Live data from Hacker News

'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

websiteplanet.com

141–150 of 193 posts

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#141

Earlier quoted context omitted.

This is abhorrent if true; truly evil behavior.

What's interesting is that broadly speaking, people acknowledge that negotiating with asymmetric information is immortal or wrong. Take the stock market for example, insider trading is illegal and you don't often hear calls to reverse these laws. But when it comes to private markets and semi-private negotiations that same sentiment doesn't easily transfer. Does society benefit in some unique way for allowing asymmetr…

> What's interesting is that broadly speaking, people acknowledge that negotiating with asymmetric information is immortal or wrong.

They do? I’m quite happy when I have more information than the party I am negotiating with.

Do you tell your customers all of the input costs of the product or service you sell? I doubt it.

Also, certain parties that trade in public markets have way more information than any retail investor could ever hope to have, hedge funds buy satellite imagery of parking lots, track oil tankers at sea, etc to gain an edge.

Insider trading rules are meant to prevent the public bagholding stocks from the management team having insider information that no other market participant could or should have, there are no rules against legally gathering or purchasing information on your own to gain an edge over other market participants.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#142
post #126

Earlier quoted context omitted.

There's no such thing as "the market", there are market segments that abstractly represent groups of people with similar characteristics. Charging different prices to people in different segments is standard business practice. Burger chains could charge wealthy individuals $100k per burger if they wanted to, just, burger chains usually have difficulty distinguishing the truly wealthy individuals who walk in the door…

Burger chains have at least gotten a start on differentiating their pricing - by raising prices dramatically across the board, and telling anyone who’s frugal or just broke that they can only get discounts (to bring prices slightly lower than today’s pricing, but still a lot more than before) if they use the app. Upper-class people don’t bother with it and pay full price, frugal people take the time to figure out the…

Upper class people don't bother with it because we all know those discounts are temporary but they'll never let go of the data they extract from those apps and will try to spam you

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#143

Earlier quoted context omitted.

This is abhorrent if true; truly evil behavior.

What's interesting is that broadly speaking, people acknowledge that negotiating with asymmetric information is immortal or wrong. Take the stock market for example, insider trading is illegal and you don't often hear calls to reverse these laws. But when it comes to private markets and semi-private negotiations that same sentiment doesn't easily transfer. Does society benefit in some unique way for allowing asymmetr…

> What's interesting is that broadly speaking, people acknowledge that negotiating with asymmetric information is immortal or wrong. Take the stock market for example, insider trading is illegal and you don't often hear calls to reverse these laws.

Insider trading is not about fairness. It’s about theft. If you overhear someone in a public place talking about an upcoming merger, you can trade on it.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#144
Incredible. Healthcare is a busted industry through and through. Even the tech companies that serve it are incompetent. There are so many things wrong here:

- the uber-fication of nursing, bc of cheap and corporate owned hospitals won't just hire them as w2 employees

- cheapness probably led hospitals to this crappy app, which probably gave kick backs to the admins that approved it

- this should totally bankrupt the ESHYFT, but more likely nothing will happen

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#145
post #126

Earlier quoted context omitted.

Burger chains have at least gotten a start on differentiating their pricing - by raising prices dramatically across the board, and telling anyone who’s frugal or just broke that they can only get discounts (to bring prices slightly lower than today’s pricing, but still a lot more than before) if they use the app. Upper-class people don’t bother with it and pay full price, frugal people take the time to figure out the…

Upper class people don't bother with it because we all know those discounts are temporary but they'll never let go of the data they extract from those apps and will try to spam you

One can always use a fake email and login account. Upper class people don't bother because they don't eat at fast food chains as often enough as lower class people to warrant needing an app for each one; 99.9% don't give a shit about data collection, only people on HN and other technical fora do.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#147

Incredible. Healthcare is a busted industry through and through. Even the tech companies that serve it are incompetent. There are so many things wrong here: - the uber-fication of nursing, bc of cheap and corporate owned hospitals won't just hire them as w2 employees - cheapness probably led hospitals to this crappy app, which probably gave kick backs to the admins that approved it - this should totally bankrupt the…

Bankrupt only? It should also be criminal negligence. Until some exec goes to jail, this kind of stuff will keep happening. Someone was (likely is...) making good profit out of this business by not investing in IT security. They cheaped out, and other people paid the price, who didn't have anything to do with the profit of the company. Watch out for the execs going around in a few years giving talks about how to build a successful company. If we let this kind of behaviour have zero repercussions, the public will continue to pay the price of private profits.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#148
post #79

I'll need to dig up a source but I recently heard about this company and, apparently, before offering gigs they do a credit report to determine how much debt the person is carrying (i.e. how desperate they are) and they use that information to _round down_ the hourly rate they offer them. In the unlikely event that there are any negative consequences for this breach, they deserve every bit of them and more.

That seems like a terrible way to estimate nurse wages. People have spouses. People’s parents pay credit cards. People with bad credit sometimes don’t care. People have family money. People with low debt can be desperate for work. Does it even work?

Agreed. And it's not just those -- if you need to pay off debt, you're extra-incentivized to take the highest-paying job, as opposed to one that pays less but is e.g. closer to home, or has a more predictable schedule, or whatever.

The idea that you'd offer less seems... counterproductive to say the least.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#149
How does the medical and healthcare industry that is notorious for gatekeeping have these problems? Leaving a database open and unprotected is just hard to understand given the levels of red tape you have to complete to develop in this space. Theranos was jailed and defamed whereas this will likely cause more damage as a whole (instead of some billionaires becoming slightly less rich).

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#150
post #9

Worth mentioning, because the authority level of medical practitioners throws people off. Don't ever give a doctor or practice your Social Security Number. They don't need it. Similarly if they want to check an ID that doesn't mean scan or photograph. Doctors, practices, etc are the worst at infosec. They have no training, basically no penalties if they do something wrong and all of that info is only to follow up in…

[deleted]
Post reply on HN