> Technically, profit tends to be the #1 goal, at least in the US. Consequentially, this also drives a lack of investment in cybersecurity.
UK's hospitals fare no better in terms of cybersecurity. This is about the culture of nursing / doctors / hospital administrators, which is largely shared between USA and UK.
This isn't a systemic issue that is solved by nationalizing health care like UK did.
USA health care system, culturally, is about saving lives. Whether our system matches it is another story. But the underlying people largely do the right thing.
------
I think the systemic issues regarding health care / infrastructure / investments are wholly independent of this cybersecurity issue.
> USA health care system, culturally, is about saving lives.
With all respect, but for someone who had lived in the US after moving from EU, I'd say it's first and foremost about making money. It saves lives where saving is needed, but I'd argue vast majority of cases are outpatient and the culture is strikingly blunt about milking the patient.
Hospitals in the US are not especially profitable. Including federal relief, median hospital profit margin is 2%.
The whole market is wildly distorted- starting with doctor education up through private insurance and government programs like Medicare and Medicaid- that simple answers like this totally miss the mark.
Agreed. Any simplistic statement like "the problem with healthcare in the US is [blank]" is evidence of someone that doesn't know very much about the many complex and interlinked issues. Likewise, someone thinking the system can be fixed by "just doing X" is also being reductionist.
The pandemic showed a number of areas in healthcare where people were generally ignorant. For example, thinking that hospitals have tons of reserve capacity to handle extraordinary events. Even well before the current situation, hospitals (community) tended to run at about 80% occupancy. Far from being a profit-consideration, even the department of Health and Human Services mandated that hospitals had to run at least 55% occupancy, or they lost benefits.
The pandemic is a bit unusual in affecting everyone at once. For a local or regional problem, staffing wouldn't be as much of an issue because workers can travel. (For example, traveling nurses.)
> that simple answers like this totally miss the mark.
I am not providing my "answer" to the US problem, I am merely noticing how strikingly different approach the healthcare has here, so I reject your insinuation.
To be honest, I don't need to care who's making how much money to make a point – all I know that from my perspective, at the end of the day it is about milking the patient and it differs wildly from the general EU experience.
If profit were the primary motive, wouldn’t you expect non-profit institutions (both healthcare and otherwise) to be in much better shape from a cybersecurity standpoint? E.g., is there evidence that a large non-profit healthcare system like the VA is substantially better at cybersecurity?
While profit no doubt impacts the decisions, it doesn't appear to be the primary driver of cybersecurity lapses.
I wouldn't. Both goals of maximizing profit and achieving a goal on a minimal possible budget end up cutting costs in places that aren't immediate blockers, where security lies. In my experience, security is a focus at places, either non-profit or otherwise, in one of the following situations:
* The organization has one or more squeaky wheel employees that force everybody else to consider security where they wouldn't otherwise.
* The organization or another in the same industry has already had a very painful security breach.
* Security itself is part of the selling point.
Non profits are slightly different, but they still experience many of the same problems because the goal is still getting the most done on the budget you've got.
Yeah, I can see that. I think you’re right. But that feels more to the "cultural" point (i.e., different perspectives having different priorities) than the specific claim specifically that "profits" are the driver.
> If profit were the primary motive, wouldn’t you expect non-profit institutions (both healthcare and otherwise) to be in much better shape from a cybersecurity standpoint?
I will respond to that partially: where profit is not a primary motive, i.e. in countries where healthcare is public, it tends to be centralized on federal or regional level, and, as such, much of the IT and cybersecurity is a lower, shared cost incurred by the government.
So if I understand your point correctly, it’s not necessarily that removing the profit incentives directly improves the outcome but rather the improvement is attributable to a better economy of scale?
There is a lack of cybersecurity investments in almost every industry. The issue is that the executives making the decisions 1) Usually aren't knowledgable about CyberSec and 2) don't justify the investment because it's not something they can physically point at and take credit for. .
The "economist" proposed a solution: tire cyber-security incidents to the stock market. The approach proposed was something akin to "have someone count and display the incidents of each company and blast radius". I'm not sure if this would actually work.
The other capitalist option is to make cybersecurity insurance mandatory, and impose high fees both to reimburse victims and to some government watchdog/agency (yes, government watchdogs and capitalism can co-exist). Then, it will be in the insurer's best interest to have clients with adequate cybersecurity implementations, and the market can sort it out.
At the same time, we should make sure that any insurance company that chooses to pay the criminals instead loses their license to operate.
The US healthcare system cannot be primarily about saving jobs or the AMA would not have ever lobbied to restrict residencies to prevent a glut of doctors.
Since the AMA is an organization of medical professionals, one must conclude that it reflects their position: protectionism for their field.
In that case it is a culture of low salaries and tech being a support function. Governments aren't paying market salaries for tech and are not willing to have highly technical people in many leadership roles.
Many governments aren't willing to have highly technical people in any leadership roles. I've worked with government IT departments before where 100% of management (not an exaggeration) was non-technical, as in had never been a developer, sys admin, or any type of engineer. From the front line managers the whole way up to the "CIO."
UK's hospitals fare no better in terms of cybersecurity. This is about the culture of nursing / doctors / hospital administrators, which is largely shared between USA and UK.
This isn't a systemic issue that is solved by nationalizing health care like UK did.
USA health care system, culturally, is about saving lives. Whether our system matches it is another story. But the underlying people largely do the right thing.
------
I think the systemic issues regarding health care / infrastructure / investments are wholly independent of this cybersecurity issue.