Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.
Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.
Or to put it another way, the worst thing possible short of no regulation at all.
Of course, that would need a sizeable investment of both money and time, but it would almost definitely be more efficient than updating one component at a time.
The struggle with these devices is that they're often cheap embedded systems that never receive firmware updates, so they do present a security concern. However, they're also immensely useful and have without a doubt saved lives.
Thats it. That's the American healthcare field and why its a complete shitshow. IT staff is made to deal with decisions they have no say or power in and turnover is quite high.
That being said, most commercial software seems to be way worse. There was the article the other month of a windows 10 machine automatically updating while a patient was being operated on forcing them to be kept under for an extra few hours.
I understand your point, but surely, simply REPORTING the current OS patch level is not, in and of itself, a change risk?
“Sunlight is the best disinfectant”, and all that.
But also what are we doing running life-critical software on Microsoft-made OS? This is idiotic, it is great for gaming and excel but not hospitals. Microsoft could make another OS based on Linux or BSD and it could not be hot garbage. But that would eat into profits and take...effort. Linux and ChromeOS + 2FA is much better although not perfect.
Hospitals need full backup machines and with health care costs already through the roof, that will just add more. Even if you have all your order entry machines setup to not make external Internet connections except to update servers, one bad e-mail getting through and you could be in trouble.
No way the operator is copying a 5GB+ dicom file to your record in your EMR manually.
You NEED to have the patient name added via modality worklists to reduce errors (ie. add the pt to the MRI software before the scan, and send the scan to the EMR once it's taken).
The worst thing is, this protocol is old and insecure. They just don't have the IT chops at hospitals to handle this.
Be careful what you wish for. Many regulations have been written in blood.
It's been a long time since 1996, but most of the IT messes inside health organizations are self-inflicted. HIPAA and friends don't mandate which operating systems you use, specify approved encryption algorithms, or tell you when and how to update your computer systems. These are all choices left to the implementation teams, and they chose to work with vendors who aligned their solutions to information architectures that just don't change very fast. I think if you compared this IT situation to, say, large scale manufacturing in the US you'd find similar problems of outdated platforms supporting expensive and hard-to-change niche software. And it's probably market forces, not government regulation, that's responsible for this similarity.
It is kind of crazy that hipaa compliance isn’t encompassing enough
I worked in hospital IT and it was a tough environment: it seemed like we had at least one big system rollout (EMR, radiology, lab, etc.) every year. It was difficult to manage when the hospital was paying a little below median for the area, now they are way below that where I live (western MA).
Linux would end up the same way, some ancient kernel/distro because the closed source driver only works on that one ancient installation.