Many people throw hospital security into the pile of "well, lots of people don't care about infosec!" In my opinion, this stance is incorrect.<p>I've performed security assessments against many different industries, including banks, large enterprise, barely-funded startups, nuclear power facilities, law firms, hospitals, and more. In each of these fields, you see the "good guys" and the "bad guys" in terms of IT security strength. In hospitals, though, <i>the whole field</i> is terrible. The best of the best -- high-tech facilities that actually care about security -- are still doing terribly compared to the average large enterprise.<p>Health records are becoming more valuable, and not just because of blackmail. Insurance fraud and identity theft are feasible if you've stolen someone's health records, and the information stored within is only getting broader.<p>Hospitals wouldn't let their medical tech slip this far. They shouldn't let their security slip, either.