41 ms·
A billion medical images are exposed online
- selimnairb 7y agoYet another reason to create a nationalized NHS-like system.
- alecco 7y agoNHS has plenty of data breaches.
- cookie_monsta 7y ago"anyone with an internet connection and free-to-download software to access over 1 billion medical images of patients across the world." Breaches on that scale?
- alecco 7y agoimages != people. NHS had a 150k patients breach not long ago. And many other of smaller scale in the thousands. It's definitely not an organization renowned for being good handling patient data. On top of that, they made recently a deal to share with Amazon and Google. They clearly don't care. Also, it's a monopoly. You can't chose something else. And never mind the politics of both the administration (who chose them to be in power?) and political pressure from whatever party is in control of funding. Pass.
- gridlockd 7y agoWhat exactly makes you think government institutions would do a better job here? I quote: "...one unprotected server at one of the largest military hospitals in the United States exposed the names of military personnel and medical images"
- basilgohar 7y agoTheoretically, there would/should be a unified system and standards applied. Realistically, it'll probably still be first attempted through vendors with exclusive contracts, which is basically the current system but with extra steps.
- reaperducer 7y agoTheoretically, there would/should be a unified system and standards applied. So, a nice convenient one stop shop for hackers. I'd rather a thief had to break into a thousand homes than one great big home.
- zpallin 7y agoOne stop shop? Even with an assumed "unified system" there is absolutely no way that even an incompetent group of IT engineers would be able to construct a single unified network with a single doorway into it to make a "one stop shop experience." It would still be "breaking into a thousand homes", but at least the difference is -- given a unified set of controls -- that reconciliation of a breach could be automated.
- incone123 7y agoThe NHS does seem to force doctors to follow security rules. But we have a different problem where the government thinks it owns my data and has the right to sell it.
- sbarre 7y agoThe key takeaway from that article, for me, is that the government body that is supposed to monitor, enforce, and penalize organizations who fail to follow the HIPAA rules is basically doing nothing. So with no consequence to these massive lapses, why would these companies care?
- modmans2nd 7y agoUnder funded...just like the IRS.
- WC3w6pXxgGd 7y agoNo, just inept like all government agencies.
- humaniania 7y agoOffice for Civil Rights (OCR) https://www.hhs.gov/ocr/index.html https://www.hhs.gov/ocr/index.html
- lunchables 7y agohttps://compliancy-group.com/hipaa-fines-directory-year/ https://compliancy-group.com/hipaa-fines-directory-year/ My honest opinion is that they know healthcare specifically is so far behind meeting their regulator requirements they have been trying to slowly phase in penalties.
- zpallin 7y agoThis is the wrong takeaway. The article states pretty clearly from the interview with Senator Mark Warner: > “To my knowledge, Health and Human Services has done nothing about it,” Warner told TechCrunch. “As Health and Human Services aggressively pushes to permit a wider range of parties to have access to the sensitive health information of American patients without traditional privacy protections attached to that information, HHS’s inattention to this particular incident becomes even more troubling,” he added. It's not that they're doing nothing, they're supposedly making it worse. They're also underfunded. OCR budget dropped to 10% of its previous budget between 2017 and 2018: https://www.hhs.gov/about/budget/fy2018/budget-in-brief/ocr/index.html https://www.hhs.gov/about/budget/fy2018/budget-in-brief/ocr/... So, when you ask "why would these companies care?", I think the current federal government is trying to say "these companies _should not_ care."
- xiphias2 7y agoSensitive data should be thrown away and the medical images could improve on the current state of the art medical image database used for machine learning. I'd be more than happy to publish my medical images with results if it would be used for an open database. I have been at doctors in third world countries, where doctors don't get the same level of education, but try to use the best tools available without paying too much money.
- ghaff 7y agoDefine sensitive data. One of the challenges is that just deleting a name, say, doesn't necessarily fully anonymize a medical record/image. In general, I actually agree with you but anonymization/privacy is a challenging problem.
- fhars 7y agoAdding enough medical data to the image to make it useful for scientific research would most likely also add enough data to deanonymize the image.
- moviuro 7y ago% curl -L 'https://techcrunch.com/2020/01/10/medical-images-exposed-pacs/' curl: (7) Failed to connect to guce.advertising.com port 443: Connection refused WTF? I have a lying DNS server, and it's getting ridiculous. Here's the outline for people who care about privacy/tracking/GDPR, etc. https://outline.com/Ep5u4K https://outline.com/Ep5u4K
- llacb47 7y agoYahoo/AOL/Oath want to set an advertising cookie before you visit any of their sites.
- moviuro 7y agoNo, they redirect you to an advertizing domain.
- eitland 7y agoFor now I'd be happy if techcrunch was blocked so people had to submit other sources. I've not been able to find a way to read content on that domain for months now. Edit: PS: unlike many here I've little against ads as long as they aren't tracking me, but the "consent screen" on techcrunch is less "consent" and more "strongarm". PPS: as others are mentioning it seems the whole thing seems to be compliance theater since they seem to set a tracking cookie before even displaying the consent screen :-/
- uponcoffee 7y agoI'm on Firefox Preview for Android and am having no problems with the article. No ads, popups etc. Just pure content.
- deleted 7y ago[deleted]
- moviuro 7y agoHere is the entire curl trace: http://ix.io/277P http://ix.io/277P
- Eikon 7y agoIt feels like the places where security is of utmost importance like in banking, security cards or health are the worst at doing it. At least, lack of security of credit cards is understandable as banks are profiting from fraud by charging the victim a fee. In health? This must stop. It's a failure of regulatory bodies as they throw so much junk policies around that the things that really require attention is just overlooked. The overabundance of paperwork and policies is not improving security, it's keeping away actors that could do way better.
- modmans2nd 7y agoThey focus on visible security more than actually securing things. Example: making it very hard for a user to log into a system “because of security “ but not using security certificates to secure their email servers.
- Eikon 7y agoRelated: https://en.wikipedia.org/wiki/Security_theater https://en.wikipedia.org/wiki/Security_theater
- fhars 7y agoThere is the complicating factor that in health, safety can be more important than security: to keep a patient alive in an acute emergency, it is imperative that the doctor can see their data right now, while that fact that third parties can later see the data doesn’t matter too much. The problem is that people tend to use the first aspect as a cheap excuse to do nothing about the second one.
- 7QdfBKNNfP 7y agoNot only is transport security mostly lacking in DICOM, but there is little to no notion of access control for records. And I'm not just talking DICOM, but the apps themselves. It's no surprise though, when the DICOM standard has sections like this: The DICOM Standard does not address issues of security policies, though clearly adherence to appropriate security policies is necessary for any level of security. The Standard only provides mechanisms that could be used to implement security policies with regard to the interchange of DICOM objects between Application Entities. For example, a security policy may dictate some level of access control. This Standard does not consider access control policies, but does provide the technological means for the Application Entities involved to exchange sufficient information to implement access control policies. http://dicom.nema.org/medical/dicom/current/output/html/part15.html http://dicom.nema.org/medical/dicom/current/output/html/part... The original DICOM TCP protocol requires that every device connected use an encrypted tunnel, and it's not easy to get all the device venders to agree on which ones to use, and then update their software. DICOM Web Services are a thing, and at least they would get HTTPS basically for free from their choice of web client and server. HIPAA has been out since the 90's so we need to get more fines against the providers to make them implement confidentiality and access controls. It's actually the GDPR which is now driving access controls rather than HIPAA. To be fair though, the DICOM folks are busy constantly trying to standardize new image data coming from innovations in the modalities (scanners).
- prostheticvamp 7y agoAn odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system like Northwell has the IT bench to do it themselves, but that would be the exception. So allow me to rephrase slightly: “technologically inept organization pays vendor to make machine go vroom. Vendor leaves keys in ignition. Damn that technologically inept organization.” To take a 10,000-foot view of the situation, though: Healthcare-related technologically was largely pushed on the industry via legislation. Said legislation was almost entirely stick, no carrot. The result was healthcare organizations with a gun to their head to buy from a handful of vendors, with no real ROI to be seen from it - aka, the government outsourcing its costs to private industry, and throwing pork to some major health IT firms along the way. When a technology is forced on you at a loss, from a vendor with little incentive to optimize ease of use or utility, you get a terrible piece of shit that no one wants to invest more time and money into than absolutely needed. That’s going to show itself in a myriad of ways.
- christophilus 7y agoI completely agree. I have friends in the medical field, and they hate their computer systems. One of them spends almost as much time on data entry as he does with his patients. He has to double and sometimes triple enter data. He’s probably going to end up hiring someone to do that full time, which is so obviously a totally broken system.
- blueboo 7y ago> One of them spends almost as much time on data entry as he does with patients ...then he’s one of the lucky ones! One study found that for every hour a physician spends with a patient, she spends two on processing health records. https://www.jwatch.org/fw111995/2016/09/06/half-physician-time-spent-ehrs-and-paperwork https://www.jwatch.org/fw111995/2016/09/06/half-physician-ti...
- savrajsingh 7y agoOn the user side, we have to jump through hoops and sign so many onerous paper HIPAA compliance forms at dr’s offices, to just get doctors to share records about us. On the backend it’s free for anyone to access. It’s all backwards!
- jessaustin 7y agoThe signature demands that really annoy me are the ones in which I must acknowledge that the provider has informed me of their HIPAA policies, which demands are seldom accompanied by actual information about HIPAA policies, which I probably wouldn't read anyway even if they were included.
- 1996 7y agoThen refuse to sign: you can't be denied care for refusing communication of your records to 3rd parties. It's certainly better for your privacy too.
- dave_aiello 7y agoIf this article is correct, it's such a huge problem that health systems are likely to hesitate to take steps toward basic imaging security, because they won't know what to do first.
- thed 7y agoI think what to do first is really quite simple: Do not let back-end servers face the internet.
- chiefalchemist 7y agoClickbait-y headline that they forget to mention hospitals as well. Yes doctors should be more responsive and responsible. But they're (only) doctors. Hospitals on the other have have staff dedicated to technology and such infrastructure. Dr X being unaware of the implications is understandable. Perhaps not forgivable but certainly no surprise. But hospitals? They have no excuse.
- reaperducer 7y agoI work in health, and I sometimes have to interact with the federal database of doctors. It's amazing the things you see in there. There are doctors who don't know their own addresses. Can't spell the name of their town. Don't know their ZIP Code. Don't know the difference between a mailing address and a physical address. Don't keep their information current. Or sometimes don't even know what town they're in, putting a neighborhood or region on federal paperwork because "everybody knows where that is." We assume that because doctors are smart at medicine, they should also be smart at computers. They're not. Just like my commercial airline pilot neighbor is great at flying transcontinental jumbo jets, but every few days has to shout across the street at me to ask if today's the day to put out the trash bins.
- jessaustin 7y agoYou're really blaming the subjects of a database for errors in that database? There are many reasons for errors that have nothing to do with anything a physician might or might not have done.
- reaperducer 7y agoThose subjects fill out the forms that end up in the database. It isn't some faceless government agency reading their minds. The data comes from what the doctors write down.
- jessaustin 7y agoIt sounds as if the physicians are not using the database themselves. Why would they expend extra effort to ensure its accuracy? Data that must be accurate must be carefully curated, and that isn't free. When we expect others to do work to make our lives easy, we may be disappointed.
- pg_bot 7y agoDICOM is a standard that does too much. They should scrub everything related to networking and focus solely on encoding/decoding medical images.
- lostlogin 7y ago> DICOM It’s a great standard compared to HL7 though. That ‘standard’ is the bane of radiology’s existence.
- quasarj 7y agoAs someone who deals with it every day, I completely agree. In fact, I mostly pretend the networking part doesn't exist anyway, and do all networking the normal way..
- OliverJones 7y agoFrom Techcrunch's article it looks like it's possible to see so-called "protected health information" (PHI) in these images. PHI includes patient names, diagnoses, hospital and doctor names, contact information, and so forth. It's sometimes possible to "de-identify" medical images by scrubbing off patient info. But I bet most of these are not de-identified. The examples in the TechCrunch article are redacted, but I guess that was done for publication and not on the stored images themselves. In the USA, HIPAA and ARRA 2009 (followon legislation) made it a federal crime to knowingly or negligently disclose PHI. It's a crime that "pierces the corporate veil." That is, natural persons can be tried and convicted, even if they were acting on behalf of corporations. The Centers for Medicare and Medicaid Services (CMS) has a Breach Notification Rule, requiring holders of data to notify patients and CMS themselves if PHI is breached. https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html https://www.hhs.gov/hipaa/for-professionals/breach-notificat... CMS announces breaches involving 500 or more patient records here https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf It wouldn't surprise me if the people involved in securing these sloppily configured DICOM servers are in a state of panic. I was involved in dealing with an unintentional breach of 44 patient records a few years back, and yeah, we had some panic. (Misrouted fax messages was the root cause, for what it's worth.) Also observe that I remember to this day how many records leaked out. Breaches are a big deal. It stinks to be them. I know that for sure. I hope they get it sorted out. It will take a while. It will also take a while for the affected medical professionals and their IT providers to start responding to these breach reports rationally. Kubler-Ross's stages of grieving are still in play for them: anger, denial, negotiation, etc.
- salad77 7y agoFrom the article : "We’re not naming the affected organizations to limit the risk of exposing patient data." However, a google inurl:dicom search sure shows up the affected organizations on the first page (and plenty pages after that). And the sites are still fully open. Absolutely zero hacking required. A lot of organizations had better get to work fast on this. (edit: no images were viewed in the making of this post)
- quasarj 7y agoIt's hard to know what Google returns for a different person these days, but inurl:dicom does not return anything suspect for me. It's also worth noting that the types of systems mentioned in the article (unsecured PACS) would not show up on Google anyway. They must be accessed using one of the DICOM network protocols.
- wswope 7y agoFun experiment: use google maps API to search a major US metro area for medical practices. Pick out any websites that don't use TLS. Crawl them for HTML forms that include common PHI keywords. You'll find a lot. Those same practices are usually going to have a whole mess of more serious HIPAA issues.
- Spooky23 7y agoI wish one of my past providers was impacted by this a few years ago. I had to waste hours and thousands on MRIs when a practice closed and they made getting imagery impossible.
- jasonlaramburu 7y agoCould this data be anonymized and open-sourced for training diagnostic algorithms? It’s hard to put the genie back in the bottle so why not at least make some use of the images?
- windyaskew 7y agoIn theory, yes. I was working on doing this (for internal data) at a large healthcare system some time ago. The de-id part was actually really easy since DICOM is a very standardized format and this hospital system had good practices in place to only input certain information about each patient.
- thed 7y agoIs it possible? The metadata is easy to anonymize. Uniquely identifying features shown in the images (scars, etc)? Not without destroying them. How much is the data worth for machine learning if you do not have access to the interpretation (and annotations) for the data? That is the hard part. But. Is it ethical or even legal to do so without patient consent? No (at least not in my country).
- quasarj 7y agoPossibly, though with only the images you'd be missing some useful info, like the actual outcome. Also they are likely not "high quality" images on average.. so for example, if there is cancer present, it may not be identified in the image. See https://www.cancerimagingarchive.net/ https://www.cancerimagingarchive.net/ for some examples of carefully curated data.
- OrgNet 7y agoDoes it need to be anonymized since it is now public? maybe just don't publish identifying information in your results
- cornflake 7y agohttps://picsafe.com https://picsafe.com is a HIPAA compliant tool that solves this. Until penalties are applied, health organizations won't act on this.
- thed 7y agoNo, picsafe does not solve the issues described in the article. What makes you think it does?
- deleted 7y ago[deleted]
- deleted 7y ago[deleted]
- ageyfman 7y agoIn 2009 I was building an enterprise medical imaging SaaS for hospitals, and we would constantly come across hospital IT admins who were adamantly against trusting a cloud vendor with their sensitive healthcare data - even one that's audited, security-checked and whose sole responsibility is to take care of these images. We always thought it was a joke that these guys questioned us, when we knew how bad their internal security practices were. At some point around 2011-2012 we seized on the idea that holding your images inside of the hospital's four walls was a liability for them, and not a point of pride. So, not at all surprised about this, nor about the complete lack of security practices at many of these healthcare IT vendors.
- carbocation 7y ago> In 2009 I was building an enterprise medical imaging SaaS for hospitals, and we would constantly come across hospital IT admins who were adamantly against trusting a cloud vendor with their sensitive healthcare data This still rings very true in 2020.
- toomuchtodo 7y agoLots of open S3 buckets full of critical data not helping the counter argument. Security is hard, proving you’re secure to others more so. How do I know you’re not just storing my data in S3, abstracting away the mechanism, but your bucket policy or acls are garbage? I don’t. Cloud does not immediately mean more secure.
- ageyfman 7y agoThe point I was making isn't that the cloud is naturally more secure, it's that the company was 100% focused on medical imaging, not the 1000 projects a typical network/system admin at a hospital has to juggle.
- anonpartners 7y agoI work for one of the largest health care networks in the northeast US. Nearly all of our PACS use the default installer password - which in at least two cases is literally just the name of the company that makes it.
- peter303 7y agoKnock. Knock. The average human body is rather boring. especially for the 3/4ths that outside the young adult age range of 15-35. As to insurance company exposure, almost all of these imaging procedures were paid by health insurance companies and already know all your ailments.
- neuro_image3 7y agoPhysician here (neuroradiologist) and after working at several hospitals in the US and abroad, let me be really clear about this: 1) I have never seen a health care organization ANYWHERE where the physicians determine the IT policy (including and especially the IT security policy). 2) Universally, healthcare organizations use the bloated garbage that gets passed off as EMRs and affiliated garbage software. None of this is up to physicians. It's up to the administrative and bureaucratic parasites that have infested healthcare at every level and based largely (I assume) on crony relationships, because it's certainly not based on competence. 3)Healthcare IT is the most abysmal software anyone anywhere has ever devised to perform any task. Systems like EPIC are bloated, barely functional trash that systems have wasted billions of dollars on. The various components of departmental IT do not co-ordinate with one another, crash on a daily basis, are not fit for purpose and would embarrass engineers in any other industry. It comes as no surprise that security for these systems is piss-poor, just like everything else about these systems. Blaming doctors for this administrative mess, whilst not unexpected, is disingenuous at best (of course this is what healthcare administration excel at - making a mess and blaming physicians).
- arminiusreturns 7y agoI've contracted for some medical orgs and I can tell you there is plenty of blame to go around, and most of it belongs on the heads of administration (C-levels), who let doctors get away with things they shouldn't while at the same time underfund and generally shit on their IT departments. IT directors without the backbone or knowledge to speak boardroom and convince the C-levels to have their back are failing, doctors are failing, and administrations are failing when it comes to IT, add all that to a complex regulatory scheme in which some vendors are basically immune to being dropped, overworked doctors and nurses because congress keeps them artificially scarce, and it's a recipe for disaster. To those making excuses for doctors, you should be ashamed of yourselves. There is enough blame for everyone in this case.