Do these organisations just sit there thinking "it can't happen to us" and then when it does claim that security is important to them?
Kidney dialysis giant DaVita tells 2.4M people they were snared in ransomware data theft nightmare
Ransomware scum breached kidney dialysis firm Davita's labs database in April and stole about 2.4 million people's personal and health-related information. In a filing with the US Department of Health and Human Services, the global healthcare provider, which operates 2,661 dialysis centers in America, reported that the breach …
COMMENTS
-
-
Saturday 23rd August 2025 09:20 GMT Anonymous Coward
That's a question you can ask any organisation using Microsoft products without a metric boatload of extra protective measures. Nobody seems to ask why that particular colander after literally decades of patches (which must be well into the Terabytes per year now) is still incapable of holding any water.
-
Monday 25th August 2025 14:46 GMT GNU Enjoyer
>without a metric boatload of extra protective measures.
Attempting to make microsoft software secure is like seeing the vulnerability of wide open windows you're not allowed to close and opting to painstakingly put plastic wrap over the windows - attackers at best might be slowed down for a few seconds (only for however long it takes to punch a hole through the wrap).
The only way to mitigate the vulnerability of microsoft software is to close the windows by not using microsoft's bugware.
-
Monday 25th August 2025 21:42 GMT David Hicklin
> nobody seems to ask why that particular colander after literally decades of patches
Simples - they have a higher priority for producing new stuff and redesigning older stuff like notepad etc over fixing anything.
AI generated code is going to make that much worse**
** moment for thought: If people start using AI to write code, will the AI remember that code , and then will a bad actor be able to query the AI for that code for that program to find any flaws??
-
-
Monday 25th August 2025 21:38 GMT David Hicklin
I think modern operating systems and software has reached the point where it is so bloated, patched and bodged together to get it out of the door that it is almost inevitable that any organisation will get breached at some point.
Sadly once inside an organisation it is far to easily to traverse sideways to just about anywhere, its is well past the time when they should be making that harder (and yes it makes working harder if you have to 2FA everywhere but operating something like a ubikey is not much of a burden) and also not having *everything* immediately on-line - had everyone forgotten about off-line archiving ??
-
Monday 25th August 2025 06:25 GMT Anonymous Coward
Common?
I get the impression big attacks on healthcare organisations is very common and increasing. Yet, we are expected to provide evermore personal data which gets splashed around even before the hackers get to work. The way things are going with the surveillance state and their ever growing appetite for our data and id, the only people that wont have access to our data is the good guys; i.e., us, the owners.
-
Monday 25th August 2025 13:55 GMT may_i
If only the USA had the GDPR
Then it would be illegal to hold personal data any longer than it is actually needed. The reason for needing it would actually have a proper definition and there would also be legal requirement that personal data held by companies is encrypted at rest so that a network intrusion would not be able to steal the data.
The only way to stop this story being played over and over again is to have a proper legal framework and to back that up with criminal penalties against the highest management in companies who flout the legal requirements to treat their customer's data like the digital gold that it is.