US prescription market hamstrung for 9 days (so far) by ransomware attack
arstechnica.com
arstechnica.com
This is really affecting doctors and patients. Patients are not getting the drugs they need or the authorization for a critical procedure. Doctors' cash flow is interrupted.
A lot of admin workers are backed up, and that itself is leading to problems too.
Why the backup? Its not just electronic data exchange being offline. Its that everything is now "going to paper" (submitted hard copy) which requires humans. Those humans used to take care of the actual work. Now they are stuck shlepping paper from A to B instead.
I submitted two links explaining this in more detail yesterday
Impacted services:
-Electronic Prescriptions -Several Patient Record Sharing (PRS) systens -Claim Submission -Prior Authorization Appeals -Almost everything involving Fax + UHC
Restored services:
-Electornic Prior Authorizations (ePA) submissions -Real-time benefit checks
For example, if it goes on longer, the FDA might allow the majority of drugs to be sold directly on online marketplaces like Amazon without a prescription. That would remove a huge amount of paperwork and doctors appointments for a massive number of people.
Let's be honest, the majority of prescription drugs don't have an abuse risk.
You have a positive outlook and that deserves kudos, but its not going to happen, at least in relation to the current fiasco.
The pharmacy lobby is too strong.
This seems false based on countless anecdotal experiences and various sources online [1]. Individuals with a valid prescription can have that (once issued by a Canadian/provincial licensed professional) filed and bring it with them or have it shipped through online marketplaces that integrate most of these steps.
Suppliers importing from other countries seems to still be illegal although Florida seems to have recently passed a law and received FDA authorization to do this for some drugs [2].
[1]: https://www.singlecare.com/blog/ordering-medications-from-ca...
[2]: https://www.kff.org/policy-watch/what-to-know-about-the-fdas...
People who take critical stuff regularly usually have to ration drugs so they have a store in case of emergencies. If you travel somewhere and you forget your life saving drugs you then have to spend a good chunk of your trip grovelling to the pharmacist and doctor (depending on the drug) to get an emergency refill if the drug is even available in that location. The whole system is bonkers.
It is absolutely disgusting, that you need a prescription for pharmacy items. There is nothing better than going into a pharmacy and just being able to buy what you need. Never had any problems in Colombia, Brazil, Russia and rarely in China.
What about people without health insurance?
> What about people without health insurance?
Are you suggesting that these people do not see doctors and self-diagnose? I could see an argument that making the drugs OTC without prescription may do this population more harm than good.Remember that in the US, drug companies market to patients, even though it's the doctor that must prescribe the medication. In other countries, this is illegal.
Maybe the barrier of a doctor's visit is not so relevant. Or, maybe it's what prevents things from becoming completely unhinged...
Really? Why?
Then again, its not exactly good intentions that got us here.
In many countries, this is forbidden.
Ah. Yes. What is the alternative if you can't afford a doctor?
" I could see an argument that making the drugs OTC without prescription may do this population more harm than good."
Please die for the greater good. I pass.
I have no idea what other people need. Beta blocker? Metformin? For a start, I would like to have every cortisone based product (cream, tablets) OTC and antibotics too.
In some countries, you can't even buy an antibiotic cream or hydrocortisone cream OTC. In Brazil, I was damn happy that once I could get antibiotic eye drops and once an antibiotic for the ear (drops).
Hey, in many countries you can even buy Viagra OTC. A buddy asked me to bring some for him from abroad.
Yes! Over-regulation cost lives. See Canada, people dying because can't see doctors. Most of prescription drugs are gatekeeper for no reason, they are not 'drugs' there is no reason for that.
Meanwhile typical Montreal health-care interaction:
1. Call your doctor - next appointment in 1-3-6 month
2. Wait till it get bad enough, go to emergency room.
3. Wait and cry there for 6-12 hours, get morphine, see a specialist, get a prescription, go home.
Since my conditions are chronical I should be able to get my meds easily, but nooooo, let's gatekeep everything and make people suffer and die.
See https://globalnews.ca/news/10148872/quebec-er-patients-death... for proofs.
There are no prescriptions in Mexico.
Medications which are scheduled controlled substances (amphetamines, codiene, morphine, etc) are sold directly by hospitals. There really aren't many of these, and hospitals already have to stock most of them for surgical use.
Everything else is cash over the counter.
And pseudoephedrine is illegal because of pressure from the US.
Is it illegal in Mexico because meth comes from there in significant quantities?
The US said "you need to stop selling this without a prescription system". So Mexico stopped selling it entirely.
It's why you can only buy pseudoephedrine from pharmacists.
A lot of “safety” concerns is just FUD spread by a system that wants to preserve itself.
If there's a database with contraindicators, make it public, let people search it, require packaging to inform the public to search the database for contraindicators for their own safety before taking the drug. If people are really unsure, they can decide to engage a doctor or pharmacist instead of being forced to engage a doctor or pharmacist.
Hardware stores also sell many things that will kill you if used incorrectly. We can't have the world revolve around the least capable of us, it's holding everyone back.
And the world has not imploded.
There's a lot of chicken-little-ism around the prescription system
The system is being attacked / interfered with, almost certainly over the money parts.
Patients using the product are by definition not reliable for self-prescribing (argue against this all you want, there is a lot there)
Specialization has risen profoundly in the digital age. Even full time MD's do not know all the aspects of the prescriptions; even full time pharmacists do not know all the medical case context; patients know almost none of this as a whole, though the have intense incentives to think they do, or try to, to varying degrees of success.
A suggestion of "just let the markets and customers work it out" is unwise at the least, and certainly will bring unintended consequences. The current system is overly gamed and now failing outright. What to do? just describing a problem space here..
Is it wrong of me to hope it stays that way?
(Yes, I know it's not bullshit - it's so that right insurers get billed. The most important part of medical art.)
Why are we sacrificing national security for the convenience of companies?
We should have strong legal protections for security researchers. Anyone who attacks a system with the intent of causing minimal harm and reporting what they find should be protected. We could also create a government agency whose job it is to continually try to break into these systems we depend on, a national red team.
The only downside is it will inconvenience and embarrass many companies. We might also find that the majority of our companies and institutions are incapable of creating secure systems, and that will be a hard political reality to deal with. But this is literally a matter of national security.
The bad guys will not be stopped by laws, but maybe the good guys can still win if we don't hamper the good guys with bad laws.
Do you think that people should be allowed to penetration test your house without your permission?
At what point does a system become big enough that you think people should be allowed to attack that system - regardless of its owner’s desires - as long as the attacker has subjectively good intentions?
I am sympathetic to the idea behind your comment, but I don’t see how it’s compatible with strong private property rights. I don’t want you attacking my systems without my permission.
A better analogy might be a friend stopping to double check that my front door is locked before he walks away leaving his child in my care.
If we use an analogy at all, it must account for the fact that millions of bad actors are constantly wandering by and checking the security of my proverbial house. Like, if my house was on an extremely busy street and a someone came to me and said "hey, the lock on your front door doesn't work", I would not have them arrested, nor would it be practical for me to arrest every passerby that checked the lock for whatever reason.
This analogy has limits, but I work in the medical field. I even worked at change healthcare until last year. The consequences of PHI data breach are almost unbounded. Furthermore, If I put my reputation and that of the business on your service you better bet I will poke around with whatever access you gave me.
The hack isn't the problem. The system that privileges access to medicine is.
That is a big part of what makes this crazy. People are in an insane system where they can't pay for drugs. Then the system goes down and they really get into trouble.
The prescription system itself could be compromised, in which case everyone in society would face the same issue (which would be mediated by the fact that paper prescriptions are still produced, and a pharmacist can telephone a prescribing surgery). Only a supply chain attack would really cripple the system.
In the USA, people can and do die because there's a financial barrier to accessing medicine. Not so in countries that care about people.
If the computers didn’t work, it would be incredibly painful in Germany because most pharmacies don’t regularly stock most prescription drugs. They’re often ordered from central warehouses on demand - i.e. if you walk in with a prescription for Xanax in the morning, you’ll typically need to come back in the afternoon to pick it up.
That ordering process is entirely digital. If you suddenly switched to paper forms, phone calls, and faxes, it’d be a nightmare.
An even more fun quirk is that because different pharmacies seem to use different distributors, you'll sometimes have to hop around until you find one whose distributor has whatever your medication is in stock. I once had to go to four different pharmacies in Mitte before I found one that could order Zolpidem.
In the US, prescriptions with refills have a label on the bottle indicating how many refills left. I imagine in a recognized crisis, you would be able to get those refilled with little trouble, maybe even if it said zero refills as long as it was a drug typically used long term and not a drug commonly abused.
We don't do that. You just get a box and that's it.
However, paper prescriptions still exist and can be used in a pinch. I had a doctor write one out for me a few months ago. He did not have access to a computer but had a pad and his stamp on him.
Keep in mind that this electronic system came online a few years ago. Most doctors have issued paper prescriptions longer than electronic prescriptions.
It’s a bit dramatic to say that there is no way to get them to do it again if the need arose.
None of this is unique to the US.
Obviously some approaches and systems work better than others and are more tolerant to some kinds of faults. Unfortunately, none of this gets away from the absurd, insulting, and grotesque reality that care has to rationed somehow.
We can fix this. Essentially, every smoker, every alcoholic, and every obese human immediately goes to the back of the line.
No need for this convoluted bullshit of a system.
Secondly, you're inviting some really complex moral and political arguments. There have been worse ideas than linking healthcare to a political assessment of lifestyle, but I suspect it'd be up there in the same orbit as communism, genocide and slavery. It is hard to see it ending well once the politicians start to disagree on the healthiness of people's lifestyles.
I dunno, in some ghoulish sense it might be the next logical thing for the US to try. Why stop at merely bad ideas?
https://www.kff.org/faqs/faqs-health-insurance-marketplace-a...
I suppose straight up denying healthcare based on class would be worse. But such a system would actually afford its customers the dignity of honesty.
I'm saying that rationing is inevitable and our thinking about health care systems needs to account for that.
I understand there are utopian arguments for healthcare, but where is the demand to respond to them?
I am in no way condemning the individual response to this I'm just earnestly curious where this impulse comes from.
The sky is the limit with what humans can do, but under late stage capitalism, it boils down to the preferences of those who control the system, and nothing more.
https://nymag.com/intelligencer/2022/03/how-asset-managers-h...
We already have a centrally planned economy, but it's only for the wealthy.
I don't think these are contradictory concepts, nor does this do much to justify the objectively atrocious method we currently use to ration healthcare. Every dime of profit could have gone to healthcare—that's not rationing, that's just unnecessary and easily preventable cruelty.
The next step is to move to declare this critical national infrastructure and create all sorts of new obtuse rules and regulations that will be in the name of security, but will mostly be theater and whose only real effect will be to create tons of new "compliance" jobs by low skilled morons who couldn't cut it in a real security job and whose primary job will be preventing actual security and sapping energy from anyone who builds things, because "it's not on the checklist".
Not to mention the dozens of new vendors who will pop up soliciting a product that will promise to ensure customers are in complaince with the new regulations.
Meanwhile Joe blow will still be unable to get his prescription filled and have his personal health data stolen and sold all over the black market.
There really only need to be 3 for critical infrastructure.
#1 - Patch your shit according to industry standards, and have documented audit records that you've done that in a timely manner.
#2 - You're fair game for NSA and DoD offensive pen testing. Failed pen tests are responsibility disclosed, then reported to the market after delay.
#3 - So goes CISO, so goes CEO. Along with a ban from leadership roles for a number of years (5?).
The issue is that the CEOs of these companies hire fall-on-your-sword guy as CISO, ignore the issues / listen to their CISO glossing over deficiencies, then claim breaches came out of nowhere, fire the CISO, and repeat business as usual.
It's not going to change until CEOs have a realistic expectation that deficiencies will be found and personal consequences when they are.
That is literally the case across all industries in every field in every area with big tech being no exception. Almost certainly everybody you have heard about does not and has never had the slightest clue on how to protect against economically motivated, professional criminals; the kinds of attackers that are now commonplace and are expected to attack every commercial system in the modern threat landscape.
This is not a problem of underinvestment, it is a problem of structural incompetence. Systems need to verifiably survive red team pentests with multi-million dollar budgets with exactly zero discovered vulnerabilities before we are even in range of reasonable solutions. Any standard lower than that is inadequate to demonstrate resistance to commonplace attacks and is not even worth discussing.
Nearly all of corporate America practices security by checklist and certification. This is not real security, it’s just CYA for careerists and legal challenges.
Actual security is hard and almost no one does it. The people capable of it are rare and expensive. They’re probably not jumping at the opportunity to work at Optum for $80,000.
You will find exactly zero people at those companies who would be willing to bet their job that a small team of say 3-5 skilled offensive specialists specifically targeting them and willing to expend a year of fulltime work (i.e. a few million dollars worth of personnel cost) would not be able to completely compromise any usable system they designed.
Exactly zero of the recognized names can protect against economically-motivated professional criminals targeting you. All they even claim to do is make you the ROI of attacking you go from the industry average of 100x to a still wildly profitable 10x under the "You don't need to be faster than the hunters, you just need to be faster than the other dodos" theory. Unfortunately, that theory does not work when the hunters keep bringing more of their friends to eat mouth-watering dodos. I mean, the cyberattacks have only been increasing by like, 500% YoY for the last 10 years. Exponential growth that slow means you can keep outrunning the hunters for like 5-10 more years until they eat everybody.
Even if $1M gets you a successful attack, doesn’t mean that the next $1M will. A strong security culture patches up holes and reduces the surface area and damage radius over time.
I agree there’s a ton of snake oil. Most of it is. I agree that actors like Google and Apple also have 0days and will continue to have them. However, there’s still a massive difference between not giving a shit and a strong security posture. Some industries (most?) are in the former camp. They’re the ones who grinds to a halt from WannaCry and friends.
As a simpler example, suppose you did a firing test of a bulletproof vest and the bullet went right through. They patch that up and then you fire again and it goes right through. They do that 10 times and literally every single time it goes right through. You can conclude that those failures were not a fluke, their bulletproof vest is just garbage.
To use a slightly more complex variant, suppose they had bulletproof vest version 1 and during acceptance testing the bullet goes right through. They go back to the drawing board and produce bulletproof vest version 2 claiming it is bulletproof and then the bullet goes right through again. They do this 10 times and literally every time they claimed it was bulletproof and every time the bullet goes right through. You can conclude that their engineering or validation processes are garbage and, additionally, you can only trust them as far as you can throw them. Until they conclusively demonstrate robust protection against bullets in representative tests their products and "expertise" should be ignored.
The thing in the cybersecurity industry is that they fail the audit every time across all fields across all products across all systems. This is not a one-off case where a company has never done it before and they failed once so it might be a fluke or they can improve. This is everybody doing thousands of audits each and literally every single one of them has never once demonstrated a defect rate better than the low M$ range no matter how many changes or "improvements" they make. And the entire time they have been issuing deceptive marketing making people think they can. That is about as clear cut statistical evidence of industry-wide quality control failures as you can find in any field.
Just for reference, this is extremely abnormal in other industries. Only in cybersecurity and software are poor quality control and validation processes so rampant that obvious global process failures are viewed as just the way things are done. Yes, some parts of the software industry are even worse, but even the "best" parts are laughably inadequate. Engineering is not about subjective evaluations like better, it is about objective evaluations like fit for purpose. And commercial IT cybersecurity fails that with a resounding no.
I agree, however say Google and Apple have very few of these despite being disproportionately targeted. Doesn’t mean they are doing enough. But it sure as hell makes a difference. In ~15 years my gmail has never been leaked or hacked. That’s better than having an unprotected DB leaking every customers credit score, like we’ve seen.
Certainly this audit-, certification- and checklist based security is a joke. Security isn’t a patch-work. It’s not separable from software development, and cannot be a separate process/workstream either (a thousand faint gasps ring out from middle managers across the enterprise world).
Anyway, I’m rambling. I guess I wanted to say that I’m optimistic for the long term. We’ve already made some significant progress in the last 10 years, for the better. I expect that to continue slowly.
Think of it as a private SWIFT vendor.
They were acquired by UHC, which is why you see the Optum name. But this is not specific to UHC/Optum patients.
Providers (hospitals, doctors, software vendors) interface with CH’s REST+JSON APIs and in turn CH emits EDI records to the insurance company backends (and translate the responses from EDI to JSON/XML/etc).
This affects general healthcare EDI messages (claims, benefits eligibility verification, ACH notices, etc).
The people impacted do not have direct EDI implementations with the insurance companies. If they did, they could side step this.
Or even a different clearinghouse.
Edit: clarified some ambiguous terms
Thank you. I was trying to figure out how this company seemingly handles most of this stuff in the US.
https://www.healthcaredive.com/news/unitedhealth-antitrust-i...
Weren't the last big attacks literally carried out by hackers exploiting security software? As in, the solarwinds thing, which was carried out on systems which were 'textbook secure' ?
If you want a secure system, my advice would be to fall back to using dumb hardware terminals, VT100 style. Anything more complicated than that will have a backdoor.
So all of the 'experts' you might draft in to give you helpful advice will be telling you exactly the opposite of what you should be doing, which is reducing your attack surface as much as possible; cutting down, not increasing, the number of apps installed.
And don't get me started on MDMs, which are basically a rootkit that's only as benign as the guy sitting behind the operator panel.
This is another reason the remote-work scenario is such an issue - it's so trivial when large numbers of people are working remotely to gain access to secure systems.
So are tanks. And so are humans.
Security is opposite to usefulness. If you harden your system thoroughly to the limit of possibility, it becomes a rock. Systems are made to do something, so some parts need to actually do that thing.
Those VT-100 terminals actually have Z80 CPUs in them, but even so, they connected to VAX or other computer systems, which are generally networked.
Our country is crippled with ineptitude and hogtied by the billionaire plutocracy. The systems the masses depend on will crumble long before the ruling class notices. Look to our national elections as a grotesque reminder.
2022: 944 billion (Medicare), 805 billion (Medicaid). [1] We could add the VA health care system (approx 100 billion), CHIP (few tens of billions), ACA subsidies (tens of billions), other publicly owned medical services (???), and probably some more things we're forgetting.
753 billion requested by the WH in defense spending. [2] This probably does not encompass all defense spending period, but there's nothing else going to add many 100s of billions to even come close to the health care figure.
The problem with the US medical system isn't that not enough dollars are being allocated to it. The US government as a whole (state and federal) is already spending as much per capita as many European countries. We just don't get as much for it. I think it's fair to say as you did that entire sectors of the US economy are being crippled by ineptitude, which I would say is institutional rather than personal. The problem is systemic and it's hard to see how it could ever be practically fixed.
[1] https://www.cms.gov/data-research/statistics-trends-and-repo...
[2] https://www.defense.gov/News/Releases/Release/Article/263871...
Of the small number of truly qualified people, many work as independent researchers or in small specialized consultancies because they are dispositionally incompatible with a giant enterprise. The remainder work in places like Google or Microsoft.
If UnitedHealth Group by some miracle broke through its cultural barriers to hiring a bunch of poorly dressed 28 year olds with bad attitudes, paying each more than a group vice president makes, plus empowering the head bad attitude former hacker CISO to block corporate initiatives in the name of security, it still would be a zero sum game. We’d end up with a less secure android or windows.
The fundamental problem is pushing to digitize everything way too fast and being totally irresponsible with the data. You should have to pass a competence test before you integrate computerization of a lot of these kinds of processes, but obviously the tech lobby would not like that one bit because they only exist on account of selling their victims a sense of overconfidence.
I’m sure this is bad for those affected, but the prescription market does not seem “hamstrung” to me.
There are plenty of drugs in Europe doctor might want to prescribe but the government says “nope, not going to pay for it”
Not only does this happen with the current system, it’s worse, because there aren’t always explicit instructions about what will be covered - so your care depends on whether your doctor is willing to beg the insurer to provide a drug to you
For instance, this is a struggle for people in many European countries who would benefit from access to specific psychiatric prescriptions which are either not prescribed except after trying various cheaper options or are not even approved because of the potential cost to the government, while the same drug is often available in the US (ranging from $10-hundreds a month, as is typical in the US). Public healthcare in at least California sounds more comparable to the universal single-payer systems I’ve seen in its relative inflexibility.
Everyone should have a reserve of everything they need to the extent it is practical. A reserve of meds should be a high priority.
Reserves act as an accumulator or a capacitor.
When we ants stock up in good times, it primes the supply chains to be ready to provide a little extra later. If half the customers buy 10% extra over time, the supply chains expect to provide an extra 5%.
When shortages hit, we ants are taken care of, and do not stand in line competing with the grasshoppers for the last few bottles of pills.
Because we ants primed the supply chains when stocked up in good times, there might even be an extra bottle of pills in addition to fewer customers fighting over it. We ants perform a public service by stocking up.
The vast majority of meds in the US say they are "made in the USA," but the precursor chemicals are usually made in China.
Trans-oceanic trade was cut off (for a while and severely reduced for longer times) in World War 1 and again in World War 2. It can happen again.
It is a common scam to buy something from China, claim to make it in the USA, and resell it at a large markup. This means that a lot of things we think are made in the USA will not be available if international trade is restricted or stopped.
I expect massive shortages of meds when/if the balloon goes up in the South China Sea.
Natural selection often eliminates certain populations in short, sharp corrections.
I hope I am wrong and the grasshoppers do just fine this winter.
The founder posted on Twitter to let people know they can also reach out directly for urgent support at change@stedi.com
“So far” seems like a stretch, unless they’re including ramp up time or something? It really sums up the whole article: great quality journalism, absolutely terrible exploitative publisher.
Is the entire system in the US really using a single private company to handle this?
Here are the beginnings of the docs:
https://www.stedi.com/docs/api-reference/post-healthcare-cla... https://www.stedi.com/docs/api-reference/post-healthcare-eli...
Our goal is to help providers submit claims and eligibility checks as quickly as possible. We’ve created a streamlined contracting process along with a standardized price list and the ability to match volume pricing. We can get folks set up with a dedicated Slack channel immediately and start working with engineering/ops teams to get back online.
If there's anything we can do to help, email us at change@stedi.com or contact me directly (zack@stedi.com).
[1]: https://x.com/zackkanter/status/1764057780800094350?s=20
We keep making this mistake as a society, assuming that centralization is the answer and that optimization when the system runs well is always worth the risk.
I always find it interesting how some Russians seem to understand our system better than we do, and we collectively seem to know so little about theirs for the same level of fun and profit
Until there are hefty fines on these companies (to the point of forcing public ownership of it if they continue to fuck up) then these issues will continue.
[0] https://www.npr.org/sections/thetwo-way/2013/07/12/201492641...
This isn't going to get better until this our fundamental OS security models get updated to reflect reality.
We already know how, in principle - capability-based, formally verified OS kernels like EROS and CapROS have shown us the way. The next step is building a real world OS and user environment that carry these principles through.
Yes, if would take 10 years at a minimum. But it wouldn't even be a charity, even if you went the OSS route! There would be massive commercial opportunities arising out of the product. If you have the money, and it's profitable and world changing in 15-20 years, why not do it?
And, even if they did decide to pursue it their every instinct is completely incorrect. They have all made their fortunes on entertainment and consumer software and principles like "move fast and break things" that are antithetical to the development of secure and reliable systems; they do not have the foggiest clue how to solve problems in security or even how to compose secure components into secure systems.
That is not to say that nobody is doing so, you can just look to what is actually being deployed in domains that actually demand high security and high reliability systems and have the testing, auditing, and verification to establish conformance like aerospace and certification requirements like the Common Criteria Separation Kernel Protection Profile (SKPP) which required formal specifications, formal proofs of security, and a clean NSA penetration test (i.e. the literal NSA could not find any vulnerabilities).
However, the market for things that actually work is not as large as you might think given how much people crow about security because again, you can just lie. The chickens have not come home to roost yet because cyberattacks are only just starting to be a serious problem. It takes a while for 18 year old kids to bootstrap worldwide criminal enterprises able to attack millions of companies. I mean, even Zuckerberg had VC funding and it still took them over a decade to saturate the world. You have to cut the cybercriminals some slack for taking a few years to become a actual crisis. Give it another 10 years.
Has that particular kind of response ever achieved anything?
(Anything germane to the concern at hand, I mean - of course it has often achieved enriching well-connected contractors and such)
I would define terrorism as something closer to “violence with the intent to intimidate political opponents”. This isn’t really violent, and even if it is (it’s certainly very dangerous!), there’s no political message. Unless this is a 4D chess play that somehow is supposed to weaken America by making us more stressed or something, this just seems like Russian privateering.
Your definition is a bit too broad, as I think you would admit to - I’m guessing you didn’t intend it as a flawless philosophical definition, just a quick one