Live data from Hacker News

'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

websiteplanet.com

111–120 of 193 posts

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#111

In the section of their Privacy Policy titled Data Security [0]: > We use certain physical, managerial, and technical safeguards that are designed to improve the integrity and security of information that we collect and maintain. Please be aware that no security measures are perfect or impenetrable. We cannot and do not guarantee that information about you will not be accessed, viewed, disclosed, altered, or destroye…

HIPAA only applies to a very specific entity called a "covered entity". At a high level, "covered entities" are health care providers that accept insurance or insurers. That's right, there's a massive caveat on "accepts insurance". You can be a healthcare provider and do not have to comply with HIPAA if you don't accept insurance. That being said, HIPAA isn't even relevant here because "ESHYFT" is just a provider a l…

> At a high level, "covered entities" are health care providers that accept insurance or insurers. That's right, there's a massive caveat on "accepts insurance". You can be a healthcare provider and do not have to comply with HIPAA if you don't accept insurance.

Again, HIPAA continues to be the most colloquially misunderstood law out there.

The rule that makes providers "covered entities" isn't really about insurance, it's about whether they transmit specific HIPAA "transactions" electronically. Now, yes, most of these transactions having to do with providers are thing like claim submissions or pre-authorizations to insurance. But there are other reasons a provider may need/want to send a HIPAA transaction electronically.

My point is that there isn't some sort of "loophole" where providers that don't accept insurance are somehow being sneaky. The whole point of the HIPAA security rule is to protect PHI when it is transferred around to different entities in the healthcare system. If the information is going just between you and your doctor, HIPAA isn't relevant, and that is by design.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#112
post #75

Earlier quoted context omitted.

HIPAA applies to patient data not providers data. > I also saw what appeared to be medical documents uploaded to the app. These files were potentially uploaded as proof for why individual nurses missed shifts or took sick leave. These medical documents included medical reports containing information of diagnosis, prescriptions, or treatments that could potentially fall under the ambit of HIPAA regulations. It looks l…

> Also just as a side note, HIPAA is not a ideal standard to begin with for security. Many large companies exchange bulk PHI via gmail since it is HIPAA compliant. You seem to imply using GMail is a bad thing? I think GMail, when appropriately configured to handle PHI, is probably a million times more secure than some crappy bespoke "enterprise" app.

It isn't that hard to setup a secure SFTP server to automate the exchange. But then again this is a post about configuring a S3 Bucket with public access for SSNs.

The issue with Gmail is sending to the wrong email, sending to a broad email list, having people download it to their local machines. And the amount of PHI being transmitted in these files is larger than this s3 bucket.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#113

Earlier quoted context omitted.

HIPAA only applies to a very specific entity called a "covered entity". At a high level, "covered entities" are health care providers that accept insurance or insurers. That's right, there's a massive caveat on "accepts insurance". You can be a healthcare provider and do not have to comply with HIPAA if you don't accept insurance. That being said, HIPAA isn't even relevant here because "ESHYFT" is just a provider a l…

> At a high level, "covered entities" are health care providers that accept insurance or insurers. That's right, there's a massive caveat on "accepts insurance". You can be a healthcare provider and do not have to comply with HIPAA if you don't accept insurance. Again, HIPAA continues to be the most colloquially misunderstood law out there. The rule that makes providers "covered entities" isn't really about insurance…

> it's about whether they transmit specific HIPAA "transactions" electronically.

That's correct, but if you don't accept insurance then you will not transmit anything that meets the criteria to be covered by HIPAA. At least, in terms of being a provider. Things are different if you're a health plan or clearing house.

I spent a lot of time and money questioning this with lawyers at a health tech startup I previously worked at. The underlying reality is nearly the entire US healthcare system falls under HIPAA because nearly everyone wants to accept insurance. However, if you're a doctor running a cash-only business you will not be a covered entity, even if you send PHI electronically.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#114

Earlier quoted context omitted.

You might be surprised to learn that they're not the only company to do so.

Names. We need names.

We don't need names, we need legislature, and we need to vote for people who will write it, as opposed to grifters who only seek to pad the pockets of billionaires.

These predators aren't scared of name and shame. Any publicity is good publicity (And if it actually gets bad, they'll sue the pants off you.). They are scared shitless of laws censuring their behavior. It's why they fight like mad to ensure that they aren't subject to them.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#115

Earlier quoted context omitted.

It's definitely shady, but it's par for the course. Uber charges you more if you have more gift cards loaded, or just spend more on average in general. You charge what the market will bear.

You charge what the market will bear, not the individual .

There's no such thing as "the market", there are market segments that abstractly represent groups of people with similar characteristics. Charging different prices to people in different segments is standard business practice. Burger chains could charge wealthy individuals $100k per burger if they wanted to, just, burger chains usually have difficulty distinguishing the truly wealthy individuals who walk in the door who would have no trouble putting down that kind of money for a burger.

.... which, in the day and age of facial recognition, gives me an idea for a startup.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#116

Earlier quoted context omitted.

It's definitely shady, but it's par for the course. Uber charges you more if you have more gift cards loaded, or just spend more on average in general. You charge what the market will bear.

You charge what the market will bear, not the individual .

No, it just hasn’t been possible to differentiate as well before.

One example is biscuit manufacturing, where it’s a fairly open secret that supermarket own brand biscuits are the same product as name brand, because it’s better to capture that segment at a lower margin than to lose it to competition.

Tech now makes it possible to target individuals rather than demographics, but there’s nothing inherently against the status quo in doing so.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#117

I'll need to dig up a source but I recently heard about this company and, apparently, before offering gigs they do a credit report to determine how much debt the person is carrying (i.e. how desperate they are) and they use that information to _round down_ the hourly rate they offer them. In the unlikely event that there are any negative consequences for this breach, they deserve every bit of them and more.

This is abhorrent if true; truly evil behavior.

What's interesting is that broadly speaking, people acknowledge that negotiating with asymmetric information is immortal or wrong. Take the stock market for example, insider trading is illegal and you don't often hear calls to reverse these laws.

But when it comes to private markets and semi-private negotiations that same sentiment doesn't easily transfer. Does society benefit in some unique way for allowing asymmetries in labor negotiations, private markets like Uber, or B2C relations like Robinhood (1,2)?

1. https://www.sec.gov/newsroom/press-releases/2020-321 2. Note, Robinhood was fined not for front-runniny customers, just for falsely claiming customers received quality orders. I suspect theyve only stopped the latter behavior.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#118
post #44
post #30

Earlier quoted context omitted.

According to the article the name is ESHYFT. It sounds like a brand of electronic found on aliexpress but with less quality!

Please invest in my startup, ENSHITIFY

Which one?!

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#119

I'll need to dig up a source but I recently heard about this company and, apparently, before offering gigs they do a credit report to determine how much debt the person is carrying (i.e. how desperate they are) and they use that information to _round down_ the hourly rate they offer them. In the unlikely event that there are any negative consequences for this breach, they deserve every bit of them and more.

this is the presentation that discusses this wage suppression for nurses. https://pluralistic.net/2025/02/26/ursula-franklin/

[deleted]

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#120

Are y'all gonna blame AWS like you blamed Firebase last week ? The security procedures I take while hacking out something for my friends at 3am should not extend to products hosting PII. It's up to YOU to implement basic data security.

It's up to YOU to implement basic data security. You definitely need to do this, but a platform should help where possible, and try to have users fall into a 'pit of success' where if a dev just goes with the defaults everything is fine. In this case, S3 buckets should be private and encrypted by default and devs should need to actively choose to switch those things off (which I think may be the case now, but it wasn…

This is like having a small store and instead of locking up at the end of the day, blaming the door for not automatically locking. Yes new automatic locks exist now, but you still need to check.

Cloud technology allows us to build fantastic software very fast. But if you’re too lazy to implement a basic api to get S3 data on a needs to know basis, that’s on you.

AWS makes this very easy. You can’t blame anyone else.

Post reply on HN