Live data from Hacker News

Show HN: Kate's App

katesapp.org

191–192 of 192 posts

Re: Show HN: Kate's App

#191

Earlier quoted context omitted.

What safeguards? Obfuscating your IDs by... replacing them with one-to-one mapped other IDs?

I believe one can readily agree that https://example.com/profiles/gooosle and https://example.com/profiles/mdaniel are not sequential and thus not subject to enumeration in any reasonable way. A concrete example of defense against this is: please link to the HN username of an account which has never posted The other very common pattern is https://example.com/profiles/852c1a9a-29ae-4638-9d82-50e0d40... or its b36 enco…

First of all exposing IDs and having non-enumerable IDs are completely different things.

Second, HN usernames are 100% enumerable. 'asdfgf' is an example of account which has never posted.

Re: Show HN: Kate's App

#192
post #177

Earlier quoted context omitted.

How could this app possibly be considered a business associate to a provider? The provider has no idea it’s even being used, let alone a formal association with the application.

Look up the definition of “provider” in HIPAA’s text. The definition is extremely broad and doesn’t just cover doctors and pharmacists.

It’s not really that broad. It amounts to medical professionals (doctors, nurses, etc.), insurers, and any systems they use to store or process data. If the medical professional or insurer is not using the app, and the app has not signed a BAA with them, then it’s not covered under HIPAA.

https://www.hhs.gov/hipaa/for-professionals/covered-entities...

Post reply on HN