7 ms·
> To ensure Uber Health meets HIPAA standards, we have been working hard to develop, implement, and customize numerous safeguards. The stories I've seen about
by nathan_long 9y ago
> To ensure Uber Health meets HIPAA standards, we have been working hard to develop, implement, and customize numerous safeguards.
The stories I've seen about employees tracking individual riders lead me to view this skeptically.
- samstave 9y agoAny links to these stories, I’d like to read some. I’m sure there are people at Uber who are fascinated by seeing where celebs take ubers... and can’t blame them.
- cryptoz 9y agoReally? You can't blame them? For wanting to and then actually executing illegal methods of spying on someone's private life? I absolutely blame them. That's abhorrent behavior. Here are some juicy stories for you to read if you want to know the details of all the kinds of stupidity and evil it takes to invade someone's privacy like that. https://www.revealnews.org/article/uber-said-it-protects-you-from-spying-security-sources-say-otherwise/ https://www.revealnews.org/article/uber-said-it-protects-you...
- samstave 9y agoI didnt say it was OK - im saying "i cant blame them"=="I understand humans, and this is not a surprising outcome from having access to that data in a company known for sexual mis-conduct, crazy ceo egoist stories and illegally accessing an employees medical records, etc etc etc" So blame was the wrong word...
- lhorie 9y agoHIPAA violations can cost a lot of money (up to $50,000 per record, depending on the severity level). A single incident can cost a few million dollars in fines, so there's a _very_ strong incentive to do things the right way.
- cryptoz 9y agoUber executives have specifically stolen health records from a patient in order to attempt to create a media frenzy about how an Uber passenger who was raped by a driver was actually liar and a cheater. Uber executives went on a long-haul journey to insanely attempt to ruin the life of one of their customers, who had already been raped by one of their drivers, by stealing her medical documents and ridiculing her in public. No thanks Uber. There is absolutely no way I would use this service. Edit: It should also be remembered that Uber hired this driver, the rapist, as a known rapist (a recorded criminal history of being convicted for rape). Uber hired him without caring about his background or past criminal behaviour. Uber hired him with the knowledge that he could well be a rapist, since they declined to do a simple background check, presumably because it would "take too long" and they consider the occasional rape just a part of doing business. The evil behaviour and willful disregard for the safety of their normal Uber passengers - before trying to ruin their lives with deception, theft and lies - makes it 100% impossible to trust them about anything ever again, especially personal health. #DeleteUber.
- EggsOnToast 9y agoI'd like to agree with your position but in the current environment I can't. Uber is a shitty company, I can get on that bandwagon and ride it to the other end of the continent. But in my country, America, this sort of service is immensely valuable to the elderly community and yet there is a dire shortage of acceptably priced choices to provide for those peoples' needs. If Uber's service is priced better than the entrenched players then I'll sign that pact with blood.
- loceng 9y agoAllowing bad behaviour in order to get something cheaper is IMHO the wrong way to do things. If you want to look at why everything is so expensive, look at capitalism and all of the for-profit layers people add to cost structures - extracting value from society and adding a constant negative pressure to the quality of everyone's lives; whether the amount of extracted is reasonable or not is what needs to be looked at in each case. A certain minimum of transportation should likely be a right.
- jtmcmc 9y agoI would bet they have put access restrictions on these because violating hippa can be a felony whereas in general there are 0 legal requirements to restrict access to internal data to a company generally.
- matheusmoreira 9y agoSo if a company stores medical history data it's only required by law to prevent the data from leaking to the public? It's okay if a system administrator employed by the company has read access to people's medical records?
- arkades 9y agoNo. Anyone internal to the company viewing medical data without an explicit need is in violation of hipaa. But I don’t think that’s what the poster was saying.
- matheusmoreira 9y agoI see. I don't know the details of HIPAA but that seems reasonable. What kinds of needs justify use of the data?
- wallflower 9y agoOne example. A friend of mine who works at a hospital told me about a colleague (a nurse) who looked up her own test results since she was anxious and could not wait using her login to the main system (for providers). She got flagged in the system and reprimanded. Every access is logged.
- northern_lights 9y agoit's worth noting for others that this was almost certainly a hospital policy violation, not a hipaa violation. There's nothing in hipaa that prevents a person from accessing their own record (though I have heard hospital administrators try to claim otherwise).
- asabjorn 9y agoUber has strong internal data access controls at this point, and any user data access need a ticket and a justification before accessing.
- cryptoz 9y agoAfter nearly a decade of lying, cheating, intentionally breaking the laws of various countries, spying on paying cusomters, spying on other people, aggressively attacking and spying on journalists, of attempting to discredit victims of rape by Uber drivers, harassing their competition using illegal tactics and lying about it, etc, I don't care if they have "strong internal data access controls". They should have had that Day 1, they should never have lied or cheated and they certainly should not ever expect anyone to trust them about anything ever again. First, I doubt that it's true that they have strong controls. I don't trust organizations that have such a long, clear and bragging history of lying. Second, that sounds like the Titanic being unsinkable. As if I'm going to trust Uber with personal health data - they are the first group I'd suspect to try to sell that data under the table, the first group I'd expect to abuse the power, and also the first group I'd expect to suffer internal leaks or external hacks. No way I would trust this given the very recent and abhorrent behaviour of the executives at the company. Edit: Also this, > and any user data access need a ticket and a justification before accessing is not secure. Sounds to me like any user can make a ticket and create any justification they like. This is like the NSA saying "any user of our PRISM system is logged and watched" - but what happens when millions of tickets are going through? Is each one actually being carefully inspected for abuse? If Uber executives are in charge of this decision then no way do I trust it.
- asabjorn 9y agoIt will definitely take time for Uber to earn trust back, and it is fair that you feel the way you do. Hopefully Uber will earn your and other people’s trust through us showing over time that we continue doing the right thing. My intention here is not to go into details, which would not be appropriate for me as an engineer that doesn’t work on those aspects. I am only saying we care a lot about this.
- sudouser 9y agonow their creepily stalking methods will allow them to know when someone famous or a loveint is sick