TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Why is my healthcare data not more protected? Epic Systems installs

7 点作者 rwoll将近 5 年前
Many major healthcare providers use Epic Systems (https:&#x2F;&#x2F;www.epic.com&#x2F;) software to manage patient records. At about half a dozen independent institutions, I’ve watched receptionists and Drs go from logging in to Epic (which contains all my and other patients health records, clinician notes, test results, etc.) to Facebook or email or general internet browsing. This smells and seems to be one phishKit or rootkit away from putting people’s health data at risk.<p>Why are these systems not airgapped or at least run on dedicated, restricted devices and networks that only allows Epic Systems activities?!

1 comment

wallflower将近 5 年前
One of my friends works in healthcare. She told me once about how a coworker who worked at the hospital had gotten a certain test done there. This coworker looked up their results through the healthcare information system, and they were brought in to their supervisor to explain why they committed a violation of the hospital system&#x27;s HIPAA rules. In some hospitals, this might not be a violation and, in fact, allowable.<p>My answer is that any rootkit or phishing schema that attempted to exfiltrate data from a client terminal would be detected by all the deeply-ingrained automated and formal procedures and systems for monitoring&#x2F;auditing&#x2F;alerting of access and usage of the healthcare information system. Also, depriving the doctors and nurses of Facebook&#x2F;website browsing would probably be a net negative for morale, most especially in these trying times of COVID-19.
评论 #23520060 未加载