3 ms·
I worked in healthcare for ~20 years. The worst casual breach I ever witnessed was a state health director emailing an unencrypted spreadsheet of all of that st
by duffpkg 6y ago
I worked in healthcare for ~20 years. The worst casual breach I ever witnessed was a state health director emailing an unencrypted spreadsheet of all of that states HIV+ persons to a widespread mailing list including name, DOB, SSN, etc. Sadly it was not accidental (would that be better?). Even worse no one batted an eye and it was not even a notable event.
For all the HIPAA lip service paid at the front end in many sites, all the data walks wholesale out the backend to an absolute parade of "hipaa business associates". It is a firehouse of data that is vacuumed by almost everyone.
Health and human services has statutory authority to fine $50k per patient violation. They never ever ever do and so no one really cares.
- stephenhuey 6y agoI’ve worked in 2 healthcare software startups and hearing this is maddening both for the privacy violation and the sheer amount of effort multitudes of IT workers put into safeguarding Protected Health Information. One would hope that there would be more repercussions than fines for willfully sharing the very thing so many expend so much time & energy to protect (and also of course for exposing something so personal to those patients).