3 ms·
I think it's interesting that while there are a ton of breaches, we only know about them because HHS requires breach reporting when it affects over 500 patients
by jtwarren 8y ago
I think it's interesting that while there are a ton of breaches, we only know about them because HHS requires breach reporting when it affects over 500 patients. How often is this happening in other industries where such regulations don't exist?
- killjoywashere 8y agoThis is the thing. HIPAA is really a gold standard in data security legislation. As terrible as it is (e.g. the fax machine loophole, which is surely put there for lawyers), at least there's something punitive. And other things can be tied to it: grants, FDA can disbar them from collaborating in drug development, etc. Imagine breach notifications for a company like Facebook. FCC could disbar you from transmitting data over mobile networks.
- djrogers 8y agoIn California that’s been the law for over a decade. Arguably, California’s breach disclosure law is the reason we know about the vast majority of large breaches we hear about.