You can also get a sense of the scale of the problem by the reported revenue and growth rates (which they're always eager to highlight).
Some merchants have multiple registers for the sale of different types of products, but generally if you receive only one receipt for your full purchase, it will be recorded under the category code for the merchant's primary business.
https://www.tidalcommerce.com/learn/what-is-level-3-data
On my American Express credit card statement, all the airline flights show the details of the flight and Staples.com transactions show the specific items that were purchased. And this has appeared for at least 6 to 8 years.
If it is insuring known or likely risks, then it becomes a subsidy or wealth transfer (which should be the domain of governments).
Besides why should less risky drivers subsidize riskier drivers?
Here is a car that sells your driving data. Here is one that won't
If you knew they were selling your data you could objectively demand a discount from one of the 2 .
They essentially do. If the safe drivers are never at fault, those premiums went somewhere. If the risky, repeat accident drivers aren't paying thr full price replacement vehicles, that money came from somewhere.
But when they use overly simplistic data (or use it in an oversimplified way) that makes the highest-skilled drivers appear in the same batch as low-skilled and high-risk drivers, that is not subsidy, it is unfair penalization by stupidity.
(see other comment on logging of g-forces)
Unknown to whom? To you, the insured? Or to them? Business thrives on customers with incomplete information.
Edit: changed prescription “data” to “records”
My understanding of HIPAA (possibly incorrect) is that it's attached to the data.
If a covered provider is leaking HIPAA covered data to a non-covered business associate entity... that's a big no-no and a fine.
See https://www.hhs.gov/hipaa/for-professionals/covered-entities... and https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-...
In my experience, covered entities are really serious about signing BAAs with any of their hosting vendors and partners, as afaik the liability falls on the covered entity if they didn't have an agreement in place and data leaked from a vendor/partner.
I'm sure there are legal HIPAA data escape pathways (given the financial incentives for companies to find them), but I'm curious on the details.
Afaik, there's no way to make HIPAA-covered data non-HIPAA-covered, and absent that everyone in the custody chain is responsible for anywhere it eventually ends up.
That said, I expect the way this works in practice is more likely data that originates with non-HIPAA-covered entities, but can be massaged/combined into a similar product.