Live data from Hacker News

'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

websiteplanet.com

21–30 of 193 posts

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#21

Yeah I remember when Amazons AWS was new and people said "hey its cool but not secure." Then AWS added all these security features but added a caveat: BTW security is your responsibility Here we are. I guess we can blame the users and not any shitty security architecture slapped on AWS. Clearly what matters most is that legal culpability be avoided, not that users will be secure. The former is 'shite security' while…

> shitty security architecture slapped on AWS

It's literally, and I do mean this literally, 1 click to block all public traffic to an S3 bucket. It can be enabled at the account level, and is on _by default_ for any new bucket. What exactly more do you want?

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#22
post #10

Move fast and violate HIPAA.

Does HIPAA apply to HR into, or just patient health data?

HR likely deals with health info related to disability or fmla claims, or work-related injuries that is shared with health care providers and/or insurance companies; this makes them a covered entity subject to the requirements under hipaa.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#23
post #8

Earlier quoted context omitted.

No. And hence this will keep happening.

Even if there are, it’ll be minuscule compared to what is necessary to drive effective change. The fine for one person’s information from this site should be equivalent to their entire revenue for the year; should not be permitted to be resolved by bankruptcy, and should be required to transfer to any company purchasing their assets. Their entire executive team should be jailed for a minimum of 3 years per individual…

> Their entire executive team should be jailed for a minimum of 3 years per individual offense.

This is so over the top reactionary and stupid, I can't help but write off your entire comment.

You want the Chief Accounting Officer to go to jail for 3 decades because of a data breach?

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#24

Yeah I remember when Amazons AWS was new and people said "hey its cool but not secure." Then AWS added all these security features but added a caveat: BTW security is your responsibility Here we are. I guess we can blame the users and not any shitty security architecture slapped on AWS. Clearly what matters most is that legal culpability be avoided, not that users will be secure. The former is 'shite security' while…

> shitty security architecture slapped on AWS It's literally, and I do mean this literally, 1 click to block all public traffic to an S3 bucket. It can be enabled at the account level, and is on _by default_ for any new bucket. What exactly more do you want?

> It's literally, and I do mean this literally, 1 click to block all public traffic to an S3 bucket.

I'm reasonably certain that for quite a while blocking all public access has been the default, and it is multiple clicks through scary warnings (through the console; CLI or IaC are simpler) to enable public access.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#26

Yeah I remember when Amazons AWS was new and people said "hey its cool but not secure." Then AWS added all these security features but added a caveat: BTW security is your responsibility Here we are. I guess we can blame the users and not any shitty security architecture slapped on AWS. Clearly what matters most is that legal culpability be avoided, not that users will be secure. The former is 'shite security' while…

The only mistake AWS made was making buckets originally public by default. It’s been many years since that’s been the case. At this point, you have to be completely ignorant to be storing PII in a public bucket.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#27
In the section of their Privacy Policy titled Data Security [0]:

> We use certain physical, managerial, and technical safeguards that are designed to improve the integrity and security of information that we collect and maintain. Please be aware that no security measures are perfect or impenetrable. We cannot and do not guarantee that information about you will not be accessed, viewed, disclosed, altered, or destroyed by breach of any of our physical, technical, or managerial safeguards. In particular, the Service is NOT designed to store or secure information that could be deemed to be Protected Health Information as defined by the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”).

IANAL and all that, but I’m not sure you can use the excuse “We didn’t design our system to be HIPAA compliant, sorry,” and hope your liability disappears. Does anyone know?

0: https://eshyft.com/wp-content/uploads/2019/06/ESHYFT-Privacy...

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#28
post #12
post #9

Worth mentioning, because the authority level of medical practitioners throws people off. Don't ever give a doctor or practice your Social Security Number. They don't need it. Similarly if they want to check an ID that doesn't mean scan or photograph. Doctors, practices, etc are the worst at infosec. They have no training, basically no penalties if they do something wrong and all of that info is only to follow up in…

In the US, HIPAA is pretty much the strongest privacy legislation there is. There's probably no group that would have a more severe penalty for leaking your info than your healthcare provider.

HIPAA has strict rules with severe penalties, but enforcement is at best spotty. So honest hospitals and doctors offices bend over backwards to comply with the rules at great expense, but bad actors are rarely punished. It's the worst of both worlds. I'm pretty sure that is why the punishments are so harsh, because they need to put the fear of god into practitioners to make them take it seriously since there are so few inspectors.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#29

I'll need to dig up a source but I recently heard about this company and, apparently, before offering gigs they do a credit report to determine how much debt the person is carrying (i.e. how desperate they are) and they use that information to _round down_ the hourly rate they offer them. In the unlikely event that there are any negative consequences for this breach, they deserve every bit of them and more.

This is abhorrent if true; truly evil behavior.

It's amazing that, on a cursory look, only 11 states make this practice illegal. The "AI scriptown" is growing.
Post reply on HN