Live data from Hacker News

'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

websiteplanet.com

11–20 of 193 posts

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#11
post #8

Earlier quoted context omitted.

No. And hence this will keep happening.

Even if there are, it’ll be minuscule compared to what is necessary to drive effective change. The fine for one person’s information from this site should be equivalent to their entire revenue for the year; should not be permitted to be resolved by bankruptcy, and should be required to transfer to any company purchasing their assets. Their entire executive team should be jailed for a minimum of 3 years per individual…

Your proposal is so bizarrely out of proportion with the harm caused that I can’t tell if it’s parody or not. Why not execute them while you’re at it?

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#12
post #9

Worth mentioning, because the authority level of medical practitioners throws people off. Don't ever give a doctor or practice your Social Security Number. They don't need it. Similarly if they want to check an ID that doesn't mean scan or photograph. Doctors, practices, etc are the worst at infosec. They have no training, basically no penalties if they do something wrong and all of that info is only to follow up in…

In the US, HIPAA is pretty much the strongest privacy legislation there is. There's probably no group that would have a more severe penalty for leaking your info than your healthcare provider.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#14
post #10

Move fast and violate HIPAA.

Does HIPAA apply to HR into, or just patient health data?

Protected health information (PHI) under U.S. law is any information about health status, provision of health care, or payment for health care that is created or collected by a Covered Entity (or a Business Associate of a Covered Entity), and can be linked to a specific individual. This is interpreted rather broadly and includes any part of a patient's medical record or payment history.

source: i run Wyndly (YC W21 https://www.wyndly.com), which is most easily understood as a telehealth allergist online.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#15
post #10

Move fast and violate HIPAA.

Does HIPAA apply to HR into, or just patient health data?

It considers non-health-specific identifying info about patients that might be stored with the health-specific info to also be PHI.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#16
I wonder how old the S3 bucket was, because at some point AWS made new S3 buckets private by default.

Which means it's either old, or they recklessly opened it up because they couldn't get files uploaded/downloaded to the bucket from their mobile app/services.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#17
post #11
post #8

Earlier quoted context omitted.

Even if there are, it’ll be minuscule compared to what is necessary to drive effective change. The fine for one person’s information from this site should be equivalent to their entire revenue for the year; should not be permitted to be resolved by bankruptcy, and should be required to transfer to any company purchasing their assets. Their entire executive team should be jailed for a minimum of 3 years per individual…

Your proposal is so bizarrely out of proportion with the harm caused that I can’t tell if it’s parody or not. Why not execute them while you’re at it?

That would be cruel and unusual — their families and friends would needlessly suffer. They'll need to be executed too.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#18
Yeah I remember when Amazons AWS was new and people said "hey its cool but not secure." Then AWS added all these security features but added a caveat: BTW security is your responsibility

Here we are. I guess we can blame the users and not any shitty security architecture slapped on AWS.

Clearly what matters most is that legal culpability be avoided, not that users will be secure. The former is 'shite security' while the latter is good security

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#19
post #12
post #9

Worth mentioning, because the authority level of medical practitioners throws people off. Don't ever give a doctor or practice your Social Security Number. They don't need it. Similarly if they want to check an ID that doesn't mean scan or photograph. Doctors, practices, etc are the worst at infosec. They have no training, basically no penalties if they do something wrong and all of that info is only to follow up in…

In the US, HIPAA is pretty much the strongest privacy legislation there is. There's probably no group that would have a more severe penalty for leaking your info than your healthcare provider.

And yet the data still seems to leak pretty frequently...

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#20

I'll need to dig up a source but I recently heard about this company and, apparently, before offering gigs they do a credit report to determine how much debt the person is carrying (i.e. how desperate they are) and they use that information to _round down_ the hourly rate they offer them. In the unlikely event that there are any negative consequences for this breach, they deserve every bit of them and more.

This is abhorrent if true; truly evil behavior.
Post reply on HN