Private Medical Data of Over 1.5 Million People Exposed Through Amazon
Gizmodo reports that a wide variety of information about 1.5 million people -- everything from police injury reports, doctor's notes about their patients, and social security numbers -- "all were inexplicably unveiled on a public subdomain of Amazon Web Services. Welcome to the next big data breach horrorshow. Instead of hackers, it's old-fashioned neglect that exposed your most sensitive information."
From the article: Tomorrow, [Texas-based researcher Chris Vickers, who discovered the breach] will turn over the data to the the Texas Attorney General, where it will be destroyed. But that doesn’t mean Systema is in the clear. Vickers may not be the only person who downloaded those millions of records as they sat out in the Amazon cloud.
We don’t know how long the information was available for everyone to see. But no matter what the timeframe, the neglect could be a HIPAA violation: Systema failed to protect the security of patients’ electronic medical information.
is secure enough to store sensitive personal data....
Should probably be pointed out that this has nothing to do with amazon other than it was their web hosting used.
So Systema is at fault for not securing the data, but the headline pins it on Amazon?
All my liberal friends think I'm a conservative, all my conservative friends think I'm a liberal.
Unfortunately, Paxton is being prosecuted for being a con man who convinced a number of people to invest under false pretenses. I can imagine that by Monday he will put the data up for sale on the 'Dark Web' to fund his defense and imminent life as a fugitive in an undisclosed tropical locations.
"She's a scientist and a lesbian. She's not going to let it slide." Orphan Black
So someone is going to jail for this and the company will soon be bankrupt, right?
Oh wait, none of this will happen, because the government is controlled by corporations. Just like the GM story where the cover-up led to people dying. No one will ever serve any time for killing people in this manner.
The real "Libtards" are the Libertarians!
"Tomorrow, Vickery will turn over the data to the the Texas Attorney General, where it will be destroyed. "
See? They're going to destroy it!
How can this possibly be "Might be a HIPPA violation?"
It is precisely what HIPPA was created to protect against.
Why does plain text still exist? Or put it another way, why is anyone who has data they must protect able to put such data into a program that will export, import or otherwise be accessed by an external system *without* an encryption key?
I know it's a stupid question, but being able to just dump a database to text is just totally wrong, no? Nobody seems to be phased by SSL over HTTP, after all. Excel, Outlook, Oracle, MySQL, etc. - stop the madness!
"And the meaning of words; when they cease to function; when will it start worrying you?"
Fuck all these people. They need to be held accountable. This should be a capitol offense. That would put a chill into all these so called "programmers", who are really nothing more than glorified mop masters.
"This is not like a tenant being responsible for what they do in their building, over which they have a high degree of control"
Have you ever used S3? That is almost exactly what it is like.
Error 404 - Sig Not Found
You looked at thei the website?
https://aws.amazon.com/ Why yes, yes I did. Awesome thing, this intertoobz
The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
At least the guy isn't being criminally held liable for bringing this to everyone's attention.
So Amazon, or whomever, lets 1.5 million personal medical records get into the wild. Will there be Congressional investigations considering this is substantially more than what happened to the IRS?
Where were the investigations about Target and its breach of 40 MILLION credit and debit card numbers?
Or is this simply another example of private industry doing it better than government?
We will bankrupt ourselves in the vain search for absolute security. -- Dwight D. Eisenhower
You have extremely fine-grained software control over what does and does not reach the machine.
Error 404 - Sig Not Found