[HN Gopher] Health care data breach affects over 600k patients, ...
       ___________________________________________________________________
        
       Health care data breach affects over 600k patients, Illinois agency
       says
        
       Author : toomuchtodo
       Score  : 132 points
       Date   : 2026-01-07 16:28 UTC (6 hours ago)
        
 (HTM) web link (www.nprillinois.org)
 (TXT) w3m dump (www.nprillinois.org)
        
       | cosmotic wrote:
       | I'm sure they "take security very seriously".
        
         | A4ET8a8uTh0_v2 wrote:
         | I will admit that a level of fatigue has reached me as well. I
         | am not even sure what would be an appropriate remedy at this
         | point. My information has been all over the place given
         | multiple breaches the past few years ( and, I might add, my
         | kid's info too as we visited a hospital for her once ).
         | 
         | Anyway, short of collapsing current data broker system, I am
         | not sure what the answer is. Experian debacle showed us they
         | are too politically entrenched to be touched by regular means.
         | 
         | At this point, I am going through life assuming most of my data
         | is up for grabs. That is not a healthy way to live though.
        
           | hmokiguess wrote:
           | If you want to get more stressed about it and consider the
           | impeding dystopian future, I invite you to think about the
           | "harvest now, decrypt later" potential reality that quantum
           | cryptography is going to enable.
           | 
           | At some point, everything that we have ever assumed to be
           | confidential and secure will be exposed and up for grabs.
        
             | A4ET8a8uTh0_v2 wrote:
             | It is a fascinating future, but wouldn't it imply quantum
             | computing will be even more restricted ( either by law or
             | pricing ) and AI hardware?
        
               | hmokiguess wrote:
               | You would hope so, with regards to law & policy, but then
               | when you consider what is happening in the current times
               | with the AI race it doesn't feel very likely.[1]
               | 
               | [1] https://torrentfreak.com/annas-archive-urges-ai-
               | copyright-ov...
        
           | stackskipton wrote:
           | >I am not even sure what would be an appropriate remedy at
           | this point.
           | 
           | It will have to be political and it's got to be fines/damages
           | that are business impacting enough for companies to pause and
           | be like A) Is it worth collecting this data and storing it
           | forever? and B) If I don't treat InfoSec as important
           | business function, it could cost me my business.
           | 
           | It also clear that certification systems do not work and any
           | law/policy around it should not offer any upside for
           | acquiring them.
           | 
           | EDIT: I also realize in United States, this won't happen.
        
           | skeptic_ai wrote:
           | Change name to a very common one. Much better privacy.
        
             | EvanAnderson wrote:
             | I grew up around some people with the last name "Null". I
             | often wonder how they're doing for data privacy today.
        
           | closeparen wrote:
           | This has nothing to do with the "data broker system." Reading
           | between the lines it was more of a "shadow IT" issue where
           | employees were using some presumably third-party GIS service
           | for a legitimate business purpose but without a proper
           | authentication & authorization setup.
        
             | A4ET8a8uTh0_v2 wrote:
             | Assuming your tea leaf reading is correct, that particular
             | third party would not even exist in its current form
             | without 'data broker ecosystem'. It is, genuinely, the
             | original sin.
        
         | SilverElfin wrote:
         | Would you like 2 years of credit monitoring? Or perhaps you can
         | get $5 from this class action settlement.
        
       | scottLobster wrote:
       | Unfortunately there's no money in privacy, and a lot of money in
       | either outright selling data or cutting costs to the bare minimum
       | required to avoid legal liability.
       | 
       | Wife and I are expecting our third child, and despite my not
       | doing much googling or research into it (we already know a lot
       | from the first two) the algorithms across the board found out
       | somehow. Even my instagram "Explore" tab that I accidentally
       | select every now and then started getting weirdly filled with
       | pictures of pregnant women.
       | 
       | It is what it is at this point. Also I finally got my last
       | settlement check from Equifax, which paid for Chipotle. Yay!
        
         | maxtaco wrote:
         | Also on the front page of HN right now is a job posting for
         | Optery (YC W22). Seems like they are growing really fast.
        
         | vasco wrote:
         | Could be as simple as buying a bunch of scent free soap /
         | lotion and some specific vitamin supplements. Walmart / Target
         | were able to detect pregnancy reliably back in 2012 from just
         | their own shopping data.
        
           | throwway120385 wrote:
           | Regular purchase of prenatal vitamins is probably a huge
           | marker for either being pregnant or intention to become
           | pregnant.
        
             | simulator5g wrote:
             | Just shopping in the store and lingering by those products
             | for a few moments is enough for the algorithm to detect a
             | possible pregnancy. They use Bluetooth beacons & camera
             | software to see how long you look at everything in the
             | store.
        
         | supertrope wrote:
         | As new moms tend to change their consumer purchasing habits
         | they are coveted by advertisers.
         | http://www.nytimes.com/2012/02/19/magazine/shopping-habits.h...
         | Certain cohorts and keywords are very valuable so even
         | searching a medical condition once or clicking on a hiring ad
         | for an in-demand job can shift ads toward that direction for a
         | long time.
        
         | jerlam wrote:
         | Also possible they have your location if you went to the
         | hospital. Maybe from any Meta "partners" or third party
         | brokers.
        
         | jablongo wrote:
         | Interestingly in healthcare there is a correlation between
         | companies that license/sell healthcare data to other ones
         | (usually they try to do this in a revokable way with very
         | stringent legal terms, but sometimes they just sell it if there
         | is enough money involved) and their privacy stance... and it's
         | not what you would think. Often it's these companies that are
         | pushing for more stringent privacy laws and practices. For
         | example, they could claim that they cannot share anonymized
         | data with academic researchers, because of xyz virtuous privacy
         | rules, when they are actually the ones making money off of
         | selling patient data. It's an interesting phenomenon I have
         | observed while working in the industry that seems to refute
         | your claim that "there's no money in privacy". Another way to
         | think about it is that they want to induce a lower overall
         | supply for the commodity they are selling, and they do this by
         | championing privacy rules.
        
       | Xeoncross wrote:
       | Restrict data collection? It would kill all startups and firmly
       | entrance a terrible provider monopoly who can comply.
       | 
       | Have the government own data collection? Yeah, I don't even know
       | where to start with all the problems this would cause.
       | 
       | Ignore it and let companies keep abusing customers? Nope.
       | 
       | Stop letting class-action lawsuits slap the company's wrists and
       | then give $0.16 payouts to everyone?
       | 
       | What exactly do we do without killing innovation, building moats
       | around incumbents, giving all the power to politicians who will
       | just do what the lobbyists ask (statistically), or accepting
       | things as is?
        
         | gassi wrote:
         | [deleted]
        
         | nemomarx wrote:
         | Why do the start ups need to collect data like this?
        
           | thinkingtoilet wrote:
           | I work for a medical technology company. How do you propose
           | we service our customers without their medical data?
        
             | cheeseomlit wrote:
             | Ask for it?
        
               | pear01 wrote:
               | I hope you're joking...
               | 
               | Otherwise it would suggest you think the problem is they
               | didn't ask? When was the last time you saw a customer
               | read a terms of service? Or better yet reject a product
               | because of said terms once they hit that part of the
               | customer journey?
               | 
               | The issue isn't about asking it's that for take your pick
               | of reasons no one ever says no. The asking is thus pro
               | forma and irrelevant.
        
             | nemomarx wrote:
             | Does it need to be hosted on your servers? Could you
             | provide something to the customers where they host the data
             | or their local doctors office does it?
             | 
             | Can you delete it after the shortest possible period of
             | using it, potentially? Do you keep data after someone stops
             | being a customer or stops actively using the tech?
        
               | closeparen wrote:
               | Having seen this world up close, the absolute last place
               | you ever want your medical data to be is on the Windows
               | Server in the closet of your local doctors office. The
               | public cloud account of a Silicon Valley type company
               | that hires reasonably competent people is Fort Knox by
               | comparison.
        
         | troupo wrote:
         | We apply crippling fines on companies and executives that let
         | these breaches happen.
         | 
         | Yes, some breaches (actual hack attacks) are unavoidable, so
         | you don't slap a fine on _every_ breach. But the vast majority
         | of  "breaches" are pure negligence.
        
         | apercu wrote:
         | > Restrict data collection? It would kill all startups and
         | firmly entrance a terrible provider monopoly who can comply.
         | 
         | That's a terrible argument for allowing our data to be sprayed
         | everywhere. How about regulations with teeth that prohibit
         | "dragons" from hoarding data about us? I do not care what the
         | impact is on the "economy". That ship sailed with the current
         | government in the US.
         | 
         | Or, both more and less likely, cut us in on the revenue. That
         | will at least help some of the time we have to waste doing a
         | bunch of work every time some company "loses" our data.
         | 
         | I'm tired of subsidizing the wealth and capital class. Pay us
         | for holding our data or make our data toxic.
         | 
         | Obviously my health provider and my bank need my data. But no
         | one else does. And if my bank or health provider need to share
         | my data with a third party it should be anonymized and
         | tokenized.
         | 
         | None of this is hard, we simply lack will (and most consumers,
         | like voters are pretty ignorant).
        
         | ourmandave wrote:
         | Honestly I'd take the 16 cents. Usually its a discount voucher
         | on a product you'd never buy.
         | 
         | Or if it's a freebie then it's hidden behind a plain text link
         | 3 levels deep on their website.
        
         | logicchains wrote:
         | The solution is to anonymize all data at the source, i.e. use a
         | unique randomized ID as the key instead of someone's name/SSN.
         | Then the medical provider would store the UID->name mapping in
         | a separate, easily secured (and ideally air-gapped) system, for
         | the few times it was necessary to use.
        
       | renewiltord wrote:
       | Until we can guarantee privacy and security maybe it's best we
       | shut down Illinois health care system.
        
         | jckahn wrote:
         | Assuming this is a serious comment, what do you propose instead
         | if the health system is shut down?
        
           | renewiltord wrote:
           | A system where no one's data is held electronically.
        
       | xbar wrote:
       | The last time this happened, did the AG prosecute the person who
       | discovered the vulnerable data?
        
         | larrymcp wrote:
         | Ah, I think I recall the story you're referring to: reporter
         | Josh Renaud of the St. Louis Post-Dispatch discovered that a
         | public web site was exposing Social Security numbers of
         | teachers in Missouri. He notified the site's administrators,
         | and later published a story about the leak after it was fixed.
         | 
         | The governor of Missouri at the time, Mike Parson, called him a
         | hacker and advocated prosecuting him. Fortunately the
         | prosecutor's office declined to file charges though.
        
       | rvz wrote:
       | I just heard a chorus of AI agents rejoicing that there's more
       | private data now made public available to train on.
        
         | swores wrote:
         | It's not often anybody writes a sentence that combines
         | cynicism/negativity about AI with anthropomorphising AI agents!
        
       | sehugg wrote:
       | _Several maps created to assist the agency with decisions -- like
       | where to open new offices and allocate certain resources -- were
       | made public through incorrect privacy settings between 2021 and
       | 2025 ... the mapping website was unable to identify who viewed
       | the maps ... implemented a secure map policy that prohibits
       | uploading customer data to public mapping websites._
       | 
       | So a state employee/contractor (doesn't say) uploaded
       | unaggregated customer records to a mapping website hosted on the
       | public internet?
        
       | teeray wrote:
       | Sounds like some patients are in for some lucrative free credit
       | and identity monitoring /s
        
       | gen220 wrote:
       | FYI, there's a .gov-maintained portal where healthcare companies
       | in the U.S. are legally obliged to publish data breaches. It's an
       | interesting dataset!
       | 
       | https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
        
       | citizenpaul wrote:
       | I've been saying this forever. Computer security is and always
       | will be nothing more than theater for with some minimal effort to
       | cover bases, like hiring an INFOSEC then ignoring them. No on in
       | charge cares about security because the number of people in
       | charge punished for these breaches is still ZERO.
        
       | tonymet wrote:
       | I've built Healthcare SAAS APIs that required custom integrations
       | with EHR partners, as well as consulted on similar apps for
       | others.
       | 
       | On top of common OWASP vulnerabilities, the bigger concern is
       | that EHR and provider service apps do not have the robust
       | security practices needed to defend against attacks. They aren't
       | doing active pen testing, red-teaming, supply chain auditing --
       | all of the recurring and costly practices necessary to ensure
       | asset security.
       | 
       | There are many regulations, HIPAA being the most notable, but
       | their requirements and the audit process are incredibly primitive
       | . They are still using a 1990s threat model. Despite HIPAA audits
       | being expensive, the discoveries are trivial, and they are not
       | recurring, so vulns can originate between the audit duration and
       | the audit summary delivery.
        
       | didgetmaster wrote:
       | Although almost every company issues a 'we care about your
       | privacy' statement, but there is often very little 'money where
       | your mouth is' resources to back that up.
       | 
       | This is why I am almost always very reluctant to give out any
       | information that is not absolutely necessary to provide me the
       | service that I need. If they don't know it, they can't leak it.
       | 
       | Every company wants you to fill out their standard form that
       | tries to get you to volunteer way more info than they really
       | need.
        
       | 1970-01-01 wrote:
       | And everyone was fired, the top management has stepped down, and
       | the fines were so massive that nobody ever took a chance with
       | sloppy security ever again. Oh, it's actually the opposite of all
       | that.
        
       ___________________________________________________________________
       (page generated 2026-01-07 23:00 UTC)