Live data from Hacker News

'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

websiteplanet.com

101–110 of 193 posts

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#102

I'll need to dig up a source but I recently heard about this company and, apparently, before offering gigs they do a credit report to determine how much debt the person is carrying (i.e. how desperate they are) and they use that information to _round down_ the hourly rate they offer them. In the unlikely event that there are any negative consequences for this breach, they deserve every bit of them and more.

This is abhorrent if true; truly evil behavior.

Game theory transcends basic humanity.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#103
post #47
post #31

Earlier quoted context omitted.

Perhaps true, but the strongest privacy protections in the US are still pretty weak. The biggest penalty I know of is Anthem 2018, where they leaked HIPAA-qualifying records on 80 million customers. Their financial penalty was a whopping... $16 million. Two dimes per affected customer!

It's true that the US rarely penalizes corporations enough to really disincentivize things, but healthcare providers probably take client data security more seriously than just about any other group besides maybe law firms. It's weird to single them out as being particularly unconcerned with and unpenalized for leaks.

[deleted]

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#104

Earlier quoted context omitted.

It's definitely shady, but it's par for the course. Uber charges you more if you have more gift cards loaded, or just spend more on average in general. You charge what the market will bear.

You charge what the market will bear, not the individual .

The market is an agglomeration of many individuals, meaning that there is no hard and fast rule that you must charge only one price for the entire market; indeed, many custom-priced products exist, enterprise SaaS being one example.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#105
post #12
post #9

Worth mentioning, because the authority level of medical practitioners throws people off. Don't ever give a doctor or practice your Social Security Number. They don't need it. Similarly if they want to check an ID that doesn't mean scan or photograph. Doctors, practices, etc are the worst at infosec. They have no training, basically no penalties if they do something wrong and all of that info is only to follow up in…

In the US, HIPAA is pretty much the strongest privacy legislation there is. There's probably no group that would have a more severe penalty for leaking your info than your healthcare provider.

HIPAA was designed for portability -- the 'p' standards for portability not privacy -- of health info, so there are immense carve outs in service of that objective. Fines for violating HIPAA are almost non-existent.

HIPAA is wildly misunderstood by the public as a strong safeguard, meanwhile medical offices just get any patient (a captive audience) to sign a release waiver as part of patient intake ...

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#106
post #9

Worth mentioning, because the authority level of medical practitioners throws people off. Don't ever give a doctor or practice your Social Security Number. They don't need it. Similarly if they want to check an ID that doesn't mean scan or photograph. Doctors, practices, etc are the worst at infosec. They have no training, basically no penalties if they do something wrong and all of that info is only to follow up in…

What do you do if they refuse to book an appointment without it?

You can just use my SSN: 123-45-6789.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#107

Are y'all gonna blame AWS like you blamed Firebase last week ? The security procedures I take while hacking out something for my friends at 3am should not extend to products hosting PII. It's up to YOU to implement basic data security.

It's up to YOU to implement basic data security.

You definitely need to do this, but a platform should help where possible, and try to have users fall into a 'pit of success' where if a dev just goes with the defaults everything is fine. In this case, S3 buckets should be private and encrypted by default and devs should need to actively choose to switch those things off (which I think may be the case now, but it wasn't in the past.)

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#108
post #82

I'll need to dig up a source but I recently heard about this company and, apparently, before offering gigs they do a credit report to determine how much debt the person is carrying (i.e. how desperate they are) and they use that information to _round down_ the hourly rate they offer them. In the unlikely event that there are any negative consequences for this breach, they deserve every bit of them and more.

I’m interested, given the massive nursing shortages, why any nurses were using this service at all? Especially for higher levels, there’s no reason to mess with a shitty app that underpays you, when you should be able to walk into any provider’s office or facility and get hired almost immediately (and for Runs, you even have wide-ranging telehealth options).

This was my thought exactly. There is a giant nursing shortage. I know some nurses who are traveling nurses and they may bank, and they don't need any BS app. (Just want to emphasize, nursing is an incredibly difficult job at the moment, but there are also currently weird dynamics where traveling nurses can actually make a lot more than "stationary" nurses).

Thus, I'm led to believe that nurses using this app have to have some sort of difficulty finding jobs for other reasons, or they're just not informed about their options.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#109

I'll need to dig up a source but I recently heard about this company and, apparently, before offering gigs they do a credit report to determine how much debt the person is carrying (i.e. how desperate they are) and they use that information to _round down_ the hourly rate they offer them. In the unlikely event that there are any negative consequences for this breach, they deserve every bit of them and more.

this is the presentation that discusses this wage suppression for nurses.

https://pluralistic.net/2025/02/26/ursula-franklin/

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#110
post #75

In the section of their Privacy Policy titled Data Security [0]: > We use certain physical, managerial, and technical safeguards that are designed to improve the integrity and security of information that we collect and maintain. Please be aware that no security measures are perfect or impenetrable. We cannot and do not guarantee that information about you will not be accessed, viewed, disclosed, altered, or destroye…

HIPAA applies to patient data not providers data. > I also saw what appeared to be medical documents uploaded to the app. These files were potentially uploaded as proof for why individual nurses missed shifts or took sick leave. These medical documents included medical reports containing information of diagnosis, prescriptions, or treatments that could potentially fall under the ambit of HIPAA regulations. It looks l…

> Also just as a side note, HIPAA is not a ideal standard to begin with for security. Many large companies exchange bulk PHI via gmail since it is HIPAA compliant.

You seem to imply using GMail is a bad thing? I think GMail, when appropriately configured to handle PHI, is probably a million times more secure than some crappy bespoke "enterprise" app.

Post reply on HN