[HN Gopher] DNA data of sexual assault victims exposed in breach...
       ___________________________________________________________________
        
       DNA data of sexual assault victims exposed in breach at US
       laboratory
        
       Author : carride
       Score  : 55 points
       Date   : 2022-02-26 14:35 UTC (8 hours ago)
        
 (HTM) web link (portswigger.net)
 (TXT) w3m dump (portswigger.net)
        
       | azinman2 wrote:
       | "The investigation determined an unauthorized party accessed the
       | network through an unknown vulnerability in a third-party
       | software provider's platform and may have compromised certain
       | personal and medical information.
       | 
       | Why do I have a feeling this was log4j...
        
       | sneak wrote:
       | There needs to be liability established for publishing private
       | and personal information; ideally criminal liability but even
       | civil would be a nice start.
       | 
       | They don't have meaningful security because they don't have to
       | have meaningful security.
        
         | 29athrowaway wrote:
         | Medical information at least is protected by HIPAA.
        
           | tzs wrote:
           | HIPAA doesn't apply as widely as most people think it does.
           | It applies to "covered entities" which are health plans,
           | health care clearinghouses, and health care providers.
           | 
           | Labs doing forensic work for police departments are probably
           | not covered entities.
        
             | theli0nheart wrote:
             | Business associates absolutely must abide by the HIPAA
             | Privacy Rule.
             | 
             | > _By law, the HIPAA Privacy Rule applies only to covered
             | entities - health plans, health care clearinghouses, and
             | certain health care providers. However, most health care
             | providers and health plans do not carry out all of their
             | health care activities and functions by themselves.
             | Instead, they often use the services of a variety of other
             | persons or businesses. The Privacy Rule allows covered
             | providers and health plans to disclose protected health
             | information to these "business associates" if the providers
             | or plans obtain satisfactory assurances that the business
             | associate will use the information only for the purposes
             | for which it was engaged by the covered entity, will
             | safeguard the information from misuse, and will help the
             | covered entity comply with some of the covered entity's
             | duties under the Privacy Rule._
             | 
             | Source: https://www.hhs.gov/hipaa/for-
             | professionals/privacy/guidance...
        
               | dontreact wrote:
               | A forensic lab doing things with DNA may have no business
               | relationship whatsoever with any covered entity (in fact
               | I would guess that this is the most likely case).
        
               | theli0nheart wrote:
               | Doesn't matter. If you're a business associate, you're
               | liable (both criminally and civilly) for violations of
               | the privacy rule, and if you share HIPAA covered data
               | with other businesses, those businesses must also adhere
               | to it.
        
               | Dracophoenix wrote:
               | How does that work for Apple Health?
        
               | theli0nheart wrote:
               | Apple Health facilitates transmitting electronic health
               | records on one's device with covered entities such as
               | clinics. For this reason, they are required by law to
               | maintain HIPAA compliance when entering into a business
               | agreement with these covered entities.
        
             | Teever wrote:
             | I wonder if the professionals who work at these labs can
             | face punishments from their professional organizations.
        
           | shagie wrote:
           | I suspect this is short tandem repeats - not full genome
           | data.
           | 
           | https://nij.ojp.gov/topics/articles/what-str-analysis
           | 
           | > Among the 3 million or so DNA bases that do not code for
           | proteins are regions with multiple copies of short repeating
           | sequences of these bases, which make up the DNA backbone (for
           | example, TATT). These sequences repeat a variable number of
           | times in different individuals. Such regions are called
           | "variable number short tandem repeats," and they are the
           | basis of STR analysis. A collection of these can give nearly
           | irrefutable evidence statistically of a person's identity
           | because the likelihood of two unrelated people having the
           | same number of repeated sequences in these regions becomes
           | increasingly small as more regions are analyzed.
           | 
           | http://www.biology.arizona.edu/human_bio/activities/blackett.
           | ..
           | 
           | https://forensicsdigest.com/short-tandem-repeats-or-strs/
           | 
           | https://youtu.be/9bEAJYnVVBA
           | 
           | This isn't data that you could reconstruct a genetic disease
           | from. It is more akin to a hash function for an individual's
           | genome. The data would be 13 pairs of numbers (13 STR loci
           | and the number of repeats on each chromosome at that
           | location).
           | 
           | This _would_ be PII, but likely not HIPAA.
        
         | smoyer wrote:
         | It's interesting because losing someone's PII that includes
         | information that can lead to financial fraud can bankrupt a
         | company. Losing someone's DNA data (or sharing it without
         | permission a la 23andme) doesn't have the potential for
         | financial losses. It will be interesting to see how this
         | company is penalized (HiPPA fines are pretty tame
         | comparatively.)
         | 
         | As an aside, in the relatively recent past I worked on a system
         | that contained data covered under HiPPA. We isolated the
         | systems (and networks) so that the health data itself had no
         | identifying information - just a unique key. When the user was
         | authenticated, their PII and the medical information was merged
         | on their browser screen. These two systems were properly
         | secured but I don't ever believe a system is invulnerable
         | (unless it has no network connection). Still, you'd have to
         | breach both systems to combine the data en masse.
        
           | Sebb767 wrote:
           | > It's interesting because losing someone's PII that includes
           | information that can lead to financial fraud can bankrupt a
           | company.
           | 
           | Experian seems to be doing quite fine
        
         | ameister14 wrote:
         | I think you'd have to establish ownership of the information.
         | Maybe you could call this a fiduciary breach because they're an
         | agent of the person giving them the DNA?
        
         | chaostheory wrote:
         | I think that was the point of HIPAA.
         | 
         | It's good to note that, if you make the penalty too high, then
         | it has the side effect of drastically increasing medical costs.
        
           | hedora wrote:
           | I doubt it. Here's an upper bound:
           | 
           | If the penalty was infinite, then they'd simply air-gap
           | patient (or victim DNA) information systems, and have
           | patients own / transfer their own medical records between
           | providers (perhaps on DVD's, because USB is a very broad
           | protocol).
           | 
           | The cost of that would he rounding error vs. other
           | inefficiencies in the US healthcare system.
        
         | hedora wrote:
         | There needs to be criminal liability for gathering the
         | information without permission.
         | 
         | Gathering = publishing for publicly held companies, since the
         | company could be acquired or subpoenaed.
        
         | Hokusai wrote:
         | > There needs to be liability established for publishing
         | private and personal information;
         | 
         | Europe has the General Data Protection Regulation.
        
       ___________________________________________________________________
       (page generated 2022-02-26 23:02 UTC)