3 ms·
> Win10 is not going to be installed in any business that needs high data security either for operations or regulatory requirements like HIPPA or the SEC, etc.
by rpgmaker 10y ago
> Win10 is not going to be installed in any business that needs high data security either for operations or regulatory requirements like HIPPA or the SEC, etc.
Nah, I have worked with HIPAA compliant businesses before and as long as the data MS collects isn't (demonstrably) leaked to malevolent third parties they won't care. They upgrade to whatever MS tells them to upgrade and these kind of OS issues aren't discussed at all. They care about the privacy of the information they deal with directly but whatever the OS does under the hood it's assumed to be proper.
- dmfdmf 10y agoI wouldn't be so blase. First, that was all true BEFORE Microsoft made Windows a marketing platform so all bets are off now. Also, that decision (what is safe and not safe) is not up to the regulated business to make, its up to the regulators. If you have not worked in a highly regulated business you can't know what this means in terms of arbitrary and unnecessary rulings and requirements imposed on a business, regardless of whether they make any sense. Moreover, for the first 10 years of its existence, HIPAA was a homeless step-child in the Federal government but fairly recently (5 years?) it found a enforcement home (and more importantly, a budget) in the Health and Human Services department. They are now building their budget and have developed their enforcement strategy that started with big insurance companies and large PPO/HMOs (you may have heard of some big cases in the news). HHS's plan is to ultimately push enforcement all the way down to the practice level. FYI, most IT companies don't know this but back in 2012 or 2013 the new HIPAA enforcement division issued a decree that HIPAA applies directly to any IT companies that service organizations that handle personal health data. Prior to that proclamation I was operating under a signed declaration with my clients that my business was not responsible for HIPAA enforcement or violations (I just fixed the computers). That method of limiting my exposure and liability, according to my lawyer, was no longer feasible and I could be hit directly with HIPAA violations and fines and they required onerous documentation and procedures when dealing with PHI. At that point, at significant cut to my income, I dropped all my healthcare/medical clients. In the long run the regulatory agencies are captured by the regulated business and the requirements imposed are fairly sensible but by my guess is that we are at least a decade away from that regarding HIPAA especially considering its only now starting to be enforced with audits and fines.
- rpgmaker 10y agoI wasn't suggesting that HIPAA compliant businesses were "blase" about data protection, just that (like many other businesses) they place way too much faith in Microsoft, sometimes sidestepping important and legitimate debates about their OS and where it's going.