If a bridge collapses people die. To my knowledge, nobody died or was put in mortal peril as a result of the Crowdstrike debacle.
If a bridge collapses people die. To my knowledge, nobody died or was put in mortal peril as a result of the Crowdstrike debacle.
With all the hospitals victim of the attack, I would be surprised if the amount of patients that died are zero.
Sure. Did this happen?
Why were the “emergency management downtime procedures” insufficient [1]?
[1] https://www.healthcaredive.com/news/crowdstrike-outage-hits-...
You just responded to an article about the implementation of emergency downtime protocols by speculating, baselessly, that such protocols cannot possibly exist because your mental model of our healthcare system prohibits it. Ironically, all within the context of why software development doesn’t hold itself to the rigors of engineering.
Because they’re more expensive. They’re all not “equally good,” they’re good enough to keep people alive. (You repurpose resources from elective and billing procedures, et cetera.)
What resources are you repurposing from elective procedures exactly? Your patient load hasn’t changed, and day surgical instruments and supplies are from the same pool. There’s no “well this pile of equipment is only for elective procedures”.
I’m not even sure what “billing procedures you’d repurpose (especially in your context of “keeping people alive”).
The outage didn’t change any of these things either.
> not even sure what “billing procedures you’d repurpose
At Mount Sinai, billing staff were redirected to watch newborn babies. Apparently the electronic doors stopped working during the outage.
Never said that it did. I just don't think your idea of emergency downtime procedures at a hospital are what they are. There's paper and offline charting, most meds can be retrieved similarly, and so on. I heard a claim (from someone here) that an ER was unable to do CPR due to the outage, which could not be remotely true. Crash carts are available and are specifically set up to not require anything else but a combination. Drugs, IV/IO access, etc.
> At Mount Sinai, billing staff were redirected to watch newborn babies.
That sounds like something I would have imagined security doing. To be clear, what they most likely meant here is in the sense of "avoiding abduction of a newborn", not any kind of access to observe and oversee neonates.
All of this without the person obviously dying due to the alternative procedures - just e.g. the doctor saw the patient less often and didn't notice some condition as early as they would have under normal procedures.
Would you consider this assumption to be wrong? (I am a layperson, not familiar with how hospitals work except from being a patient.)
Some personnel were shifted to the centers that were still up and running to help with their increased load of calls, while others switched to analog phone systems, Austin McDaniel, state public safety department spokesperson, told USA TODAY in an email. McDaniel said they had a plan in place, but the situation was "certainly unique.”
Agencies in at least seven states reported temporary outages, including the St. Louis County Sheriff's Office, the Faribault Police Department in Minnesota, and 911 systems in New Hampshire, Fulton County, Indiana, and Middletown, Ohio. Reports of 911 outages across the country peaked at more than 100 on Friday just before 3 a.m., according to Downdetector.
In Noble County, Indiana, about 30 miles northwest of Fort Wayne, 911 dispatchers were forced to jot down notes by hand when the system went down in the early morning hours, according to Gabe Creech, the county's emergency management director."
https://eu.usatoday.com/story/news/nation/2024/07/19/crowdst...
I mean, even if the dispatch could handle it in some sense, certainly it was a problem, that might have increased average time to site for the ambulance or fire fighters. I've haven't seen any report of any direct death.
Exactly. Contrast that with a bridge collapse. It isn’t a mystery or statistical exercise to deduce who died and why.
In how many of those cases were criminal charges brought? (It’s not zero. But it’s more limited.)
Absent evidence I’d say it is.
Hospitals have emergency downtime procedures [1]. From what I can tell, the outage was stressful, not deadly.
[1] https://www.npr.org/2024/07/21/nx-s1-5046700/the-crowdstrike...
Sure. Who did?
When a bridge collapses, this isn’t a tough problem. We don’t need to reason from first principles to derive the dead bodies. That’s the difference.
It wasn’t just vacation travelers that were affected by Crowdstrike’s incompetence.
Do you have clinical or hospital administration experience? A source with evidence, even circumstantial?
>> Yes
You managed a hospital and failed to implement emergency downtime procedures? (Because that is actually criminal.) Or do you have a source?
Agreed. It’s also plausible someone had a heart attack due to the stress of flight cancellations. Do we have any evidence of either?
The difference between a bridge collapsing and everything we’re discussing is there isn’t much of a discussion around who died and why.
It’s a glib response, but so is “yes” to a request for attribution.
I'm less positive than you, just because my experience of healthcare infosec is that all a doctor has to do is say "I cannot be slowed down or prevented from doing x or people will die" and that's the end of any process or technical controls on x.
Same with utilities. I've seen the ICS engineers say "No you cannot put a password on this console because I may need instant access to prevent a blackout / explosion" and that pretty much ends the discussion.
Often that's not even wrong. Of course when there is a security incident there'll be a kneejerk reaction to that, and of course that's why ransomware groups love healthcare, but in the meantime, those risks seem reasonable.
Which means I'm guessing Crowdstrike killed a lot of healthcare billing but not a lot of critical care systems because it got ripped off those 30 seconds after install if it was ever installed at all.