Live data from Hacker News

301M Records Exposed: The HIPAA Breach Epidemic

ciphercue.com

11–20 of 40 posts

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#11

1. What a wildly capitalist take on the loss of confidentiality for personnel data. 2. If you get breached, you have a problem. If everyone gets breached it starts to look more like cost-of-business (and that might be cheaper than a cyber firm that doesn't actually fix the problem [but looks good on audits]) 3. I wonder if the breached data is entering AI corpuses. Will I be able to ask OpenAI "Does Joe Bloggs, 75 Pe…

> What a wildly capitalist take on the loss of confidentiality for personnel data.

As opposed to what exactly? A "communist" take on the loss of confidentiality? How might that go?

"There's no problem comrade, what are you talking about?"

This sounds like a failure of government regulation here, not a failure of a broad economic model.

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#12
post #7

1. What a wildly capitalist take on the loss of confidentiality for personnel data. 2. If you get breached, you have a problem. If everyone gets breached it starts to look more like cost-of-business (and that might be cheaper than a cyber firm that doesn't actually fix the problem [but looks good on audits]) 3. I wonder if the breached data is entering AI corpuses. Will I be able to ask OpenAI "Does Joe Bloggs, 75 Pe…

Unless somebody from management AND engineering goes to jail, it's literally just cost of business.

I think the most feasible solution is to make companies liable for damages, not in a light way but rather that every person can sue (or in a class action) for hefty amounts, so that a breach could cost e.g. 100mil+

that should incentivize them to actually invest some money in security. right now its just tiny numbers which are easier to just pay off and forget about

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#13
Wait, the main takeaway from this article is that cybersecurity sales teams now have great leads?

Facepalm.

The real takeaway should be that at every level -- government, corporate, healthcare entities, personal -- we need to rethink how we're acting in the face of these disasters.

Government should recognize that its current regulations are insufficient and look for ways to refine them.

Corporations and health-care entities should be asking themselves, "Do I really need to store this data? If so, how do I store it securely, make my systems less vulnerable to attack, make my personnel more informed about phishing, store it for the minimum amount of time, etc."

And we as individuals should be asking ourselves whether so many health-care entities need to store so much data about us.

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#14
ai; dr

> This isn't a single point of failure - it's a systemic crisis.

> One in seven breaches isn't a sophisticated external attack - it's someone inside the organisation accessing data they shouldn't.

> These organisations aren't browsing - they're buying

https://news.ycombinator.com/newsguidelines.html#generated

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#15
post #5

1. What a wildly capitalist take on the loss of confidentiality for personnel data. 2. If you get breached, you have a problem. If everyone gets breached it starts to look more like cost-of-business (and that might be cheaper than a cyber firm that doesn't actually fix the problem [but looks good on audits]) 3. I wonder if the breached data is entering AI corpuses. Will I be able to ask OpenAI "Does Joe Bloggs, 75 Pe…

I think we're already in the "cost-of-business" stage. the industry standard seems to be: - release "oopsie" statement - engage "cybersecurity firm" to investigate - give out free credit monitoring for a year (fucking worthless) and so far it seems to be working just fine

Yup I don’t see any huge downsides here for these companies, and not much incentive to change. The more it happens the more they can point to each other and say “see, it’s not just us”

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#16

Well at least the leaks and irresponsibility have hit the HIPAA level, maybe now some old people will take it seriously? Or will the fallout continue to be normalization of data leaks like the morons in the federal government did for credit reporting agencies?

As with everything in the US, this will be politicized. I wonder which will be the party of “I’m fine with data breaches”

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#17
post #13

Wait, the main takeaway from this article is that cybersecurity sales teams now have great leads? Facepalm. The real takeaway should be that at every level -- government, corporate, healthcare entities, personal -- we need to rethink how we're acting in the face of these disasters. Government should recognize that its current regulations are insufficient and look for ways to refine them. Corporations and health-care…

> Government should recognize that its current regulations are insufficient and look for ways to refine them.

The shear hostility by many people on here to data protection law (hello GDPR) suggests you are going to have a hard time getting such laws passed in the USA.

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#18

1. What a wildly capitalist take on the loss of confidentiality for personnel data. 2. If you get breached, you have a problem. If everyone gets breached it starts to look more like cost-of-business (and that might be cheaper than a cyber firm that doesn't actually fix the problem [but looks good on audits]) 3. I wonder if the breached data is entering AI corpuses. Will I be able to ask OpenAI "Does Joe Bloggs, 75 Pe…

OTOH, breaches especially Health Data breaches are the most over-rated, hysteria inducing breaches of all time. There is ZERO use for anyone for your health data

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#19
post #12
post #7

Earlier quoted context omitted.

Unless somebody from management AND engineering goes to jail, it's literally just cost of business.

I think the most feasible solution is to make companies liable for damages, not in a light way but rather that every person can sue (or in a class action) for hefty amounts, so that a breach could cost e.g. 100mil+ that should incentivize them to actually invest some money in security. right now its just tiny numbers which are easier to just pay off and forget about

You'd have to deal with all of the binding arbitration agreements first.

That said, class action lawsuits also are part of the cost of business. Nothing is ever going to change unless the boards of directors (not CEOs) can be held liable for the behavior of the companies that they direct.

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#20
post #8

1. What a wildly capitalist take on the loss of confidentiality for personnel data. 2. If you get breached, you have a problem. If everyone gets breached it starts to look more like cost-of-business (and that might be cheaper than a cyber firm that doesn't actually fix the problem [but looks good on audits]) 3. I wonder if the breached data is entering AI corpuses. Will I be able to ask OpenAI "Does Joe Bloggs, 75 Pe…

> I wonder if the breached data is entering AI corpuses. One would like to think the creators of AI have been prudent enough to ensure AI output obeys data protection law; however the laissez-faire approach the USA takes to data protection (and the hostility of many Americans on here to the GDPR) suggests otherwise.

Wasn't Meta caught using pirate book databases for their training data? No decision maker of importance at any of these companies gives a whiff of a fart about data privacy beyond the bare minimum required by the letter of the law, and only when they think the expected cost of breaking the law would exceed the benefit.
Post reply on HN