Live data from Hacker News

'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

websiteplanet.com

151–160 of 193 posts

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#151

I'll need to dig up a source but I recently heard about this company and, apparently, before offering gigs they do a credit report to determine how much debt the person is carrying (i.e. how desperate they are) and they use that information to _round down_ the hourly rate they offer them. In the unlikely event that there are any negative consequences for this breach, they deserve every bit of them and more.

I don't remember the source, but I believe I listened to a podcast on an "uber for nurses" (not sure if it was this place), but they do all sorts of nasty things that really shaft the nurses. ISTR that the nurses when they get called in, have to be running a phone app that tracks them, and if they get stuck in traffic or lose cell signal, they get demerits. They pretty much do anything they can to give the nurses a d…

Several of my family members were or have been nurses for decades and your wife’s experience mirrors the experiences I’ve seen from that distance.

And I’ve heard “it used to be so much worse”.

The American healthcare system is fairly well broken from virtually every angle.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#152
Huh, I worked for an agency and built a site that was essentially "Uber for Nurses" back in 2010. I was immediately like "it's not them is it?" No, seems they shut down in 2017.

As far as I know, never really took off, at least while I was maintaining it, but the gig economy wasn't in full swing yet.

All that said, the sheer number of forms and amount of paperwork the site required you to fill out just to sign up had to have been a limiting factor in getting you in the door. Real high friction getting people in the door.

I wonder if Eshyft was able to somehow simplify the process.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#153
post #101

Are we pretending that there are still functional regulatory agencies that are able to take action over this?

The person working the hardest to find these is then immediately shutting them down. Makes government more efficient.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#154

Earlier quoted context omitted.

You charge what the market will bear, not the individual .

No, it just hasn’t been possible to differentiate as well before. One example is biscuit manufacturing, where it’s a fairly open secret that supermarket own brand biscuits are the same product as name brand, because it’s better to capture that segment at a lower margin than to lose it to competition. Tech now makes it possible to target individuals rather than demographics, but there’s nothing inherently against the…

Nothing against the status quo. Yes, let’s perpetuate our dystopian nightmare. Good plan.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#155
“Uber for X” has become equivalent to “let’s extract as much value as possible out of X for the benefit of some Big Corp while making the experience as horrible as possible for the people this is supposedly benefits” (drivers, nurses).

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#156
post #84

Earlier quoted context omitted.

Find a new provider. I have gone 2 decades without providing my SSN to doctors.

New provider is unrealistic for many in USA. In NYC, maybe easy; in rural WI/KS much less so.

Not in my case, I do not provide my Social Security Number to (new to me) healthcare providers from small practices to major hospitals with different branches, either.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#157
post #9

Worth mentioning, because the authority level of medical practitioners throws people off. Don't ever give a doctor or practice your Social Security Number. They don't need it. Similarly if they want to check an ID that doesn't mean scan or photograph. Doctors, practices, etc are the worst at infosec. They have no training, basically no penalties if they do something wrong and all of that info is only to follow up in…

What do you do if they refuse to book an appointment without it?

In my experience, no one has ever asked it when booking, just when you fill out forms on your first visit. I always leave it blank (and most other things that don't pertain to my healthcare issue) blank and have never been hassled.

I also always ask for a paper copy of the disclosures to sign, saying that "I don't sign blank checks" when asked to sign the electric pad. I've never had an issue with them printing it out, letting me sign, and them scanning it in.

Healthcare "security"/"authentication" is just "protected" by your name and date of birth which is easily discovered for anyone online.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#158

Incredible. Healthcare is a busted industry through and through. Even the tech companies that serve it are incompetent. There are so many things wrong here: - the uber-fication of nursing, bc of cheap and corporate owned hospitals won't just hire them as w2 employees - cheapness probably led hospitals to this crappy app, which probably gave kick backs to the admins that approved it - this should totally bankrupt the…

I'm really curious about the kickbacks comment. I'm sympathetic to it but how do you root it out practically? Noone has much incentive to fix it because the people aware of the ill doing are the ones benefiting from it.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#159

Earlier quoted context omitted.

HIPAA has strict rules with severe penalties, but enforcement is at best spotty. So honest hospitals and doctors offices bend over backwards to comply with the rules at great expense, but bad actors are rarely punished. It's the worst of both worlds. I'm pretty sure that is why the punishments are so harsh, because they need to put the fear of god into practitioners to make them take it seriously since there are so f…

It's the difference in medical establishment skill level between your doctor and you. You are always at a disadvantage. I've long thought that a disinterested third party needs to be involved. Someone with real oversight taking a position adversarial to the hospital and strictly to create the best possible outcome for the patient. The Hippocratic model isn't awesome.

This is true, however getting it funded is the difficult task.

For it to be effective, the money can't come from the provider, meaning it's either from the payer or the patient. The payer doesn't really care, costs are contained as far as they are concerned, with the various Quality Initiatives. That leaves the patient to sign up for a subscription model.

I explored that as a business 12 years ago, and sadly there is still a need. The worst part is that most clinicians actually want to do the right thing but it's the admins in their organization who set up processes that result in terrible outcomes.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#160
post #12

Earlier quoted context omitted.

In the US, HIPAA is pretty much the strongest privacy legislation there is. There's probably no group that would have a more severe penalty for leaking your info than your healthcare provider.

HIPAA was designed for portability -- the 'p' standards for portability not privacy -- of health info, so there are immense carve outs in service of that objective. Fines for violating HIPAA are almost non-existent. HIPAA is wildly misunderstood by the public as a strong safeguard, meanwhile medical offices just get any patient (a captive audience) to sign a release waiver as part of patient intake ...

They get patients to sign something permitting them to share PHI with other entities like e.g. the lab that runs blood work, not to disclaim liability for leaking it unintentionally.
Post reply on HN