DNA data of sexual assault victims exposed in breach at US laboratory
portswigger.net
portswigger.net
They don't have meaningful security because they don't have to have meaningful security.
https://nij.ojp.gov/topics/articles/what-str-analysis
> Among the 3 million or so DNA bases that do not code for proteins are regions with multiple copies of short repeating sequences of these bases, which make up the DNA backbone (for example, TATT). These sequences repeat a variable number of times in different individuals. Such regions are called "variable number short tandem repeats," and they are the basis of STR analysis. A collection of these can give nearly irrefutable evidence statistically of a person's identity because the likelihood of two unrelated people having the same number of repeated sequences in these regions becomes increasingly small as more regions are analyzed.
http://www.biology.arizona.edu/human_bio/activities/blackett...
https://forensicsdigest.com/short-tandem-repeats-or-strs/
This isn't data that you could reconstruct a genetic disease from. It is more akin to a hash function for an individual's genome. The data would be 13 pairs of numbers (13 STR loci and the number of repeats on each chromosome at that location).
This would be PII, but likely not HIPAA.
Labs doing forensic work for police departments are probably not covered entities.
> By law, the HIPAA Privacy Rule applies only to covered entities – health plans, health care clearinghouses, and certain health care providers. However, most health care providers and health plans do not carry out all of their health care activities and functions by themselves. Instead, they often use the services of a variety of other persons or businesses. The Privacy Rule allows covered providers and health plans to disclose protected health information to these “business associates” if the providers or plans obtain satisfactory assurances that the business associate will use the information only for the purposes for which it was engaged by the covered entity, will safeguard the information from misuse, and will help the covered entity comply with some of the covered entity’s duties under the Privacy Rule.
Source: https://www.hhs.gov/hipaa/for-professionals/privacy/guidance...
In the case of a police department collecting DNA data for analysis by a police forensic lab there is no covered entity involved.
Other entities besides most state and local law enforcement that often have medical data but that are not covered by HIPAA include most private employers, state agencies such as child protective services, and most schools and school districts [1].
[1] https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/un...
As an aside, in the relatively recent past I worked on a system that contained data covered under HiPPA. We isolated the systems (and networks) so that the health data itself had no identifying information - just a unique key. When the user was authenticated, their PII and the medical information was merged on their browser screen. These two systems were properly secured but I don't ever believe a system is invulnerable (unless it has no network connection). Still, you'd have to breach both systems to combine the data en masse.
Experian seems to be doing quite fine
Gathering = publishing for publicly held companies, since the company could be acquired or subpoenaed.
Europe has the General Data Protection Regulation.
It’s good to note that, if you make the penalty too high, then it has the side effect of drastically increasing medical costs.
If the penalty was infinite, then they'd simply air-gap patient (or victim DNA) information systems, and have patients own / transfer their own medical records between providers (perhaps on DVD's, because USB is a very broad protocol).
The cost of that would he rounding error vs. other inefficiencies in the US healthcare system.
2. The increase is one of many many “rounding errors” that make our healthcare system one of if not the most expensive among developed countries.
Why do I have a feeling this was log4j…