If enough companies are destroyed, eventually they will start taking security seriously.
Since that part of the data should be the most locked down, it seems like a complete lie to me. I think the health info was compromised completely.
One way to have not allowed this is to force the database to restrict queries to use two pieces of information in the where clause. This means that they would have to search for name = "John Smith" and MRN = "xyz". This would prevent mass queries and database dumps.
In the case that they stored SSN and MRN together, which I believe is highly likely, the attackers also gained access to the MRN.
If the most highly protected data demographic data (the name and identifying information about the individual patient) is unencrypted and easily compromised, I believe that patient data was very likely compromised as well.
It is possible, however, that the attackers were only after information that could be used to commit identity theft so they may have ignored the health information, however, this does not mean that the health information was properly protected.
Money begets money, power begets power. Either begets the other. The great vicious cycle of our civilization.
obviously that's broken logic since..
- you're not compromised by default/when the business starts
- when you're compromised, you probably don't even know it. you might find out in a few years if lucky.
Much of the data I presume that Google deals with is not sensitive enough to warrant the kinds of encryption that a health provider company should use. My search data and even my Google+/YouTube/Gmail accounts are enough to tie them to my person, but not my identity. I, or someone masquerading as me, cannot open a line of credit with my Google account at a bank.
Edit: This wasn't it, but interesting nonetheless: https://news.ycombinator.com/item?id=2254394