5 ms·
I assume they kept these in a database, which was sent or exported in some way to use Move-IT to transfer somewhere else. The hack was at Move-IT's servers I th
by coldcode 3y ago
I assume they kept these in a database, which was sent or exported in some way to use Move-IT to transfer somewhere else. The hack was at Move-IT's servers I think, which allowed people to read the contents. The question I have is was this information encrypted by DD or did they just assume Move-IT was safe? If the latter, it's pretty stupid.
- paulcole 3y agoI’ve done a lot of research into HIPAA (I work in a dental-adjacent field) and my guess is that it’s almost certainly the latter – an assumption, maybe based on something they were told. But it’s still on them regardless of whether they were deceived or simply didn’t ask. There have been very few dental practices who have paid fines for HIPAA violations and one that stands out is one who hired a document shredding firm to destroy old paper patient records. The shredders pick up a bunch of files and just drove around the corner and hucked them into an open dumpster where they were found. The dentist was fined as the result of their assumption that a document shredding firm would, you know, shred documents.
- Scoundreller 3y agoNot USA, but we had a case where the discarded unshredded health files somehow ended up being used in a movie shoot for “special effects” and strewn all over a street somewhere. https://decisions.ipc.on.ca/ipc-cipvp/phipa/en/item/135056/index.do?site_preference=normal https://decisions.ipc.on.ca/ipc-cipvp/phipa/en/item/135056/i... Another where a manager lit a big bonfire at home but put in too much at a time and they asteroided around in burnt and unburnt manner. Pre-tech breaches :)