Live data from Hacker News

301M Records Exposed: The HIPAA Breach Epidemic

ciphercue.com

21–30 of 40 posts

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#21

ai; dr > This isn't a single point of failure - it's a systemic crisis. > One in seven breaches isn't a sophisticated external attack - it's someone inside the organisation accessing data they shouldn't. > These organisations aren't browsing - they're buying https://news.ycombinator.com/newsguidelines.html#generated

> https://news.ycombinator.com/newsguidelines.html#generated

As written, the guidelines talk about AI generated comments, not AI generated submitted articles

In any case, just flag the submission and move on

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#22

Well at least the leaks and irresponsibility have hit the HIPAA level, maybe now some old people will take it seriously? Or will the fallout continue to be normalization of data leaks like the morons in the federal government did for credit reporting agencies?

The frog has been boiled.

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#23

ai; dr > This isn't a single point of failure - it's a systemic crisis. > One in seven breaches isn't a sophisticated external attack - it's someone inside the organisation accessing data they shouldn't. > These organisations aren't browsing - they're buying https://news.ycombinator.com/newsguidelines.html#generated

The leading paragraph is obviously AI, also:

> That number isn't a projection. It isn't an estimate. It's the sum total of confirmed individuals affected across 735 breach reports filed with the HHS Office for Civil Rights - and it's growing every week.

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#24
post #13

Wait, the main takeaway from this article is that cybersecurity sales teams now have great leads? Facepalm. The real takeaway should be that at every level -- government, corporate, healthcare entities, personal -- we need to rethink how we're acting in the face of these disasters. Government should recognize that its current regulations are insufficient and look for ways to refine them. Corporations and health-care…

This wouldn’t have solved the largest one, Change Healthcare. They are an insurance claims exchange. They have to have all of this data.

The breach was social engineering of a customer support rep.

Having worked with them, they’re absolutely necessary for healthcare (in its current form; don’t get me started) to function. The alternative is integrating with hundreds of payers (won’t happen) or doing it by fax/mail (disaster).

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#25

Well at least the leaks and irresponsibility have hit the HIPAA level, maybe now some old people will take it seriously? Or will the fallout continue to be normalization of data leaks like the morons in the federal government did for credit reporting agencies?

As with everything in the US, this will be politicized. I wonder which will be the party of “I’m fine with data breaches”

In my view that stance is becoming bipartisan as tech companies lobby nonsense like “we can’t get left behind China’s AI models so give us all the data!”

Democrats and Republicans always think they’re smart by investing in whatever wave of technology. Here we are.

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#26
post #18

1. What a wildly capitalist take on the loss of confidentiality for personnel data. 2. If you get breached, you have a problem. If everyone gets breached it starts to look more like cost-of-business (and that might be cheaper than a cyber firm that doesn't actually fix the problem [but looks good on audits]) 3. I wonder if the breached data is entering AI corpuses. Will I be able to ask OpenAI "Does Joe Bloggs, 75 Pe…

OTOH, breaches especially Health Data breaches are the most over-rated, hysteria inducing breaches of all time. There is ZERO use for anyone for your health data

Insurance companies, and companies that might look to hire you want your health data.

Others may want your health data to bribe you. Maybe you got a STD from a mistress.

Maybe you have a heart condition and the business you are interested in working for self-insures. They don't want you on their books!

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#27
post #18

1. What a wildly capitalist take on the loss of confidentiality for personnel data. 2. If you get breached, you have a problem. If everyone gets breached it starts to look more like cost-of-business (and that might be cheaper than a cyber firm that doesn't actually fix the problem [but looks good on audits]) 3. I wonder if the breached data is entering AI corpuses. Will I be able to ask OpenAI "Does Joe Bloggs, 75 Pe…

OTOH, breaches especially Health Data breaches are the most over-rated, hysteria inducing breaches of all time. There is ZERO use for anyone for your health data

> There is ZERO use for anyone for your health data0

You really think that?

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#28

Well at least the leaks and irresponsibility have hit the HIPAA level, maybe now some old people will take it seriously? Or will the fallout continue to be normalization of data leaks like the morons in the federal government did for credit reporting agencies?

This optimism in the face of the current state of government made me chuckle-sob.

HIPAA data is always talked sternly about. I’m hoping my health worker professional friends can help bring attention to the issue. Who knows if everyone will just roll over.

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#29
post #13

Wait, the main takeaway from this article is that cybersecurity sales teams now have great leads? Facepalm. The real takeaway should be that at every level -- government, corporate, healthcare entities, personal -- we need to rethink how we're acting in the face of these disasters. Government should recognize that its current regulations are insufficient and look for ways to refine them. Corporations and health-care…

Let's not forget that cybersecurity companies may also be directly involved into hacking government institutions. Case in point - the Bulgarian TAD Group cybersec firm that allegedly hacked the National Revenue Agency in 2019.

> It is still unclear what prompted the hack. The prosecution claims that TAD Group tried to blackmail several companies to hire its services, inducing them with hacked information from their websites. However, no company has publicly complained yet. [0]

0 - https://kinsights.capital.bg/politics_and_society/2019/09/17...

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#30
post #18

1. What a wildly capitalist take on the loss of confidentiality for personnel data. 2. If you get breached, you have a problem. If everyone gets breached it starts to look more like cost-of-business (and that might be cheaper than a cyber firm that doesn't actually fix the problem [but looks good on audits]) 3. I wonder if the breached data is entering AI corpuses. Will I be able to ask OpenAI "Does Joe Bloggs, 75 Pe…

OTOH, breaches especially Health Data breaches are the most over-rated, hysteria inducing breaches of all time. There is ZERO use for anyone for your health data

There is a field in a claims form that indicates what type of insurance it is.

One of these is CHAMPUS, which indicates that it is for a service member or their family. You can tell which.

As a basic case, accumulate these (as in the CHC breach of ~30% of Americans) and you have a nice map of where US military are. Since bases house particular units and types of forces, a nation state can estimate strength and investment in the US military.

In a specific case, the response to claims includes patient responsibility (deductible, co-insurance, co-pay.) Add that up for a financial picture, then you’ve got a nice lead list for service members who have money problems.

Post reply on HN