Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's less shocking when you recognise that these are simply sites to tell patients when surgeries are open etc

The question is, do patients realise that, or will they tend to assume that because a site is part of the privileged .nhs.uk hierarchy, it is properly run by the NHS?

The real problem here is about trust, specifically about what should or should not appear trustworthy to patients because it is or isn't really. Given the increasing moves to do things like making appointments on-line, the much-reported efforts to share sensitive health data more widely, and the ever-changing sources of information and ways to contact the NHS, it seems to me that it is long past time these issues were resolved. IMHO it has to be done properly and from the top to have sufficient credibility and enforcement.



For appointments, just as an example, I believe emis and others offer their own separate systems and apps for this and also provide hosted sites. No idea if they are more secure but that's where the important data lives, on systems like that, not on these wordpress sites. There are 2-3 that almost all gps use, not sure on hospitals.

http://www.emis-online.com

I do agree with most of what you're saying though, and this is far from an ideal situation. Probably a central system makes most sense long term but gov seems unable (or more recently unwilling) to deliver.


The point is that if I send you an email, claiming to be your GP, telling you about "our new appointments system", and linking to something like:

http://yourgpwebsite.nhs.uk/some-vulnerable-page?xss=...

And my XSS replaces the page with something that looks like an appointments system, the average person has no way of knowing that they shouldn't trust this. There's certainly none of the usual indicators.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: