The assault on neurosurgeons’ privileges by software and bureaucrats
blogs.law.harvard.edu
blogs.law.harvard.edu
> ‘Why forty-five?’
> ‘It’s the forty-fifth month since we signed onto that hospital’s system and one has to change the password every month,’ Caroline replied.
Every month is a little aggressive of a timeline. Also, stop making users do your bizarre regex passwords.
* include caps
* include numbers
* include symbol
* eight charachters
* must be recursive backronym
Also, stop trying to keep password requirements secret. I am sick of this guessing game. I can relate to Mr. Johnson's total indifference to the system.
Maybe we should just get rid of the damn passwords and replace them with a system that makes it easier to remember and use without compromising security. At the very least one password + a smartcard system would be way easier. You enter your password once then you just have to swipe your card when you login to another system.
Adding radio as a primary component in a security system is always going to be a bad idea. Security is hard enough without adding in the possibility of 3rd parties hearing the protoocol - or worse.
> directional
A common misunderstanding of radio is the belief that it can be contained in an area. Unless you're building a proper Faraday cage (which is hard), the ability to hear a transmmission often depends on the receiving antenna.
For convenience without involving radio, one simply has to get creative. Something like the (defunct) Java Ring[1] would allow most of the ease-of-use of RFID (possibly with a simple proximity sensor for auto-logout, if needed).
[1] http://electronics.howstuffworks.com/gadgets/home/digital-je...
edit: fixed typo
Asymmetric encryption is not that hard. In fact, you were using it while complaining about the problem it solves.
> Garaday
Faraday.
> the ability to hear a transmmission often depends on the receiving antenna
So even if you somehow get past the asymmetric crypto you need RF expertise and a special antenna to mount the attack from more than a foot away? And not even a special antenna beyond a few miles? I'd call that "defense in depth," not a flaw.
> http://electronics.howstuffworks.com/gadgets/home/digital-je...
Just what do you think "digital jewelry" can do that a smartcard can't?
Thanks, typo fixed.
> Asymmetric encryption
...doesn't protect against everything. Not letting people hear the asymmetric encryption is even better.
> special antenna
Cantennas are easy, and you should never underestimate the amount of technology people will throw at an attack. Consider, for example, the people that made ATM shims that captured the card data while recording the PIN being entered on the keypad.
> "defense in depth"
Defense in depth would be using cryto while requiring a physical connection.
> smartcard
A smartcard is fine - my argument is against RFID. A card that requires an electrical or inductive connection isn't going to leak everything over the radio.
My suggestion of "digital jewelry" is merely an example of how the form of the smartcard is flexible. Creativity in this area could allow for some easier to use devices, which could be important in places like hospitals.
> ...doesn't protect against everything.
But it does protect against the exact threat model you proposed.
> Defense in depth would be using cryto while requiring a physical connection.
> Consider, for example, the people that made ATM shims that captured the card data while recording the PIN being entered on the keypad.
How about you consider it?
Building a facade to intercept physical communications is very much on par with building increasingly large, awkward, and expensive antennas in terms of difficulty barriers (especially if you need enough polish to blend in). I'm a ham, I would know. I'm not sure why you are so insistent on drawing the line between these two particular techniques.
> A card that requires an electrical or inductive connection isn't going to leak everything over the radio.
Are you familiar with the distinction between near-field and far-field? Because both RFID and smartcards span that distinction while you just tried to draw a line down the middle.
> A smartcard is fine - my argument is against RFID.
Many (most?) smartcards communicate over RF. Your argument (and my rebuttal) was about
> Adding radio as a primary component in a security system
not the RFID technology in particular. So do you or don't you think RF communication in a security device is an inherent problem in and of itself?
Encryption doesn't protect against traffic analysis. Knowing someone is present or that some device is in use is significant information.
Does the device you are proposing authenticate the reader before transmitting anything? If not, it's not particularly difficult (probaly by modifying a reader) to test if people have a security device on them. That only requires a ping, no crypto needed.
> I'm a ham
I used to be, for many years. (I wish I had more time for such things these days)
> large, awkward, and expensive antenna
That depends entirely on what you want to do. If you want to read the entire crypto transaction from the next building, then yes, an expensive antenna[1] will be required. If I just want to detect who is carrying a security device, you won't need a particularly accurate antenna - it just needs to have a decent gain.
My point with that example is that it's never a good idea to underestimate how much time and effort people will put into an attack. If criminals can add a man-in-the-middle chip piggybacked onto a chip-and-pin smartcard[2], they can made a decent cantenna.
> So do you or don't you think RF communication in a security device is an inherent problem in and of itself?
RF is an extra risk that should be avoided whenever possible for security devices, especially when effective alternatives are available.
In your linked video about the hospital, the smart card was slotted into a reader. This would work well and has no need for RF. It's certainly a far better solution than memorizing bad passwords.
[1] The $10k antenna used for TempestSDR that was mentioned yesterday should work. https://news.ycombinator.com/item?id=10685504
[2] http://hackaday.com/2015/10/21/smart-cards-used-to-hack-smar...
>If you don't you end up with bad passwords.
This is a terrible fallacy that has brought so much pain on the world. The rate of bad passwords is probably not so different, but the rate of frustration is so much higher.
Password policies do definitely raise the entropy of the passwords, so if the attack vector you're concerned about is entropy sensitive, its a decent strategy.
As someone who has had to enforce such password policies many times, I can say that it's almost always because of some regulatory or certification organization that requires complex policies.
I've seen smartcards have the best impact. Yeah sure they can be swiped or forged, but compared to the real, effective security of passwords, they're much better. You also can't lock yourself out of a smartcard system. You can forget your card at home, but it's easy to just reissue a new card and invalidate the old one (throw it away when you get home, it's just a hunk of plastic now).
Even just a card. You can only have one per person (as opposed to passwords that can have infinite copies and are likely to be unknowingly compromised) and if a card is lost, it can be expected that it will be replaced shortly so long as the replacement process is painless which seals the leak.
Anything requiring permissions, passwords, group policy etc is a complete nightmare. I had this gem when I emailed Information Services this morning.
My email: "XXX has left the company and I've taken over their role Can you please remove them as Owner of the following sharepoint site: YYY and make me the Owner instead."
IS's reply: "Please fill out a trouble ticket *"
I proceed to fill in a digital form 2 hours later I get a terse reply.
"Hi ZZZZ please contact the owner of site YYY and get them to adjust your permission. We are now closing your ticket."
I dont think anyone wants to be the one to reduce the security of the HIPAA requirements.
password policy not strict -> IT manager gets blamed in case of issue
password written down -> sucker who wrote it down gets blamed in case of issue
Person who decides policy is IT manager... Cover your ass politics.
If I could find a device (w/ touch or keyboard for input) that fit into my pocket and has no wireless capabilities, then I would probably use that as a password manager.
http://www.amazon.com/Digital-Persona-U-are-U-4500-Fingerpri...
Full disclosure: I work at Microsoft, but not on Azure Auth.
But yes, IT admins, go on thinking if you just finely craft and tune your password policy enough you'll make users come up with secure passwords.
I worked at a place where you could log in to just about anyone's account because our managers literally told us to take this approach so that we'd be less likely to forget what our password was.
I would be fascinated to know how you determine that with a regex.
Unless it's a manually maintained list of known recursive backronyms...
* A password for the account request system
* A password for the internal services system
* My email password
* My password for the local network
* My password for the product management system
* Pass for the old product management system that we still use
* Pass to the online drawing and document retrieval system
* Password to control room computer systems
* Various maintenance laptop user names and passwords
* Various passwords to systems I'd rather not mention, call them about 10 in total
That's 25 to 30 passwords, total, that I need to remember and use on a regular basis. I've given up NOT writing them down. And IT won't give me any kind of secure password manager, so I resort to a password protected Excel spreadsheet. And I'm not alone.
Or at the very least you should sign up for a password storage system like https://passpack.com
Which would be useful but would still require me to keep track of them manually.
Then there's the password for timecards (outsourced to another company), goal setting and training (outsource to another company), 401k, medical insurance and just because, another company (that isn't our medical insurance) for handling prescriptions.
Our Corporation has one password expiration timeframe (90 days but not really because they start nagging two weeks prior and won't shut up until you change the password) and the Corporation that owns The Corporation has another timeframe (60 days, but again, they start bitching about two weeks prior) and of course, all these sites have their own ideas about "secure passwords."
Weren't certificates supposed to deal with all this?
Wait ... don't answer that. I don't think I want to know the answer.
Especially the ones that are used irregularly (annually, quarterly), so SSO isn't a priority.
My passwords are all on a whiteboard by my desk.
Even with an algorithm, you're still relying on human memory. As Schneier and other have been recommending for a long time, write down your passwords. People already understand some amount of physical security, which is knowledge that can can utilized for password storage.
As long as human memory is the weakest link, password strength will always be de facto limited to the amount of entropy that a human can reasonably memorize. Unfortunately, brute-force password cracking capabilities flew past that limit a long time ago.
I have 300+ personal passwords. 30 more for work would be a trivial addition.
Not they sent the scan over the internet but they had to copy the scan on a CD and rush it over to the hospital.
SORRY BELLOW is a comment I did this week and it seems just as appropriate.
Here is the discussion on Open Source Software for Developing World Hospitals https://news.ycombinator.com/item?id=10675275
My old comment still reliant. Another story about my journey with my son while he battled cancer. Closed Proprietary image formats and systems HURTS patients. We used the local hospital for Chemo and everything else at the Children's Hospital 1.5 hours away for his legs and lungs. I would always have to wait 20-30 minutes to get a DVD of the studies (PET, CT Scan or MRI even ultrasound, but those are worthless) and then bring them to the doctor. The doctor would be forced to use whatever the portable image viewing program that came on the DVD and then they had to be sent to the IT Department to be imported into their system. We would be there to remove some horrible tumor but before half his surgeries (I can't count how many surgeries he had) we would have to go in the day before (3 hour round trip) to get the expensive scan done again. One time I had a scan at 11 PM - Midnight and then drive home around 2 AM and be back at the hospital at 7 AM check in for a 10 hour surgery. ALL BECAUSE THE FORMATS ARE CLOSED and SYSTEMS could not connect so that my son's records were all the same every where. I carried 20 DVDs with me all the time just in case. In case you are wondering my son unfortunately passed away after almost 5 years of fighting. If you are ever interested in giving to a cancer society please consider stbaldricks.org. Most charities give 0% or 2% to pediatric research and that is why we went over 20 years without a new chemo for children till last year, which St Baldrick's funded the research for this amazing new drug to fight a different type of cancer my son did not have.
And the source of the problems in this article? The legal dept. So please don't blame this one on anyone in IT.
IT as currently and usually practised, especially in a healthcare environment, is also mostly a disaster in terms of value for expenditure. $2 billion for an Epic system in a regional hospital system... Which was obsolete before it was installed. Heck, the Deustche Bank SAP core banking replacement only cost $1 billion.
Much of the "oh but it's regulated" excuses are just that, excuses to be ignorant and stay stuck in the 1970s.
It doesn't have to be this way, but it requires a lucky administration to find a way out of the mess given the market for lemons in IT management and systems integrators in healthcare.
Open source and Cloud solutions (from an operating model perspective way more than technology) appear to be the only way out of this mess of "your mess for less" IT because it lifts the veil of sales, consultant-speak, and opaque RFP processes in favor of actually-working-and-reliable software that anyone can see and touch.
It is actually a serious problem.
You have a bunch of apparently sensible rules with apparently reasonable justifications, but without a holistic understanding of what those rules cost in terms of engineering and design trade-offs. Then compliance prohibits the use of commodity components not designed with those specific requirements in mind, which requires everything to be custom for the industry at extreme cost, which in turn impairs competition and allows the vendors who do pay all the compliance lawyers to sell low quality software for big money.
And it's not clear how open source or cloud would solve any of that, other than possibly through some kind of regulatory avoidance shell game, which sounds more like a loophole than a solution.
They are institutionally allergic to agile, iterative improvement. It sounds too scary. They want big-design-up-front, even though that's guaranteed to deliver unusable software that's far more dangerous to patients than any transient bug.
Some of this is regulatory, but most is cultural.
Think Git/Hg vs CVS when it comes to branching.
I had a friend who worked as a QA engineer (hospital processes) for a presitigious children's hospital. The QA department came up with any number of potential, well-conceived plans, but the falling-down point was always the doctors. One of the primary pain points was the lack of interoperability between different departments' record-keeping. Each department head had their favourite vendor, who would give them all sorts of goodies on the side, and as such, none of them wanted to change.
So, you'd have a heads of department meeting where the new QA plan would be discussed, which necessitated regularising the software across departments. The standard refutation was "If I can't use software X, children will die". Everyone knew this was utter bullshit, but there's nothing you can do when the head of department is considered the final domain expert. "Children will die", uttered by doctors and surgeons, killed more efficient processes in that hospital.
Another story of his was at another meeting where one specialist ventured an opinion. It was derided by one of the old-school, a veteran of nearly 30 years: "We don't do things that way; you'd know that if you'd been here any length of time". Said the opinion-venturer: "I've been here 17 years". That is one insular society...
To this date, I'm not aware of any record-keeping software that's at least half as useful and efficient as the old and tried handwritten paper records.
There were only three useful IT innovations in medicine : (a) PACS [1] allows to easily compare and transmit X-rays; (b) lab work records; (c) appointments software.
[1]https://en.wikipedia.org/wiki/Picture_archiving_and_communic...
My wife had some complications after childbirth that kept her hospitalized for a few days. Watching the staff fuck around with 3-4 EMRs to figure out what happened when was a ridiculous comedy of errors. It actually undermined my confidence in the medical staff -- they really struggled between shifts.
In the old days, the information was available at a glance, on a clipboard.
It was extremely difficult because the software was written over a long period of time by multiple generations of programming teams and programming styles. It was hodge-podge to say the least. Take that system and integrate it with another equally hodge-podge system. Then add a couple more hodge-podge systems to that. There were just lots of redundancies and disconnects. I did feel sorry for the people who were going to have to use that system.
I'd say that medical administrative software is ripe for "disruption" just because it sucks so badly. Except for the fact that the systems are a) huge b) require extensive domain knowledge c) are regulated d) sales of such systems are extremely political and e) there's no way to do an end-run around the administrators who are purchasing these systems. It doesn't seem very suited for a "move quickly and break things" scrappy startup.
Without knowing what a "big meningioma" involves, I can only imagine it's something like doing a tricky, manual deployment on Friday afternoon. In that case no, this is a completely reasonable response. People have lives outside of work. Yes, "In the pre-modern NHS consultants never counted their hours – you just went on working until the work was done.", but that doesn't mean it's a good thing. In pre-modern factory days people of any age worked there whole day, 6-7 days a week. It doesn't mean that's a good idea to do it now.
For appendix removal, and trauma surgery, sure, your statement is correct. For brain surgery your statement is a bit ridiculous.
Unless that person is on call, it sounds like someone screwed up the schedules by putting an anesthesiologist on a surgery that would take longer than they were still scheduled for.
This is a good thing. Good lord, the ego of some professionals never fails to astound. Treating people like people in the workplace and not harassing them shouldn't be a difficult concept to come to terms with.
For someone in IT, perhaps, but the professional expectations in medicine are starkly different (although they are admittedly growing more lax, to the chagrin of the old guard). In this particular case, the geriatric meningioma patient had already been cancelled on once, rescheduled with the promise of being the first procedure of the day, and then delayed to the end of the day because she tested positive for MRSA and they needed to do a decon of the OR after her procedure. You would seem to find it reasonable to reschedule her yet again, but neurosurgeons don't have much room in their schedules to play scheduling games with, and in general, patients aren't undergoing elective brain surgery for the fun of it: they need it now.
Perhaps the IT analogy is that neurosurgery is largely a hard real-time system: you must execute within a given time window or you fail.
No, I find it unreasonable that not everyone knew the schedule beforehand, or that someone who knew about it didn't raise it as a problem. This should never happen right before the operation. At that point it's too late and it's on everyone to deal with the situation at hand. What I'm pointing out that if the plan was a surprise then it's completely understandable that someone says no.
As for solutions, it depends on a hospital, location, patient's state, available team, etc. Lots of possibilities. (BTW, anyone shouting at anyone else is not even close to a solution)
It may not be a solution you approve of, but I've witnessed plenty of cases where managers have effectively bullied their subordinates into doing work they otherwise wouldn't want to do.
The problem in this case was that the meningioma's MRSA positive culture results (from the first, cancelled procedure day) came back on the day of the rescheduled procedure, and that necessitated a schedule rearrangement (placing the meningioma at the end of the day) that the substitute anesthesiologist objected to. The author points out the absurdity of the situation re the MRSA culture when, if they had performed the procedure on the day originally planned, they would not have the culture results and so would not have done a post-op decontamination, but the rescheduling had forced the additional step. I think one does the best they can to budget for unexpected problems as had happened in this case, but in an overworked system, that cushion is among the first things to go.
> This should never happen right before the operation. At that point it's too late and it's on everyone to deal with the situation at hand.
Ideally, yes, one catches complications before they are a problem. Experience suggests complications still occur, and the only solution is to "be like water" and adapt.
> What I'm pointing out that if the plan was a surprise then it's completely understandable that someone says no.
Not for a physician. It is understandable for a physician to be ticked off, it's understandable for a physician to call in a favor and find someone to cover for them, but it is not understandable for them to say "no". The substitute anesthesiologist not only said no, but was apathetic to finding someone to cover for her. To that, I respond as I did before, the expectation from what I term the old guard of medicine is that your duty is to attend to your patients. Younger physicians, such as the anesthesiologist in question, would seem to share your perspectives on work scheduling, and the old guard say that the result is decreased quality of care.
> As for solutions, it depends on a hospital, location, patient's state, available team, etc. Lots of possibilities. (BTW, anyone shouting at anyone else is not even close to a solution)
That's a lot of handwaving. Keep in mind that in medicine, you can only kick the can down the road for so long, and that in this case, the patient's family had rattled legal sabers over the first cancellation. I suspect the possibility space is not as large as you think.
What would you have had this person do? Leave their child unattended? Do you have children? Who takes care of them if you have to work late?
Irrelevant, the nature of your reason to refuse to work outside of scheduled hours is between you and your conscience. Be it a child, a dog, opera tickets, or Friday Night Magic - the rules have to be the same. Being a parent doesn't absolve you of responsibilities to patients nor does not being a parent increase your obligations to work additional hours.
Her disinterest in finding someone to cover is disappointing in a healthcare professional - but otherwise "I can't stay late tonight" is fine unless contractually you are on call.
This is potentially a reasonable point. If the surgeon can't make a compelling case to the on-call anesthetist that the case needs to be done, then the anesthetist present has a reasonable argument. That said, I've found that day shift staff may well stay late to handle a case they had already prepped for if that would prevent an up-prepped on-call from having to come in an hour later.
One of my parents is a physician and I didn't get to see them much when I was growing up (or even now); I intimately understand the point of view of those advocating for greater work-life balance in medicine. What I find lacking in the push for greater work-life balance is an acknowledgment that quality of care may be changing for the worse as a result.
There may be a problem with the system here, but the solution isn't forcing people to work past their shift without notice.
Medicine was always about putting the patients' needs above your own, and I sure hope it stays that way for the foreseeable future.
I'm not sure why you think "Medicine was always about putting the patients' needs above your own". Many hospital employees do. But I've never heard of medicine as a whole having that rule.
If you expect doctors to act like everyone's needs are above theirs, you'll end up with a current situation in the UK. Junior doctors who are overworked, hate the situation, government that wants to pay them even less for more hours (they've got patients to see, right?), and are more and more likely to move abroad - rather than just treat with respect like any other normal employee. And that's not even mentioning the dangerous situations created by tired doctors.
These concerns are seriously overblown. Most errors from fatigue occurs on routine, non critical tasks, whereas I have never seen any evidence of a significant increase in critical errors.
A well-fed, rested doctors who abides by regulation is way more dangerous than a tired, hungry one who puts patients first.
"you'll end up with a current situation in the UK"
Poor remuneration is in no way related to great bedside skills, but is due to poor negotiation skills and State control.
Google: study fatigue doctors. It's literally there on the first page.
> Poor remuneration is in no way related to great bedside skills
I'm not sure you're familiar with the issue in the UK. It's both about extra work and what counts as "unsocial hours". Considering the first to emigrate will be (were, actually) the doctors with better skills... yes, all skills are very related to how they're treated.
And it confirms exactly what I said. Among the first three results :
[1] http://www.cbc.ca/news/health/surgeon-performance-unaffected...
[2] http://ottawacitizen.com/news/local-news/no-difference-in-ca...
> all skills are very related to how they're treated.
Of course not, and that's my point.
Doctors are all paid the same in the UK, without any consideration for skills. Those who emigrate and get better pay, are paid better because they emigrate, and not because they do or do not put patients first.
That said, this sounds like a hospital procedure/scheduling fuck up. I don't think the anesthesiologist should be blamed at all, she stood up to unreasonable demands just as she should have. The hospital failed the staff and the patient here.
Professionals in western society don't just magically find themselves in the position of regularly making life and death decisions. Those who do are there by choice. At least some tolerance of discomfort is both expected and required.
so with the scale of the money involved, the system can't deal with several hours of unscheduled in advance childcare? No intern around to send take care of it?
They are a large growth in your brain or spinal cord. With this one, think softball sized. Though the link states that they may not be harmful if left to themselves, for a few days, I'd want it out asap. They can cause brain damage or paralysis in the spine. I know this as my PI had one and could only speak Spanish for a few days as his meningoma was pushing hard on his Broca's Area, the part responsible for a lot of speech.
That the lady was complaining of childcare is unacceptable and she should be reprimanded for it. Health care as a profession comes with costs that you know about when you sign up for the job. One of those is irregular hours. I can't imagine how she thought it was ok to put a person and their family through more costly time in a hospital over having her kid stay at daycare a little longer.
I honestly don't know how long I will be able to practice medicine before deciding that I can build something better (as foolhardy a notion as that is).
It's very likely that something better already exists. The reason you use something terrible is because "better" does not result in adoption. Personal relationships, salespeople, and marketers drive adoption, not the quality of the actual product.
If you aren't positive that you are one or you haven't had this tested in the real world, then you aren't one.
It's not fair to patients to play fast and loose with their data, nor is it at all easy to develop and design usable software. It's not something you could do in your spare time while also working as a doctor. You'd most likely need to start a company and put together a team.
(You would end up with the same thing)
Not that I'm advocating this as a good thing. I only report a pattern that I've seen across a number of offices. I can also report that the nurses hate the computer system as much as the doctors, probably more.
As someone here whose primary job is not programming, the tendency for posts critical of programmers to have a discussion led by minimizers is quite obvious.
You are not the issue. The hordes of upvoters are the issue.
"Anyone with even a passing familiarity with the world of medicine will be amused by the surgeon being forced by circumstances to treat staff like actual human beings. (And he complains about it!)"
Sounds about right to me. IT issues can definitely be frustrating, but this blog reads like a libertarian rant.
Plus everyone will ask "Can you convert some other EHR's notes/data into your system's notes and vice versa?" and now you get to inherit all of that system's bad decisions in that area.
http://www.theguardian.com/society/2013/sep/18/nhs-records-s...
Add to it the whole tech-health ecosystem is scorched earth after countless clueless contractors have blown their way through it (earning the tens of millions of pounds and so on in the process), it's not a great environment for trust, innovation, or making your way through everything to a real-world-usable result.
Toxic work environments in surgery are on notice in Australia: "Doctors must stand up to the ‘cowardice’ that is ignoring bullying" Victoria Atkinson, SMH ~ http://www.smh.com.au/comment/doctors-must-stand-up-to-the-c...
Anyways, the issue that stuck out most saliently to me was the cultural expectation placed upon medical staff to work through any issue regardless of personal life, and what must be a tacit management understanding of the situation. Somebody in management screwed up, and now the doctor is left holding the bag, and this doctor unfortunately feels some responsibility to manage the situation. This doctor is frustrated that the anesthesiologist did not make the same sacrifice, and wanted to tend to family.
I don't blame either of them. Kudos to the doctor for holding the bag that management dropped, and congrats for the anesthesiologist who won't submit to exploitive cultural expectations.
Doctors aren't smart, they're just friendly keeners with something to prove to their helicopter parents.
Edit:
> You know, the people who are actually saving lives every day instead of figuring out how to distract (er, engage) and bilk (er, monetize) people.
Very few doctors do anything of the sort. Most of them just charge you $100+ to tell you what you already knew and write you a scrip or a referral.
See, that's what I mean. I wasn't writing about the general population of doctors, I was writing about the specific doctors who were in the room with me, who you so arrogantly dismiss.
It's really an ugly and limiting mindset.
They hold the records of over 50% of the US. It's pretty scary when you think about it.
Any given time 1/3rd of the user-base is dead... and it's growing because the data has to remain in the system for 60 months (HIPAA). It's not scary because it's B.S... No single or group of health provider in the world is close to having access to 125 million active patient-users on an annual basis.
Until Epic disclose any numbers in their 10Q/10K, realize that they're probably taking about "rows" in a db table or nonesuch, not actual patients or anything that will get them in trouble with the SEC/FDA.
I'd guess the reality is Nike is much closer in having shoes on half of the US pedestrian population than Epic having HL7/PII data.
Source: http://host.madison.com/news/local/govt-and-politics/epic-sy...
You're probably right though. It's still scary to think that it's possible for them to be centralized to that degree at all.
Anecdotally, I find it hard to believe they can build truly cohesive software with an insane amount of developer turnover.
Anyway good luck with that. It's a job that comes with massive liabilities, unprecedented complexity and loads of political infighting.
Torture is a real and a nightmarish thing, and in this ever shrinking world of ours, we (i.e., Westerners) can no longer think of such horrors as existing only for other people in faraway lands.
Am I the only one who's a bit uncomfortable tossing around the term to apply to a well paid professional who's facing bureaucratic inefficiencies at work?
Or am I just being a sensitive ninny-nanny?
Yes. Especially if you have to ask. Either make the case and stand behind it, or don't mention it.
Often there are additional treatments available but for resource constraints. Ordinary folk die of heart disease every day, but somehow Dick Cheney lives on with an artificial heart.
I know being a doctor can be quite a stressful job and requires a certain class of personality. But still it has gone with the territory of being a doctor since the beginning of civilization.
And of course then these delays compound over time and adversely affect the entire system.
Designing good software which meets government legalese constraints (which are guaranteeedly absurd in certain instances, in wording, and nature (while others will make perfect sense and still be just as hard to implement)) in extremely complex situations (health care systems with millions of users with an outstanding number of providers of different sizes, with different conditions, and medications, and the stringency of the privacy requirements).
That's tough.
It'll be really neat to see the progression of software through time. It'll be neat if what we see today is the Model T to the Tesla (X?) of tomorrow (+~110 Years).
>Or am I just being a sensitive ninny-nanny?
At least a little.
When we describe mundane things as extreme "I'm _starving_ the slow service at this restaurant is torture" or extreme things as mundane "enhanced interrogation techniques" we lose a little bit of our ability to correctly communicate and even experience the world.
Being in awe should be a rare and wonderful state, but instead it's apt to describe a free sandwich as awesome.
The problem: lazy people with poor vocabulary (and education) and bad journalism and editorial work.
"I skipped breakfast today. I'm starving."
If you are truly uncomfortable with these sentences then it's possible that you are either a bit overly sensitive, or else you have trouble differentiating between literal statements and common english expressions.