Woman dies during a ransomware attack on a German hospital
theverge.com
theverge.com
Negligent circumstances seems controllable, whereas having no bad actors in the world (particularly the international world, including rogue states) seems nearly insurmountable.
Every time this happens, I'm going to keep saying the same thing: Management let this happen. The dangers are known, the risk mitigation is known, and their failure to act is tantamount to negligence. This didn't "have" to happen, they allowed it to happen.
But as I said at the start: Two things can be true at the same time, management's negligence let someone die and the malware authors are responsible for the death.
It is management's responsibility to assess the risks and to decide where money should be spent (in this case on patient critical infrastructure).
To use another poster's example: It is like them failing to upkeep their sprinkler system and part of the hospital burning down.
Software industry hates idea of regulation.
Additionally, you can often satisfy these things with policy statements rather than technological solutions. A weekly review of record access reports may satisfy in some cases, without needing to implement an ACL mechanism.
And after about 60 years of IT, I don't know that we ever will. Efforts to certify systems/processes are often bogus (participate in a CMMI appraisal for a good example of this). Legitimate efforts to certify them are drowned out by the charlatans. And very few in the IT industry would desire personal certifications along the lines of PEs. Either they don't want the legal and financial liability, or they truly believe there's no value in it.
However: Despite a law being in place since 2015 many hospitals are still underdeveloped when it comes to IT and IT security in particular.
If the brakes go out on your care, and you smash into a building, even though it was recently serviced to whatever 'standards' are you liable? Yes. And then it will be up to you to pursue the manufacturer of the car, who will claim they met all standards, so they're not liable. See how it works?
And that's important. You have to have some place to draw the line between "we did nothing and we're all out of ideas" and "what do you mean you didn't write your own operating system from scratch and hire fifteen security experts to continuously analyze it for un-patched zero-day exploits?"
That's where industry standard "best practices" come in. Once some sort of standard is issued (by regulation) or accepted (by industry), it becomes the thing that a Reasonable Person does. Meeting that standard is then usually sufficient to avoid charges of (or additional liability for) negligence.
> If the brakes go out on your car, and you smash into a building
In this case, you're liable because you carry strict liability for your actions as a driver. However, proof that you've kept the car in working order would be sufficient to escape any criminal charges (dangerous operation of a vehicle, for example)
Maybe comparing it to MilSpec makes it understandable to citizens of the USA: we want our hospitals IT infrastructure to be like the navy wants its warships: made out of steel, with redundant systems and sane compartmentalization so it can withstand most attacks. And we are willing to invest billions of tax money to get our existing hospitals up to these standards, because many are like viking longboats: they stay afloat and cure disease, but they are not protected against torpedoes. A hospital looses most of its infrastructure to a some ransomware? There is an investigation by the supervisory body into the technical and organizational details of the specific security incident and they really don't care about certifications printed by some private company that claims to have audited the hospital. The expected result is a "how this hospital intents to prevent this type of incident in the future" document. These standards are not about certifications of industry sector mediocrity waved around to shift blame and win liability cases in court. Also I don't think liability cases work that way over here, but i am not a lawyer.
What do you think?
I don't think there is a single hospital that completely fulfills those standards. The bar is very high and the umbrella organization of hospitals says there must be millions per hospital invested to reach the requirements.
In unrelated news: a new law was passed today, after years of preparation, that includes a 4.3 billion euro investment of tax money into hospital IT systems.
Wouldn't simply using a cloud-based B2B service with something like Chrome OS / Cloudready instead of Windows solve the entire problem?
If that wouldn't work for data privacy or network availability reasons, it could be an open-source self-hosted server application, accessible locally only through a REST API.
And the server security? Just use something like self-updating RHEL CoreOS with a bunch of isolated containers, which greatly limits the entire attack surface.
> I don't think there is a single hospital that completely fulfills those standards.
Why can't a single technical solution be designed and supported for all state-owned hospitals in Germany?
Are you aware that unlike Windows, Chromium OS has been designed from the ground up with security in mind[1]? And that it can run on almost any hardware[2]?
> All your mentioned alternatives could just as easily fail if not properly secured.
Software has to be designed and chosen with security in mind from the beginning.
If a hospital is running Windows Server instead of automatically-updating, minimal Container Linux[3], it has a much larger attack vector space.
These two factors alone (a proper client OS, and a proper server OS) can reduce the probability of a successful ransomware attack to almost zero.
[1] https://www.chromium.org/chromium-os/chromiumos-design-docs/...
I think you can’t tell the attack space from a glance like that. And there’s ways to properly lock down Windows installations too, patched or not. Careful systems design and planning is key, regardless of exact components.
That has been a solved problem, at least in Chromium OS[1]. Even hardware-based two-factor authentication can be required for all users by a click of a button.
> DDOS attacks?
If it's self-hosted by a hospital locally, most parts of the system should not be available on an open network. If it's not self-hosted locally, the largest European hosting provider, OVH, can survive a 1.1 Tbps DDoS attack[2].
> Careful systems design and planning is key, regardless of exact components.
If the solution is not designed around up-to-date technical components, it can fail regardless of careful planning.
[1] https://support.google.com/chrome/a/answer/1289314?hl=en
[2] https://arstechnica.com/information-technology/2016/09/botne...
In large organisations, the problems are always found in the organisation itself, seldom in whatever tech stack is used. That they used unpatched Windows installations is not the disease, it's a symptom of the disease.
You can enthusiastically treat the symptoms and improve the condition of the patient, but unless you go to the root causes, the patient will find new ways to be ill and you can 't be there to band-aid everything, all the time.
2: because Germany is federal-social-democratic, not stalinist.
Ah, "federal" is the right answer here. In many smaller EU countries, there is a single central social-democratic government, which can just fund an open-source solution for all regions to use.
> What do you think?
I don't understand why this apparently seems so obvious to you. I think I would need more information about the attack, the hospital's preparations for such an attack, and the legal and industry-standard security expectations for such a hospital.
The simple fact that an attack took down a hospital's computer systems is not sufficient to conclude that the hospital was negligent in its security. Surely a sufficiently sophisticated actor (e.g. a state) could take down the computers at most hospitals if they chose to.
I think you can follow all the laws and still get hacked, so I don't think the fact that they got hacked tells us much about whether they were following the rules
https://reason.com/2020/08/22/do-threatened-businesses-and-i...
I see no real moral difference between arson and launching ransomware attacks.
1. Actions that are physically violent
2. Actions that cause physical harm, but the action itself is not physically violent
If 1 and 2 were the same, it would imply that voting for a politician that decides to kill people is just as bad as killing people yourself. The consequences of that wouldn't be good.
> You wouldn't say that someone firing a gun didn't commit a physically violent act just because all they did was pull a trigger.
If the gun is their property, it's their fault that their property is attacking someone. It's not pulling the trigger that's wrong, its that their property attacked someone else. Same idea applies to killer robots.
If the gun is not their property, then it's their fault that they used someone else's property.
In that case, the active threat begins to look more like a random-chance natural disaster than the kind of event the human justice system can bring to heel. By all means use the justice system, but if the justice system is failing? Plan for fire.
(Seems like there's a lesson to be applied here to architecture in California, now that I think about it...)
Fundamentally though, this is a failure of the tech community to engage policy makers and a failure of policy makers to engage / listen to the tech community. It took me (and others?) years to get self-driving car regulations enacted in Canada. And even there, we're just getting started with the basics. Not enough programmers are politically engaged and the field is moving so fast that it is tough for regulators to keep up. I'm not surprised that people are dying. Quite the opposite, really. I'm surprised so few have died given how horrible our security is for industrial systems and other fuddy-duddy sub-industries of software. Yes it's a lot better today than it was five or ten years ago, but the offensive tools are much better as well. It's literally an arms race and sometimes it looks like only one side recognizes it as such.
IMO you should not be running windows on hardware whose failure could cause deaths. Maybe windows could be secured to prevent this but that would require IT staff to keep things updated which does not always happen.
A much better solution is to run locked down Linux or BSD.
Unfortunately, hospitals have a complex and expensive job ahead. I wonder if anyone has developed a blueprint for how to proceed?
Heck, three things can be true at the same time. For example, in the Uber self-driving car death:
- uber's safety systems failed to recognize a human in the road
- the backup human driver failed to pay attention
- the woman in the middle of the street failed to pay attention
There can be N failures that all contributed to a given disaster, and it's important to consider all points of failure which can be mitigated in the future, not just the most controversial point of failure.
For the Uber thing, what incentive does the management have to do the right thing?
Largely because the world keeps demonstrating that reputational harm just doesn't happen to large companies. Uber included in this particular case.
Here's the Uber trips per quarter (in millions) since Q2 2017 (source https://www.businessofapps.com/data/uber-statistics)
Q2 2017 889
Q3 2017 985
Q4 2017 1,088
Q1 2018 1,136
Q2 2018 1,242
Q3 2018 1,348
Q4 2018 1,493
Q1 2019 1,550
Q2 2019 1,677
Q3 2019 1,770
Q4 2019 1,907
Q1 2020 1,658
The probable reason for the Q1 dip was the pandemic. The number of riders just keeps on rising.
You can see the same with Target etc. Large breaches happen, major negative incidents, and at best you might see a blip. The large majority of people just don't give a shit, so companies are given permission to not give a shit either.
Maybe say everything has one cause: the initial conditions on the differential equation that governs all existence.
The individuals involved in an activity are the only ones responsible for avoiding negligent behavior in a society based on the liberal democratic principles of individual rights and responsibilities.
However, to give due credit to your musing, the Uber situation is somewhat different in being on public roads, which lawmakers do have some responsibility to govern an individual's use of, for the safety of others who share public roads with the individual.
Regarding self driving cars: I was once told that a big reason for the safety of fly-by-wire systems (when planes first moved from directly attached controls) is that the engineers who built those systems had to take the first flights, so they made sure their systems were good. That is probably the case for self-driving cars too, but falling out of the sky feels more viscerally unsafe than driving on a highway, and the gradual nature of the changeover probably isn't helping either.
Technology isn't neutral. The world is too complicated to hide behind that argument. We must think about the consequences of the things we build.
> The latest development in the brave new post-Bitcoin world is crypto-equity. At this point I’ve gone from wanting to praise these inventors as bold libertarian heroes to wanting to drag them in front of a blackboard and making them write a hundred times “I WILL NOT CALL UP THAT WHICH I CANNOT PUT DOWN”
https://slatestarcodex.com/2014/07/30/meditations-on-moloch/
Fortunately, Scott is wrong on this. Crypto does not only subvert old forms of coordination, it also allows new forms of coordination. Whether this will is a net win remains to be seen.
Cash, Bitcoin, and encryption are neutral technologies that can be used in negative ways.
> Weak analogy
> Definition: Many arguments rely on an analogy between two or more objects, ideas, or situations. If the two things that are being compared aren’t really alike in the relevant respects, the analogy is a weak one, and the argument that relies on it commits the fallacy of weak analogy.
> Example: “Guns are like hammers—they’re both tools with metal parts that could be used to kill someone. And yet it would be ridiculous to restrict the purchase of hammers—so restrictions on purchasing guns are equally ridiculous.” While guns and hammers do share certain features, these features (having metal parts, being tools, and being potentially useful for violence) are not the ones at stake in deciding whether to restrict guns. Rather, we restrict guns because they can easily be used to kill large numbers of people at a distance. This is a feature hammers do not share—it would be hard to kill a crowd with a hammer. Thus, the analogy is weak, and so is the argument based on it.
In this case the distinction between cash and Bitcoin is exactly what enables criminals to benefit from their crimes.
You buy a sprinkler system from Acme. Acme cheaps out and installs defective sprinklers. An arson lobs a molotov cocktail through your window to set your house on fire, but the sprinklers fail and your house burns down as a result.
The arson caused the fire, but Acme is simultaneously responsible for the defective sprinklers.
The analogy breaks down in the context of the law (as most analogies seem to) because in this case the hospital was not explicitly selling you a product to protect against hackers. However, I think it stands up from a purely ethical point of view.
In this case, I don't see many details, but it does sound like they simply couldn't access patient data and thus were transferring patients. I find it hard to believe that they couldn't have continued to provide emergency treatments that don't require networked computerized machinery.
But I'd want to know more about the attack before I could conclude that the hospital was negligent. Surely for every hospital there is some attack with sufficient sophistication to disrupt service at the hospital.
Even attacks that target patient data, and don’t directly impact medical devices, can hurt patient outcomes: one study found that a hospital’s death rate from heart attacks goes up in the years after a data breach. That’s probably because hospitals have to divert resources to respond to the attack or upgrade software in a way that changes how doctors operate.
There are tough choices to be made here. An attach that spurs them to divert resources to security causing deaths means that diverting resources to security before the breach would cause deaths also. Knowing exactly how much to spend on things other than patient care is tricky. We can say they were negligent because they didn't spend the money, but there weren't any attributable deaths yet, so they would have been spending money with an idea it would probably cause some adverse patient outcomes and not knowing if it was actually needed. That's a hard position to be in.
[0] https://www.law.cornell.edu/wex/felony_murder_doctrine
[1] https://en.wikipedia.org/wiki/Murder_in_German_law#Crimes_wi...
People call for more automation but they forget the downsides in resource constrained places such as the public hospital system.
This thread is full of people who don't know what they're talking about.
I'm not doubting you (I've worked with the manufacturing industry before, sounds eerily similar), it just seems very, uh, precarious, to say the least and I'm interested to learn more about it.
However, even if emergency escape hatches exist for the particular task at hand I'd bet on the staff on site to not be aware of those anyways.
Technology brought complexities to healthcare that healthcare workers are not educated to handle. For instance, try asking to undock a surgical robot for anesthesia to gain access to the patient in an emergency. On DaVinci robots, there's a procedure for doing that in 30 seconds. Last time we tried it in our OR, it took >10 minutes.
That said , the first time I had to use paper I felt like I had no idea what I was doing, because a lot of the EMR defaults aren't there to prompt you. So you have to specify a 'start time' for a medication, but in the EMR now is the default, so I didn't think about it as anything mandatory.
There are bundled minor upgrades (think service packs) that have short (10-60 minute) downtimes, blocking migrations run in that time but are kept to a minimum. If it is at all possible, migrations will be async (even on major upgrades) and run in the background after the new version goes live.
During downtime, bloodwork and the like involve pre-allocated barcode labels. Either the results will be accessible on the instrument afterwards in its memory, or the results will be printed out and it is up to the lab tech to transcribe the results.
I can't speak in depth for radiology, but I expect that they have file share servers involved for the raw results. Likely less local memory (in number of results that can be stored) than clinical lab instruments.
So: a gaping security hole known for eight months has been left open. This is especially important to keep in mind because their lame excuse is that they hadn't had enough time to fix the hole.
In fact i've patched things with year with CVEs published in 2012/2013.
It cost money and there is a... Hmm delayed impact (or none) that's why.
But : germany is bringing out a new law about important IT infrastructure where you need a soc/ siem etc.
I think its called IT sig.
So, the security hole was actually patched shortly after release of the security patch.
Edit:
Source: https://www.heise.de/news/Cyber-Angriff-auf-Uniklinik-Duesse...
"The cyberattack was not intended for the hospital, according to a report from the German news outlet RTL. The ransom note was addressed to a nearby university. The attackers stopped the attack after authorities told them it had actually shut down a hospital."
Source: https://www.theverge.com/2020/9/17/21443851/death-ransomware...
If this was just some ransomware attack it would be barely newsworthy, and we sure wouldn't be discussing it. The death is what makes it interesting. And in this context it is important that the hospital wasn't even the intended target but was caught in the crossfire.
That doesn't justify anything, but I think we can all agree that extortion is a less severe crime than murder.
But if I had to assign jail sentences, a ransomware author would get a decade or two (add another decade in this case for manslaughter), a murderer would get a life sentence. Life over property.
It is important to recognize that crimes have different levels. Society understands that, and it's encoded in our laws in the way we define scaling punishments, and have a difference between misdemeanors and felonies.
For thefts, there's a distinction between "burglary", "robbery", and "robbery with a deadly weapon".
And in this case-- comparing ransomware of a university to terrorism is disproportionate.
So in this case, the better analogy would be explosives - someone tried to blow a safe to get the money inside but the explosion also killed an innocent bystander.
Prosecuting them for man slaughter and arson and everything else what applies would be perfectly fine.
The Morris worm's DOS nature was a programming error; it was still prosecuted as a felony for total amount of damage done.
1) Hospitals are usually swiss cheese in terms of vulnerabilities because patient safety overrules most security issues. It’s very difficult to patch in time
2) Hospitals tend to have a tricky network and asset profile with security staff potentially inheriting decades of unmapped custom IT
3) Theyre usually underresourced and overworked
[1] https://blog.fox-it.com/2020/07/01/a-second-look-at-cve-2019...
Its plot takes mainly place in Germany, so it's written with a Europe-centric view and I'm not sure how well that translates to the US. However when looking at the brittle electric grid in parts of the US, I believe such attacks could be even worse there.
[1]: https://en.wikipedia.org/wiki/Blackout_(Elsberg_novel) [2]: https://www.amazon.com/Blackout-heart-stopping-techno-thrill...)
When the cops contacted them to tell them they had attacked a hospital, the ransomware people gave them the keys. The hospital has access to their data again.
Looks like even criminals have a conscience. Or maybe they figured if someone dies they might be an actual effort by the police to hunt them down and put them in jail for a decade or two so they better cooperate.
Yeah, we call that an accident. Just like hitting someone with your car can be an unintended consequence of driving.
> Then your defense is "I'm not a monster, of course I didn't purposely hit a pregnant woman."
The question of whether or not I'm a monster is irrelevant to the fact that hitting the pregnant woman was an accident.
Applying that to this incident seems barbaric. The "transferred intent" is stealing. Sure they're jerks, but don't make them out to be murderers. The fact that a woman died was an accident through and through.
The very worst case scenario they saw when they initiated their crime was that some data would be lost. The transferred intent is that the data of another organisation was going to be lost.
That a woman died was an accident.
Transferred intent is when a perpetrator intends to harm one victim but then "unintentionally" (quotes mine to point out it is in the defined legalese rather than "accident"). Yes, you can say they meant to steal, and not intentionally kill anyone. IANAL.
If you want to put it in legal scope though, it is involuntary manslaughter. You haven't convinced me to call it an "accident" by any means.
Look up any dictionary and I assure you that you'll find the definition fits this case perfectly.
Eg from the Oxford dictionary:
"An unfortunate incident that happens unexpectedly and unintentionally, typically resulting in damage or injury."
Death is unexpected when you hack a University server. Death was certainly unintentional in this case.
> Yeah, we call that an accident. Just like hitting someone with your car can be an unintended consequence of driving.
I would add to your statement above to make it fit the comparison to the actual incident a bit better:
> Yeah, we call that an accident. Just like hitting someone with your car can be an unintended consequence of driving a getaway car during a bank robbery.
I wouldn't use the word "accident" here. I would say someone "tragically" died when a criminal was driving away from the scene of a robbery. Of the 38,000 people who die in car "accidents" in the U.S. each year, if 30,000 of those were getaway cars or tied to criminal activity, and not just "accidents" I think there would be a different response to the scenario I just presented.
Accidental death benefits from the insurance industry exclude death caused by illegal activities, but I think this means by the person committing the illegal acts, so maybe not such a good example. I don't know.
If someone chokes someone, so that they can render them unconscious to rob them or arrest them, and the choked out person dies during the process, would you use the word "accident" in reporting the incident?
If this university/hospital hack was committed by completely naive hackers, they were still committing intentional harm to a business that affects the employees and others doing business with them. It doesn't take much imagination to figure that by using ransomware in this incident, you may affect people's lives negatively without the actual death that occurred. They might have to lay off a worker or two to cover the loss, not buy essential equipment for the university or hospital that year or more, etc.
I'll leave off here, and say you had a "convincing" argument from a concise dictionary definition, but I wouldn't sling that word so nonchalantly in applying it to this woman's death. Perhaps I misread the tone of your "Yeah, we call that and accident.", but who's we?
Germany is not a common law jurisdiction. If you use legal arguments, at least use ones that are applicable.
Similar to how we don't refer to our phones as smartphones anymore. Back in the 1990s, if you had asked me to check the weather on my phone, I would've thought you meant calling up the weather channel/hotline, but now we all know exactly what you mean.
However, that "can't accept emergency patients" is surprising. I don't care if the lights are out or if I can't digitally sign their papers: hospitals should be able to run even with no machines at all. Ideas for next time:
- Paper docs available (already printed) in case everything goes under (banks do that for example, for generic papers, like opening an account, etc.)
- Air-gapped backup machines that can be used on the MRI/scanner/ultrasound/whatever machine (that hardware hardly ever changes, so it's not like those air-gapped machines would be a pain to manage)
- Backup 4G-enabled laptop that can read the vitim's Carte Vitale (or equivalent [0]) (and which doesn't connect to the hospitals network whatsoever)
- Backup hardware (Scanner, Ultrasound machine) in case someone actually fries the regular ones thanks to their horrible security (we've had plenty of such articles on HN)
- Read-only machines. Once it works, unless it's for a patch, the OS and applications shoudln't be changed, at all.
- User awareness training. Ransomware rarely happens by accident: someone clicked a bad document in a phishing mail. (Unless, you know, Wannacry, but that's not the norm)
I don't understand the sheer incompetence involved. He had his prescriptions with him, he was lucid enough in the first 10 hours (my mother couldn't be in the emergency with him due to covid regulation but he communicated with her by phone) to explain his medical history. They had all the elements to actually do something but they didn't because "our computer systems were not working"
Hospitals should be able to run without computer systems and the budget for maintaining those same systems should be high enough to ensure things work. I can't fathom that it's not the case and I would never have expected something like this to happen. It's hard dealing both with the death of a close family member and the anger at the incompetence displayed by the French hospital system.
I suspect that they can -but- they're probably concerned about legal issues - if everything isn't logged in or authorised by the system and something goes wrong, someone (and I by no means mean to imply you here!) at some point will launch a legal claim over that mistake.
[Edit: Which is also not mean to defend the hospitals for taking this position - I think it's daft but I can understand there may be reasons for it.]
If my father had been redirected to another hospital instead of being left there to wait for hours until his situation became critical, I would have been happier with them..
Then the law should have a "best effort" provision. I believe aviation regulations have a similar thing, where the pilot doing anything possible in a best-effort attempt to survive or minimise casualties, including violating other regulations, is itself explicitly permitted.
Yep, I'd probably agree with that.
Sure but I think a lot of people would not see "we're not sure it's safe to do the surgery, let's wait" as "killing a patient" especially when you're probably going to find it hard to find anyone who'll say it was safe to do at the time.
If they found enough money eventually it would go to a sensible IT infrastructure, but these people don't view themselves as IT administrators. They view themselves as doctors trying to save lives, not computers.
It takes an event like this to drive home the point that these have become the same thing. You can't be a doctor without also caring for your IT infrastructure.
To you that may sound obvious, but consider the other way around. You can't be an IT guy without caring for your own health. Equally obvious, right? Now look around you how many unhealthy IT guys you can see who always prioritize their computer time over going out and doing some sports.
Verge coverage is... shallow
- (unquestionable) the attackers but as well as
- the IT-department that did not fix serious vulnerabilities (of an apparently mission critical system)
We have that in all kinds of places: If you neglect your duties on maintenance or diligence in areas where humans could be harmed (electrical installations, fire safety, construction, whatsoever), you are liable for whatever happens. I don't see why IT should be somewhat special. The Citrix patch came out half a year(?) in advance.
The hospital refuses to state the software, so they can't care to much.
People have died from ransonware many many times before in hospitals. ie [1]
But orders of magnitude more people have died from hospital's shitty IT systems.
[1] https://krebsonsecurity.com/2019/11/study-ransomware-data-br...
I'd really like to hear an argument saying that we need to make all hospitals robust to ransomware attacks AND THE EQUIVALENT RISK-EVENTS, because you don't get to chose before the fact which event you need to guard against. It's very cheap to say post-fact, in the comment thread of this particular news, that management should have taken care of this and screw the cost (I'd expect HN people to be aware that competent IT services aren't dirt cheap). But do we also need to guard better against falling planes? Or storms? Or homicidal family members? Or rabid dog attacks? I'm almost tempted to put shark attacks on the list as well, because at 1 victim globally, there must have been some circumstance where a floating hospital got a patient killed by a shark.
What if tomorrow, say a buggy Windows 10 update disables their systems, will someone else die?
There are multiple hospitals with emergency rooms in Düsseldorf (I grew up there). Wouldn't it have been better for the patient to be taken to one of these, even if they lack the quality of care (in terms of number of different specialists on call) compared to the university hospital?
To me, it is clear that paying a ransom encourages the crime that the ransom repairs, regardless of anything else going on.
At best, they might trigger the creation of laws that prohibit paying ransom to take away the incentives. At worst, they might get themselves tagged as terrorists and end up on the pointy side of a fairly urestricted use of attack drones by the US.
This is not IT anymore, this is in medical device territory. When you rely on a computer to send a medicine order to a hospital pharmacy, and you can't get drugs without it – that's a critical life support device at that point.
If you can't administer medicine to a PT without scanning the barcode first, that's a critical life support device.
Yes they could.
What exactly about a computer system prevents them from admitting a person?
Just pick up a piece of paper and write down whatever you'd write down later in the computer once it's back up. It's not that hard.
I could understand if a particular machine that goes ping couldn't be used because of the computer system being down. But that's a very specific issue.
I don't manage their MT systems but I know about them and I hear about them from co-workers.
And just going on common sense I don't see how a computer could prevent a hospital from admitting a patient. We're talking about admission, not any special treatment.
So it's an honest question to the community, not trying to be dogmatic here. I'm honestly asking, what in a computer system could prevent a patient from being admitted for care?
As far as I can reason, no drugs are being held hostage by a computer. Doctors can still use their training without a computer.
Humans have been treating ailments for thousands of years without the aide of computers.
It would be really sad if this woman died because hospital staff felt hopeless without computers.
Edit: Going beyond just the human dependence on computers, it would be a good exercise in society readiness to be able to treat patients during a blackout for example.
Common sense is knowledge gained by experience. Thats' why kids "don't have any".
> I'm honestly asking, what in a computer system could prevent a patient from being admitted for care?
This is a good question for us to have more detailed understanding of.
I'd say it has more to do with sound logical reasoning, and not only with accrued information.
That's exactly why I said "not only" instead of "not".
> I don't see how X
Then what's often lacking is an experience or knowledge that would allow them to imagine X.
And now computers are in many cases deciding about life and death. Very trivial example: Boeing 737 MAX. Not able to turn off automation can cause death.
> Going beyond just the human dependence on computers, it would be a good exercise in society readiness to be able to treat patients during a blackout for example.
I agree but this does not mean that we are ready for that.
>I agree but this does not mean that we are ready for that.
Yes, well then this issue is even more important.
Because the german police are treating this as a type of homicide. So they seem to be going after the hackers as the cause of death here.
Then it becomes even more important to clarify why the woman was turned away.
Others have pointed this out but it could be as simple as general policy, or a manager not willing to risk treating her without the proper tools.
Either way, european countries have been talking about society readiness lately and this is key for society preparedness.
Therefore I'm not sure we should be pointing fingers at the hackers here, seems like an easy scapegoat for a deeper issue.
Even if they have to manually operate a ventilator for 4 hours in shifts, they are still a hospital. The most qualified place to save a life, and they turned it away.
The Boeing situation is an interesting. With the Max, Boeing broke a core tenant of aircraft design that’s been a major factor in making airliners so safe. The MCAS system’s inputs (from angle of attack sensors) were not redundant. They should have been at least doubly-redundant given that the ultimate design of MCAS could pitch the aircraft down to such a degree that the pilot could not overcome it using their own control inputs. While Boeing probably should have redesigned its airframe instead of adding MCAS, it wasn’t a fundamentally bad idea to employ automation. The system behavior changed, but the company failed to re-assess the safety implications.
All Airbus products are fly-by-wire and there’s always some level of automation in play. It degrades to employ less protections when system faults occur. There’s a lesson there for Boeing!
A lot of devices in hospitals work on vendor provided machines that are not up to date. If anything happens on either end, you can't use device. I am talking about CT, MRI, endoscopy, and other devices.
If you have integrated single sign on with access cards, and AD dies, you can't login, and if you can't login you cant use the device. The reason I am pointing AD out, is because I am working in integrating such device in our software as we speak.
A nurse gives someone medication that they told you they are allergic to.
I'm not sure a nonmilitary a doctor today could spin one of those info-management systems up in a single day though.
I don't see how that is relevant
I reckon even a restaurant with a modern POS system would be problematic to switch to paper, ad-hoc.
This is essential for society readiness.
They occasionally get caught by rarer situations like a blackout combined with a flood which takes out the generators.
My local shop on the other hand would have no issues. Strictly cash only, or a verbal credit agreement if you don't have enough on you. The proprietor refuses to get a card machine, says the risk is too great for a business with such low margins.
it would be slower and a couple more orders might get messed up, but it's not that big of a problem. a lot of restaurant POS systems are just a calculator with a touchscreen that prints two tickets per order (one for the kitchen, and one for the servers) and tells you how much to charge the customer. then the kitchen spikes their copy when they finish the order, and the server spikes theirs after they bring it to the table. on fancier ones, the tickets are just shown on a screen and you "spike" them by pressing the done button. anybody who understands how to do their job in the first place can emulate the digital system on pen-and-paper. in fact, the POS went down more than once when I worked in restaurants, and this is exactly what we did.
But it was hard enough to deal with that we always waited for them to come back up before checking people out again.
Recently, after a hurricane, I heard local supermarkets were checking people out manually. It involved looking up prices of everything (by running to the shelf, I think!) and then writing it down and doing actual math. I was amazed that they even tried it. It's so difficult as to be nearly impossible thanks to the way things are done in normal times.
And that's just a grocery store. Medical stuff has to be way, way harder.
So while they could take in the patient, a lot of the equipment wouldn't work. So it's better to reject the patient and send them to a facility where they could be treated properly, instead of dealing with faulty equipment.
BTW, use the emergency info of your phone: https://www.androidcentral.com/how-add-emergency-information...; https://support.apple.com/en-us/HT207021
I think if the story went like "we treated the patient immediately, but she had a rare allergy which we couldn't look up in time because a ransomware attack took our network down", it would be much more of an everyday story.
Assuming the hospital must have had a better triage response is like assuming authorities should have taken some murder threat seriously and stopped it. Maybe.. depends on frequency and other outcomes and doesn't really absolve the murderer either way.
We are currently working with some equipment in radiology. Devices need to be connected to network, so that they can display data on proprietary viewing device connected to the network. Some devices (and viewers) are using old versions of windows (win2000 and linux, still see RH4 ) as a base. You don't have control/access over the windows machines only vendors do, and a lot of them are obsolete versions. Windos 2k is still common.
Network dies (or is inaccessible) for any reason, and device is unusable, because you cant control it or see the results.
I spoke to their systems guys, they are aware of risk, but their hands are often tied.
Either have it old and offline, or connected and updated.
Preferably offline and updated though. Forcing an online "subscription" and not keeping up their end of the bargain infuriates me.
Why? Was the ER robot down or what exactly are the dependencies for a doctor to rely on a Computer-system?
One comment mentions that the German cybersecurity agency "confirmed" that initial access occurred through public-facing Citrix servers that were missing security patches, without any source to support the claim. Another commenter linked an article[1] indicating that the attack was "likely" carried out through Citrix servers, which seems more speculative than anything.
I think that two elements are worth mentioning here. First, protecting an IT infrastructure from ransomware is not a "simple" IT task (e.g. patching a server or just doing regular backups) but requires the successful implementation and combination of a large set of technical and organizational measures/controls. Without additional details, in particular regarding how initial access[2] then lateral movement[3] were carried out by the attackers, I don't see any validity in debating whose fault this is. But that's just my opinion...
Second, press coverage[4] seems quite adamant that the hospital was not targeted and that the attack was a collateral damage that resulted from the university and the hospital having their information system mutually trusting each other. If we had to consider collateral damage as a valid ground to sentence someone to life in prison (as suggested in several comments here), many governments that offer the highest level of freedom to their citizens should definitely start expanding their prisons.
In many countries and regions, Europe in particular, collateral damage is not necessarily attributed to recklessness or negligence. In order to support the accusation made by many commenters here, we would need to demonstrate either of two of the following: 1. That the attackers knew in advance that compromising the university would also result in compromising the hospital. 2.That hospital/health critical information systems being directly linked to universities without adequate security is common practice AND common knowledge among cybercriminals.
Except for the "five eyes" countries, the justice system in most civilized countries still recognizes the notion that an accused should not necessarily carry the total burden of the damage caused by her/his actions. In other words: although Germany may charge the author(s) for homicide by negligence, they will very likely also have a good look at whether or not the hospital's management did not commit recklessness, either by refusing care to a dying patient, or by failing to protect its critical information system or by failing to implement fallback procedures as any other critical infrastructure supposedly does today.
Until then, I probably repeat myself, I don't see any validity in debating responsibilities in this specific incident, or expressing wishful thinking, until we have more information about what happened.
1: https://www.heise.de/news/Cyber-Angriff-auf-Uniklinik-Duesse... 2: https://attack.mitre.org/tactics/TA0001/ 3: https://attack.mitre.org/tactics/TA0008/ 4: https://apnews.com/cf8f8eee1adcec69bcc864f2c4308c94