Earlier quoted context omitted.
Yes. HIPPA.
But apparently they didn't go after the company, so maybe those data are not the kind of information protected by HIPPA?
FBI raids dental software researcher who discovered patient data on FTP server
71–80 of 171 posts
Re: FBI raids dental software researcher who discovered patient data on FTP server
#72Here's an investigative tool the CFAA & the FBI needs... if a company like Patterson Dental spins up an investigative raid with a baseless complaint, the Bureau should be able to charge them with a crime. One almost hopes the FBI investigation yields enough evidence to charge Patterson with a criminal violation of HIPAA.
Why would the FBI and prosecutors punish Patterson? The gave the FBI an opportunity for raids and prosecutions, and those look great on an annual review.
Why go after Patterson? Because that would give them opportunities for more raids and prosecutions, which look great on an annual review. And raids and prosecutions for acts which are probably more politically useful to politically-minded US Attorneys than whatever kind of case they could make against Shafer.
Re: FBI raids dental software researcher who discovered patient data on FTP server
#73This reminds me of something that happened to me in high school back in 1999. I found an Excel doc in a public network drive that contained every single student's SSN, DOB, whether they had free/reduced lunch, address, phone, etc. I was admittedly snooping around, but this was all public stuff every student and teacher had full access to. When I found it, I told one of the teachers that I trusted and she insisted tha…
Edit: not trying to freak you out or anything. In the spirit of this article on publicly accessible information, I wanted to see if I could find out who it was through public means.
Re: FBI raids dental software researcher who discovered patient data on FTP server
#74About a month or so a go i found a open public mongo database with about 12GB of records regarding peoples retirement founds of what i assume was hundreds of thousands of people, account numbers, how much money was in the accounts when they had moved them to various founds and so on. Thought long and hard about what to do but decided to not do anything, dont feel like risking my entire life just to help someone. This…
Perhaps the FCC has something similar?
Re: FBI raids dental software researcher who discovered patient data on FTP server
#75Earlier quoted context omitted.
Western Europe and especially Scandanavia are better. That is my opinion based on the observations I have gathered. I am not sure where you are from, but I agree that it can also get worse.
Not necessarily. I've spent the last few years fighting various hacking charges in Finland and will most likely continue to do so for several years to come. The law enforcement here will consistently take anything the FBI tells them as a fact, even when the information provided by them has been consistently shown to be false or even maliciously fabricated. I spent 3 months in jail in 2014 because the FBI emailed the…
Re: FBI raids dental software researcher who discovered patient data on FTP server
#76Earlier quoted context omitted.
Oh, I've already learned the lesson loud and clear. If I ever discover a vulnerability to disclose, I'm releasing it anonymously on pastebin sites while logged into Tor through a VPN from a free WiFi spot. And, of course, sign it with a new PGP key you've just created, so that if you ever need to release a follow-up with proof that it's you, or come forward as the author of the disclosure, you can.
Of course, said key is a liability if it is found in your possession.
Re: FBI raids dental software researcher who discovered patient data on FTP server
#77Earlier quoted context omitted.
If patterson dental (and I say if since we don't really know) is behind him getting arrested, I hope all their patients find out about the details of this and they go out of business. If nothing else they should be charged with HIPAA violations.
Patterson is not a dental clinic. Like Henry Schein which was also mentioned in TFA, it is a large dental supply company. One reason that dentistry is so expensive, is that assholes like these run an oligopoly of "specialty" dental supplies. It's not as bad as military procurement, but it's kind of like that. Dentists as a profession are risk-averse, and that includes the "risk" of purchasing dental equipment and sup…
Will they? Since Eaglesoft claimed to provide encryption, and the practices relied on that claim, it seems unlikely that the practices are at fault; if they are subject to civil liability at all for inadvertent violations -- or even if they just have costs to cure the violations without money liability, which seems more likely given the history of HIPAA enforcement -- they would seem to have a claim for at least the total resulting costs in damages against Patterson.
As far as criminal violations of HIPAA goes, it doesn't seem particularly likely that any occurred, and if any did its pretty clear that the practices are (barring any evidence of knowledge that hasn't come to light) unlikely to have had the requisite knowledge or intent to be culpable, though the violations may have been willfully caused by Patterson's actions, which -- even though Patterson might not usually be directly covered by HIPAA as regards what appears to be on-premise software they sell -- might make Patterson a (and possibly the only) chargeable principal in any crime. 18 USC Sec. 2(b): "Whoever willfully causes an act to be done which if directly performed by him or another would be an offense against the United States, is punishable as a principal."
Re: FBI raids dental software researcher who discovered patient data on FTP server
#78Earlier quoted context omitted.
Why would the FBI and prosecutors punish Patterson? The gave the FBI an opportunity for raids and prosecutions, and those look great on an annual review.
Field offices don't have unlimited budgets. If it turns out this raid was unjustified - and it certainly appears to be - its not going to reflect positively on the people who caused it.
Re: FBI raids dental software researcher who discovered patient data on FTP server
#79Many financial institutions use the last 4 of your SSN as identity verification.
If you're a business, it's the last 4 of your FEI/EIN.
I know at least in FL, this is publicily available at sunbiz.org
So with the account number printed at the bottom of your paycheck/stub and the FEI/EIN, you can often authenticate to a financial institution and obtain privileged information.
I know this not because I was on the "hacker" side, but because I was involved on the financial institution side of it and caught this as part of my engagement. The institution was issuing new logins for its internet banking site and the password would have been based on the users name, zip code, and SSN/FEI/EIN, all 3 of which are available (in FL) on that sunbiz.org site.
Re: FBI raids dental software researcher who discovered patient data on FTP server
#80Reading this, I had an idea for a new law that could counteract this stupid reaction to security research: Particularly for protected patient information (but maybe for other classes of sensitive data as well), it would be interesting to somehow classify having this information breached as a crime by the holder of the information (I realize this might be hard to do given the reality of security these days, so there w…