I have gotten several notices of medical data being leaked over the last two years. I thought HIPPA law had very harsh fines for this, but I guess they just look the other way.
HIPAA compliance was just a half hour webinar.
To be fair, I think HIPAA works in offline contexts (employers can't ask your doctor about your health) but as far as how easy it was for me to get access to customer CCs and medical information... Let's just say the barrier was basically nonexistent.
And most companies can simply price it in as cost of doing business at this point.
Not at all. The maximum fine a company has to pay is capped at $2 million per calendar year for a violation, and that's assuming it's even eligible for the highest tier of penalty.