Insecure medical equipment protocols let attackers spoof diagnostic information

HL7 is a fine protocol, and if you can find me a single major vendor that implements it fully and properly across their product line, I’ll happily buy you a beer.

Sadly, most all of them took notes from Microsoft, where once they become a major player, they try to create ecosystem lock-in by subtly breaking shit in a way that forces the upstream and downstream guys to code for their particular brokenness, which itself is more or less a way to make it more expensive to adopt a competitor’s product, because then that company’s product doesn’t work quite right, and requires, at a minimum, a secondary HL7 parser that makes the broken shit work right with the other company, and that’s expensive, so… Yeah.