Millions of Americans’ Medical Images and Data Are Available on the Internet
propublica.org
propublica.org
Take the case of "Offsite Image" as an example;
> The company referred ProPublica to its tech consultant, who at first defended Offsite Image’s security practices and insisted that a password was needed to access patient records. The consultant, Matthew Nelms, then called a ProPublica reporter a day later and acknowledged Offsite Image’s servers had been accessible but were now fixed.
> “We were just never even aware that there was a possibility that could even happen,” Nelms said.
That sounds like to me that they build a custom front-end to serve the images which was doing password authentication and billing, but failed to notice the underlying image server software was exposed and responding to queries with no authentication.
I'm guessing somewhere there's a configuration file which has a default IP binding of 0.0.0.0 and a blank password field.
There should be equivalent standards and audits and consultants for private information of all sorts, including healthcare info.
If there was a mandatory requirement (e.g., had it been incorporated in the HIPAA certification requirements that the ACA required the Department of Health and Human Services to have in place and in effect for some HIPAA transactions by the end of 2013, and for all HIPAA data by the end of 2015), the question would be equivalent to “how many businesses want to be legally permitted to conduct business involving HIPAA-covered transactions and data”.
Or course, not only was that not in the regs, the regs were late, and withdrawn without going into effect, so there are no (not even lip service audit) certification requirements for entities in health care.
There is. In fact, that standard and the regulations attending it were tailor made for healthcare information. These guys are in deep doo doo, and based on the way they talk, it's not clear to me that they understand that fact.
Number one, they took the job. The job of holding that data in the first place brings with it certain iron clad legal obligations. It's not something that some startup or random company should just launch off into willy nilly.
Number two, having taken the job, they didn't properly secure the data. Which is actually a federal crime.
Which brings me to number three. The fact that they publicly communicate these facts in as laissez faire a fashion as they do really does betray not only a level of technological ineffectiveness, but also a level of legal naiveté that borders on imbecilia.
Maybe this underlying software which has a port open does so without informing anyone that it’s doing it? I can’t quite believe that.
So that leaves me thinking that at some point, someone did not RTFM.
The analogy would be something like running a Bitcoin wallet service and leaving your bitcoind RPC bound to 0.0.0.0 with no password.
Healthcare doesn't have mandatory certification/audits (there is a legislative requirement to adopt regulations for it by a date that has long past, but it is one of many required rules under HIPAA that the executive branch has simply elected not to come up with regs for on the legally-required timeline.)
OTOH, at a minimum this triggers the breach notification requirements under HIPAA, and will also trigger scrutiny on the degree to which the breach results willful neglect of security.
I would love know exactly what they meant by that, because the way it's worded makes it sound like this is their first experience with computers.
DICOM servers are often not very secured, so if you allow the internet to talk to them, you're in for a bad time.
[0] https://www.bloomberg.com/news/articles/2019-07-09/dna-testi...
Sometimes the IT staff simply have their hands tied, and network isolation is the best they can do, at least for medical devices.
Billing and file sharing vendors should on the other hand have active maintenance contracts to prevent exactly this.
Working in healthcare IT (and I should note this is my personal opinion only), it's actually a little more complicated than that. Healthcare software vendors are generally building their software to meet certain certifications (because the clinics are demanding that), as well as fixing security/patient safety issues, and lastly adding in features the clinics want
The problem comes in that not every clinic cares about the certifications, and the software they have "works fine." So there's no incentive to upgrade to a newer version that has security fixes.
It's important to remember that, with a few exceptions, doctors are not IT, and many clinics are small enough that they outsource their IT. If that IT group doesn't force the clinics to upgrade, the clinic will continue using the version that does what they want, as long as it isn't obviously broken.
Clinics are generally risk-averse, which in many cases is the correct mindset. Unfortunately, that affects their perception of the benefits of updated software.
Of course, the vendor would be happy to sell you one running Windows 7, but the existing hardware works fine, so...
What If you went to see your doctor about some touchy subject ?(STD for example) and the transcript of your conversation gets available on internet?
What was most frustrating to me while reporting this story, was that a researcher had written about this exact problem (after scanning ipv4 for the port) back in 2016. HIPAA is one of the only federal data privacy laws w/ teeth, and this type of obvious insecurity is pretty inexcusable.
Thanks for reading. If you think there's something we should look into, we'd love to hear about it. :-)
P.S. As a fast.ai student -- thanks Jeremy for posting!
I'm guessing he might be freelancing or contracting, but he does have a ProPublica staff page.
I'd love for anyone with knowledge about this to chime in.