Ransomware, Data Breaches at Hospitals Tied to Uptick in Fatal Heart Attacks
krebsonsecurity.com
krebsonsecurity.com
In big-city Canada, patients with heart attack symptoms will usually have an ECG done by paramedics before arriving.
In the US, this has quite survival advantage.
https://heart.bmj.com/content/100/12/944
I don’t know if it’s standard practice to do another upon arrival, but it is redundant and should probably take a back seat to activating other processes that need to happen.
It also helps send them to the most appropriate facility.
If you are having chest pain, call 911. If you mention "chest pain" to them, you hear a beep in the background, and everything else is a machine.
In my locale, the paramedics carry a portable EKG. If they decide to take you for a ride, they have an EKG machine in the ambulance that's networked to the hospital, and a cardiologist is now on your team. When you arrive, you get wheeled into a special room where an entire heart attack team is standing there, waiting for you.
At that point they do another EKG, and as I understand it, their machine has a larger number of electrodes, so they can get more detailed information from it. The patient is never off an EKG at this point, and it's not a discrete step, but is a continuous monitor.
A blood test will confirm the presence of an enzyme that's produced if the heart muscle is stressed. This is a rapid test, the lab is ready and waiting for the sample.
So, the second EKG isn't really consuming time, since other stuff is happening concurrently, and they need the EKG running continuously to make minute by minute decisions. Regardless of what happens, you're on the EKG until you go home.
I don't know if rural or poorer locations have less sophisticated processes.
If you are having chest pain, call 911.
“Breach remediation efforts were associated with deterioration in timeliness of care and patient outcomes,” the authors found. “Remediation activity may introduce changes that delay, complicate or disrupt health IT and patient care processes.”
There was one interesting data point, but no source of cause listed. >for care centers that experienced a breach, it took an additional 2.7 minutes for suspected heart attack patients to receive an electrocardiogram.
Is this while they were prevented from performing care? Thankfully PBS's article goes into more details
https://www.pbs.org/newshour/science/ransomware-and-other-da...
>hospitals that experienced a data breach, the death rate among heart attack patients increased in the months and years afterward. This increased mortality doesn’t appear to be due to the perpetrators themselves — the hackers are not controlling the allocation of medications or doctors. Rather the issue may lie with how health care systems adjust their cybersecurity after an attack
Which makes a much different argument: the hospital response to a Cybersecurity incident increases mortality (thus: can we expect a similar uptick in negative outcomes amongst healthcare organizations who implement similar security polices?)
Research paper: https://onlinelibrary.wiley.com/doi/full/10.1111/1475-6773.1...
The PBS article points out that security practices applied to clinicians led to this problem.
Do we have evidence that the hacking took advantage of the EMR's security issues?
>Time from door to ECG significantly increased after a breach and the elevated time to ECG persisted at 4 years after the breach. Security typically adds inconvenience by design—making it more inconvenient for the adversary. For example, stricter authentication methods, such as passwords with two‐factor authentication, are additional steps that slow down workflow in exchange for added security. Lost passwords and account lockouts are nuisances that may disrupt workflow. The persistence in the longer time to ECG suggests a permanent increase in time requirement due to stronger security measures.
So what compromise is possible to ensure fast login? Can two factor login be limited to new login devices? (Thus limiting impact to those working in new locations?)
Login devices which aren't recognized? (Ie: external servers)
Should EMR login be separated from local PC login within a hospital/emergency department? (Cold booting a PC and logging into windows would be the slowest response time).
Can we tie logins to employee badges to skip all password entry? (Lost badges would thus warrant reporting loss.)
You can, but typically you'd use a badge with a PIN. If you use something like this[1] with virtual desktops (VDI) that don't terminate your session when you disconnect, you can get the "time to login" down to a few seconds, since it's the same RDP session following the user around.
[1] https://www.identityautomation.com/iam-platform/healthcare-c...
We use: https://www.imprivata.com/
All the emr security in the world wont help you if a random piece of critical equipment that is compromised locks you out.
ransomware existed before bitcoin; it used moneypak, western union and similar services as the payment vehicle.
There were a few predecessors (https://en.wikipedia.org/wiki/PGPCoder) using stuff like Liberty Reserve (long since shut down by the Feds), but Bitcoin made it pretty easy.
One tried "mail money to a PO box" back in the 80s. https://en.wikipedia.org/wiki/AIDS_(Trojan_horse) The downsides of that approach for a criminal should be fairly obvious.
A side effect of the anonymity is that crypto provides the opsec cover for these undesirable operations.
The main use case right now (and in the foreseeable future) for crypto is difficult-to-trace payments for illegal activities.
Why don't we in general actively engage in the behavior we want to stop in an attempt to motivate different people to stop us?
I think this is the main idea behind "The Purge," and if "The Purge: Survival" is any indication, it's unlikely to work ;)
The last one actually does happen and it would be great to have a better way to know when and where by who.
It's not impossible to do it with BTC, but at the moment, law enforcement isn't doing much about BTC, unless it involves drugs or CP.
If you're doing Moneypak fraud, and live in any country with a funcitonal rule of law, it's just a matter of time until you either find yourself booked for processing, or, alternatively, ziptied, and with a brown bag over your head, put on a flight to the US.
Select quote: "In August 2012, the FBI also issued a warning that scammers were taking advantage of MoneyPak's untraceability to coerce unwitting victims into paying a "ransom" to unlock their computers infected with malware."
https://en.wikipedia.org/wiki/Green_Dot_Corporation#MoneyPak...
We need to focus on building systems that mitigate this as a potential attack vector
https://news.ycombinator.com/newsguidelines.html
Long flamewars or long tit-for-tat arguments about a generic thing like cryptocurrency, which you unfortunately did a couple times in the last few days, are also against the site guidelines (see "generic tangents").