Hacker News new | ask | show | jobs
by Thriptic 2414 days ago
It's really tough. You have a function which is viewed purely as a cost center; you have a totally porous environment where you're required to admit tons of minimally-verified people into confidential spaces; staff and affiliates need different levels of access from all over the world; there are critical availability demands where temporary denial of service for security reasons is unacceptable; device development is optimized for safety and fault tolerance as opposed to security which isn't ever really tested for; patients need to be able to submit tons of data in myriad forms; there are few central clearing houses for transmitting data so people are all calling each other with minimal validation; etc
1 comments

Oh, and you're ultimately sourcing truth from people who are minimally trained on (and have minimal time for training on) the system.

Because they've spent the last couple decades focused on medical training.

And patients that lie / dirty input.

Sure, use cousin x’s coverage. Nobody will freak out when your blood type doesn’t match the records...