Earlier quoted context omitted.
Perhaps true, but the strongest privacy protections in the US are still pretty weak. The biggest penalty I know of is Anthem 2018, where they leaked HIPAA-qualifying records on 80 million customers. Their financial penalty was a whopping... $16 million. Two dimes per affected customer!
It's true that the US rarely penalizes corporations enough to really disincentivize things, but healthcare providers probably take client data security more seriously than just about any other group besides maybe law firms. It's weird to single them out as being particularly unconcerned with and unpenalized for leaks.
'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
61–70 of 193 posts
Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#62I thought the cloud was safe, that is why you pay premium.
Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#63The security procedures I take while hacking out something for my friends at 3am should not extend to products hosting PII. It's up to YOU to implement basic data security.
Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#64I'll need to dig up a source but I recently heard about this company and, apparently, before offering gigs they do a credit report to determine how much debt the person is carrying (i.e. how desperate they are) and they use that information to _round down_ the hourly rate they offer them. In the unlikely event that there are any negative consequences for this breach, they deserve every bit of them and more.
So they're pretty much taking the existing terrible nursing environment in healthcare, and weaponizing it. Nurses already have too many patients and not enough CNAs, on top of 12 hour shifts, needing to do charting after those 12 hours. Healthcare squeezes nurses to the breaking point. Data point: my wife is a nurse.
Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#65Earlier quoted context omitted.
This is abhorrent if true; truly evil behavior.
It's definitely shady, but it's par for the course. Uber charges you more if you have more gift cards loaded, or just spend more on average in general. You charge what the market will bear.
Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#66Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#67Earlier quoted context omitted.
[Nevermind]
The PII of the nurses being accidentally shared by a staffing agency isn't a HIPAA violation. Yes the nurses are providers but their relationship with the Uber for nurses service isn't a medical provider relationship. It's definitely a legal and ethical failing but I don't think it's a HIPAA one.
If 'Uber for nurses' is acting on behalf of nurses, it probably doesn't apply? If it's acting on behalf of the hospitals (who are indisputably covered entities), then the situation is much less clear.
I encountered a similar situation with my startup many years ago and decided "better safe than sorry" after consulting the lawyer.
Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#68Worth mentioning, because the authority level of medical practitioners throws people off. Don't ever give a doctor or practice your Social Security Number. They don't need it. Similarly if they want to check an ID that doesn't mean scan or photograph. Doctors, practices, etc are the worst at infosec. They have no training, basically no penalties if they do something wrong and all of that info is only to follow up in…
In the US, HIPAA is pretty much the strongest privacy legislation there is. There's probably no group that would have a more severe penalty for leaking your info than your healthcare provider.
Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#69Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#70In the section of their Privacy Policy titled Data Security [0]: > We use certain physical, managerial, and technical safeguards that are designed to improve the integrity and security of information that we collect and maintain. Please be aware that no security measures are perfect or impenetrable. We cannot and do not guarantee that information about you will not be accessed, viewed, disclosed, altered, or destroye…
If you're not a direct health provider, you probably can. Don't take that as an endorsement.