Live data from Hacker News

'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

websiteplanet.com

1–10 of 193 posts

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#6
I'll need to dig up a source but I recently heard about this company and, apparently, before offering gigs they do a credit report to determine how much debt the person is carrying (i.e. how desperate they are) and they use that information to _round down_ the hourly rate they offer them.

In the unlikely event that there are any negative consequences for this breach, they deserve every bit of them and more.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#8
post #4

Well there be any consequences for the company?

No. And hence this will keep happening.

Even if there are, it’ll be minuscule compared to what is necessary to drive effective change.

The fine for one person’s information from this site should be equivalent to their entire revenue for the year; should not be permitted to be resolved by bankruptcy, and should be required to transfer to any company purchasing their assets.

Their entire executive team should be jailed for a minimum of 3 years per individual offense.

Only then will there be any modicum of an opportunity for us to see some real change.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#9
Worth mentioning, because the authority level of medical practitioners throws people off. Don't ever give a doctor or practice your Social Security Number. They don't need it. Similarly if they want to check an ID that doesn't mean scan or photograph. Doctors, practices, etc are the worst at infosec. They have no training, basically no penalties if they do something wrong and all of that info is only to follow up in case you don't pay your bill.
Post reply on HN