that some employee in the hospital, or someone who has an ‘always-on’ VPN connection to the hospital and has mapped a drive to the data at the hospital became the accomplice.
No matter how hard you lock down a network or a computer the single largest point of failure is always between the keyboard and the seat.

9 Replies to “Not Paranoid Enough”

  1. yeaaaaars ago I was with a theatre company as their johnny-on-the-spot for those old 386s & 486s which were networked.
    I could *not* get the office staff idjits to comply with my insistence they NOT bring in floppy disks from home with ‘neat’ utilities and ‘harmless’ games. it took 2 severe virus infections before they realized, hey, 60something just. might. be. right. about. this.
    I wanted to disable the floppy drives and password the bloody BIOS but that would have impeded legitimate work. I don’t know how they resolved their security gaps after my contract was up.
    the funny part was how innocent these people played (no pun intended) like they couldn’t believe *their* ‘just this once’ actions were the source of the infection. the really fun part was when I told them there was a 99+% likelihood their home computer was infected.
    After that I was with a private college and their answer to the infected floppy disk situation was to have the office secretary mark the brand new uninfected disks with a silver marking pen to show they were ‘ok’.

  2. I think we put to much importance on our past medical records. I put medical history (Opinion) in the questionable folder. I have never had a doctor spend much time reading another doctors opinion unless that problem was on going. It is better to get fresh eyes & the latest science to diagnose your health. Unnecessary tests.. says who?

  3. So, when Chinese hacker X blackmails you because you had those antibiotics for an STD in your 3rd year of marriage, you’re cool with that, Phillip?

  4. “So, when Chinese hacker X blackmails you because you had those antibiotics for an STD in your 3rd year of marriage, you’re cool with that, Phillip?”
    No! lance I don’t think that information needs to exist on line….In engineering we can test & verify systems 100% on Tuesday @ 11:00Am, but on every following day when asked the condition of the system, we can only say it was OK at some point in time. If medicine follows that reasoning, the records tell you nothing about your current health. The DR treating you needs valid current records. The Medical system may want research information, but they don’t have a medical reason to have my name…
    I come from an older generation and if I had been dumb enough to get an STD, my wife would forgiven me LONG ago… Chinese Blackmailer would get cold rice

  5. It has been my experience that hospitals and the public schools are where the absolute dregs of the IT industry end up. This doesn’t surprise me in the slightest.

  6. I have noticed medical records are pretty useless, when the doctors never seem to read them.
    We have electronic records here, on my occasional visits I note the locums, shows no sign of even having perused them., often asking details of past treatments that only the records might remember.
    Course we have already had electronic accidents occur,one health worker ,emailed all, a bunch of peoples records and another lost a memory stick of a few hundred more.
    Who needs hackers.

Navigation