top | item 24665604

Hacked hospital chain says all 250 US facilities affected

78 points| finphil | 5 years ago |bleepingcomputer.com

31 comments

order
[+] martyvis|5 years ago|reply
The article says "No patient or employee data appears to have been accessed, copied or otherwise compromised.". And yet the attack seems too have potentially attacked every computer in the health service. If they don't have patient or employee data on them, what do they use their computers for? Playing Tetris?
[+] viraptor|5 years ago|reply
Disclaimer: I don't know how this specific chain does their security/it.

There are many ways the endpoints can be owned but not the data. One option common in healthcare is that the computers are dumb terminals for sessions on a remote server. Another is that to access the data you have to authenticate with a physical smart card.

As long as it's confirmed that the ransomware only attacked the endpoints and no active data exfil was attempted (or hasn't succeeded), the statement may be completely true.

[+] andrewjl|5 years ago|reply
What sort of regulatory process does software used in a hospital need to undergo? I'm aware of patient privacy requirements like HIPAA, are there others?
[+] Maven911|5 years ago|reply
There are certification programs for HIPAA such as HITRUST. US centric though, other regions will have local requirements
[+] fallingfrog|5 years ago|reply
Starting to look like a pattern, this is several major companies getting ransomed in the last month. Probably organized crime. Ransoming a hospital is especially egregious, so I hope the perpetrators are caught.
[+] ficklepickle|5 years ago|reply
Oh yeah, definitely that big bad organized crime. Evil people just being evil because they are evil, probably cackling right now, too.

Or maybe it's a moderately-skilled person in an underdeveloped country, who, despite being moderately skilled, has no legitimate opportunities. Maybe the person responsible even has mixed feelings about it. Who knows?

That poor US hospital, I'm sure it is a bastion of fairness and equality for all. I'm sure this wasn't facilitated by their own greed and negligence.

Save your pearl clutching for nextdoor. Here we like to understand the factors that lead to a particular outcome, rather than moralizing hysteria.

[+] danthemanvsqz|5 years ago|reply
I guess they don't have db snapshots.
[+] choward|5 years ago|reply
Or they don't want private information to be released. However, paying the ransom doesn't guarantee this.
[+] dc3k|5 years ago|reply
The term "hospital chain" is so strange to me. Like a restaurant chain, but for health care?
[+] Scoundreller|5 years ago|reply
It helps stop insurance companies and patients from playing them off eachother on price.
[+] rbanffy|5 years ago|reply
I find the name Universal Health Services remarkably amusing for a private healthcare enterprise.
[+] rathertrue|5 years ago|reply
A friend points out that housing developments are often named after what they destroyed to put it there. "Shady Creek", "Deer Run", "Pleasantview"...
[+] BuildTheRobots|5 years ago|reply
Name for the business you want rather than the customer base you have.

edit: apologies for the jokey answer but it's a serious point. I don't think it's an ironic name for a private company at all. If I'm selling healthcare services of course I want 100% of people buying them from me, ideally with the only competition being my subsidiaries.

[+] jrott|5 years ago|reply
They can always hope for the sweetheart public private partnership if we ever get universal health care
[+] gruez|5 years ago|reply
How so? "Universal healthcare" just mean everybody has healthcare. It doesn't mean it has to be provided by, or be paid for by the government. Several European countries (eg. Germany, Switzerland, Netherlands) all have universal healthcare that's at least somewhat privately funded.
[+] mightytravels|5 years ago|reply
Does hacked mean they had their database open to the Internet again?
[+] SkyPuncher|5 years ago|reply
My understanding is this was a ransomware attack.
[+] DudeInBasement|5 years ago|reply
Probably someone just looking for how much an xray costs. Instead got the whole database.