Live data from Hacker News

Notice of Data Breach

content.myfitnesspal.com

151–160 of 160 posts

Re: Notice of Data Breach

#151
This breach notification is very mealy mouthed.

>The affected information included usernames, email addresses, and hashed passwords

It included usernames, emails, and hashed passwords? So what else was breached? This seems like they are implying nothing serious was stolen without giving specific info.

Re: Notice of Data Breach

#152
post #70

Earlier quoted context omitted.

Hi, even if a data breach hadn't happened, did you have any concerns about people within the company having access to those photos? I also use myfitnesspal and strava but I have a strong aversion to sharing that kind of info with anyone, period. I'm 36, is this a generational thing?

I'm 9 years your junior and I wouldn't care if pictures of me fully naked were all over the internet, but at the same time I'm a privacy freak. I think the division for me is: my image says nothing about me other than my love of gluttony, but my words and actions are my identity.

Even if you don’t personally identify with it, your love of gluttony can be used by others to identity you. So in that sense it’s a part of your identity.

Re: Notice of Data Breach

#153
post #149
post #147

Earlier quoted context omitted.

Most EMR vendors specifically design their products to not be medical devices. They simply store, display, and transmit patient charts. If the FDA was to regulate EMRs as medical devices then logically they would also have to apply the same rules to filing cabinets and fax machines.

If they are used to store protected health information it’s the practice’s duty to make sure they comply with HIPAA regulations. So for example can’t leave that file cabinet unlocked out in the front lobby. When I was looking to make an app for a clinic they had to do a security review of the app. If the data wasn’t encrypted at rest it was a no-go. There are entire data companies sprouting out to address this issue.…

You missed the point. HIPAA security regulations are entirely separate from FDA medical device regulations.

Re: Notice of Data Breach

#154

This breach notification is very mealy mouthed. >The affected information included usernames, email addresses, and hashed passwords It included usernames, emails, and hashed passwords? So what else was breached? This seems like they are implying nothing serious was stolen without giving specific info.

I'm 99% certain it included everything.

From what I have seen very very few companies have strictly separated databases for different types of data and so on.

For the vast majority of companies a compromise is an all or nothing event.

Re: Notice of Data Breach

#155
post #153
post #149

Earlier quoted context omitted.

If they are used to store protected health information it’s the practice’s duty to make sure they comply with HIPAA regulations. So for example can’t leave that file cabinet unlocked out in the front lobby. When I was looking to make an app for a clinic they had to do a security review of the app. If the data wasn’t encrypted at rest it was a no-go. There are entire data companies sprouting out to address this issue.…

You missed the point. HIPAA security regulations are entirely separate from FDA medical device regulations.

Aah, gotcha. Well if the FDA medical device regulations don’t cover it, is there not still the possibility of some other regulation still effectively covering it?

For example something like, the way my device functions may not be regulated but the use of my device by a medical provider is regulated.

Re: Notice of Data Breach

#156
post #133
post #118

Earlier quoted context omitted.

Back in Roman times you'd go to the communal bathroom with your friends, sitting side by side and having a chat while doing your business. They didn't even bother with cubicles back then.

>>Back in Roman times Yes well should we talk about other things that happened back in Roman Times.... >>>sitting side by side and having a chat while doing your business. They didn't even bother with cubicles back then. Please please lets not bring that back.... restrooms are not a meeting space, I dislike it when people attempt to talk to me at the sink when washing my hands, no restrooms are not a meeting space...…

I definitely understand your discomfort! That's not something you should have to do if you don't like it.

I'm curious though, what happens if instead of reading the sentence like "back in Roman times, you read it like this:"

In rural India, it's typical for people to sit side-by-side and have a chat while doing your business. Sometimes they don't bother with cubicles there.

Or, maybe:

Wildfire firefighters, while on a line, typically squat side-by-side while doing their business. No cubicles in the wilderness.

If you don't think of it like a generational difference, and instead a cultural one, what are your thoughts? I only ask because I used to feel the same way until I witnessed #2. Sometimes it's just a mindset change, or cultural difference.

Re: Notice of Data Breach

#157
post #88

Earlier quoted context omitted.

Same here - my new roommate is constantly closing the blinds at night because he doesn't want the old lady in the building across from us see us sit around and play video games, I guess. I remember refusing to shower after the gym because I didn't want people to see my wiener. I think it changed when my friend's bathroom's door lock was broken. His brother was about to go in and was the kind of guy that liked to anno…

So you became less embarrassed at his easy dismissal of something that you were afraid of?

Exactly. Even moreso, he made me realize there was nothing to fear. This "what's the worse that could happen, and how must I react" mindset has carried across to so many things for me.

What's the worse that could happen if someone walks in on my taking a dump? Well... I guess they'll have seen me taking a dump! And I'll tell them to leave!

What's the worse that could happen in this cold call? Well, I guess he could call me an asshole and hangup, and I'll make another call!

What's the worse that could happen if I ask for a raise? I get told no, and continue on with my day!

Etc.

Re: Notice of Data Breach

#158
post #155
post #153

Earlier quoted context omitted.

You missed the point. HIPAA security regulations are entirely separate from FDA medical device regulations.

Aah, gotcha. Well if the FDA medical device regulations don’t cover it, is there not still the possibility of some other regulation still effectively covering it? For example something like, the way my device functions may not be regulated but the use of my device by a medical provider is regulated.

Most EMRs don't meet the legal definition of a medical device and nothing a provider does can change that.

There are a variety of other regulations in this space. You'll have to be more specific about functionality to determine which rules apply.

Post reply on HN