Live data from Hacker News

'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

websiteplanet.com

81–90 of 193 posts

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#81

Earlier quoted context omitted.

HIPAA has strict rules with severe penalties, but enforcement is at best spotty. So honest hospitals and doctors offices bend over backwards to comply with the rules at great expense, but bad actors are rarely punished. It's the worst of both worlds. I'm pretty sure that is why the punishments are so harsh, because they need to put the fear of god into practitioners to make them take it seriously since there are so f…

It's the difference in medical establishment skill level between your doctor and you. You are always at a disadvantage. I've long thought that a disinterested third party needs to be involved. Someone with real oversight taking a position adversarial to the hospital and strictly to create the best possible outcome for the patient. The Hippocratic model isn't awesome.

In 2025 an oath don't mean shit.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#82

I'll need to dig up a source but I recently heard about this company and, apparently, before offering gigs they do a credit report to determine how much debt the person is carrying (i.e. how desperate they are) and they use that information to _round down_ the hourly rate they offer them. In the unlikely event that there are any negative consequences for this breach, they deserve every bit of them and more.

I’m interested, given the massive nursing shortages, why any nurses were using this service at all? Especially for higher levels, there’s no reason to mess with a shitty app that underpays you, when you should be able to walk into any provider’s office or facility and get hired almost immediately (and for Runs, you even have wide-ranging telehealth options).

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#83
post #70
post #58

Earlier quoted context omitted.

If you're not a direct health provider, you probably can. Don't take that as an endorsement.

If you partner with a healthcare provider to provide any sort of technical services, you will be required to sign a BAA (Business Associates Agreement), which makes you similarly liable to the HIPAA & HITECH acts.

It depends there are some exceptions.[0]

>With persons or organizations (e.g., janitorial service or electrician) whose functions or services do not involve the use or disclosure of protected health information, and where any access to protected health information by such persons would be incidental, if at all.

Based on the context from the article of the PHI uploaded being incidental, it would probably fall under this exception. It sounds like ESHYFT isn't meant to be storing any PHI based on the privacy policy above.

0:https://www.hhs.gov/hipaa/for-professionals/privacy/guidance...

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#84

Earlier quoted context omitted.

What do you do if they refuse to book an appointment without it?

Find a new provider. I have gone 2 decades without providing my SSN to doctors.

New provider is unrealistic for many in USA. In NYC, maybe easy; in rural WI/KS much less so.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#85

In the section of their Privacy Policy titled Data Security [0]: > We use certain physical, managerial, and technical safeguards that are designed to improve the integrity and security of information that we collect and maintain. Please be aware that no security measures are perfect or impenetrable. We cannot and do not guarantee that information about you will not be accessed, viewed, disclosed, altered, or destroye…

HIPAA only applies to a very specific entity called a "covered entity". At a high level, "covered entities" are health care providers that accept insurance or insurers. That's right, there's a massive caveat on "accepts insurance". You can be a healthcare provider and do not have to comply with HIPAA if you don't accept insurance.

That being said, HIPAA isn't even relevant here because "ESHYFT" is just a provider a labor. No different than a big consultant providing staff augmentation services.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#86
post #10

Earlier quoted context omitted.

Does HIPAA apply to HR into, or just patient health data?

Protected health information (PHI) under U.S. law is any information about health status, provision of health care, or payment for health care that is created or collected by a Covered Entity (or a Business Associate of a Covered Entity), and can be linked to a specific individual. This is interpreted rather broadly and includes any part of a patient's medical record or payment history. source: i run Wyndly (YC W21 h…

Yes, but you're missing a massive caveat that is conditional on the definition of "covered entity".

Covered Entity has a narrow meaning. Notably, if you don't accept insurance, it's very unlikely you're a covered entity.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#87
post #9

Worth mentioning, because the authority level of medical practitioners throws people off. Don't ever give a doctor or practice your Social Security Number. They don't need it. Similarly if they want to check an ID that doesn't mean scan or photograph. Doctors, practices, etc are the worst at infosec. They have no training, basically no penalties if they do something wrong and all of that info is only to follow up in…

What do you do if they refuse to book an appointment without it?

I've never had that happen (sample size ~5). They accept non-citizen patients, so they probably don't make SSN a required field.

(for SSN, never tried to prevent scanning of my ID)

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#88

Earlier quoted context omitted.

HIPAA avoidance is much narrower than that. Entities which perform administrative or managerial duties on behalf of a mandated organization that have to transmit PII to provide that service are also covered, even if the entity itself isn't a provider. If 'Uber for nurses' is acting on behalf of nurses, it probably doesn't apply? If it's acting on behalf of the hospitals (who are indisputably covered entities), then t…

I used to work in the field. HIPAA protects patient data, not provider data. If my understanding is correct that only nurse PII was leaked, this has nothing to do with HIPAA. In general, I've found that people tend to think HIPAA applies much, much more than it actually does. Like people thinking if you're in a meeting at work with clients and say "Sorry, Bob couldn't be here today, he's got the flu" that that's a HI…

ESHYFT isn't a covered entity, so HIPAA doesn't apply to them. Even if they have health data of their employees in their system, they're still not a covered entity.

Really, "Uber for Nurses" is a title to drum up interest. "Large Staffing Service" would be factually accurate.

Re: 'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket

#89
post #12

Earlier quoted context omitted.

In the US, HIPAA is pretty much the strongest privacy legislation there is. There's probably no group that would have a more severe penalty for leaking your info than your healthcare provider.

How many healthcare providers do you know personally who have faced severe penalties for leaking information? The reality is that for a small doctor/dental/whatever office, there is essentially 0 risk. HIPAA violations that carry significant penalties go to huge hospitals and healthcare companies. Your neighborhood doctor has to screw up in a major way for an extended period of time to have a minute risk of any conse…

How much information do you think your neighborhood PCP is “leaking” compared to, say, Elevance? This is such a goofy take. Are you expecting that every small provider group is just firing your data off on Facebook every Tuesday, and somehow, no one cares? They’re all using certified EMRs. They all take security seriously because their licenses are literally on the line. Do you work in healthcare?

If they provably expose your data, and you report them, they will get fined. Or they would have last year, who knows if those people still have jobs.

Post reply on HN