9 ms·
It's past time for us to get serious and apply HIPAA-style protection to the storage and transmission of PII, without exemptions. Companies like Facebook will
by leggomylibro 7y ago
It's past time for us to get serious and apply HIPAA-style protection to the storage and transmission of PII, without exemptions.
Companies like Facebook will complain loudly that they won't be able to survive, but that is not our problem. If we pass legislation with teeth, they will need to change their business model. That would be the point.
- ilikehurdles 7y agoZoom has allegedly HIPAA-compliant BAAs with users in the health space. If any PHI data is making it over to Facebook without a similar agreement from Facebook, Zoom is in for some trouble.
- spitfire 7y agoIP address, telephone number, city and other identifying information is ALL considered PII. I work with (adjacent industry) HIPAA protected data, which is considered PII by virtue of knowing Bob Smith is in the system. If they're under a BAA and sending that information to Facebook they're in violation. If one of my sub-processors did this my lawyer would be livid. But hey, it's Silicon Valley, don't harsh their buzz man.
- sizzle 7y agoHow do you even report something this technical to non technical folks who oversee HIPAA? Would you have to do a case study style write up?
- Ididntdothis 7y agoI am working on adding a Zoom client to a medical device right now :)
- modzu 7y agonote the reason hippa exists has nothing to do with protecting individuals; it was drafted to protect the insurance companies. it is absolutely not that health data is somehow "private" enough to warrant some special protection for the persons themselves
- 3minus1 7y agoI never heard this before. Can you explain how it protects insurance companies?
- AnthonyMouse 7y agoInsurance companies have incentives to get better data than their competitors, so they can offer less expensive coverage to lower risk people and leave the competing insurance companies with all the higher risk people. Until the competitors do the same thing. Then you're all just offering less expensive coverage to most of your customers and making less money. (That also tends to cause trouble for higher risk patients because insurance companies could more accurately predict ahead of time that they'll incur high costs and then charge them unaffordable premiums.) If the health data they would otherwise use for that is "private" then that isn't allowed, so providing insurance is riskier, will have fewer competitors, and commands higher premiums.
- TheSpiceIsLife 7y agoWikipedia claims: It was created primarily to modernize the flow of healthcare information, stipulate how Personally Identifiable Information maintained by the healthcare and healthcare insurance industries should be protected from fraud and theft, and address limitations on healthcare insurance coverage. Is the protected from fraud and theft part somehow incorrect? https://en.wikipedia.org/wiki/Health_Insurance_Portability_and_Accountability_Act https://en.wikipedia.org/wiki/Health_Insurance_Portability_a...
- AnthonyMouse 7y agoYou're now talking about a different section of the same act. There are some separate provisions in there to fight insurance fraud, but that doesn't really have a lot to do with privacy for medical records, except to the extent that having somebody else's medical records might make it easier to commit insurance fraud against their insurance policy.
- gazzini 7y agoI disagree with this — more regulation will make it harder to innovate. For example, I’ve met several founders who wanted to enable tele-medicine years ago but decided against it because “the lawyers cost more than the engineers”, and walking-on-eggshells destroys morale & iteration speed. I’m not arguing to de-regulate heath data — my point is that we should selectively apply regulation. It’s likely a great thing to regulate self-driving cars. But please keep the lawyers away from my niche online forums, 3rd-party clients for social apps, blogs, video games, calculators etc...
- danudey 7y agoIf a company can't 'innovate' without sharing users' data with third parties or treating it recklessly through lax security (or uploading database dumps to publicly-accessible S3 buckets) then that company doesn't deserve to be in business. It doesn't take a suite of lawyers to enforce that, either. Health care is gigantic mess of bullshit in the US especially, because of the multiple different 'stakeholders' - customers, insurance companies, brokers, "networks", hospitals, doctors, etc., and every mistake is a gigantic lawsuit waiting to happen. It's a disaster however you cut it. As for personal data for some arbitrary startup, any argument that "innovation" depends on being able to be careless or cavalier with that data is just ridiculous. Be careful with it. Store it properly. Only collect what you need, and delete the rest. Expunge data you no longer need. Never send it to any third party without asking the user, and provide clear information about where and with whom the data is processed and stored at rest. There, now you're being careful with user data and you can still "innovate" decent products, as long as your business model isn't user-hostile from the start.
- dahfizz 7y agoI think you've missed your parents point. The problem they point out is that well intentioned businesspeople who want to provide you a useful service and store your data correctly are priced out. If you want to deal with medical data of any kind, you need a lawyer. Full stop. It doesn't matter how good your intentions are, or how many "best practice" blog posts you follow. You need to hire a lawyer, and lawyers are incredibly expensive. > Be careful with it. Store it properly. Only collect what you need, and delete the rest. This is great advice, but that's not how laws work. Congress won't pass a law that says "store it properly". They are going to pass a law that describes how you can and cannot store data in 600+ pages of legalese. And no matter how properly you think you're doing things, you have to have a lawyer to know you're actually doing it properly. Said another way: regulation always adds cost and barriers to entry. These affect the "good" business just as much as the "bad" business.
- ngold 7y agoPeople aren't allowed to go through my mailbox and sell that information. I don't see how this is any different.
- gowld 7y agoThey are allowed to look at you and take notes and sell them.
- munk-a 7y agoDepending on the specifics they may not be. I live in a Condo tower and my mailbox isn't visible from the street, so if you decided to take notes on me as I read my mail you'd be trespassing. The specific scenario isn't the point - but the fact that a semi-obvious scenario could be incorrect sorta is. Regulations are complex and tech has a terrible history of playing fast and loose with regulations so it's not like an imposition of regulations would be inappropriate or unwarranted - there are good and bad apples, and the bad apples spoil the bunch.
- wolco 7y agoBeing in a public area in a private business doesn't afford you that privacy. The trepassing charge would be possible if a security guard asked the person to leave.
- godelski 7y agoStalking is considered illegal in most states and countries. Frankly I can't figure out why stalking a single person is illegal but stalking a billion people is considered good business.
- mehrdadn 7y agoI understand stalking involves more than taking notes and selling them though. The other person has to feel threatened or such. Now maybe you can/make the case that you feel threatened by Facebook, and maybe you can sue them individually (good luck), but I doubt you can make the case most people feel this way.
- _cyrus 7y agoA user agent is not PII
- godelski 7y agoWhat about a Unique Advertiser Identifier? What about a UAI with a name, phone number, phone model, GPS coordinates, and software version?
- dkersten 7y agoHad a briefing with our company lawyer a while back and any information can be considered PII when paired with other information. Eg that you bought 7 foo’s is not PII, but that you bought 7 foo’s on Tuesday might be if that can then be looked up in the purchase history and you were the only one who bought 7 on Tuesday.
- OJFord 7y agoDoes it have to be uniquely identifying to be PII? Or is there some minimum threshold for k-anonymity?
- dkersten 7y agoI don't know "how unique" it needs to be. I'll ask if I get the opportunity. It just has to be correlatable if I understood it correctly, but I don't know if unique or not. To me it sounded like if there's only a small number of possible people it could identify (say 4) then its potentially PII, however I have no idea where the line is drawn. Clearly if k is 1, its PII. If k is 2, it probably is too. If k is 1000, its probably not. But at what point does it stop being PII? I have no idea! The legal person basically said "its complicated, anything can become PII when combined with something else, even if neither on their own are PII". The bottom line is does some combination of information identify a person, then its PII (its in the name really!), but unfortunately that means there is no clear simple list of things that are or aren't PII, it really depends on each individual case. Her advice was to think carefully about any data stored about or for users and to avoid storing it if possible, and if not possible, think carefully about whether or not it could identify a user in some way. Its not a very satisfying answer, I know. It also doesn't answer your question :(
- BallinBige 7y agoit's time to stop using the f'ing apps mate
- bradly 7y agoMost users of Zoom aren't choosing it–it is being chosen for them. Both of my children's schools (preschool and elementary) started using Zoom this week, so it is either use Zoom or they do not get to participate.
- manigandham 7y agoZoom has a web version.
- madars 7y agoExcept Zoom web version doesn't work: the incoming/outgoing audio is garbled (tested with Chrome, they do not support Firefox). This is in part because they were obviously too good for WebRTC native audio and instead gutted ffmpeg and compiled it to WebAssembly (I wish I was kidding but I'm not: https://webrtchacks.com/zoom-avoids-using-webrtc/ https://webrtchacks.com/zoom-avoids-using-webrtc/). Moreover, Zoom has a history of RCEs (leaving an active web server after you uninstall Zoom? so that a website can reinstall Zoom without any user interaction? why not! https://medium.com/bugbountywriteup/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5 https://medium.com/bugbountywriteup/zoom-zero-day-4-million-...), and anti-privacy behavior: meeting host gets a copy of all private messages sent between participants (there is no notice of this; https://twitter.com/rcalo/status/1237957509324746752); https://twitter.com/rcalo/status/1237957509324746752); host can monitor if your Zoom window is active (https://twitter.com/zoom_us/status/1241768006327336963); https://twitter.com/zoom_us/status/1241768006327336963); and Zoom has audio fingerprint tracing (so if you get a leaked recording Zoom can blame a particular participant: https://venturebeat.com/2019/01/22/zoom-is-bringing-ultrasonic-signatures-to-business-calls-to-deter-leaks/ https://venturebeat.com/2019/01/22/zoom-is-bringing-ultrason...). Running it under strace reveals it is fingerprinting your device as well (idk if that gets sent anywhere but iOS app sends stuff to Facebook...). Zoom is creepy and should not be used. I keep a separate VM for it, as it clearly can not be trusted.
- m463 7y agoHIPAA ha... Kaiser Permanente will contact google analytics and doubleclick as you navigate their website, even when checking test results and contacting your doctor.
- shermozle 7y agoThey're not sending your name and address. They're sending the IDFA, device ID, of your device to Facebook. The fact that Facebook can link that device ID to your identity is on YOU. You logged into Facebook in their app to make that connection.
- leggomylibro 7y agoThey still record the data and maintain a profile on me even if I don't have an account and have never used their app. How is that my fault?
- munk-a 7y agoThis uses unnecessarily accusatory wording. But it is also both unhelpful and just flat out wrong - Facebook gets data fed from a lot of sources - it can start stitching up that data into a picture of you without you ever creating a Facebook account.
- sudosysgen 7y agoThis is simply false. Facebook creates phantom profiles to track users that don't even have a Facebook account.