[HN Gopher] DNA data of sexual assault victims exposed in breach...
___________________________________________________________________
DNA data of sexual assault victims exposed in breach at US
laboratory
Author : carride
Score : 55 points
Date : 2022-02-26 14:35 UTC (8 hours ago)
(HTM) web link (portswigger.net)
(TXT) w3m dump (portswigger.net)
| azinman2 wrote:
| "The investigation determined an unauthorized party accessed the
| network through an unknown vulnerability in a third-party
| software provider's platform and may have compromised certain
| personal and medical information.
|
| Why do I have a feeling this was log4j...
| sneak wrote:
| There needs to be liability established for publishing private
| and personal information; ideally criminal liability but even
| civil would be a nice start.
|
| They don't have meaningful security because they don't have to
| have meaningful security.
| 29athrowaway wrote:
| Medical information at least is protected by HIPAA.
| tzs wrote:
| HIPAA doesn't apply as widely as most people think it does.
| It applies to "covered entities" which are health plans,
| health care clearinghouses, and health care providers.
|
| Labs doing forensic work for police departments are probably
| not covered entities.
| theli0nheart wrote:
| Business associates absolutely must abide by the HIPAA
| Privacy Rule.
|
| > _By law, the HIPAA Privacy Rule applies only to covered
| entities - health plans, health care clearinghouses, and
| certain health care providers. However, most health care
| providers and health plans do not carry out all of their
| health care activities and functions by themselves.
| Instead, they often use the services of a variety of other
| persons or businesses. The Privacy Rule allows covered
| providers and health plans to disclose protected health
| information to these "business associates" if the providers
| or plans obtain satisfactory assurances that the business
| associate will use the information only for the purposes
| for which it was engaged by the covered entity, will
| safeguard the information from misuse, and will help the
| covered entity comply with some of the covered entity's
| duties under the Privacy Rule._
|
| Source: https://www.hhs.gov/hipaa/for-
| professionals/privacy/guidance...
| dontreact wrote:
| A forensic lab doing things with DNA may have no business
| relationship whatsoever with any covered entity (in fact
| I would guess that this is the most likely case).
| theli0nheart wrote:
| Doesn't matter. If you're a business associate, you're
| liable (both criminally and civilly) for violations of
| the privacy rule, and if you share HIPAA covered data
| with other businesses, those businesses must also adhere
| to it.
| Dracophoenix wrote:
| How does that work for Apple Health?
| theli0nheart wrote:
| Apple Health facilitates transmitting electronic health
| records on one's device with covered entities such as
| clinics. For this reason, they are required by law to
| maintain HIPAA compliance when entering into a business
| agreement with these covered entities.
| Teever wrote:
| I wonder if the professionals who work at these labs can
| face punishments from their professional organizations.
| shagie wrote:
| I suspect this is short tandem repeats - not full genome
| data.
|
| https://nij.ojp.gov/topics/articles/what-str-analysis
|
| > Among the 3 million or so DNA bases that do not code for
| proteins are regions with multiple copies of short repeating
| sequences of these bases, which make up the DNA backbone (for
| example, TATT). These sequences repeat a variable number of
| times in different individuals. Such regions are called
| "variable number short tandem repeats," and they are the
| basis of STR analysis. A collection of these can give nearly
| irrefutable evidence statistically of a person's identity
| because the likelihood of two unrelated people having the
| same number of repeated sequences in these regions becomes
| increasingly small as more regions are analyzed.
|
| http://www.biology.arizona.edu/human_bio/activities/blackett.
| ..
|
| https://forensicsdigest.com/short-tandem-repeats-or-strs/
|
| https://youtu.be/9bEAJYnVVBA
|
| This isn't data that you could reconstruct a genetic disease
| from. It is more akin to a hash function for an individual's
| genome. The data would be 13 pairs of numbers (13 STR loci
| and the number of repeats on each chromosome at that
| location).
|
| This _would_ be PII, but likely not HIPAA.
| smoyer wrote:
| It's interesting because losing someone's PII that includes
| information that can lead to financial fraud can bankrupt a
| company. Losing someone's DNA data (or sharing it without
| permission a la 23andme) doesn't have the potential for
| financial losses. It will be interesting to see how this
| company is penalized (HiPPA fines are pretty tame
| comparatively.)
|
| As an aside, in the relatively recent past I worked on a system
| that contained data covered under HiPPA. We isolated the
| systems (and networks) so that the health data itself had no
| identifying information - just a unique key. When the user was
| authenticated, their PII and the medical information was merged
| on their browser screen. These two systems were properly
| secured but I don't ever believe a system is invulnerable
| (unless it has no network connection). Still, you'd have to
| breach both systems to combine the data en masse.
| Sebb767 wrote:
| > It's interesting because losing someone's PII that includes
| information that can lead to financial fraud can bankrupt a
| company.
|
| Experian seems to be doing quite fine
| ameister14 wrote:
| I think you'd have to establish ownership of the information.
| Maybe you could call this a fiduciary breach because they're an
| agent of the person giving them the DNA?
| chaostheory wrote:
| I think that was the point of HIPAA.
|
| It's good to note that, if you make the penalty too high, then
| it has the side effect of drastically increasing medical costs.
| hedora wrote:
| I doubt it. Here's an upper bound:
|
| If the penalty was infinite, then they'd simply air-gap
| patient (or victim DNA) information systems, and have
| patients own / transfer their own medical records between
| providers (perhaps on DVD's, because USB is a very broad
| protocol).
|
| The cost of that would he rounding error vs. other
| inefficiencies in the US healthcare system.
| hedora wrote:
| There needs to be criminal liability for gathering the
| information without permission.
|
| Gathering = publishing for publicly held companies, since the
| company could be acquired or subpoenaed.
| Hokusai wrote:
| > There needs to be liability established for publishing
| private and personal information;
|
| Europe has the General Data Protection Regulation.
___________________________________________________________________
(page generated 2022-02-26 23:02 UTC)