All of these healthcare software providers have to follow guidelines for making HIPAA compliant software. There are strict guidelines for how to handle data access, data backups, login security, etc.
Password generators are really simple to code. They just generate a random string that contains certain types of characters to make the password harder to brute force. Banks do not have to follow HIPAA guidelines. Their software needs to be secure, but the rules for guarding your financial data are a bit less regulated.
Practically all of the data breaches in the past few years have been caused by people getting tricked by phishing emails. That has nothing to do with the security of the portal because someone just handed their keys over.
Hospitals pay so much when infected with ransomware, not because patient data has leaked and they want to protect you, but because so much of the hospital is computerized now that they can't really provide care to patients if they are locked out of the network. A lot of hospitals can't even dispense Tylenol without logging into a computer to access the drug drawer. So, if they don't pay, people die.
I'm not familiar with this WM you referenced.
Tilley
-----Original Message-----
From: Code for Libraries <[log in to unmask]> On Behalf Of charles meyer
Sent: Wednesday, February 12, 2025 10:08 PM
To: [log in to unmask]
Subject: Re: [CODE4LIB] [External] [CODE4LIB] Patient Portals
All have at least dual if not multiple factor authentication.
Who has the security experience or articles or white papers re: how safe or hw much safer that is?
It's like pw generators. There's a lot of trust being placed in them that they have state of the art security protections.
That's what banks marketed and we now know how that went.
Read "The Battle for Your Brain' by Prof. Nita Farahany.
If you think your financial data is dangerous in miscreants hands try your health records.
One of the reasons why hospitals pay so much when infected with ransomware.
Who besides WM is assessing the risk?
Charles.
Date: Mon, 10 Feb 2025 21:05:25 +0000
From: "McDonald, Stephen" <[log in to unmask]>
Subject: Re: [External] [CODE4LIB] Patient Portals
The health care patient portals I am familiar with all have at least the option, if not a requirement, for 2-factor authentication. This seems to be pretty standard.
Steve McDonald
[log in to unmask]
|