Showing posts with label computer security. Show all posts
Showing posts with label computer security. Show all posts

Monday, October 10, 2016

Ransomware and incompetence in backups leads to medical data loss...but the thieves were honest thieves!

"An honest thief!" said Caledon Hockley of Jack Dawson, after planting the Heart of the Ocean diamond necklace in Jack's pocket.  https://www.youtube.com/watch?v=G5UEwCHUHjg



The headline of this posting may sound absolutely insane, but it is factual.

But don't worry, your precious medical data is far safer than it ever was on that 5,000-year-old invention, papyrus.

Marin patients’ medical data lost after cyber attack
By Richard Halstead, Marin Independent Journal   
September 30, 2016
http://www.mercurynews.com/2016/09/30/marin-patients-medical-data-lost-after-cyber-attack/

The Marin Healthcare District and Prima Medical Foundation are notifying more than 5,000 patients that some of their medical data was lost due to a glitch that followed a ransomware attack in August.

There's that all-purpose euphemism again, "glitch", which in this case is a euphemism for negligence.  See blog query link  http://hcrenewal.blogspot.com/search/label/glitch for more on "glitches."

Prima Medical Foundation supports the Prima Medical Group, many of whose doctors work closely with Marin General Hospital.

I covered the wondrous EHR at Marin General Hospital at my May 17, 2013 post "Marin General Hospital nurses warn that new computer system is causing errors, call for time out" at http://hcrenewal.blogspot.com/2013/05/marin-general-hospital-nurses-warn-that.html, and my May 20, 2013 post "Marin General Hospital's Nurses are Afraid a Defective EMR Implementation Will Harm or Kill Patients .. CEO Cites Defective HHS Paper and Red Herrings As Excuse Why He Knowingly Allows This To Continue" at http://hcrenewal.blogspot.com/2013/05/marin-general-hospitals-nurses-are.html.

The computer records of Marin Medical Practice Concepts, a Novato company that provides medical billing and electronic medical records services to many Marin physicians, were hacked on July 26. As a result, some Marin doctors were unable to access their patients’ medical records for more than a week.

More than a week with no records is, needless to say, putting patients at great risk.

Responding to questions from the Independent Journal on Aug. 4, Lynn Mitchell, CEO of Marin Medical Practice Concepts, confirmed the malware attack. In her email, Mitchell wrote, “Ransom was paid. For security reasons we will not be releasing the amount or denomination paid.”

That really inspires confidence.

Typically in such ransomware attacks, a sophisticated computer virus finds its way into a victim’s system when an unsuspecting employee opens an email attachment. The virus encrypts the system’s data and attackers essentially hold the data hostage until the owners of the information pay a ransom, typically in an untraceable digital currency such as Bitcoin.

A virus "finds its way" into a victim's system?

Let me rephrase into the politically incorrect, but factually correct, "due to incompetence in computer security. evil people are able to infiltrate the virus into a life-critical EHR system."

The Marin Healthcare District and Prima Medical Foundation issued nearly identical press releases on Wednesday, stating, “The third-party forensic firm hired to investigate this incident found no evidence that patient personal, financial, or health information was accessed, viewed, or transferred.

I guess they never considered that such evidence could have been removed by the hackers, who obviously had just a bot more IT expertise than the average high schooler.

But, of course, the thieves were honest thieves who would NEVER steal valuable medical charts for profit on the black market...

Here's what I consider the very worst part of this incident:

“However, during the restoration process, one of MMPC’s backup systems failed, causing information to be lost that was collected at the district’s nine medical care centers between July 11, 2016 and July 26, 2016.”

I note that a "backup system failing" causing data loss is a "never" event.  Incompetence...

The release went on to say: “This information includes vital signs, limited clinical history, documentation of physical examinations, and any record of the communication between patients and their physician during a visit in that 15 day period. Results of diagnostic tests were not lost and patients do not need to be re-tested.”

But patient safety was not compromised...

Jamie Maites, a spokeswoman for Marin General Hospital, said, “The ransom unlocked the data; however, at the time of the incident, we were in the middle of a system upgrade. The data loss occurred at the time of the system restore due to a faulty backup system — not due to the malware.”

Well, that's certainly reassuring.

Maites said Marin General’s systems were unaffected by either the ransomware or the failed backup systems. The patients being notified are patients of physician practices that are part of the Marin Healthcare District Medical Care Centers and Prima Medical Foundation.

The hackers were generous in sparing the hospital.

In a statement, Lee Domanico, chief executive of the Marin Healthcare District, said, “Our community can rest assured that the Marin Healthcare District will continue to work side by side with our vendors to ensure that all of our data is protected with today’s most advanced technology to reinforce their security systems against the most aggressive threats.”

Lee Domanico is the same CEO who I cited in my aforementioned posts who in 2013, after dire nurse warnings, brilliantly assured the board that the hospital was safe, despite "glitches" in the new system and that "I'm confident that in spite of the implementation issues, we have a system today that is safer for patients than our old paper system, and it will get even safer as we gain experience with it and work to fix some of the glitches we've experienced."

In a similar statement, Dr. Robert Newbury, chief executive of the Prima Medical Foundation, said, “It is unfortunate that these types of cyber-attacks have become so common.”

I would more precisely state that it is unfortunate that health IT leaders are so incompetent that they cannot secure their own life-critical systems.

... According to a report issued by the Attorney General’s Office in February, in the past four years the attorney general has received reports on 657 data breaches affecting a total of more than 49 million records of Californians.  The report said that malware and hacking present the greatest threat, accounting for 54 percent of the breaches. The report added that health care, which accounted for 16 percent of breaches, is starting to see an increase in hacking breaches as the sector transitions to electronic medical records. And it said that the “most vulnerable information in health care was medical information, such as patient records, and Social Security numbers.”

I really have to ask if the (increasingly elusive) benefits of EHRs warrant this level of security risk - let alone the known risks of bad health IT aside from security issues.

-- SS

Tuesday, August 16, 2016

Yes, the OS and filesystems on our EHR servers were hacked and our data encrypted for ransom, but "no medical information was looked at or compromised"

On this blog I have an entire series of posts regarding EHR crashes that point out an absurd-on-its-face and, in fact, insulting boilerplate executive response to the EHR unavailability:

"BUT patient care has not been compromised." 

The posts can be accessed via the query link http://hcrenewal.blogspot.com/search/label/Patient%20care%20has%20not%20been%20compromised.

It seems I may need another, related indexing term when EHRs get hacked and ransomware is inserted:

"BUT no information was looked at or compromised."

I've seen this in various incarnations several times now. 

For instance, see my Feb. 18, 2016 post "Hollywood Presbyterian Medical Center: Negligent hospital IT leaders allow hacker invasion that cripples EHRs, disrupts clinicians ... but patient safety and confidentiality not compromised" at http://hcrenewal.blogspot.com/2016/02/hollywood-presbyterian-medical-center.html and my March 29, 2016 post "Bad health IT at Medstar Health: FBI probing virus behind outage" at http://hcrenewal.blogspot.com/2016/03/bad-health-it-at-medstar-health-fbi.html.

This type of statement suggests that thieves who are able to gain access at highly granular levels of a server's filesystem and OS in order to encrypt the contents and insert the ransomware are "honest thieves" who would not look at the PHI for purposes of identity theft, or even sadistically alter data for purposes of causing harm.  In other words, it's the executives reassuring the populace that the thieves have honor.

The latest example:

Novato firm remains silent about ransomware attack on patient records
Richard Halstead, Marin Independent Journal
08/13/16
http://www.marinij.com/article/NO/20160813/NEWS/160819914
Officials at a Novato [California, https://en.wikipedia.org/wiki/Novato,_California - ed.] company that provides medical billing and electronic medical records services to many Marin physicians aren’t talking about a ransomware attack on their system this month that left doctors unable to access patient records for more than 10 days.

Ten days without charts is unprecedented in the paper world, except perhaps after a major physical catastrophe.

Clearly, the refrain "BUT patient care has not been compromised" would be absurd under such conditions.


Lynn Mitchell, CEO of Marin Medical Practice Concepts, issued a terse email on Aug. 4 confirming that her company had paid a ransom to regain access to its data. She wrote, “To date, there is no evidence that any patient information was accessed, transferred or otherwise compromised.”

Honest thieves were involved.

Since then, Mitchell has declined to comment on how many patient medical records were involved, how Marin Medical determined that the records weren’t compromised and whether the company reported the security breach to law enforcement or — as required by law — the state Attorney General’s Office and U.S. Department of Health and Human Services.

“We have nothing further to add at this time,” Mitchell said in an email Thursday.

Not specifying how such a determination was made significantly decreases the credibility of an already non-credible assertion, in my view.

Joe Cohen, an information technology consultant based in Greenbrae, said, “They claim no information was looked at or compromised. I don’t believe it.”

Cohen, whose personal data is in Marin Medical’s system, said he is worried that whoever encrypted the company’s files may have copied the data before demanding the ransom.

That's a best-case scenario, considering the possibility of deliberate or accidental alteration or corruption.

Typically in such ransomware attacks, a sophisticated computer virus finds its way into a victim’s system when an unsuspecting employee opens an email attachment. The virus encrypts the system’s data and attackers essentially hold the data hostage until the owners of the information pay a ransom, typically in an untraceable digital currency such as Bitcoin.

"Finds its way into a victim's system" is a rather mild way of saying "invades a victim's system due to inadequate security precautions."

Carl Chapman, operations manager of the Northern California Computer Crimes Task Force and an inspector in the Marin County District Attorney’s Office, said Marin Medical did not report the extortion to his task force.

“Typically, people don’t report them because I think it is well known throughout information technology departments that we are unable to unlock the information,” Chapman said.

... In 2012, the state began requiring businesses and government agencies to notify the attorney general on breaches affecting more than 500 Californians. The law applies to any business or agency whose unencrypted personal information was acquired, or reasonably believed to have been acquired.

I'd say it's more likely that organizations that don't report such crimes want to keep their victimhood due to negligence out of the public spotlight.

According to a report issued by the Attorney General’s Office in February, in the past four years the attorney general has received reports on 657 data breaches affecting a total of more than 49 million records of Californians. ... health care, which accounted for 16 percent of breaches, is starting to see an increase in hacking breaches as the sector transitions to electronic medical records. ... the “most vulnerable information in health care was medical information, such as patient records, and Social Security numbers.”

That level of incidents leads me to state the following:

  • Lack of EHR interoperability, so often complained about, is actually a good thing in 2016, as it may limit the scope of individual breaches of EHR security; and
  • The utopian dream of a national health information network connecting the entire country's EHR systems is a very, very bad idea in 2016 and should be postponed.  Reality is a harsh master, and the risks are clearly great in 2016 due to the immaturity of computer security.

More on ransomware:

Gordon [Amy Gordon, a partner in the Chicago law firm of McDermott Will & Emery LLP] said in addition to encrypting data, ransomware may also transfer information to a remote location.

“In this day and age, people’s personal information is valuable,” Gordon said, “so unfortunately some of these hackers may be selling this information in addition to getting the ransom from the hacked entity.”

The thieves are already taking a significant risk, and smart thieves would certainly be expected to maximize their haul..

In February, Hollywood Presbyterian Medical Center in Los Angeles paid a ransom of $17,000 in the hard-to-trace digital currency Bitcoin in order to regain access to its data.

Then in March four more organizations fell victim: MedStar Health, which operates 10 hospitals throughout the District of Columbia and Maryland; Chino Valley Medical Center in Chino and Desert Valley Hospital in Victorville, California; and Methodist Hospital in Louisville, Kentucky.

The first two incidents are covered in the aforementioned posts.

John Hall, who operates Sausalito Networking, a small system integration firm, said, “If someone hits a hospital they can usually get a lot of money because the hospital needs to get the darn patient data.”

Indeed, making them among the most pliable of victims.

Hall said several of his clients — a small construction company, a tax advisory firm and a medical facility — have been hit by ransomware attacks recently. He said he is advising all of his clients to install special anti-ransomware software.

Bret Lowry is the founder of Florida-based WinPatrol, which produces the anti-ransomware software that Hall recommends.

“This year ransomware attacks have just exploded,” Lowry said, “because organized crime has gotten involved and is using it to make money.”

That is not surprising to me.   Further evidence the "ready, aim, fire" push to national health IT by our government and IT industry with little consideration to risk, now in a stage of coercive penalties for non-users, once again has been proven to have been reckless.  As examples of the government and industry leaders downplaying risk:

March 6, 2013
On EHR's: See No Evil, Hear No Evil, Speak No Evil: Part 1
http://hcrenewal.blogspot.com/2013/03/on-ehrs-see-no-evil-hear-no-evil-speak.html

March 8, 2013
On EHR's: See No Evil, Hear No Evil, Speak No Evil: Part 2
http://hcrenewal.blogspot.com/2013/03/on-ehrs-see-no-evil-hear-no-evil-speak_8.html

In the first post I noted this:
... The head of CCHIT, Mark Leavitt, has penned the following at iHealthBeat: 

June 19, 2009 - Perspectives 

Health IT Under ARRA: It's Not the Money, It's the Message

by Mark Leavitt 

... Before ARRA, most surveys concluded that cost was the No. 1 barrier to EHR adoption. But as soon as it appeared that the cost barrier might finally be overcome, individuals with a deeper-seated "anti-EHR" bent emerged. Their numbers are small, but their shocking claims -- that EHRs kill people, that massive privacy violations are taking placethat shady conspiracies are operating -- make stimulating copy for the media. Those experienced with EHRs might laugh these stories off, but risk-averse newcomers to health IT, both health care providers and policymakers are easily affected by fear mongering.

Fear mongering.  Right.

In the second I noted this:

... Blumenthal, at the time Director of ONC at HHS had reportedly stated that:

http://www.massdevice.com/news/blumenthal-evidence-adverse-events-with-emrs-anecdotal-and-fragmented

... [Blumenthal's] department is confident that its mission remains unchanged in trying to push all healthcare establishments to adopt EMRs as a standard practice. "The [ONC] committee [investigating FDA reports of HIT endangement] said that nothing it had found would give them any pause that a policy of introducing EMR's [rapidly and on a national scale - ed.] could impede patient safety," he said.

The "nothing" includes 44 injuries voluntarily reported to FDA and 6 reported deaths in an enviroment where few know where to report such things and where no reporting requirements exist, and a statement from the head of CDRH at FDA that due to systematic impediments to accurate knowledge the known figures likely are a small fraction ("tip if the iceberg") of the actual occurrence.


Further:

Chapman said, “In the cases we’ve investigated, all of the leads go to Eastern European countries for which we don’t have the ability to do any further investigation. I’m not aware of any federal agencies that are specifically working on ransomware.”

In other words, the hackers cannot be identified nor brought to justice.

Under these conditions, continued pushes for interoperability and mass networking of multiple EHR's is simply reckless.  The proper caution calls for a slowdown in those efforts until security issues are under reasonable control.  However, the past decade has shown that "caution" seems an abstract concept to our government and industry with respect to the health IT sector.

Finally:

"BUT no information was looked at or compromised"
is a phrase that also needs to be backed up by robust proof, because it rings as hollow as, or perhaps more hollow than "BUT patient care has not been compromised." 

-- SS

Monday, August 15, 2016

Politicians get a very bitter taste of the very same medicine they've forced onto clinicians and the public

This is a case of education - I hope - by fire on electronic information security, and why "going electronic" can be a risky business.  This is a lesson deeply needed by our government leadership who have been pushing an unfettered national rollout of electronic medical records systems, despite known and exploited security concerns of EHRs, among other concerns discussed at this blog.

I've written dozens of posts, just based on casual searches of news, illustrating breaches of healthcare information technology security and privacy of information, as have others focusing primarily on these issues such as Patient Privacy Rights DOT org (https://patientprivacyrights.org/).  

Examples of my own occasional posts in this domain are at query links such as:
http://hcrenewal.blogspot.com/search/label/medical%20record%20confidentiality

http://hcrenewal.blogspot.com/search/label/medical%20record%20privacy

http://hcrenewal.blogspot.com/search/label/computer%20security

Our wise political leaders, however, have been pushing this technology, despite its numerous drawbacks  - full steam ahead - on clinicians and patients, now under the gun of Medicare payment cuts for "refuseniks."

Now, the political leadership has just gotten a bitter taste of the dish they've been serving up:

Hacker releases cell phone numbers, personal emails of House Democrats
By Daniella Diaz, CNN
Updated 4:04 PM ET, Sat August 13, 2016
http://www.cnn.com/2016/08/12/politics/guccifer-2-0-hacker-dnc-dccc/

The hacker who goes by "Guccifer 2.0" is claiming credit for the release of personal cell phone numbers and private email addresses of Democratic House members.

The data -- posted to their WordPress blog on Friday night -- also contains the contact information for staff members and campaign aides.

In the trove of information released on Friday "Guccifer 2.0" also uploaded files to the blog post that contains login information to subscription services used by the Democratic Congressional Campaign Committee, including Lexis-Nexis and Washington newspapers ... In addition to lawmakers' personal information, the hacker uploaded documents analyzing candidates for Florida's 18th congressional district, and a fundraiser memo to House Minority Leader Nancy Pelosi about Morgan Carroll's congressional campaign in Colorado.

In a statement, DCCC Press Secretary Meredith Kelly said: "As previously noted, the DCCC has been the target of a cybersecurity incident, and we are cooperating with federal law enforcement in their ongoing investigation. We are aware of reports that documents claimed to be from our network have been released and are investigating their authenticity."

Rep. Adam Schiff of California, the ranking Democratic on the House Intelligence committee, suggested a law enforcement probe is necessary. 

Perhaps a probe of the competence of those responsible for electronic security hired by our wise government officials should come first.

"The unauthorized disclosure of people's personally identifiable information is never acceptable, and we can fully expect the authorities will be investigating the posting of this information," Schiff said.

But it's just fine to keep rolling out insecure electronic records systems.

... The hacker wrote in the blog post, "It's time for new revelations now. All of you may have heard about the DCCC hack. As you see I wasn't wasting my time! It was even easier than in the case of the DNC breach."

Remarkable incompetence on the part of the politicians.

... The hack of the DNC was originally discovered as being two separate breaches, both by hacking groups identified by cybersecurity experts as working for the Russian military and intelligence complex. One hack was said to have lasted a year and targeted internal communications, the other was for a few months and targeted opposition research on Donald Trump.
 
Federal investigators had tried to warn the DNC months before, sources told CNN, but by the time the suspected Russian hackers were kicked out of the systems damage had been done: Nearly 20,000 emails between a handful of DNC officials were dumped on the web by WikiLeaks as the Democratic National Convention was kicking off. The emails showing opposition to Vermont Sen. Bernie Sanders during the primary led to the resignation of DNC Chairwoman Debbie Wasserman Schultz on the eve of the convention and departure of more party officials later.

The politicians of both parties behind the EHR mandate, in effect at least since the HITECH Act of 2009, should have heeded those questioning EHR security before mandating a national rollout.  My only comment is that I hope the politicians unabashedly pushing EHR's on the public may have learned a valuable, needed, and well-deserved lesson about electronic information security from these events.  

However I am not optimistic about that.

-- SS

Tuesday, March 29, 2016

Bad health IT at Medstar Health: FBI probing virus behind outage (And: ka-ching! ka-ching! EHR costs continue their upward spiral)

Once again, a definition of bad health IT:

Bad Health IT ("BHIT") is defined as IT that is ill-suited to purpose, hard to use, unreliable, loses data or provides incorrect data, is difficult and/or prohibitively expensive to customize to the needs of different medical specialists and subspecialists, causes cognitive overload, slows rather than facilitates users, lacks appropriate alerts, creates the need for hypervigilance (i.e., towards avoiding IT-related mishaps) that increases stress, is lacking in security, compromises patient privacy or evidentiary fitness, or otherwise demonstrates suboptimal design and/or implementation. (http://cci.drexel.edu/faculty/ssilverstein/cases/)

I observed bad health IT leading to HIT compromise, hospital chaos and paying of a ransom demand at my Feb. 18, 2016 post "Hollywood Presbyterian Medical Center: Negligent hospital IT leaders allow hacker invasion that cripples EHRs, disrupts clinicians ... but patient safety and confidentiality not compromised" at http://hcrenewal.blogspot.com/2016/02/hollywood-presbyterian-medical-center.html.

It's happened again, at least with regard to publicly-disclosed stories (there is no requirement for hospital disclosure, more on that below).

FBI probing virus behind outage at MedStar Health facilities - AP
By JACK GILLUM, DAVID DISHNEAU and TAMI ABDOLLAH March 28, 2016 10:04 pm
http://wtop.com/consumer-tech/2016/03/fbi-probing-virus-behind-outage-at-medstar-health-facilities/


WASHINGTON (AP) — Hackers crippled computer systems Monday at a major hospital chain, MedStar Health Inc., forcing records systems offline for thousands of patients and doctors. The FBI said it was investigating whether the unknown hackers demanded a ransom to restore systems.

A computer virus paralyzed some operations at Washington-area hospitals and doctors’ offices, leaving patients unable to book appointments and staff locked out of their email accounts. Some employees were required to turn off all computers since Monday morning.

A law enforcement official said the FBI was assessing whether the virus was so-called ransomware, in which hackers extort money in exchange for returning a victim’s systems to normal. The official spoke on condition of anonymity because the person was not authorized to discuss publicly details about the ongoing criminal investigation.


Not discussed is corporate accountability for deficient IT security.

“We can’t do anything at all. There’s only one system we use, and now it’s just paper,” said one MedStar employee who, like others, spoke on condition of anonymity because this person was not authorized to speak to reporters.

I note that if the cybernetic pundits were listened to, patients would now be considered at deadly risk due to paper records being used - not due to critical IT infrastructure being hacked and disabled.  Yet it's impossible to disable paper charts en masse.

MedStar said in a statement that the virus prevented some employees from logging into systems. It said all of its clinics remain open and functioning and there was no immediate evidence that patient information had been stolen.

These must be honest thieves.

Of course, we hear the "patient care has not been compromised" line once more (http://hcrenewal.blogspot.com/search/label/Patient%20care%20has%20not%20been%20compromised).

Company spokeswoman Ann Nickels said she couldn’t say whether it was a ransomware attack. She said patient care was not affected and the hospitals were using a paper backup system.

The absurdity of this claim is that if patient care is not affected by returning to paper, then why did the hospital invest hundreds of millions on EHRs?

(Considering a increasing evidence base of clinician distraction and disaffection e.g., the Jan. 2015 Medical Societies letter to ONC as at http://hcrenewal.blogspot.com/2015/01/meaningful-use-not-so-meaningul.html, EHR-related errors, many of which would likely not occur under a well-staffed paper system e.g., as at http://hcrenewal.blogspot.com/2014/04/fda-on-health-it-risk-reckless-or.html, and plentiful security breaches e.g., the many posts at http://hcrenewal.blogspot.com/search/label/medical%20record%20privacy, I would also ask if patient care is in fact improved by the return to paper [1].)

When asked whether hackers demanded payment, Nickels said: “I don’t have an answer to that,” and referred to the company’s statement.

Dr. Richard Alcorta, medical director for Maryland’s emergency medical services network, said he suspects it was a ransomware attack. He said his suspicion was based on multiple earlier ransomware attempts on individual hospitals in the state. Alcorta said he was unaware of any ransoms paid by Maryland hospitals or health care systems.

The rather calmly-stated "multiple earlier ransomware attempts on individual hospitals in the state" suggests that

  • Hospitals are being targeted in an organized fashion, and
  • Costs to implement proper security will draw even more capital and resources from direct patient care and from real brick and mortar facilities, such as entire new hospital wings that would cost less than an EHR, to cybernetics of increasingly dubious value.  (Past projected cost benefits are certainly being proven even more naive.)

Terrorism or just plain old crime, the medical driector asks...

“People view this, I think, as a form of terrorism and are attempting to extort money by attempting to infect them with this type of virus,” he said.

God help us if true terrorists get in the act of cybernetically paralyzing hospitals.

Alcorta said his agency first learned of MedStar’s problems about 10:30 a.m., when the company’s Good Samaritan Hospital in Baltimore called in a request to divert emergency medical services traffic from that facility. He said that was followed by a similar request from Union Memorial, another MedStar hospital in Baltimore. The diversions were lifted as the hospitals’ backup systems started operating, he said.

It used to be that patient diversions were due to doctors and nurses having too many sick patients they are caring for.  Here it seems due to doctors having to many sick computers to deliver proper patient care.

MedStar operates 10 hospitals in Maryland and Washington, including the MedStar Georgetown University Hospital, along with other facilities. It employs 30,000 staff and has 6,000 affiliated physicians.

That's a lot of paralysis.

Monday’s hacking at MedStar came one month after a Los Angeles hospital paid hackers $17,000 to regain control of its computer system, which hackers had seized with ransomware using an infected email attachment.

Hollywood Presbyterian Medical Center, which is owned by CHA Medical Center of South Korea, paid 40 bitcoins — or about $420 per coin of the digital currency — to restore normal operations and disclosed the attack publicly. That hack was first noticed Feb. 5 and operations didn’t fully recover until 10 days later.

Hospitals are considered critical infrastructure, but unless patient data is impacted there is no requirement to disclose such hackings even if operations are disrupted.

I won't even comment on why a US hospital is owned by a Korean medical center.  The statement "unless patient data is impacted there is no requirement to disclose such hackings even if operations are disrupted" implies yet another blind spot in the unregulated health IT industry.  Add that to the blindness towards close-calls and actual harms, and you have a field being pushed on the population under penalty by those somewhat deaf, dumb and blind to the downsides.


Computer security of the hospital industry is generally regarded as poor, and the federal Health and Human Services Department regularly publishes a list of health care providers that have been hacked with patient information stolen. The agency said Monday it was aware of the MedStar incident.

All I can hear is "ka-ching! ka-ching!" as the costs to fix the poor computer security in the hospital industry accrues. 

How much will patient care suffer as a result of the diversion of yet more resources to cybernetics?

As I've written before, stories like this support a serious rethinking of the entire healthcare IT hyper-enthusiast movement to whom the considerable downsides (even patient death) are just an unfortunate "bump in the road" (http://hcrenewal.blogspot.com/2012/03/doctors-and-ehrs-reframing-modernists-v.html), or perhaps more accurately, the healthcare IT hyper-enthusiast religion.

-- SS

[1] I've written that paper for many clinical settings, including highly specialized forms as I implemented highly successfully in invasive cardiology (http://cci.drexel.edu/faculty/ssilverstein/cases/?loc=cases&sloc=Cardiology%20story), needs reconsideration, relieving clinicians of clerical work and employing data entry clerks to enter the data.  This would be supplemented by far less expensive document imaging systems for 24/7 availability, and computerized lab results retrieval - the latter with appropriate humans on the receiving end to prevent the "silent silo" syndrome of lab results returned to a computer silo but missed by clinicians due to being very busy and due to unreliable/fatiguing cybernetic alerting.  A lot of workers can be paid for by saving $50 or $100 million on software.

3/30/2016 Addendum:

This is not the first time for EHR outages at MedStar.

As in my May 16, 2015 post "Another day, another EHR outage: MEDSTAR EHR goes dark for days" at http://hcrenewal.blogspot.com/2015/05/another-day-another-ehr-outage-medstar.html, I cited Politico. 

The doctor's observation I highlighted below is of interest.

4/9/15
http://www.politico.com/morningehealth/0415/morningehealth17818.html

MEDSTAR EHR GOES DARK FOR DAYS: MedStar’s outpatient clinics in the D.C. and Baltimore area lost access to their EHRs Monday and Tuesday when the GE Centricity EHR system crashed. The system went offline for scheduled maintenance on Friday and had come back on Monday when it suffered a “severe” malfunction, according to an email from Medstar management that was shared with Morning eHealth.

“All of a sudden the screens lit up with a giant text warning telling us to log off immediately,” a doctor said. “They kept saying it would be back up in an hour, but when I left work Tuesday night it was still down.”

This doctor told us that the outage was “disruptive and liberating at the same time. I wrote prescriptions on a pad for two days instead of clicking 13 times to send an e-script. And I got to talk to my patients much more than I usually do.

But of course we didn’t have access to any notes or medication history, and that was problematic.” MedStar notified clinicians in the email that any information entered in the EHR after Friday was lost.

-- SS


Thursday, February 18, 2016

Hollywood Presbyterian Medical Center: Negligent hospital IT leaders allow hacker invasion that cripples EHRs, disrupts clinicians ... but patient safety and confidentiality not compromised

To the cybernetic idealists out there who think computers are the greatest thing next to sliced bread in the healthcare environment, I say, pray you are not on the operating table when something like this happens:

Hackers’ Ransom Attack On California Hospital More Proof Healthcare Cybersecurity Is Floundering
International Business Times
Jeff Stone
02/17/16
http://www.ibtimes.com/hackers-ransom-attack-california-hospital-more-proof-healthcare-cybersecurity-2309720

Who would have thought that, for healthcare professionals, performing surgery, working long hours and navigating the dense world of U.S. health law would be easier than protecting hospital computer networks? That, however, appears to be the case after yet another hospital was victimized in a cyberattack. It’s just the latest example of a U.S. medical provider on the wrong end of a digital assault made possible by a lack of security measures.

I, for one, would have thought that.  In fact, I've been writing about these issues for years (see my many posts at query links http://hcrenewal.blogspot.com/search/label/medical%20record%20confidentiality and http://hcrenewal.blogspot.com/search/label/medical%20record%20privacy).

Doctors at Hollywood Presbyterian Medical Center, in southern California, have been suffering serious computer issues for at least a week, the CEO announced Sunday. Doctors have been unable to digitally access patients’ medical records, staff has been communicating via fax machines and patients have reported long delays in receiving care. It’s all the result of a cyberattack carried out by unknown hackers who are demanding 9,000 bitcoins (roughly $3.4 million) to restore the system to normal.

Ransom for access to EHRs.  The hospital's IT leadership should be held accountable for this invasion of the clinic by cybercriminals.  It's not like the issue is unknown:

... “Hospitals are a veritable bullseye for hackers,” said Grayson Milbourne, security intelligence director at the cybersecurity company Webroot, which works with a number of hospitals and healthcare companies. Milbourne added that the value of patient records is an irresistible target for cybercriminals. “For starters, [hospitals] run on a tight budget and their IT infrastructure is often a very low priority when compared to affording new medical devices and staff. 

More from techtimes.com at http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm:

... According to NBC, the damage has caused the hospital to be unable to continue day-to-day operations. To keep up activity at the medical center, the staff has turned to manual documentation using pen and paper to take down patient information and jammed fax lines and telephones to communicate from one department to another. The administration has forbidden the use of other computers for fear that the harmful software could spread to more workstations.  Allen Stefanek, President and CEO of the hospital, says that "significant IT issues" began to emerge last week, leading to a declaration of "internal emergency." He also mentions that the attack was random, not malicious, noting that the emergency rooms have been "sporadically impacted since Friday."

The realities of IT in 2016, when hospitals are increasingly dependent on IT command-and-control systems through which every transaction of care must pass, lead to the conclusion that "IT infrastructure is often a very low priority" reflects negligence.

Back to the IBT article.  The CEO at this hospital proffers the usual BS:

Hollywood Presbyterian’s CEO [Allen Stefanek] told NBC, “Patient privacy has not been compromised."  ...The intrusion  has been described as a ransomware attack, which is typically defined as an attack that involves a hacker infiltrating a victim’s computer, and encrypting their data until the victim agrees to pay a bitcoin ransom. The hospital denies any patient data has been compromised.

Right.  Hackers take control of information systems, but patient data has neither been altered, nor its privacy impaired.

From the second article:

... the patients are not safe from harm. Stefanek insists that the incident has no impact on the overall care for the patients, but some have spoken out to say otherwise. Jackie Mendez and her 87-year-old mother say that they have to drive to Palmdale to pick up medical tests, which takes them over one hour to do so. "It's bad. She's an older person. It's not right she has to do this," she says. Another patient named Belmont West is also affected by the incident. Belmont says he went to the hospital to get his grandmother's medical test results to no avail.

and there's this:

... some patients had to be transferred to other hospitals, as some of the medical equipment that need computers at the Hollywood Presbyterian Medical Center were rendered inoperable, including apparatuses for X-ray and CT scans, documentation and pharmacy and lab work.

These ridiculous executive canned lines, including "the incident has no impact on the overall care for the patients" a.k.a. "patient safety had not been compromised" (see query link http://hcrenewal.blogspot.com/search/label/Patient%20care%20has%20not%20been%20compromised), are increasingly absurd, non-credible, and tiring.

The urgency [for hospitals to meet standards of care for IT security -ed.] is growing. One in three Americans had their health records breached in 2015, according to multiple reports released last month. Many of those records were breached as part of the nation-state hacks on health insurers Anthem and Primera, though experts predict hospitals will become more attractive targets as they begin to rely on insulin pumps, intravenous flows and other machines that are connected to the Internet.

I note that if hospitals cannot afford the required diligence, they need to get out of the IT business.  Paper cannot be hacked or held for ransom en masse.

In the end, the hospital appeased the hackers:

Hospital paid 17K ransom to hackers of its computer network
By ANDREW DALTON
Associated Press
http://bigstory.ap.org/article/d89e63ffea8b46d98583bfe06cf2c5af/hospital-paid-17k-ransom-hackers-its-computer-network
Feb. 17, 2016 11:44 PM EST

LOS ANGELES (AP) — A Los Angeles hospital paid a ransom of about $17,000 to hackers who infiltrated and disabled its computer network because paying was in the best interest of the hospital and the most efficient way to solve the problem, the medical center's chief executive said Wednesday.  Hollywood Presbyterian Medical Center paid the demanded ransom of 40 bitcoins — currently worth $16,664 dollars — after the network infiltration that began Feb. 5, CEO Allen Stefanek said in a statement. ... "The quickest and most efficient way to restore our systems and administrative functions was to pay the ransom and obtain the decryption key," Stefanek said. "In the best interest of restoring normal operations, we did this."

They got off cheap for their negligence, relative to the initial demands.

Questions remain, however:

  • Was any patient data altered or corrupted, either deliberately or as a result of the hack?
  • Was any patient data copied or stolen?
  • Was any malicious code left behind by the hackers on any computer on the network, e.g., "back doors" or other malware that could cause future problems?  Put another way, after paying the ransom, does the hospital believe it is dealing with 'honorable criminals'?
  • One might presume the hospital, in an abundance of caution, is now paying after-the-fact for the expertise required to fully assure the integrity of its networks, computers and EHR and other business systems, but is this truly the case?
  • Were any patients harmed as a result of the disruptions to information flows, and of so, are the IT leaders in part liable? 
  • Will any patients suffer harm moving forward as a result of lost computer information during the episode, incomplete backloads of data on the paper that was resorted to during the crisis, or other factors?  Medical errors due to lost data can propagate forward in time, as I can attest to both personally and professionally.

It is my belief that, until and unless hospital leadership is held fully accountable for incidents such as this, such incidents will be one of many more moving forward.

Incidents like this are made more tragic by the increasing evidence that the benefits from healthcare cybernetics are not exactly what the zealots, pundits and industry opportunists advertised.

-- SS

Monday, August 18, 2014

Don't worry, your information's safe. Community Health Systems says data stolen in cyber attack: just a mere 4.5 million people affected this time.

I have often written about my observations of the generally unimpressive qualifications and capabilities of IT personnel, up to and including the CIO's, in healthcare settings (e.g., baccalaureate-level education in a doctoral and post-doctoral setting, usually no clinical or biomedical experience, no computer science background, no medical informatics background, and sometimes not even a formal management information systems education) compared to other sectors such as pharma and academia.  I've written about this as an impediment to health IT progress and to healthcare IT safety.

Now, I increasingly believe the healthcare IT backwater is becoming a downright societal threat, for another reason.  Yet another in my "don't worry, your information's safe" series (http://hcrenewal.blogspot.com/search/label/medical%20record%20privacy):

Community Health Systems says data stolen in cyber attack
http://www.foxbusiness.com/industries/2014/08/18/community-health-systems-says-data-stolen-in-cyber-attack/
Published August 18, 2014
Reuters

U.S. hospital operator Community Health Systems Inc said on Monday personal data, including patient names and addresses, of about 4.5 million people were stolen by hackers from its computer network, likely in April and June.

The company said the data, considered protected under the Health Insurance Portability and Accountability Act, included patient names, addresses, birth dates, telephone numbers and Social Security numbers. It did not include patient credit card or medical information, Community Health Systems said in a regulatory filing.

It said the security breach had affected about 4.5 million people who were referred for or received services from doctors affiliated with the hospital group in the last five years.

If you're a department store, or a McDonald's, such breaches might be more understandable.  When you're a life-critical industry such as healthcare, and under HIPAA regulations regarding privacy and confidentiality, these incidents are increasingly unforgivable.

The FBI warned healthcare providers in April that their cybersecurity systems were lax compared to other sectors, making them vulnerable to hackers looking for details that could be used to access bank accounts or obtain prescriptions, Reuters previously reported.

Again, inexcusable.  Health IT amateurs (and, of course, the Management Recruiting Firms that hospital retain to find them, who are equally clueless about what it takes to be a health IT expert) don't just endanger your health; they endanger your economic well being, even when you're not ill.
The company said it and its security contractor, FireEye Inc unit Mandiant, believed the attackers originated from China. They did not provide further information about why they believed this was the case. They said they used malware and other technology to copy and transfer this data and information from its system.

Just great.

Community Health, which is one of the largest hospital operators in the country with 206 hospitals in 29 states, said it was working with federal law enforcement authorities in connection with their investigation into the attack. It said federal authorities said these attacks are typically aimed at gathering intellectual property, such as medical device and equipment development data.

Oh. that's reassuring - our data's being stolen by honest thieves who would never, EVER think of selling the data to dishonest thieves who steal people's identities, and then money...

It said that prior to filing the regulatory document, it had eradicated the malware from its systems and finalized the implementation of remediation efforts. It is notifying patients and regulatory agencies as required by law, it said.

It also said it is insured against such losses and does not at this time expect a material adverse effect on financial results.

Oh, that's very nice.  Millions of people potentially put at risk, but insurance will cover for incompetence.

Perhaps the insurers should more critically evaluate the quality of work of the people they're insuring.

-- SS

Friday, December 20, 2013

Another Reason to Put Everyone's Confidental Medical Information Into Today's Massively Secure (Surely They Are, No?) EHR systems

Office of Inspector General
Department of the Treasury
Oct. 17, 2013

Audit report

INFORMATION TECHNOLOGY: OCC's (Office of the Comptroller of the Currency) Network and Systems Security Controls Were Deficient

PDF available at: http://www.treasury.gov/about/organizational-structure/ig/Audit%20Reports%20and%20Testimonies/OIG-14-001.pdf

Highlights:

... To accomplish our objective, we performed a series of internal and external vulnerability assessments and penetration tests on OCC’s workstations, servers, network-attached peripherals (such as cameras and printers), infrastructure devices, and Internet websites.

... We determined that OCC’s security measures were not sufficient to fully prevent and detect unauthorized access into its network and systems by internal threats,or external threats that gained an internal foothold. Also, OCC’s security measures were not adequate to fully protect personally identifiable information (PII) from Internet-based threats.

We found that default factory-preset administrative usernames and passwords were present in OCC’s systems. In one test we conducted, we discovered a default username and password of an internal service account on an OCC server which had local administrator privileges. We used those privileges and deployed our penetration test tool’s agents to the host server. That server contained password hashes for local and domain administrator accounts. Using these hashes, we obtained a domain administrator’s password, which we then used to log on to the network domain controller. With full access given to a typical domain administrative account, we created a domain administrator account and thereby had full control of OCC’s network.

... In accordance with our Rules of Engagement, we did not attempt to perform actions that would disrupt OCC’s operations, such as deleting data, powering off servers or other resources, locking out accounts, and similar activities, any of which could have resulted in interruption or shutdown of devices or services. However, malicious attackers would have no such restrictions against performing these actions

... Because systems and devices connected to OCC’s internal network could freely communicate between one another, with very little internal partitioning, we successfully attacked multiple OCC systems in a very short amount of time from a single workstation.

I offer no additional comments other than, if Treasury's IT security is this lax, just imagine how secure your health information is, sitting on servers at Podunk Hollow General Hospital.

-- SS

Monday, December 09, 2013

But Don't Worry, Your Health Information is Secure: the Enforcers are Themselves Incompetent and Broke

Another in my "But Don't Worry, Your Health Information is Secure" series (see http://hcrenewal.blogspot.com/search/label/medical%20record%20privacy) ... a promise blindly made by the healthcare information technology hyper-enthusiasts.

The Office of the Inspector General for HHS just issued a report finding that the Office of Civil Rights (OCR), which is charged with enforcing the HIPAA/HITECH law, had itself failed to adequately protect the security of the health information it handled. Specifically OIG found that OCR “focused on system operability to the detriment of system and data security.”

From “The Office for Civil Rights Did Not Meet All Federal Requirements in Its Oversight and Enforcement of the Health Insurance Portability and Accountability Act Security Rule”, p. ii (Nov. 2013).  http://oig.hhs.gov/oas/reports/region4/41105025.asp

Summary:

The Office for Civil Rights (OCR) did not meet certain Federal requirements critical to the oversight and enforcement of the Health Insurance Portability and Accountability Act Security Rule (Security Rule). OCR had not assessed risks, established priorities, or implemented controls for its Federal requirements to provide for periodic audits of covered entities to ensure their compliance with Security Rule requirements. In addition, OCR's Security Rule investigation files did not contain required documentation supporting key decisions made because management had not implemented sufficient controls, including supervisory review and documentation retention, to ensure investigators follow investigation policies and procedures for properly initiating, processing, and closing Security Rule investigations. Further, OCR had not fully complied with Federal cybersecurity requirements for its information systems used to process and store investigation data because it focused on system operability [I presume they mean 'interoperability' - ed.] to the detriment of system and data security.

We recommended that OCR (1) assess the risks, establish priorities, and implement controls for its HITECH auditing requirements; (2) provide for periodic audits in accordance with HITECH to ensure Security Rule compliance at covered entities; (3) implement sufficient controls, such as supervisory reviews and documentation retention, to ensure policies and procedures for Security Rule investigations are followed; and (4) implement the National Institute of Standards and Technology Risk Management Framework for systems used to oversee and enforce the Security Rule. In its comments on our draft report, OCR generally concurred with our recommendations and described the actions it has taken to address them. In specific comments on our second recommendation, however, OCR explained that no funds had been appropriated for it to maintain a permanent audit program and that funds used to support audit activities previously conducted were no longer available.

The enforcers are themselves negligent, incompetent and broke.  And hospitals are expected to keep electronic protected health information secure?

I comment no further.  What more could I possibly write?

-- SS

Dec. 9, 2013 Addendum:

This woman would probably agree that this is a problem

Dec. 9, 2013
http://www.thestar.com/news/gta/2013/11/28/disabled_woman_denied_entry_to_us_after_agent_cites_supposedly_private_medical_details.html

Disabled woman denied entry to U.S. after agent cites supposedly private medical details

A Toronto woman is shocked after she was denied entry into the U.S. because she had been hospitalized for clinical depression.

Ellen Richardson went to Pearson airport on Monday full of joy about flying to New York City and from there going on a 10-day Caribbean cruise for which she’d paid about $6,000.

But a U.S. Customs and Border Protection agent with the Department of Homeland Security killed that dream when he denied her entry.

“I was turned away, I was told, because I had a hospitalization in the summer of 2012 for clinical depression,’’ said Richardson, who is a paraplegic and set up her cruise in collaboration with a March of Dimes group of about 12 others.

The Weston woman was told by the U.S. agent she would have to get “medical clearance’’ and be examined by one of only three doctors in Toronto whose assessments are accepted by Homeland Security. She was given their names and told a call to her psychiatrist “would not suffice.’’

At the time, Richardson said, she was so shocked and devastated by what was going on, she wasn’t thinking about how U.S. authorities could access her supposedly private medical information.

“I was so aghast. I was saying, ‘I don’t understand this. What is the problem?’ I was so looking forward to getting away . . . I’d even brought a little string of Christmas lights I was going to string up in the cabin. . . . It’s not like I can just book again right away,’’ she said, referring to the time and planning that goes into taking a trip as a disabled person.

Richardson said she’d had no discussion whatsoever with the agent at the airport about her medical history or background.

Read the whole thing.

-- SS

Friday, September 06, 2013

N.S.A. Able to Foil Basic Safeguards of Privacy on Web, Including Medical Records - Yet Another Reason To Be Concerned About What You Tell Your Physician

There's already a major issue with privacy and protection of medical records in electronic form.  See the multiple blog posts at this query link:  http://hcrenewal.blogspot.com/search/label/medical%20record%20privacy

Now this from the New York Times:

N.S.A. Able to Foil Basic Safeguards of Privacy on Web
By NICOLE PERLROTH, JEFF LARSON and SCOTT SHANE
September 5, 2013

The National Security Agency is winning its long-running secret war on encryption, using supercomputers, technical trickery, court orders and behind-the-scenes persuasion to undermine the major tools protecting the privacy of everyday communications in the Internet age, according to newly disclosed documents.

The agency has circumvented or cracked much of the encryption, or digital scrambling, that guards global commerce and banking systems, protects sensitive data like trade secrets and medical records, and automatically secures the e-mails, Web searches, Internet chats and phone calls of Americans and others around the world, the documents show.  

But don't worry, your electronic medical records are secure, and will NEVER be used for political purposes by your adversaries...

Beginning in 2000, as encryption tools were gradually blanketing the Web, the N.S.A. invested billions of dollars in a clandestine campaign to preserve its ability to eavesdrop. Having lost a public battle in the 1990s to insert its own “back door” in all encryption, it set out to accomplish the same goal by stealth. 

The agency, according to the documents and interviews with industry officials, deployed custom-built, superfast computers to break codes, and began collaborating with technology companies in the United States and abroad to build entry points into their products. The documents do not identify which companies have participated.

At least we may have gotten faster PC's as a side result of the research that supported these efforts.

... the agency used its influence as the world’s most experienced code maker to covertly introduce weaknesses into the encryption standards followed by hardware and software developers around the world.

Some of the agency’s most intensive efforts have focused on the encryption in universal use in the United States, including Secure Sockets Layer, or SSL; virtual private networks, or VPNs; and the protection used on fourth-generation, or 4G, smartphones. Many Americans, often without realizing it, rely on such protection every time they send an e-mail, buy something online, consult with colleagues via their company’s computer network, or use a phone or a tablet on a 4G network. 

Might as well just send them a copy of all your communications to spare them the effort...

... Ladar Levison, the founder of Lavabit, wrote a public letter to his disappointed customers, offering an ominous warning. “Without Congressional action or a strong judicial precedent,” he wrote, “I would strongly recommend against anyone trusting their private data to a company with physical ties to the United States.”

Hey, how about let's ALL have our medical records stored by health IT companies providing ASP (Application service provider, http://en.wikipedia.org/wiki/Application_service_provider) offsite EHR hosting services to hospitals and clinics...

From the site "techdirt.com":

Allegedly the NSA and GCHQ (UK Government Communications Headquarters) have basically gotten backdoors into various key security offerings used online, in part by controlling the standards efforts, and in part by sometimes covertly introducing security vulnerabilities into various products. They haven't "cracked" encryption standards, but rather just found a different way in. The full report is worth reading ... (http://www.techdirt.com/articles/20130905/12295324417/nsa-gchq-covertly-took-over-security-standards-recruited-telco-employees-to-insert-backdoors.shtml).

Half facetiously: unless you're a real nobody, if you, say, contracted V.D. from that sexy prostitute at that Vegas Convention, you perhaps better not tell your doctor about it.

Maybe this is what it will take to get the government to start taking electronic medical record privacy, confidentiality and security more seriously.

Our legislators, like everyone else, have a stake in the game.

-- SS


Wednesday, August 28, 2013

Calling Dr. Moe, Dr. Larry and Dr. Curly: Advocate Medical Breach of Four Million Patient Records, and No Encryption

At my Oct. 2011 post "Still More Electronic Medical Data Chaos, Pandemonium, Bedlam, Tumult and Maelstrom: But Don't Worry, Your Data is Secure" (http://hcrenewal.blogspot.com/2011/10/still-more-ehr-chaos-pandemonium-bedlam.html) I thought I'd seen the worst.

Yet another post to add to the category of medical record privacy/confidentiality/security (http://hcrenewal.blogspot.com/search/label/medical%20record%20privacy), however:

Advocate Medical Breach: No Encryption?
Computer Theft Raises Questions About Unencrypted Devices
By Marianne Kolbasuk McGee, August 27, 2013.

The recent theft of four unencrypted desktop computers from a Chicago area physician group practice may result in the second biggest healthcare breach ever reported to federal regulators. But the bigger issue is: Why do breaches involving unencrypted computer devices still occur?

According to the Department of Health and Human Services' "wall of shame" website listing 646 breaches impacting 500 or more individuals since September 2009, more than half of the incidents involved lost or stolen unencrypted devices. Incidents involving data secured by encryption do not have to be reported to HHS.

... The four unencrypted but password-protected computers [passwords on PC's are bypassable by smart teenagers - ed.] stolen during a burglary in July from an office of Advocate Medical Group in Illinois may have exposed information of about 4 million patients, according to an Advocate spokesman.

4 million is about 1.3 percent of the entire U.S. population (about 313.9 million in 2012) ... on just four desktop computers.

Try that with paper ...

As to the subtitle of the article, "Computer Theft Raises Questions About Unencrypted Devices", I've written on that issue before.  I'd noted questions like that are remarkable considering both MacOS and Windows have built-in, readily available encryption, the latter for a few extra $ for the "deluxe version" (see  http://en.wikipedia.org/wiki/FileVault and http://en.wikipedia.org/wiki/Bitlocker).  

Perhaps the best explanation in 2013 for unencrypted desktop PC's containing millions of confidential medical records is this picture, symbolic of the apparent attitudes of corporate and IT management on health IT security:


Encryption?  We don't need no encryption.  We got triple protection already!


-- SS

Wednesday, March 13, 2013

But don't worry, your EHR information is secure

My last reminder of this issue was almost a half-year ago, but I think a repeat is in order.

More bugs squashed:

Microsoft fixes critical Windows, IE flaws for Patch Tuesday

Microsoft has released four critical security updates for Windows and Internet Explorer, along with a bevy of other products, in order to protect against at least 19 vulnerabilities identified in its software.

On deck this month, there are four "critical" vulnerabilities that affect Windows, Internet Explorer, Office, and Windows Server, including one for Silverlight that affects both Windows and Mac machines.

The most severe Internet Explorer flaw affected all versions of Windows XP (Service Pack 3) and above, including Vista, Windows 7, and Windows 8 — including tablets running Windows RT — running Internet Explorer 6 and above. The flaw could have allowed a hacker to access the vulnerable system with the same user rights.

... The other vulnerabilities rated as "important" could allow data and information disclosure, or an elevation of privileges on affected machines. These affect SharePoint, OneNote, Outlook for Mac, and kernel-mode drivers in Windows-based machines.

I note that Windows XP is now more than a decade old, but Windows RT is brand-spanking new.

In a Nov. 2012 post somewhat vexatiously entitled "Why It's Crazy to Want Your Most Confidential Information Put into An Electronic Medical Records System" about Windows 8 flaws, I had indicated how common Microsoft products were in hospital IT.

I stand by that vexatious title.

But don't worry, your confidential medical information is secure, and your safety against malfunctioning IT that loses your critical medical information after hackers invade is assured, in our current rushed national health IT rollout.

What is the answer?  Until this technology has significantly been secured and debugged, this old triad applies:

  • If you want your information secure, don't put it on a computer.
  • If you must put it on a computer but still want some degree of security, don't put the computer on a network.
  • If you must put the computer on a network, especially a network connected to the Internet, your information is no longer secure. 
It's premature in my view to be building and operationalizing national health records networks.  Unless, that is, patient information privacy, security and confidentiality are secondary considerations.

(In my view, they are seen by the national IT builders and promoters as secondary considerations, but the builders and promoters will never admit it, perhaps even to themselves.)
-- SS

Friday, November 09, 2012

Why It's Crazy to Want Your Most Confidential Information Put into An Electronic Medical Records System

Besides the reasons I outlined in posts retrievable by these query links (link, link), there's this from ZDNet.com:

Microsoft warns of first critical Windows 8, RT security flaws

It's been less than a month since Windows 8 and Windows RT-powered Surface tablets were launched and went on sale, but Microsoft is already warning that the two next-generation operating systems contain critical security vulnerabilities that are due to be patched this coming Tuesday.

Among the various flaws, versions from Windows XP (Service Pack 3) all the way through to Windows 8 are affected, including versions of the Office suite, and versions of Windows Server. Released only in September, Windows Server 2012 requires patching to maintain maximum security.

The latest vulnerabilities include three critical security vulnerabilities for Windows 8, and one critical security vulnerability for the Surface-based Windows RT operating system. These flaws are considered "critical" and could allow remote code execution on vulnerable systems.

I note that Windows XP was released worldwide for retail sale on October 25, 2001, which was more than eleven years ago.  That security vulnerabilities are still being patched in 2012 is stunning.  Also, many enterprise information systems and most hospital clients (workstations) run on Windows-based servers and Windows installed local machines (UNIX, MacOS and other OS's are very rare on general-purpose hospital workstations).

From a Microsoft website here:


This partial list includes many very large HIT sellers.  There are many others as well.

By simple reckoning, it's likely we'll be seeing critical security vulnerabilities in Windows 8 - in 2023.

It goes without saying that these security problems will continue to be exploited by identity thieves, medical information merchants, and others with no rights to "protected" information.

In my opinion, the (still not yet realized) convenience of being able to have one doctor transmit your record to another, thus avoiding a FAX machine, the Postal Service or the telephone, and the trillion-dollar "solution" to the nearly non-existent problem of being found unconscious in some foreign land with no ID, no companions, and some hidden, critical medical condition not findable on physical exam and bloodwork, EKG, x-rays etc. that will cause death if not treated in minutes, is not worth the risk of having one's most private information spilled all over the Internet.

EHR's should not be accessible on networks beyond a physician's office or the robustly encrypted network of a hospital, and the information security personnel kept on very short leashes, for the foreseeable future.

I am unwilling to cede my own privacy to cybernetic utopians who ignore alarming evidence - plain to see at the aforementioned query links at the top of this post - nor can I in good faith recommend doing so to the public in 2012.

Considering the information in the many posts at the aforementioned query links (as here: link, link -- be aware you need to hit "older posts" at the bottom of each page to see all of them), that position is straightforward.

-- SS

11/9/2012 Addendum:

Also see my Oct. 2012 post "Computer Viruses Are 'Rampant' on Medical Devices in Hospitals."

-- SS

Wednesday, October 17, 2012

Computer Viruses Are "Rampant" on Medical Devices in Hospitals

As if there weren't enough problems with hospitals as computing backwaters, now there's this:

Computer Viruses Are "Rampant" on Medical Devices in Hospitals

A meeting of government officials reveals that medical equipment is becoming riddled with malware.

Technology Review
Published by MIT
David Talbot
Wednesday, October 17, 2012

Computerized hospital equipment is increasingly vulnerable to malware infections, according to participants in a recent government panel. These infections can clog patient-monitoring equipment and other software systems, at times rendering the devices temporarily inoperable.

While no injuries have been reported, the malware problem at hospitals is clearly rising nationwide, says Kevin Fu, a leading expert on medical-device security and a computer scientist at the University of Michigan and the University of Massachusetts, Amherst, who took part in the panel discussion.

I note the seemingly universal refrain "no injuries have been reported" once more (see this query link to similar statements regarding IT malfunctions), which is irrelevant since reporting mechanisms for medical errors are noted to be deficient.

Software-controlled medical equipment has become increasingly interconnected in recent years, and many systems run on variants of Windows, a common target for hackers elsewhere. The devices are usually connected to an internal network that is itself connected to the Internet, and they are also vulnerable to infections from laptops or other device brought into hospitals.  [I note that it should be impermissible to connect "alien" machines to a hospital's network without authorization, and that attaining that level of security protection is not difficult - ed.]  The problem is exacerbated by the fact that manufacturers often will not allow their equipment to be modified, even to add security features.

In a typical example, at Beth Israel Deaconess Medical Center in Boston, 664 pieces of medical equipment are running on older Windows operating systems that manufactures will not modify or allow the hospital to change—even to add antivirus software—because of disagreements over whether modifications could run afoul of U.S. Food and Drug Administration regulatory reviews, Fu says.

In other words, let's run at high risk if it avoids the time and expense of FDA reviews that would ensure the equipment is safe and operates as expected with the software updates.

As a result, these computers are frequently infected with malware, and one or two have to be taken offline each week for cleaning, says Mark Olson, chief information security officer at Beth Israel.

It is unclear how the servers running the hospital information system, electronic health records systems, physician order entry systems etc. are immune to spread of the malware.

"I find this mind-boggling," Fu says. "Conventional malware is rampant in hospitals because of medical devices using unpatched operating systems. There's little recourse for hospitals when a manufacturer refuses to allow OS updates or security patches."

The worries over possible consequences for patients were described last Thursday at a meeting of a medical-device panel at the National Institute of Standards and Technology Information Security and Privacy Advisory Board, of which Fu is a member, in Washington, D.C. At the meeting, Olson described how malware at one point slowed down fetal monitors used on women with high-risk pregnancies being treated in intensive-care wards.

In its face, that is potentially catastrophic depending on the degree of "slowdown" and whether data is lost.

"It's not unusual for those devices, for reasons we don't fully understand, to become compromised to the point where they can't record and track the data," Olson said during the meeting, referring to high-risk pregnancy monitors. "Fortunately, we have a fallback model because they are high-risk [patients]. They are in an IC unit—there's someone physically there to watch. But if they are stepping away to another patient, there is a window of time for things to go in the wrong direction."

The reasons seem obvious to anyone who's had a serious malware infection on their PC.  I've only had one - a computer I bought at a fleamarket for $7 was so severely infected it was unusable for even basic tasks, and was resistant to virus removal.  I solved that problem by installing a fresh copy of the OS, immediately followed by all patches and the latest anti-malware software.

The computer systems at fault in the monitors were replaced several months ago by the manufacturer, Philips; the new systems, based on Windows XP, have better protections and the problem has been solved, Olson said in a subsequent interview.

This implies the older systems were running on Win 98 or earlier or an old version of Win NT.  Amazing.

At the meeting, Olson also said similar problems threatened a wide variety of devices, ranging from compounders, which prepare intravenous drugs and intravenous nutrition, to picture-archiving systems associated with diagnostic equipment, including massive $500,000 magnetic resonance imaging devices.

Olson told the panel that infections have stricken many kinds of equipment, raising fears that someday a patient could be harmed. "We also worry about situations where blood gas analyzers, compounders, radiology equipment, nuclear-medical delivery systems, could become compromised to where they can't be used, or they become compromised to the point where their values are adjusted without the software knowing," he said. He explained that when a machine becomes clogged with malware, it could in theory "miss a couple of readings off of a sensor [and] erroneously report a value, which now can cause harm."

I opine that harm could already have occurred; it just may not been recognized as such nor reported.  Disappearing data and other EHR failure modes known to have caused harm and/or deaths could be related to malware, for example.

... Malware problems on hospital devices are rarely reported to state or federal regulators, both Olson and Fu said. This is partly because hospitals believe they have little recourse. Despite FDA guidance issued in 2009 to hospitals and manufacturers—encouraging them to work together and stressing that eliminating security risks does not always require regulatory review—many manufacturers interpret the fine print in other ways and don't offer updates, Fu says. And such reporting is not required unless a patient is harmed. "Maybe that's a failing on our part, that we aren't trying to raise the visibility of the threat," Olson said. "But I think we all feel the threat gets higher and higher."

I note that health IT related problems are also rarely reported, with only one vendor being the exception (see my post on the FDA MAUDE voluntary reporting database here).  The reasons likely are not because "hospitals believe they have little recourse" - the real reasons may be fear, complacency and/or incompetence.

Speaking at the meeting, Brian Fitzgerald, an FDA deputy director, said that in visiting hospitals around the nation, he has found Beth Israel's problems to be widely shared. "This is a very common profile," he said. The FDA is now reviewing its regulatory stance on software, Fitzgerald told the panel. "This will have to be a gradual process, because it involves changing the culture, changing the technology, bringing in new staff, and making a systematic approach to this," he said.

Changing the culture would be nice, considering we are now entering a national rollout of complex enterprise clinical resource and workflow control systems anachronistically known as "electronic medical records."

In an interview Monday, Tam Woodrum, a software executive at the device maker GE Healthcare, said manufacturers are in a tough spot, and the problems are amplified as hospitals expect more and more interconnectedness. He added that despite the FDA's 2009 guidance, regulations make system changes difficult to accomplish: "In order to go back and update the OS, with updated software to run on the next version, it's an onerous regulatory process."

My comment is, if you can't take the heat of work in the real-world medical setting, if you cannot be part of the medical team, then get out of the clinic.  You're likely to do more harm than good.

John Halamka, Beth Israel's CIO and a Harvard Medical School professor, said he began asking manufacturers for help in isolating their devices from the networks after trouble arose in 2009: the Conficker worm caused problems with a Philips obstetrical care workstation, a GE radiology workstation, and nuclear medical applications that "could not be patched due to [regulatory] restrictions." He said, "No one was harmed, but we had to shut down the systems, clean them, and then isolate them from the Internet/local network."

He added: "Many CTOs [chief technology officers - ed.] are not aware of how to protect their own products with restrictive firewalls. All said they are working to improve security but have not yet produced the necessary enhancements."

Then why are they CTO's?  Is this the phenomenon of generic or underqualified managers rearing its head?


Fu says that medical devices need to stop using insecure, unsupported operating systems. "More hospitals and manufacturers need to speak up about the importance of medical-device security," he said after the meeting. "Executives at a few leading manufacturers are beginning to commit engineering resources to get security right, but there are thousands of software-based medical devices out there."

One can only wonder if others have done a Ford Pinto cost-benefit analysis and decided the costs of settlement from injured and dead patients is less than the cost of remediation.

-- SS