The stories I've seen about employees tracking individual riders lead me to view this skeptically.
The stories I've seen about employees tracking individual riders lead me to view this skeptically.
It’s not fixed.
IMHO, that couldn't have been handled better.
And Aug 30 to Nov 21 is very much “months”.
This convo sounds like when folks were jokingly asking Dara the week after he started the job if he had fixed all the problems in the company, made it profitable and ready for IPO yet.
Considering that the timeframe in question would be probationary period for a normal person in a normal job and that the guy was jumping into what was effectively a burning transcontinental train wreck, I'd say getting an investigation completed and disclosed within a few months of his job start date is actually pretty commendable. By comparison, it took like half a year for people to see anything come out of the Holden report, and timeframes for resolution for some historically big scandals in other companies have taken far longer (e.g. the Equifax one is still making news with bigger and bigger impact estimate corrections).
Also, I find it curious that you think Joe Sullivan was made a scapegoat out of convenience, since there isn't a single news article about him complaining of being fired unjustly. You'd think news orgs would be all over such a story.
It's not like Dara walked into a whiteboard in the CEO office that said "list of 2016 suckers lol" and then sat on it twiddling his thumbs for a month. My understanding of the incident is that it had been covered up by Sullivan and TK. In my mind, an investigation is precisely for figuring out what the hell happened, who was affected and to what extent.
I don't know the specific details of this investigation in particular, but for the Holden one, it involved a lot of one-on-one interviews with various employees to try to reconstruct the stories of each harassment claim so that an appropriate punishment/course of action could be determined for each case. If this investigation was conducted in a similar manner, it wouldn't surprise me that finding out the blame would occur in tandem with discovering the extent of the breach.
it's more than 1 month, but "months" is a stretch here
It’s not a “delay and get people to show up to town hall” sort of issue.
Yet I’ve never heard of a major company fined or punished for HIPAA violations. Have there been any such notable incidents in the past few years?
They lose like 1000x that per year.
One can try to argue that uber is lying about its hipaa compliance efforts in order to save the few hundred thousands that they would be paying Clearwater and in dev costs, and one can counter argue that that accusation has no reliable sources to back it up and is fueled by a desire for internet karma points.
If a company just has data about you that is not medical data then there is no legal requirements as to who can have access to it internally. (So Joe's Sprocket's has a list of everyone who has bought sprockets and their phone numbers - anyone in the company could look at that info and there would be no legal implications)
But I don’t think that’s what the poster was saying.
Med students get a little grey area on this because their job is to absorb as much info as possible without necessarily providing care, but even they shouldn’t venture outside the census of their supervising physician.
So if any breach occurs, access can be tracked to individuals.
In my country, one programmer who unfortunately lost his newborn daughter to sepsis decided to make a machine learning program to help doctors diagnose the infection early. The software has access to patient data and it recognizes patterns that match the development of sepsis. It decreased the number of severe sepsis cases per month from 1.5 to 0.5 and cut the waiting time before effective treatment was administered by 60%.
People have told me this sort of system would not have been impossible in the USA because of the HIPAA. Is this true?
That said, the company has to make sure that only the people that have a clinical need to access the data have access. So the developers would probably use a de-identified data set to write and test the program. Only the clinicians (care management and disease management nurses) would have access to the identified data so they can contact the patient to offer care.
that said, compliance audits are pretty strict if they are doing it correctly, and not-so-fun. It will be an interesting world when there is a medical-data-firehose pointed at an AI that is looking at all the available med records to do predictive analytics against an entire population....
We are likely a decade from that.
There is absolutely no way I would use this service.
Edit: It should also be remembered that Uber hired this driver, the rapist, as a known rapist (a recorded criminal history of being convicted for rape). Uber hired him without caring about his background or past criminal behaviour. Uber hired him with the knowledge that he could well be a rapist, since they declined to do a simple background check, presumably because it would "take too long" and they consider the occasional rape just a part of doing business. The evil behaviour and willful disregard for the safety of their normal Uber passengers - before trying to ruin their lives with deception, theft and lies - makes it 100% impossible to trust them about anything ever again, especially personal health.
#DeleteUber.
What sort of transportation? Are you talking about based on income level? Age? Could you clarify?
Obviously my experience is anecdotal, so I'd be interested to see if similar patterns are true elsewhere. But when there are so few companies competing with each other it seems a lot more likely that there's some sort of regulatory burden or capture in play rather than simple greed. Capitalism might explain why a service with few competitors is expensive but it doesn't explain why there are so few competitors to begin with.
This is literally the endpoint of Capitalism without regulation to prevent monopolies and a floor of public goods. You absolutely should blame it and those who fail to either check or dismantle its power.
Throughout American history, corporations have explicitly undermined and destroyed public transportation so they can profit from it. That’s why things are so bad. First they did it to sell individual cars and now to sell taxi services. Uber’s express ambition is to become the transportation monopoly you decry.
No, they've been doing this since at least railroads, the OG monopolies
We're quickly derailing from my initial point though, that however things got here I think Ubera new service has the potential to relieve a lot of people in a market which I believe is inadequately served at the moment.
I don't care if they have "strong internal data access controls". They should have had that Day 1, they should never have lied or cheated and they certainly should not ever expect anyone to trust them about anything ever again.
First, I doubt that it's true that they have strong controls. I don't trust organizations that have such a long, clear and bragging history of lying.
Second, that sounds like the Titanic being unsinkable. As if I'm going to trust Uber with personal health data - they are the first group I'd suspect to try to sell that data under the table, the first group I'd expect to abuse the power, and also the first group I'd expect to suffer internal leaks or external hacks.
No way I would trust this given the very recent and abhorrent behaviour of the executives at the company.
Edit: Also this,
> and any user data access need a ticket and a justification before accessing
is not secure. Sounds to me like any user can make a ticket and create any justification they like. This is like the NSA saying "any user of our PRISM system is logged and watched" - but what happens when millions of tickets are going through? Is each one actually being carefully inspected for abuse? If Uber executives are in charge of this decision then no way do I trust it.
My intention here is not to go into details, which would not be appropriate for me as an engineer that doesn’t work on those aspects. I am only saying we care a lot about this.
There are so many alternatives to Uber that are better, safer, and even cheaper that there will never be a need to use Uber and they will never get any trust. The people up-top there have been so thoroughly evil for so long and the damage they have done so great that I have no interest trusting them ever again.
Edit: You downvoters have downvoted me so much I'm no longer allowed to reply or otherwise talk on HN. Goodbye.
There was a time when there was a lot of animosity towards Microsoft, but over the years, younger people that had not been exposed to the drama grew up with a more neutral stance, and many many years of not-really-dramatic developments means that nowadays, people only really think of Microsoft as the company behind MS Office, XBox, etc and not so much about what its ethics framework looks like. Obviously you can still see people referring to it as M$ and similar and making fun on windows users, but it certainly isn't _common_ for average people to outright _hate_ Microsoft on ethical grounds.
Uber, Microsoft, Enron, Blackwater, Comcast, Oracle, all get plenty of hate, even from non techies.
I’m sure there are people at Uber who are fascinated by seeing where celebs take ubers... and can’t blame them.
Here are some juicy stories for you to read if you want to know the details of all the kinds of stupidity and evil it takes to invade someone's privacy like that.
https://www.revealnews.org/article/uber-said-it-protects-you...
So blame was the wrong word...