Earlier quoted context omitted.
HIPAA has strict rules with severe penalties, but enforcement is at best spotty. So honest hospitals and doctors offices bend over backwards to comply with the rules at great expense, but bad actors are rarely punished. It's the worst of both worlds. I'm pretty sure that is why the punishments are so harsh, because they need to put the fear of god into practitioners to make them take it seriously since there are so f…
It's the difference in medical establishment skill level between your doctor and you. You are always at a disadvantage. I've long thought that a disinterested third party needs to be involved. Someone with real oversight taking a position adversarial to the hospital and strictly to create the best possible outcome for the patient. The Hippocratic model isn't awesome.
'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
81–90 of 193 posts
Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#82I'll need to dig up a source but I recently heard about this company and, apparently, before offering gigs they do a credit report to determine how much debt the person is carrying (i.e. how desperate they are) and they use that information to _round down_ the hourly rate they offer them. In the unlikely event that there are any negative consequences for this breach, they deserve every bit of them and more.
Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#83Earlier quoted context omitted.
If you're not a direct health provider, you probably can. Don't take that as an endorsement.
If you partner with a healthcare provider to provide any sort of technical services, you will be required to sign a BAA (Business Associates Agreement), which makes you similarly liable to the HIPAA & HITECH acts.
>With persons or organizations (e.g., janitorial service or electrician) whose functions or services do not involve the use or disclosure of protected health information, and where any access to protected health information by such persons would be incidental, if at all.
Based on the context from the article of the PHI uploaded being incidental, it would probably fall under this exception. It sounds like ESHYFT isn't meant to be storing any PHI based on the privacy policy above.
0:https://www.hhs.gov/hipaa/for-professionals/privacy/guidance...
Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#84Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#85In the section of their Privacy Policy titled Data Security [0]: > We use certain physical, managerial, and technical safeguards that are designed to improve the integrity and security of information that we collect and maintain. Please be aware that no security measures are perfect or impenetrable. We cannot and do not guarantee that information about you will not be accessed, viewed, disclosed, altered, or destroye…
That being said, HIPAA isn't even relevant here because "ESHYFT" is just a provider a labor. No different than a big consultant providing staff augmentation services.
Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#86Earlier quoted context omitted.
Does HIPAA apply to HR into, or just patient health data?
Protected health information (PHI) under U.S. law is any information about health status, provision of health care, or payment for health care that is created or collected by a Covered Entity (or a Business Associate of a Covered Entity), and can be linked to a specific individual. This is interpreted rather broadly and includes any part of a patient's medical record or payment history. source: i run Wyndly (YC W21 h…
Covered Entity has a narrow meaning. Notably, if you don't accept insurance, it's very unlikely you're a covered entity.
Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#87Worth mentioning, because the authority level of medical practitioners throws people off. Don't ever give a doctor or practice your Social Security Number. They don't need it. Similarly if they want to check an ID that doesn't mean scan or photograph. Doctors, practices, etc are the worst at infosec. They have no training, basically no penalties if they do something wrong and all of that info is only to follow up in…
What do you do if they refuse to book an appointment without it?
(for SSN, never tried to prevent scanning of my ID)
Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#88Earlier quoted context omitted.
HIPAA avoidance is much narrower than that. Entities which perform administrative or managerial duties on behalf of a mandated organization that have to transmit PII to provide that service are also covered, even if the entity itself isn't a provider. If 'Uber for nurses' is acting on behalf of nurses, it probably doesn't apply? If it's acting on behalf of the hospitals (who are indisputably covered entities), then t…
I used to work in the field. HIPAA protects patient data, not provider data. If my understanding is correct that only nurse PII was leaked, this has nothing to do with HIPAA. In general, I've found that people tend to think HIPAA applies much, much more than it actually does. Like people thinking if you're in a meeting at work with clients and say "Sorry, Bob couldn't be here today, he's got the flu" that that's a HI…
Really, "Uber for Nurses" is a title to drum up interest. "Large Staffing Service" would be factually accurate.
Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket
#89Earlier quoted context omitted.
In the US, HIPAA is pretty much the strongest privacy legislation there is. There's probably no group that would have a more severe penalty for leaking your info than your healthcare provider.
How many healthcare providers do you know personally who have faced severe penalties for leaking information? The reality is that for a small doctor/dental/whatever office, there is essentially 0 risk. HIPAA violations that carry significant penalties go to huge hospitals and healthcare companies. Your neighborhood doctor has to screw up in a major way for an extended period of time to have a minute risk of any conse…
If they provably expose your data, and you report them, they will get fined. Or they would have last year, who knows if those people still have jobs.