[HN Gopher] Health care data breach affects over 600k patients, ...
___________________________________________________________________
Health care data breach affects over 600k patients, Illinois agency
says
Author : toomuchtodo
Score : 132 points
Date : 2026-01-07 16:28 UTC (6 hours ago)
(HTM) web link (www.nprillinois.org)
(TXT) w3m dump (www.nprillinois.org)
| cosmotic wrote:
| I'm sure they "take security very seriously".
| A4ET8a8uTh0_v2 wrote:
| I will admit that a level of fatigue has reached me as well. I
| am not even sure what would be an appropriate remedy at this
| point. My information has been all over the place given
| multiple breaches the past few years ( and, I might add, my
| kid's info too as we visited a hospital for her once ).
|
| Anyway, short of collapsing current data broker system, I am
| not sure what the answer is. Experian debacle showed us they
| are too politically entrenched to be touched by regular means.
|
| At this point, I am going through life assuming most of my data
| is up for grabs. That is not a healthy way to live though.
| hmokiguess wrote:
| If you want to get more stressed about it and consider the
| impeding dystopian future, I invite you to think about the
| "harvest now, decrypt later" potential reality that quantum
| cryptography is going to enable.
|
| At some point, everything that we have ever assumed to be
| confidential and secure will be exposed and up for grabs.
| A4ET8a8uTh0_v2 wrote:
| It is a fascinating future, but wouldn't it imply quantum
| computing will be even more restricted ( either by law or
| pricing ) and AI hardware?
| hmokiguess wrote:
| You would hope so, with regards to law & policy, but then
| when you consider what is happening in the current times
| with the AI race it doesn't feel very likely.[1]
|
| [1] https://torrentfreak.com/annas-archive-urges-ai-
| copyright-ov...
| stackskipton wrote:
| >I am not even sure what would be an appropriate remedy at
| this point.
|
| It will have to be political and it's got to be fines/damages
| that are business impacting enough for companies to pause and
| be like A) Is it worth collecting this data and storing it
| forever? and B) If I don't treat InfoSec as important
| business function, it could cost me my business.
|
| It also clear that certification systems do not work and any
| law/policy around it should not offer any upside for
| acquiring them.
|
| EDIT: I also realize in United States, this won't happen.
| skeptic_ai wrote:
| Change name to a very common one. Much better privacy.
| EvanAnderson wrote:
| I grew up around some people with the last name "Null". I
| often wonder how they're doing for data privacy today.
| closeparen wrote:
| This has nothing to do with the "data broker system." Reading
| between the lines it was more of a "shadow IT" issue where
| employees were using some presumably third-party GIS service
| for a legitimate business purpose but without a proper
| authentication & authorization setup.
| A4ET8a8uTh0_v2 wrote:
| Assuming your tea leaf reading is correct, that particular
| third party would not even exist in its current form
| without 'data broker ecosystem'. It is, genuinely, the
| original sin.
| SilverElfin wrote:
| Would you like 2 years of credit monitoring? Or perhaps you can
| get $5 from this class action settlement.
| scottLobster wrote:
| Unfortunately there's no money in privacy, and a lot of money in
| either outright selling data or cutting costs to the bare minimum
| required to avoid legal liability.
|
| Wife and I are expecting our third child, and despite my not
| doing much googling or research into it (we already know a lot
| from the first two) the algorithms across the board found out
| somehow. Even my instagram "Explore" tab that I accidentally
| select every now and then started getting weirdly filled with
| pictures of pregnant women.
|
| It is what it is at this point. Also I finally got my last
| settlement check from Equifax, which paid for Chipotle. Yay!
| maxtaco wrote:
| Also on the front page of HN right now is a job posting for
| Optery (YC W22). Seems like they are growing really fast.
| vasco wrote:
| Could be as simple as buying a bunch of scent free soap /
| lotion and some specific vitamin supplements. Walmart / Target
| were able to detect pregnancy reliably back in 2012 from just
| their own shopping data.
| throwway120385 wrote:
| Regular purchase of prenatal vitamins is probably a huge
| marker for either being pregnant or intention to become
| pregnant.
| simulator5g wrote:
| Just shopping in the store and lingering by those products
| for a few moments is enough for the algorithm to detect a
| possible pregnancy. They use Bluetooth beacons & camera
| software to see how long you look at everything in the
| store.
| supertrope wrote:
| As new moms tend to change their consumer purchasing habits
| they are coveted by advertisers.
| http://www.nytimes.com/2012/02/19/magazine/shopping-habits.h...
| Certain cohorts and keywords are very valuable so even
| searching a medical condition once or clicking on a hiring ad
| for an in-demand job can shift ads toward that direction for a
| long time.
| jerlam wrote:
| Also possible they have your location if you went to the
| hospital. Maybe from any Meta "partners" or third party
| brokers.
| jablongo wrote:
| Interestingly in healthcare there is a correlation between
| companies that license/sell healthcare data to other ones
| (usually they try to do this in a revokable way with very
| stringent legal terms, but sometimes they just sell it if there
| is enough money involved) and their privacy stance... and it's
| not what you would think. Often it's these companies that are
| pushing for more stringent privacy laws and practices. For
| example, they could claim that they cannot share anonymized
| data with academic researchers, because of xyz virtuous privacy
| rules, when they are actually the ones making money off of
| selling patient data. It's an interesting phenomenon I have
| observed while working in the industry that seems to refute
| your claim that "there's no money in privacy". Another way to
| think about it is that they want to induce a lower overall
| supply for the commodity they are selling, and they do this by
| championing privacy rules.
| Xeoncross wrote:
| Restrict data collection? It would kill all startups and firmly
| entrance a terrible provider monopoly who can comply.
|
| Have the government own data collection? Yeah, I don't even know
| where to start with all the problems this would cause.
|
| Ignore it and let companies keep abusing customers? Nope.
|
| Stop letting class-action lawsuits slap the company's wrists and
| then give $0.16 payouts to everyone?
|
| What exactly do we do without killing innovation, building moats
| around incumbents, giving all the power to politicians who will
| just do what the lobbyists ask (statistically), or accepting
| things as is?
| gassi wrote:
| [deleted]
| nemomarx wrote:
| Why do the start ups need to collect data like this?
| thinkingtoilet wrote:
| I work for a medical technology company. How do you propose
| we service our customers without their medical data?
| cheeseomlit wrote:
| Ask for it?
| pear01 wrote:
| I hope you're joking...
|
| Otherwise it would suggest you think the problem is they
| didn't ask? When was the last time you saw a customer
| read a terms of service? Or better yet reject a product
| because of said terms once they hit that part of the
| customer journey?
|
| The issue isn't about asking it's that for take your pick
| of reasons no one ever says no. The asking is thus pro
| forma and irrelevant.
| nemomarx wrote:
| Does it need to be hosted on your servers? Could you
| provide something to the customers where they host the data
| or their local doctors office does it?
|
| Can you delete it after the shortest possible period of
| using it, potentially? Do you keep data after someone stops
| being a customer or stops actively using the tech?
| closeparen wrote:
| Having seen this world up close, the absolute last place
| you ever want your medical data to be is on the Windows
| Server in the closet of your local doctors office. The
| public cloud account of a Silicon Valley type company
| that hires reasonably competent people is Fort Knox by
| comparison.
| troupo wrote:
| We apply crippling fines on companies and executives that let
| these breaches happen.
|
| Yes, some breaches (actual hack attacks) are unavoidable, so
| you don't slap a fine on _every_ breach. But the vast majority
| of "breaches" are pure negligence.
| apercu wrote:
| > Restrict data collection? It would kill all startups and
| firmly entrance a terrible provider monopoly who can comply.
|
| That's a terrible argument for allowing our data to be sprayed
| everywhere. How about regulations with teeth that prohibit
| "dragons" from hoarding data about us? I do not care what the
| impact is on the "economy". That ship sailed with the current
| government in the US.
|
| Or, both more and less likely, cut us in on the revenue. That
| will at least help some of the time we have to waste doing a
| bunch of work every time some company "loses" our data.
|
| I'm tired of subsidizing the wealth and capital class. Pay us
| for holding our data or make our data toxic.
|
| Obviously my health provider and my bank need my data. But no
| one else does. And if my bank or health provider need to share
| my data with a third party it should be anonymized and
| tokenized.
|
| None of this is hard, we simply lack will (and most consumers,
| like voters are pretty ignorant).
| ourmandave wrote:
| Honestly I'd take the 16 cents. Usually its a discount voucher
| on a product you'd never buy.
|
| Or if it's a freebie then it's hidden behind a plain text link
| 3 levels deep on their website.
| logicchains wrote:
| The solution is to anonymize all data at the source, i.e. use a
| unique randomized ID as the key instead of someone's name/SSN.
| Then the medical provider would store the UID->name mapping in
| a separate, easily secured (and ideally air-gapped) system, for
| the few times it was necessary to use.
| renewiltord wrote:
| Until we can guarantee privacy and security maybe it's best we
| shut down Illinois health care system.
| jckahn wrote:
| Assuming this is a serious comment, what do you propose instead
| if the health system is shut down?
| renewiltord wrote:
| A system where no one's data is held electronically.
| xbar wrote:
| The last time this happened, did the AG prosecute the person who
| discovered the vulnerable data?
| larrymcp wrote:
| Ah, I think I recall the story you're referring to: reporter
| Josh Renaud of the St. Louis Post-Dispatch discovered that a
| public web site was exposing Social Security numbers of
| teachers in Missouri. He notified the site's administrators,
| and later published a story about the leak after it was fixed.
|
| The governor of Missouri at the time, Mike Parson, called him a
| hacker and advocated prosecuting him. Fortunately the
| prosecutor's office declined to file charges though.
| rvz wrote:
| I just heard a chorus of AI agents rejoicing that there's more
| private data now made public available to train on.
| swores wrote:
| It's not often anybody writes a sentence that combines
| cynicism/negativity about AI with anthropomorphising AI agents!
| sehugg wrote:
| _Several maps created to assist the agency with decisions -- like
| where to open new offices and allocate certain resources -- were
| made public through incorrect privacy settings between 2021 and
| 2025 ... the mapping website was unable to identify who viewed
| the maps ... implemented a secure map policy that prohibits
| uploading customer data to public mapping websites._
|
| So a state employee/contractor (doesn't say) uploaded
| unaggregated customer records to a mapping website hosted on the
| public internet?
| teeray wrote:
| Sounds like some patients are in for some lucrative free credit
| and identity monitoring /s
| gen220 wrote:
| FYI, there's a .gov-maintained portal where healthcare companies
| in the U.S. are legally obliged to publish data breaches. It's an
| interesting dataset!
|
| https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
| citizenpaul wrote:
| I've been saying this forever. Computer security is and always
| will be nothing more than theater for with some minimal effort to
| cover bases, like hiring an INFOSEC then ignoring them. No on in
| charge cares about security because the number of people in
| charge punished for these breaches is still ZERO.
| tonymet wrote:
| I've built Healthcare SAAS APIs that required custom integrations
| with EHR partners, as well as consulted on similar apps for
| others.
|
| On top of common OWASP vulnerabilities, the bigger concern is
| that EHR and provider service apps do not have the robust
| security practices needed to defend against attacks. They aren't
| doing active pen testing, red-teaming, supply chain auditing --
| all of the recurring and costly practices necessary to ensure
| asset security.
|
| There are many regulations, HIPAA being the most notable, but
| their requirements and the audit process are incredibly primitive
| . They are still using a 1990s threat model. Despite HIPAA audits
| being expensive, the discoveries are trivial, and they are not
| recurring, so vulns can originate between the audit duration and
| the audit summary delivery.
| didgetmaster wrote:
| Although almost every company issues a 'we care about your
| privacy' statement, but there is often very little 'money where
| your mouth is' resources to back that up.
|
| This is why I am almost always very reluctant to give out any
| information that is not absolutely necessary to provide me the
| service that I need. If they don't know it, they can't leak it.
|
| Every company wants you to fill out their standard form that
| tries to get you to volunteer way more info than they really
| need.
| 1970-01-01 wrote:
| And everyone was fired, the top management has stepped down, and
| the fines were so massive that nobody ever took a chance with
| sloppy security ever again. Oh, it's actually the opposite of all
| that.
___________________________________________________________________
(page generated 2026-01-07 23:00 UTC)