Live data from Hacker News

'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

websiteplanet.com

161–170 of 193 posts

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#161

Earlier quoted context omitted.

It's definitely shady, but it's par for the course. Uber charges you more if you have more gift cards loaded, or just spend more on average in general. You charge what the market will bear.

You charge what the market will bear, not the individual .

I have a side business and virtually every customer pays a different price, what you’re saying is simply not true. Airlines do it, hotels do it, I have different rates for my customers at my day job, etc.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#162

Earlier quoted context omitted.

> Their entire executive team should be jailed for a minimum of 3 years per individual offense. This is so over the top reactionary and stupid, I can't help but write off your entire comment. You want the Chief Accounting Officer to go to jail for 3 decades because of a data breach?

I assumed there was more than 10 folks impacted by their poor business decisions; based on the number of images of SS cards, it should be life without parole. Preferably with hard labor in Siberia or western Nebraska.

> or western Nebraska.

Now you've taken it too far.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#163
post #44
post #30

Earlier quoted context omitted.

According to the article the name is ESHYFT. It sounds like a brand of electronic found on aliexpress but with less quality!

Please invest in my startup, ENSHITIFY

I think I once bought an iPhone charging cable from you guys on Amazon.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#164
This is shameful. S3 buckets have not been public by default for many years. You have to make a choice to make them publicly accessible. And to not have the contents encrypted at rest. I just can’t.

The lack of respect that some companies have for their customers is appalling.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#166

Earlier quoted context omitted.

You charge what the market will bear, not the individual .

I have a side business and virtually every customer pays a different price, what you’re saying is simply not true. Airlines do it, hotels do it, I have different rates for my customers at my day job, etc.

And even if they pay the same price, they’ll have different costs.

I’ll gladly take all the free alcohol an airline will give me, but other people don’t at all!

I sell some stuff on eBay. If you appear untrustworthy, I’ll spend more for tracking/better tracking on your order so you’ll actually get your stuff faster/more reliably.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#167
post #82

I'll need to dig up a source but I recently heard about this company and, apparently, before offering gigs they do a credit report to determine how much debt the person is carrying (i.e. how desperate they are) and they use that information to _round down_ the hourly rate they offer them. In the unlikely event that there are any negative consequences for this breach, they deserve every bit of them and more.

I’m interested, given the massive nursing shortages, why any nurses were using this service at all? Especially for higher levels, there’s no reason to mess with a shitty app that underpays you, when you should be able to walk into any provider’s office or facility and get hired almost immediately (and for Runs, you even have wide-ranging telehealth options).

You can get paid more as a contractor than an employee.

Some may just want to pick up casual shifts without any obligation on top of their full-time work. This is kinda double dipping because your full time work is paying your benefits, so why work overtime at time and a half for them when you can get 2x+ somewhere else with + pay in lieu of benefits?

Big orgs don’t want to deal with 1000 different individual contractors (especially if it means taking potential misclassification of employee as a contractor) risk.

I think the bigger issue is the myth of nurse fungibility. A rando nurse unfamiliar with your setup/org is unlikely to be very productive.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#168

Earlier quoted context omitted.

This was my thought exactly. There is a giant nursing shortage. I know some nurses who are traveling nurses and they may bank, and they don't need any BS app. (Just want to emphasize, nursing is an incredibly difficult job at the moment, but there are also currently weird dynamics where traveling nurses can actually make a lot more than "stationary" nurses). Thus, I'm led to believe that nurses using this app have to…

I imagine many of them are people who can't commit to full or even part-time jobs because of responsibilities like childcare or eldercare; their own physical or mental health issues; etc.

Or they have full time jobs already and aren’t generally interested in extra shifts, unless the price is right.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#169
post #47

Earlier quoted context omitted.

It's true that the US rarely penalizes corporations enough to really disincentivize things, but healthcare providers probably take client data security more seriously than just about any other group besides maybe law firms. It's weird to single them out as being particularly unconcerned with and unpenalized for leaks.

We saw ours input PII into a Windows box. The idea that their ActiveX monstrosity has any security is not very persuasive.

ActiveX... haven't read that in a long time...
Post reply on HN