7 ms·
$200k is an amazingly cheap fine for a HIPAA and PII breach of 114,979 peoples information. Each of those people could get like 1.5 bags of M&Ms. Other compani
by seized 3y ago
$200k is an amazingly cheap fine for a HIPAA and PII breach of 114,979 peoples information. Each of those people could get like 1.5 bags of M&Ms.
Other companies may be taking note, but more of the sheer affordability of that.
- Ekaros 3y agoIt is sad that these sort of discounts exist. You should never get discount with crimes, but the penalties should always scale linearly with amount of damage or importance. I think 200k for each person involved would be entirely reasonable and make the companies and people really fear these crimes.
- seized 3y agoAnd HIPAA spells out fines of up to a very high amount for breaches. This firm didn't even get the minimum fine per person.
- anonymouskimmer 3y ago> You should never get discount with crimes, but the penalties should always scale linearly with amount of damage or importance. I think "damage" and "importance" are important distinctions. I'd find it worse if a person non-violently stole $100 worth of goods from the homes of 50,000 people than stealing a Van Gogh from the home of one person. And I'd find the Van Gogh theft a bit worse than an equivalent theft from a bank. This is one case of negligence that led to the theft of all of these records. It also seems, at worst, negligence that led to the theft, not a purposeful disclosure. And not negligence in their license specialty (law), but IT negligence. Did Redmond take affirmative action to ensure all instances of its server software was patched? Redmond knows who it sold software to. Why would they not also be at fault? Servers are their specialty. Harsh penalties for negligence, even for serious events such as human death, should probably be limited to negligence within the scope of a person's or business' specialty. With less harsh penalties for incidental negligence.
- throwaway426079 3y agoIf your bank lost your money due to getting hacked would you just shrug and accept that they do money, not IT security and therefore it's outside scope for a negligence claim?
- anonymouskimmer 3y agoIf the negligence directly led to provable harm to me (such as getting evicted because I couldn't make rent), then I would want a negligence suit. If it didn't cause provable harm to me, merely some annoyance, and I got all of my money back from FDIC insurance, then I believe any negligence claim should be greatly limited, or even outside of scope, yes. If probable harm happens to people because of these record leaks I believe the law firm should be part of the joint liability to make that harm as financially whole as possible. But that's what a civil suit is for, not a DA enforcement.
- throwaway426079 3y agoNegligence doesn't work the way you describe with potential to be out of scope. It is a finding of fact: there was negligence or there was not. The law has a separate mechanism for situations that you might call 'out of scope' which is to award zero damages.
- anonymouskimmer 3y agoI understand that. You were the one who chose "scope" as the word to use to describe this and I was just using your word in order to facilitate conversation between us.
- albntomat0 3y agoI have to imagine a full time IT person was running the Exchange server, not a lawyer. This was a highly publicized vulnerability, with a patch readily available. There are degrees to negligence, and this one is only slightly better than literally leaving the door to their office open at night.
- tinus_hn 3y agoIf you take this as the cost of doing business you could probably sell the data and turn a profit.
- Veserv 3y agoCompanies should not be allowed to advertise blanket statements like: “We value your privacy.” Instead, they should be required to write into their privacy policy/contracts a pre-computed/liquidated damages clause in the event of breach and only be allowed to advertise that. So, in this case, they would only be able to advertise: “We value your privacy at $2.” And see how many takers they would get. If they want to make a more compelling privacy case, then they would be required to take on the risk of their increased promises in the event of breach. This allows small companies with no security to not get slaughtered as long as they accurately inform you of the risk profile of using their service, while preventing large companies that you would expect to be stable from lying about their guarantees.