Live data from Hacker News

Patient details of 'any Australian' for sale on darknet

theguardian.com

41–50 of 58 posts

Re: Patient details of 'any Australian' for sale on darknet

#41
post #21

Earlier quoted context omitted.

One way to avoid this would be to limit the access of a doctor to patient records. Unless you give permission at a doctor/hospital to have them access your record, they won't be able to do a lookup. Retract the permission automatically/renew it once every X months. This would make stolen/misused creds a much smaller risk.

This runs into problems when the patient can't give permission e.g. because they are unconscious.

This is a problem that can be solved in a low tech way using a medical bracelet / necklace for patients who have chronic diseases that doctors might need to know about.

Re: Patient details of 'any Australian' for sale on darknet

#42
post #9

Anyone have any feasible monetization schemes for personal healthcare data?

Free or subsidised healthcare. If you're an overseas resident living in Australia and can produce a valid medicare number you can get access to a fairly comprehensive range of medical services under somebody else's name. It would be very rare for any medical facility to request ID beyond a medicare card. Actually happens fairly frequently with visiting overseas relatives borrowing family member's medicare cards.

Re: Patient details of 'any Australian' for sale on darknet

#43
post #38
post #2

TWO file photos of shady hooded figures with obscured faces and glitch art effects or other digital overlays put over the pic! Truly, this is a very comprehensive report about hacking indeed. On a serious note, I'm not at all surprised that my government's screwed up some sort of online database of private information. We had the famous census night access issues due to a DDoS and I am just waiting for that data to l…

Privacy has never been a priority for the Australian government - its citizens simply don't have the right. So there really shouldn't be much surprise over this. More importantly is that this story should educate Australians as to just how much their government values their privacy - sure, this will be hailed as a reason for even more political oversight over technological processes, but only for as long as there isn…

Australia has much stricter privacy laws than many countries, and has had them for a relatively long time (starting in 1988 and updated since).

The privacy laws apply to government agencies and any non-government organisation with > $3m in turnover.

https://www.oaic.gov.au/privacy-law/privacy-act/australian-p...

Re: Patient details of 'any Australian' for sale on darknet

#44
post #33

Earlier quoted context omitted.

This is just as likely to be a rogue employee/sysadmin as it is a actual hack. I wouldn't start placing blame until it's determined what the actual cause is.

If it is an employee or sysadmin, they are an idiot. Its $30 a pop for small volume and large risk. If you have a job with access to this data you should be charging a hell of a lot more. But its enough to get someone in a poorer country with little at risk to create a fake gmail account and use it to bootstrap access to an online self service portal or whatever approach they are using.

> If it is an employee or sysadmin, they are an idiot. Its $30 a pop for small volume and large risk

In this scenario, I expect a bad egg would've sold the records in bulk to a middleman for a high price.

Re: Patient details of 'any Australian' for sale on darknet

#45
post #9

Anyone have any feasible monetization schemes for personal healthcare data?

Information from your Medicare card is frequently used to authenticate identity, so ... identity theft.

The blast radius is somewhat limited by the 100-point identity check.

Medicare cards are only worth 25 points in the 100-point check. You must present one of the "primary" 70-point documents: birth certificate, birth card, citizenship certificate, current or recently-expired passport, diplomatic or refugee papers.

Then you will need another form of identification, on top of the primary and medicare, to pass 100 points.

Re: Patient details of 'any Australian' for sale on darknet

#46
post #9

Anyone have any feasible monetization schemes for personal healthcare data?

Advertising? "Buy medicine X now because it's much better than medicine Y for your condition". Also, insurance companies like to know what you have. If they secretly have your personal healthcare data, they could do a more focused 'sampling'.

I don't think medical data, other than information that is actually directly printed on a card, is obtained or sold.

Re: Patient details of 'any Australian' for sale on darknet

#47

Wait, this is 75 records ? What kind of leak is that? Seems far more likely to be one user accessing data over an insecure network and having that session captured, or similar one-instance leak. But on the other hand...what are the odds this journalist was one of a random 75 records?

They had successfully sold 75 records as of the date of the journalist's investigation. But that was a demand-side limitation - they apparently could supply any record on request.

Re: Patient details of 'any Australian' for sale on darknet

#48
On a related note, I've recently had two UK banks request more personal documents from me, and a video, for anti-fraud or anti-laundering, blah, blah reasons. When, not if, they get hacked, the intruders will have even greater ability to abuse my identity. Data protection acts are barking up the wrong tree - what we need are data limitation acts to require corporations to store as little data as possible.

Re: Patient details of 'any Australian' for sale on darknet

#49
post #7
post #2

TWO file photos of shady hooded figures with obscured faces and glitch art effects or other digital overlays put over the pic! Truly, this is a very comprehensive report about hacking indeed. On a serious note, I'm not at all surprised that my government's screwed up some sort of online database of private information. We had the famous census night access issues due to a DDoS and I am just waiting for that data to l…

I'd encourage Australians to submit a privacy complaint. Every chance it will be "just for laughs", but never know, it might get a coherent response. The URL with the Department of Human Services is: https://www.humanservices.gov.au/customer/contact-us/submit-... If they haven't responded to your satisfaction within 30 days, you can escalate the complaint to the Office of the Australian Information Commissioner. http…

I mean, if the us can't keep its tools for hacking citizens safe, how can yours

Re: Patient details of 'any Australian' for sale on darknet

#50
post #41
post #21

Earlier quoted context omitted.

This runs into problems when the patient can't give permission e.g. because they are unconscious.

This is a problem that can be solved in a low tech way using a medical bracelet / necklace for patients who have chronic diseases that doctors might need to know about.

Somebody with sickle cell disease or otherwise transfusion dependent greatly benefits from electronic records, which help minimize antibody reactions (not just ABO and Rh, but Duffy, Kell, Kidd, MNS, etc)
Post reply on HN