Live data from Hacker News

'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

websiteplanet.com

51–60 of 193 posts

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#52
post #9

Worth mentioning, because the authority level of medical practitioners throws people off. Don't ever give a doctor or practice your Social Security Number. They don't need it. Similarly if they want to check an ID that doesn't mean scan or photograph. Doctors, practices, etc are the worst at infosec. They have no training, basically no penalties if they do something wrong and all of that info is only to follow up in…

What do you do if they refuse to book an appointment without it?

[dead]

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#53
post #12
post #9

Worth mentioning, because the authority level of medical practitioners throws people off. Don't ever give a doctor or practice your Social Security Number. They don't need it. Similarly if they want to check an ID that doesn't mean scan or photograph. Doctors, practices, etc are the worst at infosec. They have no training, basically no penalties if they do something wrong and all of that info is only to follow up in…

In the US, HIPAA is pretty much the strongest privacy legislation there is. There's probably no group that would have a more severe penalty for leaking your info than your healthcare provider.

PCI-DSS is the strongest, HIPAA is just a rubber stamp

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#55
post #10

Earlier quoted context omitted.

Does HIPAA apply to HR into, or just patient health data?

Protected health information (PHI) under U.S. law is any information about health status, provision of health care, or payment for health care that is created or collected by a Covered Entity (or a Business Associate of a Covered Entity), and can be linked to a specific individual. This is interpreted rather broadly and includes any part of a patient's medical record or payment history. source: i run Wyndly (YC W21 h…

Sure, that's the definition of PHI but is ESHYFT a HIPAA covered entity? If not then the definition of PHI isn't legally relevant (although they still have an ethical requirement to secure employee data, and might have violated other data protection laws).

https://www.hhs.gov/hipaa/for-professionals/covered-entities...

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#57

I'll need to dig up a source but I recently heard about this company and, apparently, before offering gigs they do a credit report to determine how much debt the person is carrying (i.e. how desperate they are) and they use that information to _round down_ the hourly rate they offer them. In the unlikely event that there are any negative consequences for this breach, they deserve every bit of them and more.

This is abhorrent if true; truly evil behavior.

It's definitely shady, but it's par for the course. Uber charges you more if you have more gift cards loaded, or just spend more on average in general. You charge what the market will bear.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#58

In the section of their Privacy Policy titled Data Security [0]: > We use certain physical, managerial, and technical safeguards that are designed to improve the integrity and security of information that we collect and maintain. Please be aware that no security measures are perfect or impenetrable. We cannot and do not guarantee that information about you will not be accessed, viewed, disclosed, altered, or destroye…

If you're not a direct health provider, you probably can. Don't take that as an endorsement.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#60
post #53
post #12

Earlier quoted context omitted.

In the US, HIPAA is pretty much the strongest privacy legislation there is. There's probably no group that would have a more severe penalty for leaking your info than your healthcare provider.

PCI-DSS is the strongest, HIPAA is just a rubber stamp

That's not actually law at all. It's part of the contract with payment processors.
Post reply on HN