Uber rape victim sues Uber, says execs got her medical records
arstechnica.com
arstechnica.com
I would personally like to see white collar crime lead to incarceration more often as that seems like a stronger deterrent. Having said that, I am not deeply knowledgeable about the facts of this particular case.
[1] https://en.wikipedia.org/wiki/United_States_incarceration_ra...
[2] "Comparing some countries with similar percentages of immigrants, Germany has an incarceration rate of 76 per 100,000 population (as of 2014),[25] Italy is 85 per 100,000 (as of 2015),[26] and Saudi Arabia is 161 per 100,000 (as of 2013).[27] Comparing other countries with a zero tolerance policy for illegal drugs, the rate of Russia is 455 per 100,000 (as of 2015),[28] Kazakhstan is 275 per 100,000 (as of 2015),[29] Singapore is 220 per 100,000 (as of 2014),[30] and Sweden is 60 per 100,000 (as of 2014).[31]"
For example, maybe Nick Denton should have gone to jail for invasion of privacy against Hulk Hogan? I don't agree with that either.
I will say this clearly and I mean it: If you use uber, or you work for uber, you are morally wrong. You are choosing to enrich people and a company who have shown you multiple times that they are terrible human beings who lack even the concept of a moral compass.
OTOH, Uber and it's employees are not HIPAA covered entities, nor, generally, are doctors in India. So I don't see how anyone could have violated HIPAA here.
There seems to be an insatiable need for Americans or Westerners to project their laws/moralities to other countries, and then refuse the accept the reverse, except for certain cultural minorities logical inconsistencies.
Mainly because our laws are voted on by our own citizens and because the rest of the world doesn't accept our laws and doesn't have a say in creating them. Your statement seems nonsensical.
If there is an action that breaks the law of two countries there can be joint law enforcement activities. The US cannot punish actions that are legal in one country but illegal in the United States by acting in that foreign country.
https://www.justice.gov/criminal-ceos/extraterritorial-sexua...
Also, the US government will arrest you on US soil or while transiting an airport in the US for certain crimes that take place outside the US.
My post you replied to said "sex trafficking"; I meant sex tourism. Mea culpa.
However, in this case, HIPAA wouldn't apply to a purely Indian health organization, or the records of a foreign national in a foreign organization.
Note that in your situation (sex tourism) all prosecution/wrong doing is based on being a US citizen doing stuff and then returning to US soil. It does not apply to any sort of foreign national - you cannot be prosecuted for sex tourism under the US statute while on US soil if you are not a US national and the crime did not occur on US soil.
The percentage of white collar criminals would still be low (ie, won't change the incarceration numbers much), and it would connect more influential families to the problems with our prison system instead of having a classist divide on who it impacts.
I propose that we institute "murder" enhancements: any financial crime that causes more than $9mil in damages (the cost of a life [0]) must carry the same penalty as a murder (with the same level of intent, eg, planned versus unplanned); add multiplier for every additional $9mil in damages (ie, $9mil-17.9mil is 1x, $18-26.9mil is 2x, etc); leaders of organizations should be charged equivalently to leaders of other criminal enterprises -- if your organization committed $9bil in fraud, you should be charged as a leader of an organization which committed 1,000 murders.
[0] https://en.wikipedia.org/wiki/Value_of_life#United_States
> "You put Lloyd Blankfein in pound-me-in-the-ass prison for one six-month term, and all this bullshit would stop, all over Wall Street," says a former congressional aide. "That's all it would take. Just once."
It's not perfect, but if you make ten billion dollars from fraud, I feel like first you should lose the whole ten billion dollars as a matter of course, after which we can start discussing what if any punishment is appropriate.
I'm not saying that should be the only punishment. I don't even think it should technically count as part of the punishment. I'm just saying that if the prosecution can demonstrate that you (or your employer) profited from a crime, then you should always lose those profits in addition to whatever punishment the court deems appropriate.
I don't see how this applies to this matter. From what I read in the article, Uber was being sued and investigating a crime that occurred through the application of their service. In other words, if they did something wrong, it wasn't in the pursuit of profit, it was in defense of another lawsuit or the ultimate private settlement thereof.
Of course this is in the case of criminal fraud, which hasn't been brought up in this news case you are correct.
A fine proportional to the resulting profits and the risk of discovery would change the profile from the former to the latter, and would hopefully result in fewer people playing the game.
No it should be higher than that.
Expected ROI = profits - P*fine.
P is probability of getting caught and is strictly less than one. If fine is equal to profits ROI is positive and engaging in illegal activity is a rational, if immoral, thing to do.As I said in another comment, today, from my perspective, the average American faces much greater terror from being screwed over by "too big to punish (let alone fail)" corporations, than they do from actual terrorists -- manufactured fear aside.
Fines mostly don't hurt corporate members, individually, and often represent a fraction of the profit they've gained by breaking laws and regulations.
Pierce the corporate veil. Lock them up.
Assign law enforcement resources to relevant crime that weakens our society -- not in overwhelming numbers to another "War on..." fearscape.
A great example is the HSBC money laundering case. Go actually read the DOJ statement of facts in that case. As a preliminary matter, every large bank is used for money laundering. And bank executives all know, in the abstract, that their banks are used for money laundering. That's not illegal--it'd be impossible to have a bank that wasn't used for money laundering. The gist of the case was that HSBC failed to classify Mexico as a higher risk country and implement appropriate controls despite warnings from non-binding authorities about the risk of money laundering in Mexico. Who should go to prison for that?
http://www.rollingstone.com/politics/news/outrageous-hsbc-se...
> Breuer admitted that drug dealers would sometimes come to HSBC's Mexican branches and "deposit hundreds of thousands of dollars in cash, in a single day, into a single account, using boxes designed to fit the precise dimensions of the teller windows."
The gist of the case is that HSBC were so brazenly negligent, that the only logical conclusion is that they were deliberately looking the other way in order to make more profit, and they paid $1.9B to make the problem go away. That's on $670 billion in wire transfers and $9.4 billion in cash transactions from its Mexico bank operations during the period under question [1].
[1]: http://money.cnn.com/2012/12/10/news/companies/hsbc-money-la...
> The gist of the case is that HSBC were so brazenly negligent, that the only logical conclusion is that they were deliberately looking the other way in order to make more profit, and they paid $1.9B to make the problem go away.
Even if that's true, note how many steps removed it is from actual culpable conduct. You're not the drug dealer, you're not the guy employed by the drug dealer to launder his money, you're not the guy assisting in specific money laundering transactions you know about. You're the guy who doesn't bother to find out more about certain transactions to avoid learning that they may be illegal. There is, of course, no universal "due diligence" requirement to find out whether bad people are using your service for bad things. The only "due diligence" you have to do is what the government makes you do. Here, the allegation was that HSBC didn't do the diligence the government would have made it do had HSBC classified Mexico in a risk category that government did not make HSBC classify Mexico in.
You are repeating your previous assertion about how the case is actually about a technicality that HSBC shouldn't have been held to. Can you provide a citation for that?
From the CNN article I linked, "The DOJ said HSBC also helped process $660 million in prohibited transactions from Iran, Cuba, Sudan, Libya and Burma by deliberately hiding the identities of these countries."
That doesn't sound like "HSBC didn't do the diligence the government would have made it do", it sounds like more willful misdirection on their part.
Edited to add:
> The only "due diligence" you have to do is what the government makes you do.
I don't think this is true. Doing your "due diligence" doesn't protect you against activity that is otherwise criminal, it just protects you from being in breach of your regulatory requirements, and the penalties that are included in those regulatory frameworks. "Due diligence" doesn't protect you if you murder someone, and it doesn't protect you if you commit another crime, like (say) conspiracy to launder drug money.
Yes, that's not fair, but it's logical.
Having lived for some time in another country, I've seen counter-examples too: when execs were incarcerated for minor things and mere accusations, effectively destroying the companies they've built, so hundreds of employees had to look for another job. Everyone's seen that fairness doesn't play well with pragmatics, and it's better to let them go even if they are guilty.
1. https://news.ycombinator.com/item?id=14562331 (was flagged)
2. https://news.ycombinator.com/item?id=14563285
3. https://news.ycombinator.com/item?id=14562862
Other sources:
1. The New York Times: Uber Is Sued by Woman Who Was Raped by One of Its Drivers in India from https://www.nytimes.com/2017/06/15/technology/uber-india-rap...
2. Bloomberg: Uber Accused of `Rape Denialism' by Victim of India Assault from https://www.bloomberg.com/news/articles/2017-06-15/uber-sued...
3. CNBC: Rape victim files new lawsuit against Uber from http://www.cnbc.com/2017/06/15/rape-victim-files-new-lawsuit...
Edited to correct formatting.
So the crime, sharing personal health records, occurred in India. But it was an American victim, American company and American employees allegedly getting and sharing her health information.
I'm interested in how this plays out legally.
Where did you get that impression the closet I could find in the article was
>speculating that Plaintiff had made up the brutal rape in collusion with a rival of Uber in India to undermine Uber's business
I'm no fan of uber but the allegations made by the plaintiff do not even amount to your description of them
HIPAA requires that our medical data is secured when stored at a medical facility, but I still have to drive over with CDs and printed X rays if I have to go to different doctors and specialists. Doctor's referrals are still paper printouts, and you have to show up early to any doctor as a new patient, and fill out the same form about your medical history all over again. Things are still faxed, sometimes emailed.
This problem is still completely unsolved in the US. The closest thing is maybe if you're going across doctors in one hospital or hospital network, then your records are electronically "transferred"
Well, actually HIPAA stands for "Health Insurance Portability and Accountability Act" - it's specifically about making health records portable.
The security provisions were it's more minor, yet, best know part.
No, it's about making health insurance portable. [0] (The Security and Privacy pieces—as well as the IT standards bits—are part of the one “accountability” piece of the title, and largely irrelevant to the “portability” piece.)
Health records, in terms of interoperability, weren't a big focus in the legislation (they became a bigger focus with meaningful use and related rules in the ACA.)
EDIT: to be fair, though, access to your own records is also part of the accountability part, which isn't exactly portability of records, but it's related.
[0] See, e.g , http://www.investopedia.com/terms/p/portability.asp
Defamation, sure.
Repugnant indeed.
Not to the victim it ain't.
The fact is that given the heap of problems seemingly continuously coming out of Uber, the company doesn't seem to be changing, and these problems aren't slowing down.
Uber needs to change practice, and we need to communicate to the market that this behavior isn't acceptable via our wallets; they don't really seem to understand any other message. If it means that this company ultimately folds under the weight of these problems, so be it. The message needs to be clear to others: this is NOT acceptable.
* They already settled the lawsuit. At the very least, Doe should forfeit the money she already received before beginning this lawsuit regarding substantially the same matter. Otherwise, what's the point of settling if you can't forget about it?
* The onus for keeping medical records private is usually on the medical provider, not on the people interested in obtaining them.
This is a separate lawsuit. This is about them illegally obtaining her medical records.
"At the very least, Doe should forfeit the money she already received before beginning this lawsuit regarding substantially the same matter. "
No. This is a separate action.
"Otherwise, what's the point of settling if you can't forget about the matter?"
Settling does not give you carte blanche to keep being shitty.
"The onus for keeping medical records private is usually on the medical provider, not on the people interested in obtaining them."
How does this excuse Uber's behavior in the slightest?