Live data from Hacker News

2.7M medical calls breached in Sweden

twitter.com

61–70 of 116 posts

Re: 2.7M medical calls breached in Sweden

#61

Earlier quoted context omitted.

This is a far more general problem of states in general. They always see themselves above the rules they apply to others and this is particularly problematic in the medical realm, but also affects criminal justice for example. Governments just don't follow their own rules. This means that medical files just aren't trustworthy anymore, in the sense that the patient has no control over who sees these and how far they a…

Plug: this is what we're trying to solve (amongst other things) at Patients Know Best. Giving the control back to the patient (you should always have full access to all data about yourself, and be able to control sharing of these records). We're mostly present in the UK at the moment.

More would be solved with simply the ability to, on a simple request and without justification, delete all data associated with yourself. Including all shared copies.

Re: 2.7M medical calls breached in Sweden

#62

On my machine Google translate seems to "boot-loop" that site because of the cookie settings so I'll just do this: Files were stored on a server using HTTPS but requiring no credentials. http://188.92.248.19:443/medicall/ Part of the calls were saved as .mp3s with the customers phone number as file name. CEO when confronted wouldn't believe it and hung up when the reporter asked if he could play one of the tapes. The…

The "funny" thing is, it wasnt using HTTPS, it was on the 443 port. But the data was sent unencrypted.

These calls were answered by Swedish-speaking people in Thailand.

Their business idea was to handle calls that were placed in inconvenient hours, relative to Swedish business hours.

My best guess is that the Thai ISP this office used filtered all outgoing connections except port 80 and 443.

And then someone decided that the way to implement this securely while still allowing this office to access the data was to put a plain HTTP server on port 443. "Who is ever going to crack that?"

Re: 2.7M medical calls breached in Sweden

#63
post #33

Yep. My calls with personal identification number are absolutely in there, with list of 10+ medications, and medical history including genetic disorders and other things. Imagine becoming a public person in the future with random russian mobs blackmailing me based on me and my family's medical history.

> My calls with personal identification number are absolutely in there

Is this an assumption, or were you able to find a list of leaked calls somewhere?

Re: 2.7M medical calls breached in Sweden

#64

Let's talk legal ramifications. The cause of technical breaches falls onto a sliding scale in my mind. That scale goes from pure technical negligence to overbearing technical complexity. This breach seems like pure negligence. In a surgery this wouldn't be "complications", it would be malpractice. Does GDPR protect those breached here? What recourse do these people have? We really need to change the narrative around…

Sure!

Breach against patientdatalagen and GDPR

Shall be encrypted so that the patients identity are protected.

"Uppgifter om en patients identitet som har dokumenterats inom hälso- och sjukvården och som landstingen ska sambearbeta med sådana uppgifter som avses i första stycket, ska vara krypterade så att patientens identitet skyddas vid behandlingen. Lag (2013:1024)." "Information about a patient's identity that has been documented in the health and medical care and which the county councils are to co-operate with the information referred to in the first paragraph, shall be encrypted so that the patient's identity is protected during the treatment. Swedish law (2013: 1024)"

Transfer of personal data outside EU Tredjelandsöverföring. "Transfers of personal data to third countries or international organisations" Thailand is not on the list of authorized countries. https://gdpr-info.eu/chapter-5/

The GDPR section about sensitive data records * medical records.

Den personuppgiftsansvarige ska genomföra lämpliga tekniska och organisatoriska åtgärder för att, i standardfallet, säkerställa att endast personuppgifter som är nödvändiga för varje specifikt ändamål med behandlingen behandlas. Den skyldigheten gäller mängden insamlade personuppgifter, behandlingens omfattning, tiden för deras lagring och deras tillgänglighet. Framför allt ska dessa åtgärder säkerställa att personuppgifter i standardfallet inte utan den enskildes medverkan görs tillgängliga för ett obegränsat antal fysiska personer.

Further persons working at tillsyndsmyndigheter may have done "Tjänstefel", that is fault committed by a public sector official servant that is not minor. 20 kap. Om tjänstefel m. m. "Section 1 Anyone who intentionally or negligently neglects the exercise of authority by action or omission shall be sentenced for misconduct for fines or imprisonment for a maximum of two years. If the act, having regard to the perpetrator's powers or the task's relation to the exercise of authority in other respects or to other circumstances, is to be regarded as poor, shall not be held liable."

Failure to run a network security scanner, failure to encrypt sensitive data records, failure to use passwords, failure to limit access to sensitive records

Re: 2.7M medical calls breached in Sweden

#65

So, who thought it was a good idea to record these in the first place and then to store them on an internet facing server? It doesn't surprise me one bit though.

Recording the calls could even be a requirement. You call in to get medical advice, then later decide the advice was wrong and sue them for malpractice. Recordings of the calls could be crucial to deciding the case later on.

Re: 2.7M medical calls breached in Sweden

#66

Earlier quoted context omitted.

No, we're highly judgemental, but an employer is not allowed to inquire or make hiring/firing decisions with regard to your health status. Likewise life insurance might have a higher premium if you regularly engage in extreme sports, but they can't deny you. Health care is ubiquitous regardless of your condition.

You seem to be missing the point. The boss does not have to enquire if the information is already public!

I understood the point. If an employee/applicant felt they had been discrimitated against and reported it there would be an inquiry and serious financial/social consequences. Hiring is a lengthy process and firing is very difficult.

Lots of information is available in Sweden that would make Americans squeemish to have public. The difference is that most people aren't interested in the sordid details of their neighbors.

Re: 2.7M medical calls breached in Sweden

#67
post #18

Earlier quoted context omitted.

> and things like acid attacks against women are decently common. Wait, what? Where's your source on this. Via google I can find references to one case from 1997 and one from 2002, and that's it. The idea that this would in any way be "decently common" here is preposterous.

https://en.wikipedia.org/wiki/Acid_throwing#United_Kingdom London Metropolitan Police showed a sharp rise in attacks, with 465 recorded in 2017 Particularly common in London, and amongst some immigrant communities. Other countries are not so far behind, and I gather it is quite common in some of the developing world, like India and Pakistan.

In the UK it seems it has mostly been a weapon among criminals more than a honor thing that is more common in the developing world.

Re: 2.7M medical calls breached in Sweden

#68

On my machine Google translate seems to "boot-loop" that site because of the cookie settings so I'll just do this: Files were stored on a server using HTTPS but requiring no credentials. http://188.92.248.19:443/medicall/ Part of the calls were saved as .mp3s with the customers phone number as file name. CEO when confronted wouldn't believe it and hung up when the reporter asked if he could play one of the tapes. The…

The "funny" thing is, it wasnt using HTTPS, it was on the 443 port. But the data was sent unencrypted.

Still, sending the data unencrypted wasn't so much the issue here as the server was open to anyone.

Re: 2.7M medical calls breached in Sweden

#69
post #65

So, who thought it was a good idea to record these in the first place and then to store them on an internet facing server? It doesn't surprise me one bit though.

Recording the calls could even be a requirement. You call in to get medical advice, then later decide the advice was wrong and sue them for malpractice. Recordings of the calls could be crucial to deciding the case later on.

That's Sweden, not the USA.

Re: 2.7M medical calls breached in Sweden

#70

Earlier quoted context omitted.

Because Swedes are uniquely morally upstanding and non-judgemental?

No, we're highly judgemental, but an employer is not allowed to inquire or make hiring/firing decisions with regard to your health status. Likewise life insurance might have a higher premium if you regularly engage in extreme sports, but they can't deny you. Health care is ubiquitous regardless of your condition.

Health care insurance, privat sjukvårdsförsäkring, can deny you. Talk from experience.

Makes a lot of sense as well, anything else would be weird. If this was not the case you could just get it when you have already been deemed sick, to get the faster private care instead of public health care.

Post reply on HN