Skip to content
  • About
  • Contact
  • Contribute
  • Book
  • Careers
  • Podcast
  • Recommended
  • Speaking
KevinMD
  • All
  • Physician
  • Practice
  • Policy
  • Finance
  • Conditions
  • .edu
  • Patient
  • Meds
  • Tech
  • Social
  • Video
  • All
  • Physician
  • Practice
  • Policy
  • Finance
  • Conditions
  • .edu
  • Patient
  • Meds
  • Tech
  • Social
  • Video
    • All
    • Physician
    • Practice
    • Policy
    • Finance
    • Conditions
    • .edu
    • Patient
    • Meds
    • Tech
    • Social
    • Video
    • About
    • Contact
    • Contribute
    • Book
    • Careers
    • Podcast
    • Recommended
    • Speaking
KevinMD
  • All
  • Physician
  • Practice
  • Policy
  • Finance
  • Conditions
  • .edu
  • Patient
  • Meds
  • Tech
  • Social
  • Video
    • All
    • Physician
    • Practice
    • Policy
    • Finance
    • Conditions
    • .edu
    • Patient
    • Meds
    • Tech
    • Social
    • Video
    • About
    • Contact
    • Contribute
    • Book
    • Careers
    • Podcast
    • Recommended
    • Speaking
  • About KevinMD | Kevin Pho, MD
  • Be heard on social media’s leading physician voice
  • Contact Kevin
  • Discounted enhanced author page
  • DMCA Policy
  • Establishing, Managing, and Protecting Your Online Reputation: A Social Media Guide for Physicians and Medical Practices
  • Group vs. individual disability insurance for doctors: pros and cons
  • KevinMD influencer opportunities
  • Opinion and commentary by KevinMD
  • Physician burnout speakers to keynote your conference
  • Physician Coaching by KevinMD
  • Physician keynote speaker: Kevin Pho, MD
  • Physician Speaking by KevinMD: a boutique speakers bureau
  • Primary care physician in Nashua, NH | Doctor accepting new patients
  • Privacy Policy
  • Recommended services by KevinMD
  • Terms of Use Agreement
  • Thank you for subscribing to KevinMD
  • Thank you for upgrading to the KevinMD enhanced author page
  • The biggest mistake doctors make when purchasing disability insurance
  • The doctor’s guide to disability insurance: short-term vs. long-term
  • The KevinMD ToolKit
  • Upgrade to the KevinMD enhanced author page
  • Why own-occupation disability insurance is a must for doctors

The Heartbleed bug compromises EHRs: Physicians and patients beware

Rigel Hope
Tech
April 9, 2014
Share
Tweet
Share

Technology finds its way into our lives not so much in big flashy ways as little ones. Oh, I can do this a little bit faster now, isn’t that cool? Wow, isn’t this convenient? Oh, isn’t this a huge risk to my privacy?

Oftentimes, when I start talking about Linux or scripting or the command line or any number of tech subjects that seem increasingly esoteric, I get blank stares from my colleagues, medical students and practitioners alike. As a lifelong tinkerer, though, I’ve witnessed an increasing convergence of technology and medicine. Not in the gee-whiz look-what-this-new-device-or-drug-can-do-what-a-breakthrough way, but in the oh-you-have-to-log-in-to-the-VPN-what-a-pain way.

So, Heartbleed is what this latest vulnerability is being called. It’s a newly discovered vulnerability in the OpenSSL software package, CVE-2014-0160 if you want to look up the gory details. About two-thirds of the web uses it, including both of the major web servers, Apache and nginx, and lots and lots of other software projects besides. What it means is that anyone who has captured traffic that used this particular version of SSL (the “s” in https) in the last two years can, potentially, decrypt that traffic. All of it. So, those VPN sessions that started with going to a website? Assume they are compromised. Change your passwords. Does your VPN use the same package to log in to your EHR? Do you know?

I don’t want to sound alarmist here, but this is serious. And it speaks to both the best and worst of free and open-source software (FOSS) projects. Best, because it was found, disclosed, and promptly patched for many projects that depend on it. For closed-source or proprietary projects, who knows how long that will take. And it speaks to the worst of FOSS because since everyone uses it for free, thorough audits of the codebase are not done as often as perhaps they should be for software that two-thirds of the web is based on.

How much money have the big EHR vendors contributed to the OpenSSL foundation that writes and debugs the software, if they use it? And if they have written their own versions of SSL or a X.509 certificate validator, how do you know how secure that is?

Now, what does this have to do with medicine? As we become increasingly dependent on EHRs and other technical means for communicating and distributing information, the projects that make up the web (a large proportion of which are FOSS) become de facto public health projects. Don’t get me wrong, I certainly wouldn’t want people to start moving to proprietary software more so than they already have. This is what people in the security world call “security through obscurity” and it’s a bit like approaching a MRSA outbreak by simply not surveilling it, and then saying we don’t have a problem.

Privacy is something we take seriously in medicine, but also a thing that in practice we allow our vendors to do the absolute minimum to address, mainly so we’re not worried about HIPAA fines. That is a terrible way to think about security, and it ensures that when vulnerabilities like Heartbleed are found, we are left questioning whether we’ve just exposed our patients’ medical records to the world.

Rigel Hope is a medical student.

Prev

The alarming decline of internal medicine recertification pass rates

April 9, 2014 Kevin 18
…
Next

What health care can learn from Katz's Delicatessen

April 9, 2014 Kevin 30
…

Tagged as: Health IT

< Previous Post
The alarming decline of internal medicine recertification pass rates
Next Post >
What health care can learn from Katz's Delicatessen

ADVERTISEMENT

More in Tech

  • Iterative mindset versus AI and GLP-1s: Why shortcuts weaken the brain

    Martha Rosenberg
  • Why voicemail in outpatient care is failing patients and staff

    Dan Ouellet
  • Building a clinical simulation app without an MD: a developer’s guide

    Helena Kaso, MPA
  • AI-enabled clinical data abstraction: a nurse’s perspective

    Pamela Ashenfelter, RN
  • Agentic AI in medicine: the danger of automating the doctor

    Shiv K. Goel, MD
  • Will AI replace primary care physicians?

    P. Dileep Kumar, MD, MBA
  • Most Popular

  • Past Week

    • My wife’s story: How DEA and CDC guidelines destroyed our golden years

      Monty Goddard & Richard A. Lawhern, PhD | Conditions
    • Why medical school DEI mission statements matter for future physicians

      Aditi Mahajan, MEd, Laura Malmut, MD, MEd, Jared Stowers, MD, and Khaleel Atkinson | Education
    • Breaking the silence: mental health and racism in medical school

      Michael F. Myers, MD | Physician
    • Health insurance waste: Why eliminating the middleman saves billions

      Edward Anselm, MD | Policy
    • Why AI in health care is the only fix for physician shortages

      John C. Hagan III, MD | Physician
    • High-protein diet risks: Why more isn’t always better

      Farid Sabet-Sharghi, MD | Conditions
  • Past 6 Months

    • Will AI replace primary care physicians?

      P. Dileep Kumar, MD, MBA | Tech
    • A physician father on the Dobbs decision and reproductive rights

      Travis Walker, MD, MPH | Physician
    • What is the minority tax in medicine?

      Tharini Nagarkar and Maranda C. Ward, EdD, MPH | Education
    • Why the U.S. health care system is failing patients and physicians

      John C. Hagan III, MD | Policy
    • Alex Pretti: a physician’s open letter defending his legacy

      Mousson Berrouet, DO | Physician
    • Why voicemail in outpatient care is failing patients and staff

      Dan Ouellet | Tech
  • Recent Posts

    • Teaching joy transforms the future of medical practice [PODCAST]

      The Podcast by KevinMD | Podcast
    • Why Filipino nurses faced higher COVID-19 mortality rates

      Joaquim Diego Santos | Policy
    • Frailty and functional decline: Why diagnosis is not enough

      Gerald Kuo | Conditions
    • Moral injury in medicine: When silence becomes a survival strategy

      Timothy Lesaca, MD | Physician
    • Iterative mindset versus AI and GLP-1s: Why shortcuts weaken the brain

      Martha Rosenberg | Tech
    • Autism comorbidities: the hidden link between POTS, GI issues, and hypermobility

      Carrie Friedman, NP | Conditions

Subscribe to KevinMD and never miss a story!

Get free updates delivered free to your inbox.


Find jobs at
Careers by KevinMD.com

Search thousands of physician, PA, NP, and CRNA jobs now.

Learn more

Leave a Comment

Founded in 2004 by Kevin Pho, MD, KevinMD.com is the web’s leading platform where physicians, advanced practitioners, nurses, medical students, and patients share their insight and tell their stories.

Social

  • Like on Facebook
  • Follow on Twitter
  • Connect on Linkedin
  • Subscribe on Youtube
  • Instagram

ADVERTISEMENT

ADVERTISEMENT

  • Most Popular

  • Past Week

    • My wife’s story: How DEA and CDC guidelines destroyed our golden years

      Monty Goddard & Richard A. Lawhern, PhD | Conditions
    • Why medical school DEI mission statements matter for future physicians

      Aditi Mahajan, MEd, Laura Malmut, MD, MEd, Jared Stowers, MD, and Khaleel Atkinson | Education
    • Breaking the silence: mental health and racism in medical school

      Michael F. Myers, MD | Physician
    • Health insurance waste: Why eliminating the middleman saves billions

      Edward Anselm, MD | Policy
    • Why AI in health care is the only fix for physician shortages

      John C. Hagan III, MD | Physician
    • High-protein diet risks: Why more isn’t always better

      Farid Sabet-Sharghi, MD | Conditions
  • Past 6 Months

    • Will AI replace primary care physicians?

      P. Dileep Kumar, MD, MBA | Tech
    • A physician father on the Dobbs decision and reproductive rights

      Travis Walker, MD, MPH | Physician
    • What is the minority tax in medicine?

      Tharini Nagarkar and Maranda C. Ward, EdD, MPH | Education
    • Why the U.S. health care system is failing patients and physicians

      John C. Hagan III, MD | Policy
    • Alex Pretti: a physician’s open letter defending his legacy

      Mousson Berrouet, DO | Physician
    • Why voicemail in outpatient care is failing patients and staff

      Dan Ouellet | Tech
  • Recent Posts

    • Teaching joy transforms the future of medical practice [PODCAST]

      The Podcast by KevinMD | Podcast
    • Why Filipino nurses faced higher COVID-19 mortality rates

      Joaquim Diego Santos | Policy
    • Frailty and functional decline: Why diagnosis is not enough

      Gerald Kuo | Conditions
    • Moral injury in medicine: When silence becomes a survival strategy

      Timothy Lesaca, MD | Physician
    • Iterative mindset versus AI and GLP-1s: Why shortcuts weaken the brain

      Martha Rosenberg | Tech
    • Autism comorbidities: the hidden link between POTS, GI issues, and hypermobility

      Carrie Friedman, NP | Conditions

MedPage Today Professional

An Everyday Health Property Medpage Today

Copyright © 2026 KevinMD.com | Powered by Astra WordPress Theme

  • Terms of Use | Disclaimer
  • Privacy Policy
  • DMCA Policy
All Content © KevinMD, LLC
Site by Outthink Group

Leave a Comment

Comments are moderated before they are published. Please read the comment policy.

Loading Comments...