Live data from Hacker News

'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

websiteplanet.com

71–80 of 193 posts

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#71

Earlier quoted context omitted.

It's definitely shady, but it's par for the course. Uber charges you more if you have more gift cards loaded, or just spend more on average in general. You charge what the market will bear.

You charge what the market will bear, not the individual .

Aren’t they just creating a market of 1?

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#72

Earlier quoted context omitted.

The PII of the nurses being accidentally shared by a staffing agency isn't a HIPAA violation. Yes the nurses are providers but their relationship with the Uber for nurses service isn't a medical provider relationship. It's definitely a legal and ethical failing but I don't think it's a HIPAA one.

HIPAA avoidance is much narrower than that. Entities which perform administrative or managerial duties on behalf of a mandated organization that have to transmit PII to provide that service are also covered, even if the entity itself isn't a provider. If 'Uber for nurses' is acting on behalf of nurses, it probably doesn't apply? If it's acting on behalf of the hospitals (who are indisputably covered entities), then t…

I used to work in the field. HIPAA protects patient data, not provider data. If my understanding is correct that only nurse PII was leaked, this has nothing to do with HIPAA.

In general, I've found that people tend to think HIPAA applies much, much more than it actually does. Like people thinking if you're in a meeting at work with clients and say "Sorry, Bob couldn't be here today, he's got the flu" that that's a HIPAA violation. No, it's not.

This is just an employee data leak, just like a bajillion other employee data leaks. The fact that the employees happen to be nurses still doesn't mean it has anything to do with HIPAA.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#73

Earlier quoted context omitted.

[Nevermind]

The PII of the nurses being accidentally shared by a staffing agency isn't a HIPAA violation. Yes the nurses are providers but their relationship with the Uber for nurses service isn't a medical provider relationship. It's definitely a legal and ethical failing but I don't think it's a HIPAA one.

This 100%. This needs to be a top level comment.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#74
post #12
post #9

Worth mentioning, because the authority level of medical practitioners throws people off. Don't ever give a doctor or practice your Social Security Number. They don't need it. Similarly if they want to check an ID that doesn't mean scan or photograph. Doctors, practices, etc are the worst at infosec. They have no training, basically no penalties if they do something wrong and all of that info is only to follow up in…

In the US, HIPAA is pretty much the strongest privacy legislation there is. There's probably no group that would have a more severe penalty for leaking your info than your healthcare provider.

How many healthcare providers do you know personally who have faced severe penalties for leaking information?

The reality is that for a small doctor/dental/whatever office, there is essentially 0 risk. HIPAA violations that carry significant penalties go to huge hospitals and healthcare companies.

Your neighborhood doctor has to screw up in a major way for an extended period of time to have a minute risk of any consequence.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#75

In the section of their Privacy Policy titled Data Security [0]: > We use certain physical, managerial, and technical safeguards that are designed to improve the integrity and security of information that we collect and maintain. Please be aware that no security measures are perfect or impenetrable. We cannot and do not guarantee that information about you will not be accessed, viewed, disclosed, altered, or destroye…

HIPAA applies to patient data not providers data.

> I also saw what appeared to be medical documents uploaded to the app. These files were potentially uploaded as proof for why individual nurses missed shifts or took sick leave. These medical documents included medical reports containing information of diagnosis, prescriptions, or treatments that could potentially fall under the ambit of HIPAA regulations.

It looks like providers accidentally uploaded some PHI.

IANAL so may be wrong, but I worked for a healthcare company. Whether HIPAA applies to them depends on if they are considered a covered entity or a business associate [0].

IMO they aren't bound to HIPAA requirements as a covered entity.

Business associate is a little tricky to determine. But business associates have to sign a BAA (Business Associate Agreement). And I doubt they would have signed one if they have that in their privacy policy.

Also just as a side note, HIPAA is not a ideal standard to begin with for security. Many large companies exchange bulk PHI via gmail since it is HIPAA compliant..

0: https://www.hhs.gov/hipaa/for-professionals/covered-entities...

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#76
post #9

Worth mentioning, because the authority level of medical practitioners throws people off. Don't ever give a doctor or practice your Social Security Number. They don't need it. Similarly if they want to check an ID that doesn't mean scan or photograph. Doctors, practices, etc are the worst at infosec. They have no training, basically no penalties if they do something wrong and all of that info is only to follow up in…

What do you do if they refuse to book an appointment without it?

Find a new provider. I have gone 2 decades without providing my SSN to doctors.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#77

Earlier quoted context omitted.

It's definitely shady, but it's par for the course. Uber charges you more if you have more gift cards loaded, or just spend more on average in general. You charge what the market will bear.

You charge what the market will bear, not the individual .

The market ensure (mostly) there is another individual.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#78
post #16

I wonder how old the S3 bucket was, because at some point AWS made new S3 buckets private by default. Which means it's either old, or they recklessly opened it up because they couldn't get files uploaded/downloaded to the bucket from their mobile app/services.

Also possible a webdev opened it up so they could use the assets on a website, and didn't think about other private data in the bucket.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#79

I'll need to dig up a source but I recently heard about this company and, apparently, before offering gigs they do a credit report to determine how much debt the person is carrying (i.e. how desperate they are) and they use that information to _round down_ the hourly rate they offer them. In the unlikely event that there are any negative consequences for this breach, they deserve every bit of them and more.

That seems like a terrible way to estimate nurse wages.

People have spouses.

People’s parents pay credit cards.

People with bad credit sometimes don’t care.

People have family money.

People with low debt can be desperate for work.

Does it even work?

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#80

Earlier quoted context omitted.

You charge what the market will bear, not the individual .

Aren’t they just creating a market of 1?

"just" is doing a lot of heavy lifting here
Post reply on HN