Live data from Hacker News

Five million Danish ID numbers sent to Chinese firm by mistake

thelocal.dk

71–80 of 84 posts

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#71
post #20
post #18

Earlier quoted context omitted.

> But again there is little to no way to figure out for sure whether the Chinese government has this information assume they have it.

Let's assume they have it. What kind of interest would you say the Chinese government has in the health records of a few million Danish residents? I don't know, maybe it's really important, but then maybe it's not that critical after all.

Executive blackmail I imagine. You're a Chinese billionaire with connections to the government, you are in the midst of a deal with a large Danish corporation, you email you're government contacts for the medical records of all the executives of that company. You find out one is an alcoholic, one has recently contracted herpes (and his wife hasn't), and so forth.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#72

Earlier quoted context omitted.

Likely the capability exits for when someone moves to another part of the country, and the local doctor wants to check the new patient's medical history. Note also that the data was meant for what i assume is the national statistics office. Likely for investigating changes in danish public health over recent years. Unless by airgapped you mean to build a separate, free standing, network just for delivering medical re…

First, this is not about doctors exchanging patients' medical histories, it's about two central government offices exchanging everybody's medical histories. Second, the fact that security is (really!) hard is not a valid argument against doing it. Third, there's a huge difference between the appropriate levels of security around individual patients' medical histories, a single doctors office worth of patients' data,…

Yes if its everyone's data you have a senior member of staff drive over and deliver it by hand Denmark isn't a very large.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#73

Earlier quoted context omitted.

Likely the capability exits for when someone moves to another part of the country, and the local doctor wants to check the new patient's medical history. Note also that the data was meant for what i assume is the national statistics office. Likely for investigating changes in danish public health over recent years. Unless by airgapped you mean to build a separate, free standing, network just for delivering medical re…

First, this is not about doctors exchanging patients' medical histories, it's about two central government offices exchanging everybody's medical histories. Second, the fact that security is (really!) hard is not a valid argument against doing it. Third, there's a huge difference between the appropriate levels of security around individual patients' medical histories, a single doctors office worth of patients' data,…

> Third, there's a huge difference between the appropriate levels of security around individual patients' medical histories, a single doctors office worth of patients' data, and then the collective medical histories for every single patient in the nation.

Hang on: If you're extracting an individual's medical data and putting that on a USB stick you better make sure it's encrypted, and that there are audit trails in place for who extracted the data, when, and why, and where they put it.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#74
post #10
post #8

Earlier quoted context omitted.

That's the problem with blame culture. It needs to be someones (emphasis ONE) fault, and then anyone else can breathe a sigh of relief and move on. It's blatantly irresponsible that SSI even has the infrastructure to burn CDs with this information on it (it needs to live in heavily secured, jealously guarded and scrupulously audited (ideally airgapped) computer system). If they absolutely need this capability, it's b…

I apologise, that summary was inaccurate. But parent's wording seemed to indicate that the SSI had sent the letter to the wrong recipient when that was not the case. I wanted to clear that up. The problem is that SSI sent the data unencrypted.

The problem was that they sent it at all.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#75
post #60
post #59

Earlier quoted context omitted.

Are ID numbers confidential in Denmark? They (personnumer) seem fairly widely shared in Sweden and Finland.

They are confidential in Denmark, or rather they were supposed to be.

They used to be regarded as confidential here in Norway but that has been rather de-emphasised in recent years. But you won't get anywhere asking for information from a bank if you only have the account and personnummer because all the banks here require two factor authentication, as far as I know.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#76
post #18
post #6

Earlier quoted context omitted.

No long, I'd imagine. But again there is little to no way to figure out for sure whether the Chinese government has this information. The story really highlights the careless handling of data, because the chances of the Chinese government (or any other third part) getting access to these data is way too high.

> But again there is little to no way to figure out for sure whether the Chinese government has this information assume they have it.

Assume they had it already.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#77
post #60
post #59

Earlier quoted context omitted.

Are ID numbers confidential in Denmark? They (personnumer) seem fairly widely shared in Sweden and Finland.

They are confidential in Denmark, or rather they were supposed to be.

They aren't confidential, at least not more than your full name. It's a common myth, probably stemming from the fact that there's plenty of laws about how to treat information that can be used to identify people. But those laws pretty much also applies if you just a have list of peoples full name.

Edit: Reading through the law, they are more confidential than your full name, though not by much. Generally you can't publish them publicly. And usage within companies and the state are regulated, but fairly permissive. Datatilsynet has explicitly said that they shouldn't be used to identity that a person is who they say they are, and only should be used as a primary key to differentiate people.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#78
Just came here to ask what do you guys' think about centralized health care records?

It seems impossible to prevent these kinds of "stupid" mistakes from happening.

My doctor still works mostly on a paper based system, so in the worst kind of situation just his patients data are lost.

Are there any alternatives that prevent those kinds of leaks - esp. considering that even the NSA got out-Snowdened.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#79
post #8
post #4

Earlier quoted context omitted.

Correction: SSI sent a letter containing two unencrypted CDs containing CPR-numbers and health records for 5.28 residents in Danish municipals between 2010 and 2012 to the Danish statistics agency (Statistics Denmark). Post Danmark (postal service) accidentally delivered the letter to Chinese Visa Application Centre instead. When the employee responsible for receiving the letter noticed the mistake upon opening, the…

That's the problem with blame culture. It needs to be someones (emphasis ONE) fault, and then anyone else can breathe a sigh of relief and move on. It's blatantly irresponsible that SSI even has the infrastructure to burn CDs with this information on it (it needs to live in heavily secured, jealously guarded and scrupulously audited (ideally airgapped) computer system). If they absolutely need this capability, it's b…

I hate to tell you this but such information is widely emailed around as excel spreadsheet attachments by unthinking people. I would virtually guarantee it happens every day.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#80
post #20

Earlier quoted context omitted.

Let's assume they have it. What kind of interest would you say the Chinese government has in the health records of a few million Danish residents? I don't know, maybe it's really important, but then maybe it's not that critical after all.

Hi, nice to meet you Johan! Can I get you a drink? Oh, you're an electrician? That's nice, I sell light fixtures. ... Good to see you again Johan! You'll never believe, I was down at XYZ Clinic yesterday, and they'd left your file out!! Careless right? How did you break it to your wife you had herpes? Oh, she didn't know?! Man, sorry I mentioned it, I'll keep that quiet for sure. ... Man, it's been a hard month Johan…

You forgot the part after step two where Johan the electrician beats the shit out of the little Chinese guy.
Post reply on HN