frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

301M Records Exposed: The HIPAA Breach Epidemic

https://ciphercue.com/blog/hipaa-breach-epidemic-301-million-records
53•adulion•1h ago

Comments

philipwhiuk•1h ago
1. What a wildly capitalist take on the loss of confidentiality for personnel data.

2. If you get breached, you have a problem. If everyone gets breached it starts to look more like cost-of-business (and that might be cheaper than a cyber firm that doesn't actually fix the problem [but looks good on audits])

3. I wonder if the breached data is entering AI corpuses. Will I be able to ask OpenAI "Does Joe Bloggs, 75 Penn Ave NY have an underlying health conditions I should know about"

righthand•1h ago
Since tech community has been going on for years that it could cause a problem, I now don’t see any way out of this mess other than problems start arising since our politicians and leaders can’t be bothered to take the experts claims as legitimate ahead of time.
r_lee•1h ago
I think we're already in the "cost-of-business" stage.

the industry standard seems to be:

- release "oopsie" statement

- engage "cybersecurity firm" to investigate

- give out free credit monitoring for a year (fucking worthless)

and so far it seems to be working just fine

rdtsc•1h ago
Yup I don’t see any huge downsides here for these companies, and not much incentive to change. The more it happens the more they can point to each other and say “see, it’s not just us”
mapt•52m ago
I don't think I would favor executions or anything.

But forcible dilution (partial or total seizure) of the corporation? A mandatory insurance coverage? Absolutely.

We already have statutory HIPAA violation penalties, and I am extremely in favor of assessing them in a breach. The question is whether they are sufficient.

nlitened•1h ago
Unless somebody from management AND engineering goes to jail, it's literally just cost of business.
r_lee•1h ago
I think the most feasible solution is to make companies liable for damages, not in a light way but rather that every person can sue (or in a class action) for hefty amounts, so that a breach could cost e.g. 100mil+

that should incentivize them to actually invest some money in security. right now its just tiny numbers which are easier to just pay off and forget about

gwerbin•1h ago
You'd have to deal with all of the binding arbitration agreements first.

That's it, class action lawsuits also are part of the cost of business. Nothing is ever going to change unless the boards of directors (not CEOs) can be held liable for the behavior of the companies that they direct.

GJim•1h ago
> I wonder if the breached data is entering AI corpuses.

One would like to think the creators of AI have been prudent enough to ensure AI output obeys data protection law; however the laissez-faire approach the USA takes to data protection (and the hostility of many Americans on here to the GDPR) suggests otherwise.

gwerbin•1h ago
Wasn't Meta caught using pirate book databases for their training data? No decision maker of importance at any of these companies gives a whiff of a fart about data privacy beyond the bare minimum required by the letter of the law, and only when they think the expected cost of breaking the law would exceed the benefit.
ericmay•1h ago
> What a wildly capitalist take on the loss of confidentiality for personnel data.

As opposed to what exactly? A "communist" take on the loss of confidentiality? How might that go?

"There's no problem comrade, what are you talking about?"

This sounds like a failure of government regulation here, not a failure of a broad economic model.

ai-x•1h ago
OTOH, breaches especially Health Data breaches are the most over-rated, hysteria inducing breaches of all time. There is ZERO use for anyone for your health data
esseph•58m ago
Insurance companies, and companies that might look to hire you want your health data.

Others may want your health data to bribe you. Maybe you got a STD from a mistress.

Maybe you have a heart condition and the business you are interested in working for self-insures. They don't want you on their books!

inetknght•57m ago
> There is ZERO use for anyone for your health data0

You really think that?

tyre•56m ago
There is a field in a claims form that indicates what type of insurance it is.

One of these is CHAMPUS, which indicates that it is for a service member or their family. You can tell which.

As a basic case, accumulate these (as in the CHC breach of ~30% of Americans) and you have a nice map of where US military are. Since bases house particular units and types of forces, a nation state can estimate strength and investment in the US military.

In a specific case, the response to claims includes patient responsibility (deductible, co-insurance, co-pay.) Add that up for a financial picture, then you’ve got a nice lead list for service members who have money problems.

NegativeK•48m ago
Abortion prosecution or societal ostracization.

Streamer doxing.

Literally just being trans.

HIV fear mongering.

Illegal fuckery with your insurance rates.

Employment discrimination.

Stalking.

Racial discrimination.

Can you imagine trying to fully trust a mental health professional today? A patient can't see a therapist's notes, but they sure as hell can be breached.

There is zero LEGITIMATE use for your breached health data.

righthand•1h ago
Well at least the leaks and irresponsibility have hit the HIPAA level, maybe now some old people will take it seriously? Or will the fallout continue to be normalization of data leaks like the morons in the federal government did for credit reporting agencies?
encomiast•1h ago
This optimism in the face of the current state of government made me chuckle-sob.
righthand•57m ago
HIPAA data is always talked sternly about. I’m hoping my health worker professional friends can help bring attention to the issue. Who knows if everyone will just roll over.
LastTrain•1h ago
As with everything in the US, this will be politicized. I wonder which will be the party of “I’m fine with data breaches”
righthand•58m ago
In my view that stance is becoming bipartisan as tech companies lobby nonsense like “we can’t get left behind China’s AI models so give us all the data!”

Democrats and Republicans always think they’re smart by investing in whatever wave of technology. Here we are.

gwerbin•1h ago
The frog has been boiled.
tyre•53m ago
As far as I’m aware, no one at United Healthcare (the monopoly that owns Change Healthcare, which was hacked for most of these) was held accountable.
quercusa•1h ago
The attack on Stryker used Microsoft InTune to remote-wipe all of Stryker's systems. If you can wipe a system, could you also drop code on it exfiltrate data and credentials?

[0] https://news.ycombinator.com/item?id=47346091

esafak•1h ago
Microsoft Strykes again. What a surprise...
jawns•1h ago
Wait, the main takeaway from this article is that cybersecurity sales teams now have great leads?

Facepalm.

The real takeaway should be that at every level -- government, corporate, healthcare entities, personal -- we need to rethink how we're acting in the face of these disasters.

Government should recognize that its current regulations are insufficient and look for ways to refine them.

Corporations and health-care entities should be asking themselves, "Do I really need to store this data? If so, how do I store it securely, make my systems less vulnerable to attack, make my personnel more informed about phishing, store it for the minimum amount of time, etc."

And we as individuals should be asking ourselves whether so many health-care entities need to store so much data about us.

GJim•1h ago
> Government should recognize that its current regulations are insufficient and look for ways to refine them.

The shear hostility by many people on here to data protection law (hello GDPR) suggests you are going to have a hard time getting such laws passed in the USA.

tyre•1h ago
This wouldn’t have solved the largest one, Change Healthcare. They are an insurance claims exchange. They have to have all of this data.

The breach was social engineering of a customer support rep.

Having worked with them, they’re absolutely necessary for healthcare (in its current form; don’t get me started) to function. The alternative is integrating with hundreds of payers (won’t happen) or doing it by fax/mail (disaster).

jawns•43m ago
I would say that if it is possible to exfiltrate 193 M sensitive records through a social engineering attack on one customer support rep, then there are multiple failure points that they and other businesses need to address:

- better security training for employees

- don't store 193 M sensitive records in such a way that one social-engineering attack gives you access to all of them

- don't store 193 M sensitive records without appropriate encryption, and make it hard to steal both the records and the decryption mechanism.

p2detar•56m ago
Let's not forget that cybersecurity companies may also be directly involved into hacking government institutions. Case in point - the Bulgarian TAD Group cybersec firm that allegedly hacked the National Revenue Agency in 2019.

> It is still unclear what prompted the hack. The prosecution claims that TAD Group tried to blackmail several companies to hire its services, inducing them with hacked information from their websites. However, no company has publicly complained yet. [0]

0 - https://kinsights.capital.bg/politics_and_society/2019/09/17...

roywiggins•1h ago
ai; dr

> This isn't a single point of failure - it's a systemic crisis.

> One in seven breaches isn't a sophisticated external attack - it's someone inside the organisation accessing data they shouldn't.

> These organisations aren't browsing - they're buying

https://news.ycombinator.com/newsguidelines.html#generated

nextaccountic•1h ago
> https://news.ycombinator.com/newsguidelines.html#generated

As written, the guidelines talk about AI generated comments, not AI generated submitted articles

In any case, just flag the submission and move on

fwip•1h ago
The leading paragraph is obviously AI, also:

> That number isn't a projection. It isn't an estimate. It's the sum total of confirmed individuals affected across 735 breach reports filed with the HHS Office for Civil Rights - and it's growing every week.

Free cost calculators for home improvement – no framework, no signup

https://projectcostcalc.com/
1•smarthomeu•1m ago•1 comments

Show HN: A conversation about OS design turned into an actual OS in a week

1•jonathanrtuck•2m ago•0 comments

The point-and-click UI paradox

https://bandarra.me/posts/point-and-click-paradox
1•andreban•3m ago•0 comments

Gillian Anderson (The X Files) Just Made a Surprise Catwalk Cameo

https://www.vogue.co.uk/article/gillian-anderson-miu-miu-aw26
1•reconnecting•4m ago•0 comments

#535: AI's Labor Market Impact, Killing Your Darlings, Learned Helplessness

https://age-of-product.com/food-agile-thought-535-ais-labor-market-impact/
1•swolpers•5m ago•0 comments

Candidates' faces on punching bags linked to 37 uncounted ballots in Hamtramck

https://www.votebeat.org/michigan/2026/03/10/hamtramck-37-voters-disenfranchised-rana-faraj-adam-...
1•hn_acker•5m ago•1 comments

Reinforcement Learning environments and how to build them

https://unsloth.ai/blog/rl-environments
1•vinhnx•5m ago•0 comments

Old risks reemerge in an era of Fed credibility

https://www.federalreserve.gov/econres/notes/feds-notes/why-have-far-forward-nominal-treasury-rat...
1•toomuchtodo•6m ago•1 comments

From plastics to pharmaceuticals, a new discovery sparks chain reactions

https://phys.org/news/2026-03-plastics-pharmaceuticals-discovery-chain-reactions.html
2•Brajeshwar•7m ago•0 comments

How The Pentagon Got Hooked on AI War Machines

https://www.bloomberg.com/news/features/2026-03-12/iran-war-tests-project-maven-us-ai-war-strategy
2•macleginn•8m ago•0 comments

GenCAD

https://gencad.github.io/
1•bilsbie•9m ago•0 comments

Gephi – The Open Graph Viz Platform

https://gephi.org
1•Tomte•10m ago•0 comments

Show HN: Coral – Visualize .proto file dependencies as an interactive graph

https://github.com/daisuke8000/coral
1•dsk8000•10m ago•0 comments

I Built Google File System in Go: One File, Zero Dependencies

https://jitesh117.github.io/blog/google-file-system-in-go/
1•caust1c•10m ago•1 comments

WiFi 8 silicon is shipping before most people even own a WiFi 7 router

https://medium.com/@robert.shane.kirkpatrick/wifi-8-is-coming-before-most-people-even-own-a-wifi-...
1•totalvaluegroup•11m ago•0 comments

The Model Is the Company

https://alexwang.ai/posts/the-model-is-the-company/
1•ketothekingdom•11m ago•0 comments

Ask HN: What makes a great programmer vs what makes a great SRE?

1•ernesto905•12m ago•0 comments

The Chokepoint We Missed: Sulfur, Hormuz, and the Threats to Military Readiness

https://mwi.westpoint.edu/the-chokepoint-we-missed-sulfur-hormuz-and-the-threats-to-military-read...
1•r721•13m ago•1 comments

Mysterious large steel cylinder disrupts traffic in Japan

https://www.rte.ie/news/world/2026/0313/1563216-japan-cylinder/
2•austinallegro•13m ago•0 comments

Triassic Period

https://www.nps.gov/articles/000/triassic-period.htm
1•mooreds•14m ago•0 comments

HAL – Harmful Action Limiter: Lean command guard for AI coding agents.

https://github.com/otherland/hal
2•otherland26•15m ago•2 comments

Show HN: OpenLight – Lightweight Telegram AI Agent for Raspberry Pi

https://github.com/evgenii-engineer/openLight
1•evgenii_isupov•17m ago•1 comments

A Cloudflare Worker that generates dynamic SVG bar charts of your traffic

https://github.com/sd416/cloudflare-worker-stats
1•rishikeshs•17m ago•0 comments

The Disaggregation of the Lakehouse Stack

https://cdelmonte.dev/essays/the-disaggregation-of-the-lakehouse-stack/
1•cdelmonte•18m ago•1 comments

AI Agent Broke into McKinsey's Internal Chatbot and Accessed Records

https://www.inc.com/leila-sheridan/an-ai-agent-broke-into-mckinseys-internal-chatbot-and-accessed...
1•nadis•19m ago•1 comments

France and Italy open talks with Iran in hope of securing safe Hormuz passage

https://www.ft.com/content/96b8e0a4-9ecb-4e07-a96d-7debcfe3bfa6
1•vrganj•19m ago•0 comments

Molting.org – HN: Molting.org – Verifiable reputational layer for AI agents

https://molting.org
1•Roboz•20m ago•0 comments

Ask HN: AI Agents took my programming job. What can I do?

1•butILoveLife•22m ago•2 comments

Jeff Kaplan: World of Warcraft, Overwatch, Blizzard, and Future of Gaming [video]

https://www.youtube.com/watch?v=H9rF1CSSh-w
1•neko_ranger•22m ago•0 comments

High court claimant was fed answers through his smart glasses, judge finds

https://www.theguardian.com/uk-news/2026/mar/13/high-court-smart-glasses-fed-answers-evidence
3•chrisjj•24m ago•1 comments