Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Technically, profit tends to be the #1 goal, at least in the US. Consequentially, this also drives a lack of investment in cybersecurity.

UK's hospitals fare no better in terms of cybersecurity. This is about the culture of nursing / doctors / hospital administrators, which is largely shared between USA and UK.

This isn't a systemic issue that is solved by nationalizing health care like UK did.

USA health care system, culturally, is about saving lives. Whether our system matches it is another story. But the underlying people largely do the right thing.

------

I think the systemic issues regarding health care / infrastructure / investments are wholly independent of this cybersecurity issue.



> USA health care system, culturally, is about saving lives.

With all respect, but for someone who had lived in the US after moving from EU, I'd say it's first and foremost about making money. It saves lives where saving is needed, but I'd argue vast majority of cases are outpatient and the culture is strikingly blunt about milking the patient.


Hospitals in the US are not especially profitable. Including federal relief, median hospital profit margin is 2%.

The whole market is wildly distorted- starting with doctor education up through private insurance and government programs like Medicare and Medicaid- that simple answers like this totally miss the mark.


Agreed. Any simplistic statement like "the problem with healthcare in the US is [blank]" is evidence of someone that doesn't know very much about the many complex and interlinked issues. Likewise, someone thinking the system can be fixed by "just doing X" is also being reductionist.

The pandemic showed a number of areas in healthcare where people were generally ignorant. For example, thinking that hospitals have tons of reserve capacity to handle extraordinary events. Even well before the current situation, hospitals (community) tended to run at about 80% occupancy. Far from being a profit-consideration, even the department of Health and Human Services mandated that hospitals had to run at least 55% occupancy, or they lost benefits.


The pandemic is a bit unusual in affecting everyone at once. For a local or regional problem, staffing wouldn't be as much of an issue because workers can travel. (For example, traveling nurses.)


> Any simplistic statement like "the problem with healthcare in the US is [blank]" is evidence of someone that doesn't know very much

But who made such statement in this discussion?


> that simple answers like this totally miss the mark.

I am not providing my "answer" to the US problem, I am merely noticing how strikingly different approach the healthcare has here, so I reject your insinuation.

To be honest, I don't need to care who's making how much money to make a point – all I know that from my perspective, at the end of the day it is about milking the patient and it differs wildly from the general EU experience.


Profit in this sense likely refers to the value of the hospital (or greater provider network) rather than simply their EBITDA or whatever.


If profit were the primary motive, wouldn’t you expect non-profit institutions (both healthcare and otherwise) to be in much better shape from a cybersecurity standpoint? E.g., is there evidence that a large non-profit healthcare system like the VA is substantially better at cybersecurity?

While profit no doubt impacts the decisions, it doesn't appear to be the primary driver of cybersecurity lapses.


I wouldn't. Both goals of maximizing profit and achieving a goal on a minimal possible budget end up cutting costs in places that aren't immediate blockers, where security lies. In my experience, security is a focus at places, either non-profit or otherwise, in one of the following situations:

* The organization has one or more squeaky wheel employees that force everybody else to consider security where they wouldn't otherwise.

* The organization or another in the same industry has already had a very painful security breach.

* Security itself is part of the selling point.

Non profits are slightly different, but they still experience many of the same problems because the goal is still getting the most done on the budget you've got.


Yeah, I can see that. I think you’re right. But that feels more to the "cultural" point (i.e., different perspectives having different priorities) than the specific claim specifically that "profits" are the driver.


> If profit were the primary motive, wouldn’t you expect non-profit institutions (both healthcare and otherwise) to be in much better shape from a cybersecurity standpoint?

I will respond to that partially: where profit is not a primary motive, i.e. in countries where healthcare is public, it tends to be centralized on federal or regional level, and, as such, much of the IT and cybersecurity is a lower, shared cost incurred by the government.

Taking my native Poland as an example, there is a single country-wide portal available for patients (http://pacjent.gov.pl), as well as a single, centralized API for doctor/hospital software (https://cez.gov.pl/interoperacyjnosc/interfejsy/) and a bunch of helper systems (https://cez.gov.pl/projekty/nasze-systemy/project/rejestr-as...). Naturally hospitals would have their own 3rd party systems, etc., but the tendency is to unify everything, which logically reduces number of attack vectors.

Hopefully someone with a better experience in the field can attest to that.


So if I understand your point correctly, it’s not necessarily that removing the profit incentives directly improves the outcome but rather the improvement is attributable to a better economy of scale?


There is a lack of cybersecurity investments in almost every industry. The issue is that the executives making the decisions 1) Usually aren't knowledgable about CyberSec and 2) don't justify the investment because it's not something they can physically point at and take credit for. .


The "economist" proposed a solution: tire cyber-security incidents to the stock market. The approach proposed was something akin to "have someone count and display the incidents of each company and blast radius". I'm not sure if this would actually work.


The other capitalist option is to make cybersecurity insurance mandatory, and impose high fees both to reimburse victims and to some government watchdog/agency (yes, government watchdogs and capitalism can co-exist). Then, it will be in the insurer's best interest to have clients with adequate cybersecurity implementations, and the market can sort it out.

At the same time, we should make sure that any insurance company that chooses to pay the criminals instead loses their license to operate.


I think that the moral hazard associated with insurance would just make the problem worse.


The US healthcare system cannot be primarily about saving jobs or the AMA would not have ever lobbied to restrict residencies to prevent a glut of doctors.

Since the AMA is an organization of medical professionals, one must conclude that it reflects their position: protectionism for their field.


In that case it is a culture of low salaries and tech being a support function. Governments aren't paying market salaries for tech and are not willing to have highly technical people in many leadership roles.


Many governments aren't willing to have highly technical people in any leadership roles. I've worked with government IT departments before where 100% of management (not an exaggeration) was non-technical, as in had never been a developer, sys admin, or any type of engineer. From the front line managers the whole way up to the "CIO."


Oh I get it. I was a government dev too and sometimes (I went through 3 managers in a year once) we had non-technical management too.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: