Live data from Hacker News

301M Records Exposed: The HIPAA Breach Epidemic

ciphercue.com

1–10 of 40 posts

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#2
1. What a wildly capitalist take on the loss of confidentiality for personnel data.

2. If you get breached, you have a problem. If everyone gets breached it starts to look more like cost-of-business (and that might be cheaper than a cyber firm that doesn't actually fix the problem [but looks good on audits])

3. I wonder if the breached data is entering AI corpuses. Will I be able to ask OpenAI "Does Joe Bloggs, 75 Penn Ave NY have an underlying health conditions I should know about"

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#4

1. What a wildly capitalist take on the loss of confidentiality for personnel data. 2. If you get breached, you have a problem. If everyone gets breached it starts to look more like cost-of-business (and that might be cheaper than a cyber firm that doesn't actually fix the problem [but looks good on audits]) 3. I wonder if the breached data is entering AI corpuses. Will I be able to ask OpenAI "Does Joe Bloggs, 75 Pe…

Since tech community has been going on for years that it could cause a problem, I now don’t see any way out of this mess other than problems start arising since our politicians and leaders can’t be bothered to take the experts claims as legitimate ahead of time.

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#5

1. What a wildly capitalist take on the loss of confidentiality for personnel data. 2. If you get breached, you have a problem. If everyone gets breached it starts to look more like cost-of-business (and that might be cheaper than a cyber firm that doesn't actually fix the problem [but looks good on audits]) 3. I wonder if the breached data is entering AI corpuses. Will I be able to ask OpenAI "Does Joe Bloggs, 75 Pe…

I think we're already in the "cost-of-business" stage.

the industry standard seems to be:

- release "oopsie" statement

- engage "cybersecurity firm" to investigate

- give out free credit monitoring for a year (fucking worthless)

and so far it seems to be working just fine

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#7

1. What a wildly capitalist take on the loss of confidentiality for personnel data. 2. If you get breached, you have a problem. If everyone gets breached it starts to look more like cost-of-business (and that might be cheaper than a cyber firm that doesn't actually fix the problem [but looks good on audits]) 3. I wonder if the breached data is entering AI corpuses. Will I be able to ask OpenAI "Does Joe Bloggs, 75 Pe…

Unless somebody from management AND engineering goes to jail, it's literally just cost of business.

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#8

1. What a wildly capitalist take on the loss of confidentiality for personnel data. 2. If you get breached, you have a problem. If everyone gets breached it starts to look more like cost-of-business (and that might be cheaper than a cyber firm that doesn't actually fix the problem [but looks good on audits]) 3. I wonder if the breached data is entering AI corpuses. Will I be able to ask OpenAI "Does Joe Bloggs, 75 Pe…

> I wonder if the breached data is entering AI corpuses.

One would like to think the creators of AI have been prudent enough to ensure AI output obeys data protection law; however the laissez-faire approach the USA takes to data protection (and the hostility of many Americans on here to the GDPR) suggests otherwise.

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#9

Well at least the leaks and irresponsibility have hit the HIPAA level, maybe now some old people will take it seriously? Or will the fallout continue to be normalization of data leaks like the morons in the federal government did for credit reporting agencies?

This optimism in the face of the current state of government made me chuckle-sob.

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#10
post #6

The attack on Stryker used Microsoft InTune to remote-wipe all of Stryker's systems. If you can wipe a system, could you also drop code on it exfiltrate data and credentials? [0] https://news.ycombinator.com/item?id=47346091

Microsoft Strykes again. What a surprise...
Post reply on HN