Live data from Hacker News

2.7M medical calls breached in Sweden

twitter.com

1–10 of 116 posts

Re: 2.7M medical calls breached in Sweden

#3
Let's talk legal ramifications.

The cause of technical breaches falls onto a sliding scale in my mind. That scale goes from pure technical negligence to overbearing technical complexity.

This breach seems like pure negligence. In a surgery this wouldn't be "complications", it would be malpractice. Does GDPR protect those breached here? What recourse do these people have?

We really need to change the narrative around data. It should be a liability. Unlike other disruptions software drives, this will need to be driven by governments.

Re: 2.7M medical calls breached in Sweden

#5
On my machine Google translate seems to "boot-loop" that site because of the cookie settings so I'll just do this:

Files were stored on a server using HTTPS but requiring no credentials. http://188.92.248.19:443/medicall/ Part of the calls were saved as .mp3s with the customers phone number as file name. CEO when confronted wouldn't believe it and hung up when the reporter asked if he could play one of the tapes.

The articles states that the server was a NAS (nas.applion.se).

All files have been available since 2013.

When calling 1177, there's no need to identify yourself with your personal identity number. You can if you want to if your medical history is of significance to your call.

Source: Am swede and this article... https://computersweden.idg.se/2.2683/1.714787/inspelade-samt...

And I want you guys to hear it from me before you hear it on the streets... I once called 1177 wanting to order a new pair of knees because one of mine hurt. The nurse who answered had a good laugh.

Re: 2.7M medical calls breached in Sweden

#6
I'm not clear on why medical records are so sensitive. I can understand some people might want to hide HIV status - but is there anything else? In the US people have wanted to hide prior conditions from insurance companies, but I wouldn't expect this a problem in Sweden.

Re: 2.7M medical calls breached in Sweden

#7

The government can't fine itself I guess, so it would have to be the EU that fines sweden? Or some kind of class action from swedes?

Government is not the justice system. It is one of the basis of Democracy: separation of power. You can absolutely take your government to court (at least in democratic country).

Class action doesn't exist in all country though. Each person that want to sue the government might have to do it in his own name.

Re: 2.7M medical calls breached in Sweden

#8
post #6

I'm not clear on why medical records are so sensitive. I can understand some people might want to hide HIV status - but is there anything else? In the US people have wanted to hide prior conditions from insurance companies, but I wouldn't expect this a problem in Sweden.

There are many more embarrassing medical conditions other than HIV status.

Re: 2.7M medical calls breached in Sweden

#10
post #6

I'm not clear on why medical records are so sensitive. I can understand some people might want to hide HIV status - but is there anything else? In the US people have wanted to hide prior conditions from insurance companies, but I wouldn't expect this a problem in Sweden.

There is many example why medical record is a very sensitive data.

You can be blackmailed because you have or had a "shameful" disease, a potential employer can deny you a job because you were too often sick for his own taste, insurance might deny you because you have a too risky profile, ...

Post reply on HN