It’s not fixed.
IMHO, that couldn't have been handled better.
And Aug 30 to Nov 21 is very much “months”.
This convo sounds like when folks were jokingly asking Dara the week after he started the job if he had fixed all the problems in the company, made it profitable and ready for IPO yet.
Considering that the timeframe in question would be probationary period for a normal person in a normal job and that the guy was jumping into what was effectively a burning transcontinental train wreck, I'd say getting an investigation completed and disclosed within a few months of his job start date is actually pretty commendable. By comparison, it took like half a year for people to see anything come out of the Holden report, and timeframes for resolution for some historically big scandals in other companies have taken far longer (e.g. the Equifax one is still making news with bigger and bigger impact estimate corrections).
Also, I find it curious that you think Joe Sullivan was made a scapegoat out of convenience, since there isn't a single news article about him complaining of being fired unjustly. You'd think news orgs would be all over such a story.
It's not like Dara walked into a whiteboard in the CEO office that said "list of 2016 suckers lol" and then sat on it twiddling his thumbs for a month. My understanding of the incident is that it had been covered up by Sullivan and TK. In my mind, an investigation is precisely for figuring out what the hell happened, who was affected and to what extent.
I don't know the specific details of this investigation in particular, but for the Holden one, it involved a lot of one-on-one interviews with various employees to try to reconstruct the stories of each harassment claim so that an appropriate punishment/course of action could be determined for each case. If this investigation was conducted in a similar manner, it wouldn't surprise me that finding out the blame would occur in tandem with discovering the extent of the breach.
it's more than 1 month, but "months" is a stretch here
It’s not a “delay and get people to show up to town hall” sort of issue.
Yet I’ve never heard of a major company fined or punished for HIPAA violations. Have there been any such notable incidents in the past few years?
They lose like 1000x that per year.
One can try to argue that uber is lying about its hipaa compliance efforts in order to save the few hundred thousands that they would be paying Clearwater and in dev costs, and one can counter argue that that accusation has no reliable sources to back it up and is fueled by a desire for internet karma points.
But I don’t think that’s what the poster was saying.
Med students get a little grey area on this because their job is to absorb as much info as possible without necessarily providing care, but even they shouldn’t venture outside the census of their supervising physician.
So if any breach occurs, access can be tracked to individuals.
In my country, one programmer who unfortunately lost his newborn daughter to sepsis decided to make a machine learning program to help doctors diagnose the infection early. The software has access to patient data and it recognizes patterns that match the development of sepsis. It decreased the number of severe sepsis cases per month from 1.5 to 0.5 and cut the waiting time before effective treatment was administered by 60%.
People have told me this sort of system would not have been impossible in the USA because of the HIPAA. Is this true?
That said, the company has to make sure that only the people that have a clinical need to access the data have access. So the developers would probably use a de-identified data set to write and test the program. Only the clinicians (care management and disease management nurses) would have access to the identified data so they can contact the patient to offer care.
that said, compliance audits are pretty strict if they are doing it correctly, and not-so-fun. It will be an interesting world when there is a medical-data-firehose pointed at an AI that is looking at all the available med records to do predictive analytics against an entire population....
We are likely a decade from that.
If a company just has data about you that is not medical data then there is no legal requirements as to who can have access to it internally. (So Joe's Sprocket's has a list of everyone who has bought sprockets and their phone numbers - anyone in the company could look at that info and there would be no legal implications)