3 ms·
I wonder what it will take for data security to ever be taken seriously.
by ferros 6y ago
I wonder what it will take for data security to ever be taken seriously.
- NegativeLatency 6y agoEnforcement of monetary penalties.
- innagadadavida 6y agoIn this instance the company can declare bankruptcy and the founders and investors can move on to their next gig - perhaps even throw a hapless developer to the authorities. Unless hippa somehow has special provisions. They need to go after the personal wealth of founders and investors to make this a serious crime.
- WrtCdEvrydy 6y agoThat's the thing. If HIPAA could pierce the corporate veil, this could no longer occur. Wanna dick around and not do your job as a founder / investor? Your personal assets are on the line.
- gravypod 6y agoI don't think this is the case. Last I read up you are personally liable for HIPAA violations. If you do something, knew it wasn't something you should do, and refused to fix it, stuff gets really bad. To stay safe with medical data, however, you basically just need to hit whatever standard you think is reasonable. There's no established standards other than: 1. "PII" encrypted during storage/transfer. 2. Customers can request a download of their data. 3. Customers can request you delete ALL their data. 4. Fast track sec fixes above all other company goals.
- unishark 6y agoSomeone with a medical license and the legal ability to collect and secure data gave it to these clowns who clearly had no idea what they were doing.
- g_p 6y agoMy guess is the blame lies with insurers, probably keen to automate detection of "fraudulent whiplash claims" based on "the data". They'd get access to the records via their claims. This incident should show why sharing of data needs to be on a "need-to-share" basis by default if we want to have any hope of trying to stop this kind of thing in future.
- hackinthebochs 6y agoThis is the other side of the coin of "everyone can be a coder after a few months of self-study". We eschew the idea of licensing and the result is the general public suffers under technical incompetence.
- claudeganon 6y agoEven well-trained engineers engage in brazen acts of insecurity and data-harvesting because a lot of money can be made doing it. Just look at Facebook’s business model and breaches. They probably have more Stanford grads than boot campers.
- ZephyrBlu 6y agoThat's a strawman. You can have competent people working on these systems and still have breaches occur.
- hackinthebochs 6y agoOf course you can have data breaches even if you do everything right. But it takes incompetence to do everything wrong, especially when it involves medical records. The fact that this low hanging fruit of data leaks keeps happening is telling.
- photon12 6y agoA come to Jesus moment in the industry that if you produce code at a rate higher than you can mitigate risk in that code, you are not engineering but masturbating. It's a collective action problem that needs collective action. Individual incentive changes aren't going to cut it. Unfortunately many thought leaders in the industry have tried to build a culture of suggesting that the solution to collective action problems is individual iteration. Unless you want to keep pentesters like me burned out because the mail of dumb bugs doesn't stop coming until we all go postal.
- totetsu 6y agoWell somehow PCI compliance seems to work well enough for credit card payment processing. But what happens is, the payment handling is passed off to a vendor, so not every company has to get things right in house.. I wonder if that can be a solution here.. medical data is handled by external vendors.
- colechristensen 6y agoPCI compliance works because of the aligned financial interests of the actors. Most kinds of compliance are linked to legal costs as the ultimate source of consequences, not so for PCI. The ultimate costs for failing to comply with PCI are the actual costs of card fraud which don’t depend on anything in the legal system. When your regulations are designed and enforced by the entity that actually loses money when they aren’t followed, motivation lines up and they work better.
- totetsu 6y agoGood point. It seems like it might be hard for regulations to be designed and enforced by the losers of personal medical data leaks.
- photon12 6y agoCredit card data is relatively small cardinality and easy to predict the form of. Medical data is... not that
- bnegreve 6y agoI'm reposting a dead comment by photon12 which was probably killed for using too many profanities. I agree with this part: > It's a collective action problem that needs collective action. Individual incentive changes aren't going to cut it. Unfortunately many thought leaders in the industry have tried to build a culture of suggesting that the solution to collective action problems is individual iteration.