5 ms·
> As someone who has worked in this field, I'm not. Marketing is generally exempt from massive legal review as they hand wave away "We don't deal with HIPPA dat
by chimeracoder 1y ago
> As someone who has worked in this field, I'm not. Marketing is generally exempt from massive legal review as they hand wave away "We don't deal with HIPPA data" and developers just wanting marketing to go away, dropped the Javascript block into files that were used for a ton of products including HIPAA containing ones.
I don't know why you're being downvoted, because this is unfortunately quite accurate. You'd be shocked how often this happens, even for tools they think are totally secure and "HIPAA-compliant".
> EDIT: Most of these places are just feature factories with offshore developers who are very unlikely to raise concerns.
I don't think there's any meaningful difference based on where the developers are located. The developers aren't the ones making the decisions. Usually the issue is that the higher-ups want it, which is why practices can continue even after concerns are raised.
- gausswho 1y agoI worked at an org that give Google Tag Manager access to marketing, effectively as means of bypassing engineering to try whatever spyslime of the month they could paste into a box.