Earlier quoted context omitted.
>Facebook is guilty because they turned around and used the medical data themselves to advertise without checking if it was legal to do so. What exactly did this entail? I haven't read all the court documents, but at least in the initial/amended complaint the plaintiffs didn't make this argument, probably because it's totally irrelevant to the charge of whether they "intentionally eavesdropped" or not. Either they we…
> What do you think this should look like? Institutions that handle sensitive data that is subject to access regulations generally have a compliance process that must be followed prior to accessing and using that data, and a compliance department staffed with experts who review and approve/deny access requests. But Facebook would rather move fast, break things, pay some fines, and reap the benefits of their illegal b…
Facebook isn't running an electronic medical records business. It has no expectation that it's going to be receiving sensitive data, and specifically discourages it. What more are you expecting? That any company dealing with bits should have a moderation team poring over all records to make sure they don't contain "sensitive data"?
>But Facebook would rather move fast, break things, pay some fines, and reap the benefits of their illegal behavior.
Running an analytics service that allows apps to send arbitrary events is "move fast, break things" now?