There’s a reason we have laws against both negligent manslaughter and first degree murder, and there’s also a reason why the penalties for the latter are much more severe than for the former.
It's not victim blaming because the victims are the patients. The people who were in charge of securing the records and left the creds as root:root are not victims.
We have to stop designing systems where if one administrative task is mistakenly skipped, the result is catastrophic. Imagine if when you tried to start your car that if you didn't have the brake fully pressed that your car blew up. Would you say "Oh, wow, how irresponsible it is to not fully press the brake"? No, you'd blame the manufacturer for building an exploding car.
Systems should not start if strong admin credentials are not the first thing that are set up.
A better analogy would be accidentally crashing the vehicle - an action resulting from negligence or incompetence rather than some 1/1000000 chance of your car exploding due to a failure in functional safety. If someone is operating a vehicle in a manner that it was not intended to be used should we blame the manufacturer? You expect litigation to follow someone forgetting their keys, driving their car into a lake, or running out of gas on a busy freeway?
The solution should be to mandate more certifications and security audits for high-risk organizations. The safety mechanisms should be legal and not technical; you shouldn't be permitted to operate a business dealing with sensitive data if you haven't been audited. Delegating more responsibility to the system architects doesn't solve the fact that you have incompetent people performing the administrative tasks and malicious actors abusing this incompetence. It isn't about someone making a mistake, it's about someone being irresponsible in a security sensitive environment - something that should carry severe legal repercussions.
Forgetting to change the default password on a system before starting it up and putting it into production (negligently or not), is not a very "obvious" type of failure. Hey the software is working! People can us it to accomplish their daily tasks! Everything is fine! There are basically no signals to the average, non-sophisticated user that something is amiss, for the vast majority of security vulnerabilities/misses.
So the real problem IMHO, is less about addressing systematic lack of competency or lack of oversight or licensing or things like that, and better tackled as questions of better UX, of failing fast and transparently to the user, or of making invalid/undesired states impossible (and user education yes, to some degree... but cars really do not require that crazy of an investment in training to operate, though different countries certainly set different expectations/standards). These are the sorts of problems that tech is used to solving, that the tech industry is optimized around solving. Of course, for tech to care about working on these problems, requires market incentives to be there (and by and large, the incentives are not there today). Which is what one of the GP ideas about fines and insurance costs/premiums is trying to address.
If you are hired to secure a system and leave the credentials as root:root, you are derelict in your duty. Period.
If there is a system with external access, someone set it up. It is the responsibility of whoever setup that system to ensure access controls are in place. The barest minimum of that is to change the default creds to something unguessable.
Similarly, I don't hold any credence to a black hat saying "but look at how insecure they were".
People hired to secure records that then do an exceedingly poor job are not the victims in this situation. Victims == patients.
In your analogies of rape/murder, the (almost) equivalent would be if there was a doorman at an apartment building who was supposed to verify the identity of everyone entering the building, but failed to do so, letting the unauthorized perpetrator into the building and thus allowing the victim to be raped/murdered. It was literally his job to prevent such a situation, and he failed. You maintain that he has no responsibility in this matter?
Probably because the OC had already hedged:
> if true, I see two quilty parties here.
The entity that stored the data is to some small extent a victim, but most importantly they are a perpetrator.
And this meme is silly, because more than one person can be at fault in a situation. This binary division of blame simply doesn't deal with the complexity of the real world.
If their security really was that bad--something which has to be proven by more than a random, anonymous rumor--then they should be financially liable for contributing to the situation.
Just because someone else is even more at fault doesn't absolve these jokers the tiniest bit. If this isn't a criminal offense, Finnish law is broken.
Hackers are an inevitability. You can't shed responsibility when they come for your unprotected data anymore than you can blame the water if you swim out in the deep alone and get caught in a riptide.
If you want a rape analogy, it's like blaming a police officer for failing to prevent a rape due to the police officer being drunk.
Of course, I agree that the care provider also did something wrong (as well as the hacker(s)) and that the people are also victims, but "the people vs. the care provider" is a separate matter from "the care provider vs. the criminal".