4 ms·
I worked as a bioinformatician at a medical device company. We did genetic testing on cancer patients, and had huge amounts of private, personal information on
by biotinker 4y ago
I worked as a bioinformatician at a medical device company. We did genetic testing on cancer patients, and had huge amounts of private, personal information on the patients we were testing, because it was necessary to provide the correct clinical determination.
We also didn't have bossware. There were access controls on the data itself, audit trails on who accessed the data, but no software running locally on my personal dev machine looking at what I did at any particular moment.
HIPAA governs the storage, transport, and use of that health information, and we all knew we were criminally liable if the information got out.
Bossware in a HIPAA environment (or other environment where not having leaks in important) can be more of a liability than a boon, because it becomes yet another vector for attack or data leakage. You are in effect sharing all data a machine can access, with the maker of the bossware.
Something with the teeth of HIPAA but for other pieces of personal information could go a long way. It's amazing how differently executives behave when the consequences of data leaks change from "customers could be unhappy if they found out" to "I could personally go to prison".