Data breach at Kaiser Permanente affects 13.4M people
restoreprivacy.com
restoreprivacy.com
I am still a satisfied Kaiser customer.
----
Hi KP.org Team,
Just now, I logged into KP.org. Something was loading slowly, so I viewed the network requests the website was making. I was surprised to see requests to Google, Adobe, Bing, Qualtrics, BTTag.com, and Unpkg.com. A request to Google includes info intended to de-anonymize my computer: time, IP addr, device type, display size, browser window size, timezone, and others. These requests occur even while reading messages with my doctor!
The page loads JavaScript from Adobe, Bing, Google, and Qualtrics. People who control those companies' servers can read my confidential messages. Adobe has a track record of incompetence in IT security.
Please review your decision to make KP.org load external code and trackers. If you do not respond by 2022-01-14 (90 days), I will disclose this information to privacy-oriented media organizations and HHS.gov. I saved screenshots for this purpose.
Sincerely, Michael
source: personal exposure to "ad markets in hospitals" here in the SF Bay Area
URL (gets redirected): https://healthy.kaiserpermanente.org/consumer-sign-on
If one had a list of patient portals[0], what would be the simplest way to check each for 3rd party trackers? Use Selenium?
0. curl -s "https://www.mychart.org/LoginSignup" | grep 'JSON.par' | sed -e 's;^.*JSON.parse('\'';;' -e 's;'\'').*$;;' | jq '.Customers[].LoginUrl' | tr -d '"'I haven't a clue if either of those companies do, though it wouldn't surprise me if they did.
I have respect for the individuals that started this investigation, and the ones that made sure this is publicly disclosed. This could have easily been swept under the carpet.
Actually, that they uncovered this on their own and publicly disclosed it sounds like they have an above-average privacy culture in place.
I know the odds that the person(s) who kicked off this investigation are reading this comment are very low, but if so: Kudos, well done!
The case of insurance providers having a microscope into everyone's lives is simply dystopian. As with political campaigns, potential employers, law enforcement, and so on.
To be fair to Kaiser, that really isn't their problem.
You should be griping to the telco (yes, I know it's a waste of time) and your politicians (marginally more useful than the former), because that is their problem.
Also, source that call records are sold? I thought even the government (non federal security apparatus) needed a warrant to get access to that information?
* There are limited carve-outs for medical records and such.
Yes. I think what's being alluded to is that the ultimate problem lies there, and carving out special systems and cases to legislate to avoid bad behavior that might results from that will always fall short of what we could get with some more overarching legislation that makes it so the end person retains at least enough rights about that data to know when it's happening and preferably be able to stop it and requiring very stringent rules about those that do attempt it with permission from end users.
At that point it's no longer about finding which if the data aggregators are doing unsavory things with the data they get from you and trying to find some way to get them to stop and it's then about any data broker that wants your information trying to get you to allow it (because there are undoubtedly cases where the data is good for society and even good for you) needs to justify what and why and how they use it.
Edit: And there would be legal recourse if they don't follow those legal standards, of course. It's implied, but might as well be stated outright.
Then the carved out allowances for specific companies or industries are clear and their need can always be weighed against our rights, making them much easier to pull back, because it's obvious when it comes to our rights and the needs of an industry to continue making money, our rights come first. If it's approached from a non-rights angle at some point we are attempting to curtail an industry, I think that might be a much more contentious discussion.
If we can't get rights, I wouldn't mind HIPAA being expanded into an overall PII protection system with two or more levels, one being current HIPAA health info, and the other main one being all other PII info and that allows a company to collect it for internal use without lots of constraints (depending on info, and purely so it doesn't accidentally tank existing industries that aren't problematic because all of a sudden they can't store some benign info they need that the law accidentally targets) but once they want to share it at all they need to adopt a much more stringent framework like medical info requires for tracking and accounting of it, which would probably weed out the vast majority of random "collect the PII and sell it because it's cheap" stuff that goes on, since it's no longer low cost at all given the requirements that would exist around it (including authorization to share). Just the cost structure around strict legal and storage compliance and requiring authorization and tracking of all sharing of information would disincentivize a huge amount of the abuse we see.
Perhaps there should also be a nonprofit clearinghouse like a "credit agency" that provides a centralized portal for reviewing all of the permission links at and between businesses, and also a central point for changing phone numbers, email, shipping, mailing address, etc.
https://archive.nytimes.com/www.nytimes.com/interactive/2013...
Therefore, I am confused whether or not a warrant is needed. If the phone networks were straight up selling call records, then surely no law enforcement agency would bother with warrants.
That said I would be completely unsurprised if they were used for 'parallel discovery' purposes.
Communications: warrant.
Metadata: it depends.
(Not a general rule but a useful heuristic).
Plus the individuals found responsible thrown into prison, and personally bankrupted.
Plus a punitive hit to the stockholders, including clawbacks of past realized gains, to align incentives better with productive society, and not let a corporation be a shield for routine criminal conspiracy.
Working backwards from the desired state, what legislation do we need?
Not much for the jackboot police state you look to create
Creeping suspicion is too much focus on doing ”smart” things with data, AI and such and not enough on actually worrying about not getting breached.
Huh? Your passive tense suggests this happened to KP’s teams.
From what I’m reading, those are the teams who would have had to actively take action to import the tracking code on their pages.
My money is on “we imported a thing on the website because our advertising team needed to know when advertised users converted from any of many different advertising channels”. Usually it’s easier to import a script on a common layout, rather than just a single landing page.
Ad teams overrule the website / security teams because one is a profit center and the other is a cost center.
Then as engineers / product teams turn over, the new employees don’t know the original intention of the old imported code and are wary to remove it (and if they do, the process is long and drawn out).
It blows my mind that these multibillion dollar institutions are so poorly managed on the technology/IT front. I think most people will have their health data likely leaked at some point.
Just don't go to the hospital or in any other way involve your system with the InsuroServo complex. Problem solved!
Hospitals. Banks. Airline industry.
The shit I have seen in just these industries made me think twice about having my private information held here.
Of course, the “IT” is often outsourced or “in sourced” (often juniors fresh out of college). Thus simple shit such as network segmenting production and development environments; and limiting access to production databases/assets is nonexistent.
I remember working in an airline where the backend systems were still running on outdated mainframe systems. Nobody had a clue how the existing mainframe systems worked. No documentation. Only poorly maintained support docs on how to keep it running. I ended up silent quitting after 3 months because management kept shutting down all of my initiatives to improve ops and quality. This company later had a massive meltdown. I wasn’t surprised and just glad I wasn’t subpoenaed.
Too many little ways to manipulate your artifacts to pass SOC2 and no accountability when it goes wrong.
Also, for the entrepreneurs out there, they seem to really need some kind of tubing that won't collect air bubbles. Something with a hydrophobic interior? I don't know. There's a related area regarding flushing IV systems that could use attention as well.
Maybe they kept the wrong ones haha
they now disclose these are used at login.
Glad to know they’re a forest fire away from being lost. If you haven’t used your medical records or had them forwarded to another provider in over three decades, I think it’s ok if they go bye-bye.
I've been with KP most of my life, yeah. And I think you're right that in most cases, it's not really necessary to have the old records. It would have been useful in this case, but it's a niche case.