I'll need to dig up a source but I recently heard about this company and, apparently, before offering gigs they do a credit report to determine how much debt the person is carrying (i.e. how desperate they are) and they use that information to _round down_ the hourly rate they offer them. In the unlikely event that there are any negative consequences for this breach, they deserve every bit of them and more.
This is abhorrent if true; truly evil behavior.
'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
41–50 of 193 posts
Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#42In the section of their Privacy Policy titled Data Security [0]: > We use certain physical, managerial, and technical safeguards that are designed to improve the integrity and security of information that we collect and maintain. Please be aware that no security measures are perfect or impenetrable. We cannot and do not guarantee that information about you will not be accessed, viewed, disclosed, altered, or destroye…
[Nevermind]
Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#43Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#44Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#45Worth mentioning, because the authority level of medical practitioners throws people off. Don't ever give a doctor or practice your Social Security Number. They don't need it. Similarly if they want to check an ID that doesn't mean scan or photograph. Doctors, practices, etc are the worst at infosec. They have no training, basically no penalties if they do something wrong and all of that info is only to follow up in…
In the US, HIPAA is pretty much the strongest privacy legislation there is. There's probably no group that would have a more severe penalty for leaking your info than your healthcare provider.
Last year the total HIPAA violations fines were less than $9.2 million.
A figure I could find for hospital revenue in the same year which is a good enough proxy for fines vs revenue is about $1.2 trillion.
Which rounding because who cares comes to 0.001% of medical revenue ends up being paid for HIPAA violation fines.
Or the equivalent ratio of about a cup of coffee for a typical enough person per year.
HIPAA needs teeth, what it says you're supposed to do is quite strong, the enforcement of it is pathetic.
Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#46Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#47Earlier quoted context omitted.
In the US, HIPAA is pretty much the strongest privacy legislation there is. There's probably no group that would have a more severe penalty for leaking your info than your healthcare provider.
Perhaps true, but the strongest privacy protections in the US are still pretty weak. The biggest penalty I know of is Anthem 2018, where they leaked HIPAA-qualifying records on 80 million customers. Their financial penalty was a whopping... $16 million. Two dimes per affected customer!
Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#48Earlier quoted context omitted.
[Nevermind]
The PII of the nurses being accidentally shared by a staffing agency isn't a HIPAA violation. Yes the nurses are providers but their relationship with the Uber for nurses service isn't a medical provider relationship. It's definitely a legal and ethical failing but I don't think it's a HIPAA one.
If you replaced nurses with gig workers and uber for nurses with something like WeWork this would just be like every other leak we talk about on HN.
Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#49In the section of their Privacy Policy titled Data Security [0]: > We use certain physical, managerial, and technical safeguards that are designed to improve the integrity and security of information that we collect and maintain. Please be aware that no security measures are perfect or impenetrable. We cannot and do not guarantee that information about you will not be accessed, viewed, disclosed, altered, or destroye…
[Nevermind]
Maybe you think the startup maintains patient records?
The article lays out the nurses uploaded them, the provider. This is a temp booking system. The health records were uploaded by the nurses to communicate reasons for absences to their employee and weren't required or requested
They have as much responsibility as Dropbox does. Nurses shouldn't have uploaded them.
Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#50Earlier quoted context omitted.
[Nevermind]
The PII of the nurses being accidentally shared by a staffing agency isn't a HIPAA violation. Yes the nurses are providers but their relationship with the Uber for nurses service isn't a medical provider relationship. It's definitely a legal and ethical failing but I don't think it's a HIPAA one.
>I also saw what appeared to be medical documents uploaded to the app. These files were potentially uploaded as proof for why individual nurses missed shifts or took sick leave. These medical documents included medical reports containing information of diagnosis, prescriptions, or treatments that could potentially fall under the ambit of HIPAA regulations.
The title is exaggerating what the article says and the article is making a big stretch about this being possibly HIPAA covered, I stand corrected, this has nothing to do with HIPAA.
What was leaked was nurses' doctors notes submitted justifying calling out of work. Still a serious leak but nowhere near what is being suggested.