Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This seems like a five alarm fire for HIPPA, is there something I’m missing?




It’s a bug. He reported it, they fixed it.

It is not a five alarm fire for HIPAA. HIPAA doesn’t require that all file access be logged at all. HIPAA also doesn’t require that a CVE be created for each defect in a product.

End of the day, it’s a hand-wavy, “look at me” security blog. Don’t get too crazy.


I am more on the privacy side of things like HIPAA, but I would like to link the following.

https://www.hhs.gov/sites/default/files/january-2017-cyber-n...


There’s discretion in reasonable and appropriate.

Biggest thing is to have plan and policy. I’d agree in general that more audit is better.


It's HIPAA.

The HIPAA hippo certainly encourages this confusion

It's HIPPA now for all intensive purposes.

For all intents and purposes



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: