Live data from Hacker News

'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

websiteplanet.com

31–40 of 193 posts

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#31
post #12
post #9

Worth mentioning, because the authority level of medical practitioners throws people off. Don't ever give a doctor or practice your Social Security Number. They don't need it. Similarly if they want to check an ID that doesn't mean scan or photograph. Doctors, practices, etc are the worst at infosec. They have no training, basically no penalties if they do something wrong and all of that info is only to follow up in…

In the US, HIPAA is pretty much the strongest privacy legislation there is. There's probably no group that would have a more severe penalty for leaking your info than your healthcare provider.

Perhaps true, but the strongest privacy protections in the US are still pretty weak. The biggest penalty I know of is Anthem 2018, where they leaked HIPAA-qualifying records on 80 million customers. Their financial penalty was a whopping... $16 million. Two dimes per affected customer!

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#32

In the section of their Privacy Policy titled Data Security [0]: > We use certain physical, managerial, and technical safeguards that are designed to improve the integrity and security of information that we collect and maintain. Please be aware that no security measures are perfect or impenetrable. We cannot and do not guarantee that information about you will not be accessed, viewed, disclosed, altered, or destroye…

[Nevermind]

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#33
post #12

Earlier quoted context omitted.

In the US, HIPAA is pretty much the strongest privacy legislation there is. There's probably no group that would have a more severe penalty for leaking your info than your healthcare provider.

HIPAA has strict rules with severe penalties, but enforcement is at best spotty. So honest hospitals and doctors offices bend over backwards to comply with the rules at great expense, but bad actors are rarely punished. It's the worst of both worlds. I'm pretty sure that is why the punishments are so harsh, because they need to put the fear of god into practitioners to make them take it seriously since there are so f…

It's the difference in medical establishment skill level between your doctor and you. You are always at a disadvantage. I've long thought that a disinterested third party needs to be involved. Someone with real oversight taking a position adversarial to the hospital and strictly to create the best possible outcome for the patient.

The Hippocratic model isn't awesome.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#34
post #11
post #8

Earlier quoted context omitted.

Even if there are, it’ll be minuscule compared to what is necessary to drive effective change. The fine for one person’s information from this site should be equivalent to their entire revenue for the year; should not be permitted to be resolved by bankruptcy, and should be required to transfer to any company purchasing their assets. Their entire executive team should be jailed for a minimum of 3 years per individual…

Your proposal is so bizarrely out of proportion with the harm caused that I can’t tell if it’s parody or not. Why not execute them while you’re at it?

I recommend we summarily execute people who don’t use the middle lane to go straight at an intersection, blocking everyone else from turning right on red; I feel as if jail time for these executives was pretty reasonable.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#37
I am confused, the article seems to be short on details. Was the attack an open S3 bucket? The company in question seems to be hiring for GCP, so I imagine they don’t use S3 at all.

Did the submitter intentionally change the post title to get more clicks?

https://eshyft.com/careers/gcp-devops-engineer/

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#38
post #8

Earlier quoted context omitted.

Even if there are, it’ll be minuscule compared to what is necessary to drive effective change. The fine for one person’s information from this site should be equivalent to their entire revenue for the year; should not be permitted to be resolved by bankruptcy, and should be required to transfer to any company purchasing their assets. Their entire executive team should be jailed for a minimum of 3 years per individual…

> Their entire executive team should be jailed for a minimum of 3 years per individual offense. This is so over the top reactionary and stupid, I can't help but write off your entire comment. You want the Chief Accounting Officer to go to jail for 3 decades because of a data breach?

I assumed there was more than 10 folks impacted by their poor business decisions; based on the number of images of SS cards, it should be life without parole. Preferably with hard labor in Siberia or western Nebraska.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#39
post #9

Worth mentioning, because the authority level of medical practitioners throws people off. Don't ever give a doctor or practice your Social Security Number. They don't need it. Similarly if they want to check an ID that doesn't mean scan or photograph. Doctors, practices, etc are the worst at infosec. They have no training, basically no penalties if they do something wrong and all of that info is only to follow up in…

What do you do if they refuse to book an appointment without it?

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#40

I am confused, the article seems to be short on details. Was the attack an open S3 bucket? The company in question seems to be hiring for GCP, so I imagine they don’t use S3 at all. Did the submitter intentionally change the post title to get more clicks? https://eshyft.com/careers/gcp-devops-engineer/

Multi-cloud isn't uncommon, especially interacting with vendors. It has been a long time since I've worked somewhere that didn't have at least some usage in more than one cloud provider.
Post reply on HN