5 ms·
Enforcing laws against illegal use of sensitive data sounds cool, except that only the most incompetent ones will ever meet that bar federally. HIPAA’s privacy
by csnover 4y ago
Enforcing laws against illegal use of sensitive data sounds cool, except that only the most incompetent ones will ever meet that bar federally. HIPAA’s privacy protections are so weak that companies can just shove things like this in their EULA[0] and they are good to go:
> Any information in the FollowMyHealth Universal Health Record is considered PHR Data. PHR Data might include, but is not limited to the following:
> Your name and contact information, such as your address, phone number, or email address
> Your medical history, conditions, treatments, and medications
> Your healthcare claims, health plan account numbers, bills, and insurance information
> Demographic information, such as your age, birthdate, gender, ethnicity, and occupation
> […]
> Allscripts may use your PHR Data for marketing and advertising purposes, including sending you customized marketing and advertising communications whether on our behalf or on behalf of third party partners with whom we may engage.
As a postscript, if you are curious how some Allscripts subsidiaries used PHR Data for marketing purposes in the past, the answer is to get doctors to push opioids[1].
[0] https://www.followmyhealth.com/UseDocuments/PrivacyPolicy https://www.followmyhealth.com/UseDocuments/PrivacyPolicy
[1] https://www.justice.gov/opa/pr/electronic-health-records-vendor-pay-145-million-resolve-criminal-and-civil-investigations-0 https://www.justice.gov/opa/pr/electronic-health-records-ven...
- bigbacaloa 4y agoThe whole idea of EULA needs to be scrapped. As currently configured they will never be fair to consumers. They institutionalize unethical, bad faith agreements.
- hackernewds 4y agoThats one side of the argument. However they are necessary for companies to function, and have some protections from fraudsters, con artists, hackers, litigious opportunitists, etc now you may argue that there are not freq enough instances of these frauds to require EULAs. anticipate that the counterargument could be that they aren't BECAUSE of the presence of EULAs
- jstanley 4y agoHow does an EULA defend against fraudsters, con artists, and hackers?
- ClumsyPilot 4y agoULAS didn't exist 50 years ago and we survives somehow! Now my phone, TV, and my floorlamp has a EULA. Industry thatsl can't function without EULA are the ones defrauding consumers, they should burn down to the ground.
- carapace 4y agoYou bought your phone, TV, and floorlamp from companies that should burn down to the ground? Is arson (metaphorical, I hope) really the best option here?
- ClumsyPilot 4y agodefinately the floorlamp one, iylt refuses to connect to the app because it's in a different country, the lamp is country-locked, its telling me what do to, and none of this was in the original contract of sale. Also arson is illegal. I am thinking more like witch-burning
- carapace 4y agoWitch-burning is, if anything, more illegal. (That lamp is messed up tho. I feel ya.)
- DelightOne 4y agoThe problem is that clauses unfair or suprising to the consumer are not considered invalid.
- Cthulhu_ 4y agounder US law anyway; some EULAs are unenforcable under EU laws.
- voxic11 4y ago> For a contract to be treated as a contract of adhesion, it must be presented on a standard form on a "take it or leave it" basis, and give one party no ability to negotiate because of their unequal bargaining position. The special scrutiny given to contracts of adhesion can be performed in a number of ways: > If the term was outside of the reasonable expectations of the person who did not write the contract, and if the parties were contracting on an unequal basis, then it will not be enforceable. The reasonable expectation is assessed objectively, looking at the prominence of the term, the purpose of the term and the circumstances surrounding acceptance of the contract. https://en.wikipedia.org/wiki/Standard_form_contract#Contracts_of_adhesion https://en.wikipedia.org/wiki/Standard_form_contract#Contrac...
- hourago 4y ago"By reading this message you agree that me [the writer of the message] gets access to all your data and that you [the reader of the message] agrees on using the data for all purposes deemed as necessary to exploit such data for fun and economic gain." EULAs are a joke and everybody knows that people does not read them.
- TylerE 4y agoThis fails contracts 101. There has to be consideration. Reading the contract is not consideration.
- bratwurst3000 4y agoCan you explain further please? Or give some links? Here in Germany reading those „internet contracts“ doesnt count in court because they are intentionaly unreadable and to long
- dan-robertson 4y agoIn common law jurisdictions contracts generally require consideration. Consideration is a technical legal term which roughly means that both sides need to have some kind of obligation. E.g. maybe I give my labour and you give me money. One weird consequence you used to get were friendly entities leading things to each other for trivial rents (e.g. one Oxford college might lease land to another for a few pence a year) instead of for free so that there is consideration.
- eftychis 4y agoThe counter-argument they would give is that you get to use the site/service, thus, that is your consideration -- of course consideration for both parties has to be balanced/equivalent. Thus, the "consideration." But contracts also require both parties to explicitly acknowledge them and understand them -- thus e.g. modifying in secret a contract before signing will just offer a cause for invalidation and fraud to be brought up etc. EULAs are hilarious in this respect that it is an open secret that only a few devout users read them or even skim them.