Unencrypted patient medical information is being broadcast across Vancouver
openprivacy.ca
openprivacy.ca
edit: to be fair, it should be possible to encrypt some of the traffic, but things should fail open, not closed, or people will die.
Mobile phones continue to work during a disaster as long as the base station batteries hold out and that’s with cheap base stations serving very large amounts of idiot users using the cheapest of the cheap handsets limited by regulations. Why wouldn’t you be able to make this work indefinitely with a limited amount of trained users using selected, powerful expensive handsets.
In other words, a bunch of poor excuses made by coincidentally those same people who love to profess that privacy doesn’t matter as long as it’s someone else’s privacy.
Except when you go over your Verizon bandwidth limit.
https://arstechnica.com/tech-policy/2018/08/verizon-throttle...
It was no a disaster, far from it. In Belgium, few years ago, a fire under a bridge broke an bunch of fibers from the main telco operator.
Result on a region of about 200,000 inhabitants:
- no radio (on my usual station), first thing I noted that morning.
- no internet
- no TV (comes via internet)
- no cell phone coverage
- no land-line either
- emergency calls impossible (by cell-phone or land-line)
This started early in the morning and was only solved in the afternoon for most people.
We are over-reliant on some technology with many single point of failure we do not even know about.I would hope most telco networks would be somewhat resilient.
I also heard the railways are the main fiber provider: They have long stretches of rail between all major cities, so they are ideal for fiber. But very bad for redundancy
I imagine that's internet radio? That couldn't be normal AM/FM radio.
It's happening slowly in the US. Biggest reason it's slow is "defense/law enforcement" suppliers and their markups for the industry which add cost and causes departments to delay as long as they can until someone ponies up the money. Not to mention there is new IT overhead in managing the configuration on said radios and while bigger agencies have the internal team to do it, smaller agencies don't have that benefit.
Unlike say France where there is one singular police force that can share resources, in the US there's hundreds of them in just one state. Don't get me started about ambulances. Because this is #amerika, there are thousands of private ambulance services. Getting them on board with encrypted comm isn't really going to work given they begrudgingly paying most EMTs minimum wage.
Maybe? There are numerous accounts of inoperable service when incidents like 9/11 or the Boston bombing occurred. So in cases where the system is flooded, it might be a crap shoot.
The only way this would work is with dedicated frequency and possibly infrastructure, similar to FirstNet.
Why "idiot"? Are they idiots for using cheap handsets? I really can't tell why you added that word.
Of course there are.
It's not PII when a police officer says your name and address. It's only protected health information when someone who is governed by medical privacy laws does it, like a nurse.
Sure the cost is higher, but the cost is for privacy. This would also allow an actual backup system, versus purely VHF.
So, a like-to-like alternative is probably a encrypted local mesh network.
I have mixed feelings about the encryption though, especially with police data, generally I feel much of that data should be public with a more limited amount which should not. It's good to make public "there's a drunk driver on this street, right now", you just might not need to share their plate with the public.
It's mentioned in passing in this talk description from 2011:
https://2011.ruxcon.org.au/2011-talks/all-your-rfz-belong-to...
" ... and security-through-obscurity in hospital pager systems."
I'm 99% certain I saw him give that talk at Dorkbot in Sydney, which make it maybe 5 or more years earlier than that...
PDW has been going since 2003 and I only mention it because I can't remember the name of the DOS software that preceded it...
I remember that in the 90s, the local PD had learned that some folks would listen to scanner traffic to figure out when their rowdy parties were going to be broken up, so everyone could hide and make the scene look calm by the time officers arrived. So they stopped using voice radios for this sort of call, and instead switched to their Mobile Data Terminals.
Which was even better, because MDTMON had an alert feature where it'd sound the PC speaker when your keywords (say, your street name) showed up in the decoded traffic. That freed up one partygoer from scanner duty!
POCSAG/FLEX were even more of a treasure trove, but that's a story for another day.
I feel weird saying I've "discovered" or "found" something that's merely new to me. I left "uncovered" untried, because I don't consider myself that clever.
I'll try "noticed" and see if it flows better.
In the US, this would be a HIPAA violation but I'm not sure of the Canadian law. We still use pages at my hospital, but no PHI, only room numbers in the ER for admissions are paged and then you log into the EMR. We use HIPAA compliant texting apps to communicate PHI.
I think aspects of it could definitely be improved. I see HIPAA violations at doctor's offices all the time - but they are usually still fairly minor, and doctors and nurses grow concerned quickly as soon as you mention a possible violation.
One cool thing I remember is that the phone lines within the building had to be in armored cable, so they couldn’t be tapped without leaving a huge mess.
https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/ad...
To tackle the problem HIPPA tries to solve, that is making sure that data sharing is secure and only with the intended parties, I want to see stronger enforcement of liability. Granted, the US doesn't have a great track record on that, seeing Equifax get away with what their doing. But I think that's the system that needs to be improved.
Instead of government dictating what "secure" means, different approaches can be experimented with on the market with strong enforcement of liability providing the necessary incentives.
Then Facebook would become a Business Associate and would have to protect information in a variety of very strict ways and could face a fine of up to $10,000 per patient record, per violation. If they had 25 million health records and decided to target advertising to those people on two separate occasions, then they are liable for a fine of up to $500 billion. So sure, let Facebook get into health, it wouldn’t take long for them to run afoul of the law given their move-fast-break-things attitude.
It’s very likely your aren’t seeing actual violations. These “violations” are likely considered incidental uses and disclosures. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance...
The idea that whispering in the waiting room was an important attack vector while whitelisting us IT people is hilarious. (For lack of a better adjective.)
For a middle ground example:
My SO did clinical trials at the local research hospital. She went to ANOTHER hospital for some surgery, because she knows her coworkers look up people's records, and she didn't want them knowing about her troubles.
Like the systems I created, of course there were access logs. But like our systems, no one ever reviewed or audited them.
Hopefully things have gotten better.
I worked on some exchanges in the mid-2000s. 5 exchanges, 80 orgs, 100s of data feeds, including govts.
We had to do HIPAA "training" every year. It was just corporate CYA.
Those of us working on the systems resigned ourselves to the fact that disclosures were inevitable. Even if we could technically secure stuff (encrypt all data at rest, PKI for all access, RBAC, audits, etc), we'd never be able to get all our partners up to speed.
They're a lot more resilient than the cell phone network, especially if there's a mass disaster.
They tend to work better in basements or deep in buildings.
They don't get annoying amber alerts (important in Canada where they're all sent as Presidential/ICBM), constant "IRS" or "Dell" call spam from your area+exchange code (ie: lookalike numbers that seem internal to your hospital) or SMS spam.
These are excellent features if you're on-call, but must respond to anything.
I’d like to know how they think pagers operate.
Military communications for a given mission are mainly all in the same security domain so key management is relatively easy. Co-ordinating key management for daily use between police forces, ambulance services, hospitals, fire stations, and other responders is non-trivial.
I do suspect the best possible privacy solution would be a regulation that made personal and health information acquired without explicit consent inadmissible in a civil court case, regulatory tribunal, or other government process, and heavy fines for using it for insurance and credit and licensing other decisions by regulated/protected businesses. Not so much GDPR regs, but just removing legal leverage from the data.
We still need technical security and privacy controls, but creating legal liability for the people who hold and exploit it is the real solution. Agencies can't hide behind, "machine learning," and "random checks," for targeting people. There will be some hard cases, but if you use PII/PHI without explicit informed consent and collection, use and disclosure for specific purposes, you should be handicapped legally, imo.
If I failed at a hit, and I can watch the POCSAG traffic and see the that the guy I tried to take out is in a coma (and not dead), and is in room 404 at Vancouver General Hospital, that's very valuable information.
Maybe some people get identified as "VIPs" and it's not so easy. Dunno if every random gun-shot victim makes that, but if your "hit" was more an "accidental" car wreck, you can probably ask and find out where they are.
A license is only required to transmit. There is no license required to receive (how would that work, anyway?).
By prosecuting anyone who receives without a license.
Laws are often passed without regard for how enforceable they are.
https://en.wikipedia.org/wiki/Television_licence
Ask all of those countries.
Until listening to cellular calls was made illegal, it had always been legal (AFAIK) to receive any transmissions on any frequency (the reasoning was that the signal was being broadcasted into, e.g., your home).
[0]: https://en.wikipedia.org/wiki/Electronic_Communications_Priv...
* In Canada, we have jurisdictional privacy law. In this case BC FIPPA. This is different than in the US where the few privacy laws that exist are mostly sectoral, such as health (HIPPA). https://www.oipc.bc.ca/guidance-documents/1466
* In Canada, only only one party has to agree to agree to record a telephone conversation.
* In Canada, it is not illegal to have a scanner and listen to phone calls even, hence the need to encrypt them faster up here. POGSAC decoding was done in the middle of the 90s with my local #2600 group. It even easier now with RTL-SDR. https://twitter.com/cqwww/status/1171113297011019781
* I've been in two states of emergency in my life. Cell phone switches go down in minutes. You want to have your amateur radio licence, an amateur radio, and battery, on standby for when this happens. Practice setting up a data connection to is, as the internet goes away quickly as well. Get your ham radio licence, it's free, and you have your call sign for life. It's a nerdy thing to have except in an emergency, where you quickly turn to hero if you're the only person in your area capable of communicating with emergency services.
HL7 was around since 1987, while Dicom is older than TCP/IP I believe. I think requirements for data exchange fundamentally changed in the last 30 years and at least Dicom is just horrible to handle.
True, you could upgrade it with putting everything in a crypt container, but that is just a quick fix.
This is a case where I fully support software engineers that say that we need to fully reimplement these formats. It is good to have standards here, but many manufacturers of medical devices have their own proprietary adaptations anyway. It shouldn't mean to throw everything learned from these formats away. Just maybe it should all be reevaluated.
The current thing is called FHIR though and instead of sending text HL7v2 messages directly to a port over SSL now we can use a web service, HTTPS, and exchange JSON messages.
The beginning of a HL7 (2.4) message with the header and patient ID node might look like this (this example looks like an ORU^R01 inbound lab result)
MSH|^~\&|GHH LAB|ELAB-3|GHH OE|BLDG4|200202150930||ORU^R01|CNTRL-3456|P|2.4
PID|||555-44-4444||EVERYWOMAN^EVE^E^^^^L|JONES|19620320|F|||153 FERNWOOD DR.^^STATESVILLE^OH^35292||(206)3345232|(206)752-121||||AC555444444||67-A4335^OH^20030520
Just a list of offsets using |^~\& seperators sent directly over a port.
The JSON/FHIR versions are nicer even if they are more verbose.
I have dealt with a vendor who’s existence began is still heavily propped up by their HL7 broker service. It seems rather lucrative.
Yes, there are newer standards, specifically FHIR (OAuth authenticated API). But why switch over to FHIR when HL7v2 works really well? Everybody in the medical industry supports this standard, and it’s super easy to work with once you know what you’re doing. It’s also arguably more interoperable than FHIR, because the sending and receiving parties don’t need to fully agree on the spec (like they must for an API). For HL7 messages, there’s a layer that sits in between called an “interface engine” that can modify messages, which opens up more capability with less development and coordination.
pole around 929.600mhz and you'll eventually find a shitload of phi in most metro areas. you'll probably also find a ton of industrial traffic, and the occasional weather and sports scores.
it's also not far fetched to think it's used as a means to broadcast to/from field operatives. most pager lines offer an smtp gateway, so a bit of "spam" could have a intended recipient anywhere in the region, or possibly country based on network.
One time I had my audio misconfigured to use my microphone instead of the line-in, and I had my radio disconnected from the computer to tune the antenna. As I was listening through the radio's built-in speaker, my computer properly decoded a number of FT8 transmissions... through the microphone. You really don't need anything expensive or interesting to do SDR stuff on the HF bands.
People that buy the "real" ham SDRs are doing things like contesting, where they really need to see entire bands, or even multiple bands, at once. And they're paying over $10,000 for that.
The cheap "hacker" SDRs are largely inadequate for ham work. They are OK, but not great. They don't have proper frontends, so transmit a lot of out-of-band garbage. They don't have niceties like an antenna matching network, or even a power amplifier. I have a KX3 which has a maximum transmit power of 12W. But these hobbyist boards will max out in the mW range. It is adequate for some digital modes, but even then, it's pretty low. I typically run FT8 at 1-3W. So generally, would not recommend these for someone new to the hobby. Buy an RTL-SDR stick for $20. Listen to some stuff. When you get bored, find a proper HF radio in the $300 range and use that. If you then decide you want to spend $10,000 on the hobby, then you can start looking into the SDRs ;)
A much less costly (but still highly flexible) option is to combine a high-performance SDR receiver from Elad or SDRPlay with a conventional transceiver. A T/R switch like the MFJ-1708SDR will protect your SDR receiver when you key up, while CAT control allows both rigs to be operated from the same software.
What did they think it relies on? Fairy dust?
Edit: Huh, I guess you might be right. https://www.beckershospitalreview.com/cybersecurity/man-s-an... (2018)
Nobody‘s gonna put up an antenna over years collecting all this noisy stuff.
On top, my condolences for the hospital IT staff having to exchange thousands of real pagers with real doctors, and train them again over the course of several months, all for a pretty synthetic finding that took them a couple of hours.
Builders vs. breakers all again... Well, you got your attention, guys.
What do you think all the antennas on embassy buildings are for?
I think you misjudged how interested in radio some people can be. People do this to ADS-B (airplane location) all the time.
> 2018-11-12: Sarah Jamie Lewis reaches out to Vancouver Coastal Health Privacy Office (VCH-P) with information about the breach.
> 2019-03-04: Sarah Jamie Lewis meets with two journalists and demonstrates the pager breach. This meeting was not recorded and this meeting is never followed up on.
> 2019-07-23: During an interview with journalist Francesca Fionda, on Open Privacy’s research into Swiss election systems, Sarah Jamie Lewis discusses the pager breach.
[...]
> 2019-08-15: Sarah Jamie Lewis reaches out to the Office of the Information and Privacy Commissioner for B.C. (OIPC), offering to help aid any investigation they wish to undertake in regards to this data breach.
They waited nine months before contacting the provincial Privacy Commissioner? They contacted journalists before the OIPC?
> I've been asked why there are some big gaps in the timeline early this year, and that was mostly because I was working on the research around the cryptographic flaws in the Swiss evoting system. We get a lot done at @OpenPriv but we are limited!