back

by dt3ft·5y ago·view on hn ↗
Here is a hospital scenario (I worked at one): 400+ users only use e-mail, browser and a local clinical information system or two. They never generate gigabytes of local data and never modify local data other than dragging an email attachment (or scanning a paper lab result) and dropping it into a clinical IS from time to time.

How is it possible that ransomware can wreck this (windows computer) and hundreds like it? Hundreds of similar hospital scenarios are happening all over the world as we speak. The issue here is that clinical IS will not be accessible because 400+ machines are refusing to boot into windows.

Should Microsoft be working on a windows version for healthcare, where execution of unsigned application is simply not allowed? The best we could do is "this application was downloaded from the internet, are you sure you want to allow it to run?"

1 comments
I feel like the most logical explanation, given what you wrote, is lack of software updates and/or lack or lax procedures on behalf of system users (f.e. people opening up attachments they shouldn't, etc).

Microsoft could do that, but hospitals would shell out way more money for a niche feature. Remember that once you specialize something it becomes expensive. Should a fix come to light it has to be as general as possible. The fix should solve a problem experienced by everyone if it is to be adopted en masse and cheap.

Personally, I'd change / reinforce users' behaviours such as not opening attachments from e-mails they do not know (or have a good anti-virus scan their attachments OR have their SMTP server helper do that), maintain a strict software update policy and so on. The usual procedures. Quite frankly, I don't believe this is what a good percentage of people, companies, etc do.