Medical Records and Default Passwords

No ratings

Presented at PacificHackers 2019 by

As a penetration tester with focus on the healthcare industry, I’ve seen patient data in medical devices that lacked authentication, portrayed a medical doctor to dupe help desk into handing over credentials (and vice versa), and gone as far as gaining domain admin in 10 minutes (thank you defaults). This talk will be full of stories, memes, and screenshots portraying cybersecurity issues affecting healthcare environments. I will discuss what I see as root causes and talk about regulatory & industry frameworks that try to mitigate these issues. The attendees will leave the talk with a better understanding of healthcare security issues, a methodology for conducting HIPAA penetration tests, and ideas to combat these issues head-on.