Live data from Hacker News

Aetna accidentally exposed customer HIV statuses in clear envelope windows

washingtonpost.com

31–40 of 130 posts

Re: Aetna accidentally exposed customer HIV statuses in clear envelope windows

#31
post #6

Earlier quoted context omitted.

You shouldn't be downvoted for normal and reasonable questions, or even for self doubt. Aetna is terrible. The lobby against healthcare reform at every turn. They didn't want obamacare/ACA they didn't want to compete accross state lines, they want to be able to exempt people from pre-existing conditions, they want to give people the run-around. They are not trustworthy and they are run by bad people. (don't beat up o…

What insurer is trustworthy? They make money by denying claims and coverage to people who actually need it; that's the business model.

Under the ACA they are not allowed to deny coverage.

They certainly do act to minimize the claims they pay.

Re: Aetna accidentally exposed customer HIV statuses in clear envelope windows

#33
post #18

Wow, this is actually something I consider when sending letters to my clients. I don't ever want to "leak" their info, even if it's not really considered sensitive. I always assume the top third to be "compromised", only putting the private contents in the lower two thirds or on the back. I wonder why they don't have the mailing rule of the top third as a written policy.

A cost/benefit analysis of "put all HIPAA-relevant information inside an opaque envelope" probably comes out ahead if it prevents one issue like this. Hell, make the envelope a specific color to make it really obvious that you've done things correctly.

Would the differently colored envelope itself be a HIPPA violation?

Re: Aetna accidentally exposed customer HIV statuses in clear envelope windows

#34
post #12
post #2

Oh neat, I just signed up for Aetna (first time working in America since ACA). Is this normal for them? Am I an idiot?

If you know how to "don't take no for an answer" I'll say optimistically, you'll be alright. My experience with my wife's health care (Aetna) has been that she will call, try to get an issue resolved, be told "there is no resolution possible" enough times by enough different people that she is ready to give up. Then we call together, and suddenly the story changes. The particular issue we were dealing with, is not re…

Your advice is spot on.

We had a very similar experience with Blue Cross for many years. I'd swear they have an RNG that randomly denies claims 80% of the time. You just had to fight each one on the phone.

The people on the phone only had the apparent authority to "send the claim through the system again". About a month later you'd find out what happened. If denied again, we would just repeat until we eventually got lucky with the RNG.

They did eventually pay everything they should have, but we'd average about two hours on the phone per doctor visit.

Re: Aetna accidentally exposed customer HIV statuses in clear envelope windows

#35
post #22
post #6

Earlier quoted context omitted.

You shouldn't be downvoted for normal and reasonable questions, or even for self doubt. Aetna is terrible. The lobby against healthcare reform at every turn. They didn't want obamacare/ACA they didn't want to compete accross state lines, they want to be able to exempt people from pre-existing conditions, they want to give people the run-around. They are not trustworthy and they are run by bad people. (don't beat up o…

Awesome. I can't change my decision for another year, and then only to Blue Cross. Are they also terrible?

Right now I'm on the hook for 5 figures with BC/BS for my son's birth expenses, because HR screwed up his application. It's a Kafkaesque byzantine labyrinth of red tape and buck passing. I'm not sure they're evil, just bureaucratic.

Re: Aetna accidentally exposed customer HIV statuses in clear envelope windows

#36

Reading further in, it was a screw-up on the paper envelope that had too big of a window and referred to HIV treatment connected to the person's name. This is really bad, but it was 12k localized instances of crummy physical mailing. Its pretty bad, but it's not like this was "300k people leaked by hackers for ransom".

If I were HIV positive, I would much rather my neighbors know my social security number than my HIV status.

Re: Aetna accidentally exposed customer HIV statuses in clear envelope windows

#37

Earlier quoted context omitted.

What insurer is trustworthy? They make money by denying claims and coverage to people who actually need it; that's the business model.

Under the ACA they are not allowed to deny coverage. They certainly do act to minimize the claims they pay.

Just add "to the extent permitted by law" if you want. There are still circumstances where you can't sign up, like missing an enrollment period.

Re: Aetna accidentally exposed customer HIV statuses in clear envelope windows

#38
post #6

Earlier quoted context omitted.

You shouldn't be downvoted for normal and reasonable questions, or even for self doubt. Aetna is terrible. The lobby against healthcare reform at every turn. They didn't want obamacare/ACA they didn't want to compete accross state lines, they want to be able to exempt people from pre-existing conditions, they want to give people the run-around. They are not trustworthy and they are run by bad people. (don't beat up o…

Competing across state lines means all insurance will be regulated by the state with rules that most favor the insurer, it isn't all that likely to be good for consumers. The banking renaissance in South Dakota is a result of a similar situation. https://www.theatlantic.com/business/archive/2013/07/how-cit...

> Competing across state lines means all insurance will be regulated by the state with rules that most favor the insurer

Not really; states are still free to set additional requirements for insurance plans that cover members of that state.

To be honest, competing across state lines would not actually do much in the long run. It'd provide an extra degree of competition in the short-term, but ultimately then insurers would consolidate into multistate operations (which is already the case to a large degree).

Re: Aetna accidentally exposed customer HIV statuses in clear envelope windows

#39

Earlier quoted context omitted.

Phew, they only needlessly and carelessly divulged 12,000 people's HIV status.

I never said it was a good thing. Even though the badness of the situation, I'm saying it would have been terribly worse with mass leaks of the DB this came from. It's not like we in the tech community have seen leaks like that... Regardless, I see this as a bad screw-up with with no ill intent behind it. It was literally a "too large window" on an envelope...

Yes, but it's almost surreal how negligent this was.

Re: Aetna accidentally exposed customer HIV statuses in clear envelope windows

#40
post #2

Oh neat, I just signed up for Aetna (first time working in America since ACA). Is this normal for them? Am I an idiot?

I have them through work, they're pretty shitty, for example, I currently have to either turn of uBlock (not an option) or open dev tools to unhide a div in order to log in. Why there is anything on health insurance website that communicates with a third-party server baffles me. That said, I don't think there are any good options in the US. They all have weird quirks like this, they all require a fight to get the pay…

Aetna uses JavaScript for everything on their website. Can't middle-click a link to open in a new tab because it's JS, not a proper link.
Post reply on HN