Quest Diagnostics says nearly 12M patients may have had data breached
cnbc.com
cnbc.com
That we have so much fallibility in medical billing is still a sad statement, though.
https://www.reddit.com/r/personalfinance/wiki/collections
https://www.kalzumeus.com/2017/09/09/identity-theft-credit-r... (excellent resource by patio11 on how to present to CRAs and build a paper trail, although more focused on responding to identify theft)
https://web.archive.org/web/20190604005100/https://www.balla... (Sample letters to respond to debt collectors)
Disclaimer: Not an attorney, not your attorney.
Medical payments in the US are a joke and laughable. I have a chronic illness, so I gained some experience dealing with those snakes.
Ex 1. I was charged 20k for pre-authorized procedure. After procedure insurance could not agree with the company on the payment, as average payment for such procedure is $1800(according to insurance) and insurance refused to pay. I stressed over it but didn't pay it, I was young and didnt have 20k laying around. I told the company to get lost and invited them to send my account to collections and that I will fight them in court if I had to. 7 years later I received a bill after they agreed with insurance on discounted rate for $300, at that point they started calling me again. It was too late and they could not put it on my credit report, therefore, again I explained that I will not pay as this barely covers time lost dealing with it. Bills stopped coming and they accepted defeat.
Ex.2 Mother was in ER, 40 minutes for abdomen pain. 0 tests, doctor pressed her stomach and gave her high strength Tylenol. Bill total $3500, just absurd IMO. Parents are lower middle class, I sent a letter with their income, debt and some nice words. Took me about 2 hours tops to come up with it and find where to drop it off. Bill instantly reduced to $350.
Healthcare prices in the US cannot be taken seriously. It is so anti-patient it is unbelievable. Go to ER and get 10 different bills. There is definitely room for a company to come in and represent patients and easily save money.
Plus, patients are OFTEN billed for stuff they didn't not get. The abuse in the industry is insane. You can get double billed, there is also upcoding and unbundling, which results in higher bills.
I did this to a debt collection agency and they became enraged, presumably trying to scare me into allowing them to cut corners. Sure enough I never did get the validation and the collection vanished from my credit report.
Reason #283942 that our medical system is horrendously broken in the US.
You get low-hundreds (not an exaggeration) different documents, handed to you and via mail over the course of a year (9ish months + a few after, ends up close to a year), some of which are bills and some of which look like bills but say "this is not a bill" (so... why'd you send it?) and some of which are from your insurance referencing other things and blah blah blah, then you get a few that are clearly a screwup and you call the provider and they're all "LOL no your insurance got it it's fine, ignore that bill" (!?!?! seriously, dafuq, how many people just pay it and do you give them their money back unless they ask?) and of course one of those pieces of paper is gonna slip through the cracks.
Insurances companies get a lot of shit, but the whole medical billing complex is rotten, top to bottom.
https://www.sec.gov/Archives/edgar/data/1022079/000094787119...
Just a reminder to everyone to keep passwords rotated, and to monitor your credit/bank account...
PayPal used to have that feature but got rid of it for some reason.
If they come looking for the money I supposedly owe them on that account, I should be able to tell them to fuck off and collect from whoever they sent the card to of their own volition.
If they can't figure out whose business they took, maybe they need to reconsider their practices, otherwise they're just giving away money.
We're not solving this.
With SIM cards or other hardware devices, your private key is never leaked (if "done properly")
With cryptos like BTC, you can generate many keys from one source of entropy, and treat them as disposable.
I don't see why medical records couldn't be encrypted with a disposable key, given by a hardware device which stores the seed, and only linked to the matching public key.
https://de.wikipedia.org/wiki/Postident
(And I just see that the service is also offered by mailman as well, so they can come to you. Austria and Switzerland have similar services.)
edit: It's quite remarkable how sometimes people online say there should be something, and I'm like, yeah, we have that.. I wonder if it works the other way too. Probably.
[0] - https://en.wikipedia.org/wiki/Electronic_identification#Swed...
But if my medical ID got stolen I could turn it off and get a new one without invalidating my passport and disqualifying me from a car loan and locking me out of my college transcripts etc.
That (along with standard identifiers for health plans and providers, which survived as requirements) was originally part of HIPAA, though it was stripped out.
Never the less it's inexcusable to keep such PIs in an open database without encryption and tight controls. I'm sure they allowed anyone in the company to browse peoples personal info so the leaches could go out to suck blood.
It's why I froze all five credit agency accounts & signed up for a credit monitoring agency via work.
Quest doesn't store SSNs but the 3rd party evidently did as part of their efforts to identify people so they can collect.
That company needs a massive fine and being forced to offer free credit monitoring for LIFE for anyone so compromised.
So Quest has pretty much no blame here - it's the collection agencies that are allowed to buy people's financial records which include SSNs that are the bad guys here.
—- Or — Your insurance only covered part of the blood labs on the 12th. To release the results to you doctor I need to secure payment today for 189.74.
Seriously, these two pieces of data that are innocent alone, when taken separately (HIV, chlamydia, cancer...) should NEVER have been linked together, ESPECIALLY when given to a third party, EVEN MORE stored together.
I pray it will result in many lawsuits with hefty punitive damages, and that as a consequence private data will be considered a liability to be deleted as early as possible (just like corporate email in many companies)
If the "allowed" ICD code is linked to the public key, or in the worst case if the patient provides the disposable private key to the insurance for verification (along with PCI like rules forbidding this key to be stored, like credit card expiration date if I remember correctly) this couldn't happen.
It is gross negligence to keep these things together for longer than they need to be. Private data should be seen as a liability.
> The system contained sensitive data, including credit card numbers, bank account information, medical information and Social Security numbers, Quest said. Lab results were not provided to AMCA and were not exposed in the breach. AMCA thinks 11.9 million Quest patients were affected as of May 31, 2019, Quest said.
But it only says lab results were not leaked with the extremely generic label of medical information as being leaked. I wonder if "medical information" includes lab codes or what exactly it consists of?
This is worse than full text medical information because everything is already coded, so you can make some simple algorithms to find crunchy details with a very high specificity.
You can order anonymous labs for yourself through various online lab resellers. At the lab, you don't need ID, just the order. You will get lab results; you will not get a diagnosis.
For instance, and not a recommendation:
FAQ: https://www.health-tests-direct.com/frequently-asked-questio...
Q: How can I keep my “true” identity from HTD, and the clinic, and the lab?
A: Easy -- Don’t give us your phone number or credit card info. Then mail us a money order (a money order does not require your name or signature) for the total amount due for the blood draw and lab analysis. We will e-mail the lab paperwork to you when the money order arrives and email the lab results to you the same day we receive those 2-3 days later. If you want, you can even set up a temporary (and free) “alias” e-mail address at Yahoo! (e.g.,“YourAliasName”@yahoo.com) for the purpose of our email communications with you...
There are two more things we hope that you will feel more comfortable knowing: First, 99.99% of the blood draw centers we send you to will NOT ask for your photo I.D. when you go in for your blood test. And, in the very-very rare event that one should they do so, don’t feel obligated to show it to them. Instead, leave the PSC and immediately call us. We will find you another PSC! Or, keep in mind, that your lab tests results are NEVER sent to or shared with the clinic or its personnel that does your blood draw. Only YOU get your lab results, and NOBODY else. So, if you are asked, and you DO decide to show them your drivers license or other ID, rest assured that they will NEVER see or know the result of your test(s) anyway!
See also: https://www.walkinlab.com/help-contents#privacy
Q - Can I do anonymous testing?
A - Yes, an order can be placed anonymously. The First Name field must start with an alpha or numeric character and the Last Name must be an alpha character. Your correct date of birth and gender are required.
Both of these work with LabCorp and Quest Diagnostics, DuckDuckGo can help you find more.
But I think to be a HIPPA violation it would need to have information about what tests are involved - eg just a monetary debt and knowing it came from a lab might be argued as not being a violation?
That said until there are mandatory per-person-per-data-leaked fines, coupled with liability for misuse of that data, companies are just going to continue leaking because they “compensate” people by giving them “free” credit monitoring.
That last bit is great because it only resolves financial service harm, and offloads actually preventing fraud to the victims of these companies.
Which politician can make ID data breaches financially ruinous and their concealment criminal?