Categories
Software development

Another day, another healthcare related hacking

Reading Time: 4 minutes

Or ransomware as a service or RaaS, please refer to this Pensacola News Journal article, search for “Black Basta” for the detailed information. I felt this article was well written. Unfortunately, this one is the place I used to work – Ascension Health (company official note on this cyber security event). I also talked about Ascension from time to time, after I left the company in June 2021. Here are some tweets.

Impacts

My 1st worry is its impact on patients, such as this patient in Wisconsin (I tweet below too). The impact to the patients is real and in a way is similar to the recent Change Healthcare hack (WSJ; I have a blog post too).

It impacts the caregivers too – Ascension cyberattack: Patients, nurses frustrated as problems persist. And all over Ascension service area, such as this one in Middle Tennessee, ‘Chaos’: Nurses, visitors describe conditions inside Ascension hospitals after cyberattack. This is very unfortunate for the patients, caregivers and impacted families. I just don’t have words for them – I hope they all can pull through. I will touch upon the evil of the bad actors below.

All this also showed the computerization of the medicine (or healthcare), while has its advantage: electronic medical record in theory at least gave the provider a holistic view of patient health issues. At the same time it shows its fragility (easy to break). Paper based process is always needed, because no computer systems is 100% reliable. This is somewhat like the Disaster Recovery (business continuity process) many decent sized organizations run or try to run, in case something horrendous happens (natural disaster, fire and so on). But in real life, how many hospitals or providers have the paper process nailed down, and have regularly ran the DR exercises. For me personally, I only saw DR exercise in action at Mastercard (and I participated it once as a lead, and it was quite interesting). In fact to me “production” is also interesting 🙂

Last but not least, if there is no lawsuit, then it’s not America. Central Texas woman sues Ascension following cyberattack.: interesting part of this article is it talked about RaaS and “Black Basta” in more details.

Health Insurance

We know in the US, health care system is very complicated (I wrote a series on this, the 3rd post is here).

Also note Ascension’s insurance (Blue Cross Blue Shield of Michigan) is not that great to begin with, as I learned 1st hand from my COBRA usage, or attempt to use my COBRA coverage after I left. My new employer’s benefits didn’t kick in immediately and there was two months gap.

Why I left Ascesnion

Below is one reason, the event proceeded my leaving. But not the only reason. I guess we may say that’s last straw.

Incidentally I worked at another major catholic hospital chain in the St. Louis area, and while my experience is not as bad, nonetheless I was not happy on one project – at one time we were briefly asked by the management to come in on Saturdays to complete the project “on time”. I knew it was mostly for “a show” not for actual completion of the project. And we had quite a few people quit (jump ship) during that time.

At both places, I have seen or worked on ambitious projects that started because one executive has the budget, and later on had to abandon because of various reasons. I understand software development projects are notoriously for cancellation and budget overrun because its complexity, hard to estimate and changing (or sometimes random) requirements. But I have worked on other industries too, and they usually “fail early, fail faster” (the agile way).

Recent cyber security events that I wrote

Panera Bread System Down

UnitedHealth Group Change Health Hack

Odds and Ends

Before I join the company (Ascension.org), I encountered some issues (login or single sign on SSO related) at myAscension.org. I still encountered similar issues (I would say about 33% failure rate) when I was working there. Looking back, this is a red flag of an organization’s IT capability.

If you happen to work in the IT/software development field, think “security security and security” all the time. It won’t prevent all the hacks. But it’s a good starting point. Btw, once when I was working for the Mastercard, I had the fun task to investigate the bad guys logged into a bank’s rewards redemption website and redeemed air tickets and hotels. One thing I still remember is this “client attorney privilege… ” in the email thread; another thing I was emotionally drained was seeing how some people can be that kind of malicious (stealing is bad, stealing on internet is equally bad as physically stealing). I also recalled when I was at college, I was stolen twice, once at a bus, someone picked up my wallet (when I realized, it was a bit late); another time, someone broke the lock on my drawer and took the money that my dad sent me recently. Always have the “security in mind” in daily life and in IT. Learn as much as you can, such as this Security in Mind channel on YT.

Last but not least, I understand we are going towards “electronic medical record” world, but we probably still need to keep some papers around prescription, vaccination records and testing results etc., better yet, back them up in the iCloud or somewhere you believe is safe, just in case the MyChart etc. goes down.

More Coverage in the news

Retired FBI agent weighs in on Ascension cyberattack

Fallout from Ascension cyberattack continues: Michigan pharmacies can’t fill prescriptions

Healthcare leaders praise Ascension cyberattack response

Ascension nurse: Ransomware attack makes caring for hospital patients ‘so, so dangerous’

Delays in cancer treatment. Canceled appointments. Long wait times. Ascension patients still grapple with fallout from cyberattack

How the Ascension cyberattack is disrupting care at hospitals

Ascension Saint Thomas Health patient files class action lawsuit over data breach

Ascension patients still grappling with fallout from cyberattack

Nurses fed up with Ascension Healthcare security breach issues

‘They need to step up’: Retired FBI Special Agent speaks on current Ascension cybersecurity attack

(June 13, 2024 at 7:21 AM) Ascension cyber attack caused by worker who accidentally downloaded malware – Officials: Attackers accessed 7 of 25,000 servers

(06-19-2024) Patients at Ascension hospital network given dangerous doses of narcotics after disastrous cyberattack: “In another case, a female patient suffered a cardiac arrest and died after data mishaps delayed test results that would determine her life-saving treatment.”

(09-19-2024) Ascension posts $1.1B net loss for 2024 after May cyberattack

(12-20-2024) Ransomware attack on health giant Ascension hits 5.6 million patients

(Update 04-29-2025) Ascension data breach impacts patients in 5 states, including Michigan

Categories
Life Politics

American Healthcare Systems I:美国的医疗系统系列之一

Reading Time: 3 minutes

American healthcare systems are probably the most convoluted healthcare system in the world. The US probably has the world most advanced medical device and pharmaceuticals industry, many brilliant doctors and great hospitals, e.g., the BJC hospital in the St. Louis area, which is one of the top research hospital in the USA. At the same time, we can see the average life expectancy in the USA is dropping in recent years. The Covid obviously has impact on that. But the overall issues of population health in the USA and the healthcare system were there before pandemic. 美国的医疗保健系统可能是世界上最复杂的医疗保健系统。美国可能拥有世界上最先进的医疗器械和制药工业,许多优秀的医生和一流的医院,例如圣路易斯地区的BJC医院,它是美国顶尖的研究型医院之一。与此同时,我们可以看到近年来美国的平均预期寿命正在下降。 Covid显然对此产生了影响。但美国的人口健康和医疗体系的整体问题在大流行之前就已经存在。

Back to the healthcare system, on both hospitals and the payer (insurance companies for the most part, individuals do have some responsibility). I did not realized the seriousness of the issue until I joined the workforce. I come to the US for graduate school in 1997, I was relatively young and partially due to that I did not visit the hospital or the clinic in the university, another reason was I did not know how to describe medicine in English. At work I got better coverage, and I had first hand knowledge of surgery and emergency room in early 2000s. I vaguely recall the “tonsil removal” surgery cost about $50 from my perspective: the insurance company probably paid $5,000. The personal out of pocket cost will be much higher today. So will be the insurance company’s payment. An emergency room visit, I vaguely it was about $2,300 for about 6, 7 hours stay, with some testing and medicine obviously. There is another bill from the X-ray, MRI office which is a few hundred dollars. We eventually negotiated with the hospital as the patient (a relative) doesn’t have insurance, and we paid $700 and settled it. It as also during that time I realized that patient can negotiate bill with the providers. 回到医疗保健系统,对医院和付款人(大部分是保险公司,个人确实有一些责任)。直到我加入劳动力大军,我才意识到问题的严重性。我是 1997 年来美国读研究生的,当时我还比较年轻,部分原因是我没有去过大学里的医院或诊所,另一个原因是我不知道如何用英语描述医学。在工作中,我得到了更好的报道,并且在 2000 年代初期我对手术和急诊室有了第一手的了解。我依稀记得“摘除扁桃体”的手术费用在我看来是50美元左右:保险公司大概赔了5000美元。今天的个人自付费用会高得多。保险公司的赔付也是如此。一次急诊室就诊,我大概花了 2,300 美元,停留了大约 6、7 个小时,显然还做了一些测试和药物。 X 光、核磁共振办公室还有一张几百美元的账单。由于患者(亲属)没有保险,我们最终与医院协商,我们支付了700美元并解决了。也是在那段时间里,我意识到患者可以与提供者协商账单。

But remember always pay the bills, even after negotiation sometimes. Don’t ignore the bills. Because the bill ignored will be sent to collection (a 3rd party), and it will put a dent on one’s credit score. And we know credit score is quite important for many things range from rent an apartment, buy a car house, find a job and so on.
但请记住始终支付账单,即使有时经过谈判。不要忽视账单。因为被忽略的账单将被发送到收款处(第 3 方),并且会降低一个人的信用评分。我们知道信用评分对很多事情都非常重要,从租房、买房、找工作等等。

From patient point of view, the insurance premium went up a lot in last 20 years or so. And there are some improvements such as the Obama Care, meaning individuals who don’t work for a company can buy health insurance from marketplace. But those plans sometimes don’t have great coverage. Here is one example. Jeff is my former coworker at Mercy Health: ironically Mercy is a large provider in the St. Louis area. I think ultimately one root cause is most those insurances are for profit. From provider (hospital)’s point of view, the Medicare did not pay great, the Medicaid pays horribly, and the regular insurance made up most of the cost or profit for them. 从病人的角度来看,保险费在过去20年左右涨了很多。还有一些改进,例如奥巴马医改,这意味着不为公司工作的个人可以从市场购买健康保险。但这些计划有时覆盖面并不广。这是一个例子。 Jeff 是我在 Mercy Health 的前同事:具有讽刺意味的是,Mercy 是圣路易斯地区的一家大型供应商。我认为最终的一个根本原因是大多数保险都是为了盈利。从提供者(医院)的角度来看,Medicare 支付的不多,Medicaid 支付的很惨,常规保险占了他们的大部分成本或利润。

The medical workers need to eat too. And support family. And the doctors pay are still fairly good in the USA. But as my former boss at Mercy used to say (we were both at IT dept), the 50% of people who visited emergency room don’t have insurance or put wrong names. You can refer to the example above in which we negotiated the price. Another hidden cost for the providers, mainly for the doctors and the nurse practitioners, they have this burden of electronic health records, both for record keeping, for meeting regulation and insurance reimbursement need. One direct result is less face time with patients. 医护人员也要吃饭。并支持家庭。而且美国的医生待遇还是不错的。但正如我在 Mercy 的前任老板曾经说过的(我们都在 IT 部门),50% 的去急诊室的人没有保险或输入错误的名字。您可以参考上面我们协商价格的例子。供应商的另一个隐性成本,主要是医生和执业护士,他们有电子健康记录的负担,既用于记录保存,也用于满足监管和保险报销需求。一个直接的结果是减少了与患者面对面的时间。

To be continued… 未完待续。。。

Categories
Master Series

Peter Peterson on Blackstone, China, deficit and healthcare etc.

Reading Time: < 1 minuteMr. Peterson has background both in government and private sector: he has been commerce secretary and is co-founder and senior chairman of Blackstone (the private equity group). Very wise guy in my mind.

Charlie Rose interview July 3, 2009 (link)

Categories
Economy

My analogies on healthcare reform protest

Reading Time: 2 minutesMy wife asked me why there are so many outraged people on those congressmen/senators townhalls (she reads that from WSJ). I used an analogy. Imagine the metro (or buses) during rush hours in Shanghai (I used to take a bus almost every Monday morning in early 1990s, from my brother’s place to my working place, a 1.5-2 hrs journey). Suppose you are the guy (or the lady) already on a bus, the bus is packed and the driver requested everyone move inside “a little bit” so that more people can squeeze in.

In this case, many old people protest against the reform because they are already covered in Medicare and they fear their coverage will be less generous, as you and I know, this country is running out of money. There is few such thing as win-win, or free lunch these days. More people got covered, but coverage will be less generous overall. Doctors will see more patients, possibly with less income (profit). Blah blah blah.

Categories
Economy

My thoughts on US healthcare reform

Reading Time: < 1 minuteThis topic is heating up in recent days. I think there are a lot of mis-understandings and mis-conception on this. One is a lot people think medicare is inefficient, I have not used medicare but it seems quite efficient in reality.

Obama healthcare reform pic
(Source: economist)

The bottom line is healthcare boils down to two issue:

Categories
Business Stocks

Bush is more influential than Bernanke?

Reading Time: 2 minutes(Update noon Jan 18) Opps, the Bush rally only last couple hours 🙁 Seriously, I do welcome this $1,600 per family tax rebate. Maybe a trip to Europe this Spring? Oh well, that won’t help the US economy directly.

(Original) I mean, to the stock market. Yesterday, after Ben spoke in Congress and painted a bleak picture of US economy, and asked for some sorts of stimulus package. The DOW tanked 300 points, S&P and Nasdaq did no better. Today as Bush is unveiling his economy package: good old things like tax rebate for individuals and business, the US market seems took the cue and is up in the morning. Another amazing thing is the Overseas market (Japan, Korea, Hongkong and Shanghai) also reversed course (last night). So when Bush speaks, the world listens 🙂

Just kidding. Seriously speaking, I think US president has little to do with the US economy cycle, nor can a Fed chairman. The US is heading to a recession, period. But see, the problem is people (include myself) don’t want to hear the harsh words, facing the reality. A few days ago in Michigan John McCain did his straight talk “some of the jobs lost (in auto industry) is not coming back, we need to re-train our people for new skills”, while his rival Mitt Ronmey says he will do everything to get back auto jobs. It’s so obvious that US auto industry is losing ground in the US market, but people still elected Mitt: the guy who tells white lies.

Healthcare cost for US companies