Live data from Hacker News

301M Records Exposed: The HIPAA Breach Epidemic

ciphercue.com

31–40 of 40 posts

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#31

Well at least the leaks and irresponsibility have hit the HIPAA level, maybe now some old people will take it seriously? Or will the fallout continue to be normalization of data leaks like the morons in the federal government did for credit reporting agencies?

As far as I’m aware, no one at United Healthcare (the monopoly that owns Change Healthcare, which was hacked for most of these) was held accountable.

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#32
post #5

1. What a wildly capitalist take on the loss of confidentiality for personnel data. 2. If you get breached, you have a problem. If everyone gets breached it starts to look more like cost-of-business (and that might be cheaper than a cyber firm that doesn't actually fix the problem [but looks good on audits]) 3. I wonder if the breached data is entering AI corpuses. Will I be able to ask OpenAI "Does Joe Bloggs, 75 Pe…

I think we're already in the "cost-of-business" stage. the industry standard seems to be: - release "oopsie" statement - engage "cybersecurity firm" to investigate - give out free credit monitoring for a year (fucking worthless) and so far it seems to be working just fine

I don't think I would favor executions or anything.

But forcible dilution (partial or total seizure) of the corporation? A mandatory insurance coverage? Absolutely.

We already have statutory HIPAA violation penalties, and I am extremely in favor of assessing them in a breach. The question is whether they are sufficient.

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#33
post #18

1. What a wildly capitalist take on the loss of confidentiality for personnel data. 2. If you get breached, you have a problem. If everyone gets breached it starts to look more like cost-of-business (and that might be cheaper than a cyber firm that doesn't actually fix the problem [but looks good on audits]) 3. I wonder if the breached data is entering AI corpuses. Will I be able to ask OpenAI "Does Joe Bloggs, 75 Pe…

OTOH, breaches especially Health Data breaches are the most over-rated, hysteria inducing breaches of all time. There is ZERO use for anyone for your health data

Abortion prosecution or societal ostracization.

Streamer doxing.

Literally just being trans.

HIV fear mongering.

Illegal fuckery with your insurance rates.

Employment discrimination.

Stalking.

Racial discrimination.

Can you imagine trying to fully trust a mental health professional today? A patient can't see a therapist's notes, but they sure as hell can be breached.

There is zero LEGITIMATE use for your breached health data.

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#34
post #24
post #13

Wait, the main takeaway from this article is that cybersecurity sales teams now have great leads? Facepalm. The real takeaway should be that at every level -- government, corporate, healthcare entities, personal -- we need to rethink how we're acting in the face of these disasters. Government should recognize that its current regulations are insufficient and look for ways to refine them. Corporations and health-care…

This wouldn’t have solved the largest one, Change Healthcare. They are an insurance claims exchange. They have to have all of this data. The breach was social engineering of a customer support rep. Having worked with them, they’re absolutely necessary for healthcare (in its current form; don’t get me started) to function. The alternative is integrating with hundreds of payers (won’t happen) or doing it by fax/mail (d…

I would say that if it is possible to exfiltrate 193 M sensitive records through a social engineering attack on one customer support rep, then there are multiple failure points that they and other businesses need to address:

- better security training for employees

- don't store 193 M sensitive records in such a way that one social-engineering attack gives you access to all of them

- don't store 193 M sensitive records without appropriate encryption, and make it hard to steal both the records and the decryption mechanism.

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#35
post #11

1. What a wildly capitalist take on the loss of confidentiality for personnel data. 2. If you get breached, you have a problem. If everyone gets breached it starts to look more like cost-of-business (and that might be cheaper than a cyber firm that doesn't actually fix the problem [but looks good on audits]) 3. I wonder if the breached data is entering AI corpuses. Will I be able to ask OpenAI "Does Joe Bloggs, 75 Pe…

> What a wildly capitalist take on the loss of confidentiality for personnel data. As opposed to what exactly? A "communist" take on the loss of confidentiality? How might that go? "There's no problem comrade, what are you talking about?" This sounds like a failure of government regulation here, not a failure of a broad economic model.

I'm referring to the last few lines for that point - turning this failure of companies and governments into a nothing more than a lame pitch for their sales funnel platform.

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#37

Earlier quoted context omitted.

This optimism in the face of the current state of government made me chuckle-sob.

HIPAA data is always talked sternly about. I’m hoping my health worker professional friends can help bring attention to the issue. Who knows if everyone will just roll over.

HIPAA and other medical data protection laws are violated routinely. This could be important or it might be ignored in the face of the broader problem. I wonder if there is an authoritative deep dive on the nature of the UnitedHealthCare breach.

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#38
post #18

Earlier quoted context omitted.

OTOH, breaches especially Health Data breaches are the most over-rated, hysteria inducing breaches of all time. There is ZERO use for anyone for your health data

Abortion prosecution or societal ostracization. Streamer doxing. Literally just being trans. HIV fear mongering. Illegal fuckery with your insurance rates. Employment discrimination. Stalking. Racial discrimination. Can you imagine trying to fully trust a mental health professional today? A patient can't see a therapist's notes, but they sure as hell can be breached. There is zero LEGITIMATE use for your breached hea…

Can you give me example of it actually happening? If not this is the definition of hysteria

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#39
post #26
post #18

Earlier quoted context omitted.

OTOH, breaches especially Health Data breaches are the most over-rated, hysteria inducing breaches of all time. There is ZERO use for anyone for your health data

Insurance companies, and companies that might look to hire you want your health data. Others may want your health data to bribe you. Maybe you got a STD from a mistress. Maybe you have a heart condition and the business you are interested in working for self-insures. They don't want you on their books!

has it actually happened? If not, it literally fits my definition of hysteria

Re: 301M Records Exposed: The HIPAA Breach Epidemic

#40
post #18

Earlier quoted context omitted.

OTOH, breaches especially Health Data breaches are the most over-rated, hysteria inducing breaches of all time. There is ZERO use for anyone for your health data

> There is ZERO use for anyone for your health data 0 You really think that?

Yes. You can give me actual data points to disprove that, especially one with statistical significance (compared to other means such data can be obtained like impersonation)
Post reply on HN