Discussion about this post

User's avatar
Doug White's avatar

Look into A very similar situation re EMR (electronic medical records) and the Veterans Administration and health care. The VA developed a very cheap, open , user war friendly, interoperable electronic health record (VISTA) that could have been scaled up nicely and cheaply and fulfilled most clinicians needs. But private EMR companies lobbied to make sure it wasn’t made available to any hospital outside of the VA system , and Trump awarded a no bid contract with an initial outlay of $10 billion over ten years (It wasn’t even the best PRIVATE sector solution, but it was the product of big donors to trump campaign funds. . (I guess the last thing we needed was a simple , effectively “free” , robust, stable, off the shelf, scalable solution that allowed patient and doctors to see their health records across institutions/geography/health care systems , right ?) surprise Oracle/cerner got a huge contract and failed to deliver after making 16 BILLION. Even bigger surprise, the Senior service official at the VA was taking bribes from them ! (God knows how much these contractors bribed congresswomen with campaign funds !) https://www.npr.org/2023/05/01/1173141145/an-electronic-health-records-system-for-veterans-has-caused-unnecessary-sufferin#:~:text=It%20took%20decades%20for%20the,the%20Oracle%2DCerner%20electronic%20health%20record.

Flash WASHINGTON – John H. Windom, 64, a member of the Senior Executive Service who previously served as Executive Director of the Office of Electronic Health Record Modernization (OEHRM) in the Department of Veterans Affairs, has just been charged in relation to his alleged failure to disclose his receipt of thousands of dollars in cash, casino chips, gift cards, and other gifts from contractors while leading the project. (You cant make this stuff up)

Cyril Simonnet's avatar

COMMON SENSE REBEL, the ThinThread story is a perfect case of institutions optimizing for self-preservation over actual security. The Cathedral did not kill ThinThread because it failed. It killed it because it worked too well, too cheaply, and made the expensive alternative look unnecessary. That same institutional logic plays out today in how companies pick their security vendors. They consolidate everything into one provider because it feels safe, because it is easy to justify to a board, not because it reduces risk. I wrote about this exact pattern: the provider you trust to protect you becomes your biggest single point of failure, and nobody questions it until something breaks.

https://cyrilsimonnet.substack.com/p/your-security-provider-is-a-bigger

9 more comments...

No posts

Ready for more?