Live data from Hacker News

Five million Danish ID numbers sent to Chinese firm by mistake

thelocal.dk

21–30 of 84 posts

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#21
post #20
post #18

Earlier quoted context omitted.

> But again there is little to no way to figure out for sure whether the Chinese government has this information assume they have it.

Let's assume they have it. What kind of interest would you say the Chinese government has in the health records of a few million Danish residents? I don't know, maybe it's really important, but then maybe it's not that critical after all.

Probably none, but you don't stay a power in the modern world by turning up your nose at any kind of information that comes your way.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#22
post #8
post #4

Earlier quoted context omitted.

Correction: SSI sent a letter containing two unencrypted CDs containing CPR-numbers and health records for 5.28 residents in Danish municipals between 2010 and 2012 to the Danish statistics agency (Statistics Denmark). Post Danmark (postal service) accidentally delivered the letter to Chinese Visa Application Centre instead. When the employee responsible for receiving the letter noticed the mistake upon opening, the…

That's the problem with blame culture. It needs to be someones (emphasis ONE) fault, and then anyone else can breathe a sigh of relief and move on. It's blatantly irresponsible that SSI even has the infrastructure to burn CDs with this information on it (it needs to live in heavily secured, jealously guarded and scrupulously audited (ideally airgapped) computer system). If they absolutely need this capability, it's b…

Likely the capability exits for when someone moves to another part of the country, and the local doctor wants to check the new patient's medical history.

Note also that the data was meant for what i assume is the national statistics office. Likely for investigating changes in danish public health over recent years.

Unless by airgapped you mean to build a separate, free standing, network just for delivering medical records to doctor's offices around the nation.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#24

This is ridiculous. It's not just Danish personal identification numbers, but ID numbers and health records for everyone who have lived in Denmark from 2010 through 2012. Quick recap since it's in Danish: A danish health authority, SSI, accidentally mailed two CDs containing unencrypted CPR-numbers and health records for 5.28m residents to the Chinese Visa Application Office. The Chinese delivered the letter to the i…

This happens more than you think, although not usually at this scale and this high up in the chain. When a care institution needs to communicate with one of their vendors handling health records about a problem with a specific person's record, most IT-workers at those institutions tend to just mail all details they feel are relevant to the issue without even considering encryption or the necessity of sending all that…

> most IT-workers at those institutions tend to just mail all details they feel are relevant to the issue

Not necessarily disbelieving you, but why do you say this? Every place I've worked or contracted at with PII, I've had to sit through training about not doing this, and management provided tools for proper handling.

I don't mean to say that because there are policies that no one ever breaks them. I've also encountered places where what was encouraged on the ground was different than what was listed in policy.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#25

This is ridiculous. It's not just Danish personal identification numbers, but ID numbers and health records for everyone who have lived in Denmark from 2010 through 2012. Quick recap since it's in Danish: A danish health authority, SSI, accidentally mailed two CDs containing unencrypted CPR-numbers and health records for 5.28m residents to the Chinese Visa Application Office. The Chinese delivered the letter to the i…

That's like the entire Danish population. Also, who sends CDs these days?

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#26
post #8

Earlier quoted context omitted.

That's the problem with blame culture. It needs to be someones (emphasis ONE) fault, and then anyone else can breathe a sigh of relief and move on. It's blatantly irresponsible that SSI even has the infrastructure to burn CDs with this information on it (it needs to live in heavily secured, jealously guarded and scrupulously audited (ideally airgapped) computer system). If they absolutely need this capability, it's b…

Likely the capability exits for when someone moves to another part of the country, and the local doctor wants to check the new patient's medical history. Note also that the data was meant for what i assume is the national statistics office. Likely for investigating changes in danish public health over recent years. Unless by airgapped you mean to build a separate, free standing, network just for delivering medical re…

https://en.m.wikipedia.org/wiki/N3_(NHS)

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#27
post #20
post #18

Earlier quoted context omitted.

> But again there is little to no way to figure out for sure whether the Chinese government has this information assume they have it.

Let's assume they have it. What kind of interest would you say the Chinese government has in the health records of a few million Danish residents? I don't know, maybe it's really important, but then maybe it's not that critical after all.

[deleted]

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#29
post #20
post #18

Earlier quoted context omitted.

> But again there is little to no way to figure out for sure whether the Chinese government has this information assume they have it.

Let's assume they have it. What kind of interest would you say the Chinese government has in the health records of a few million Danish residents? I don't know, maybe it's really important, but then maybe it's not that critical after all.

They use it can track the movements of Chinese residents abroad, to blackmail Danes who are assisting Chinese disidents, run scams at doctors offices or insurers in order to get documentation for spies. I am sure there is more, I am no expert in this sort of thing.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#30
post #7

Google Translate gives me, "Data Protection Agency takes no further action". Is that true? No-one is fined or prosecuted for this? Or even sacked?

Yes that's true - The Data Protection Agency see no reason to take any further action in this case. Their assessment is that there is a low likelihood of an actual leak (based on a written statement from the Chinese employee who opened the letter). And the SSI has promised to send such information encrypted going forward.

If I were a senior official at the Chinese foreign service, and I heard that one of my employees got such a CD and just gave it back to the Danes without notifying higher-ups, then I would want that employee's head.

On the other hand, if I were a senior official in the Danish foreign service, then I would find my life a lot easier if no one was kicking up a fuss about the Chinese.

Post reply on HN