this post was submitted on 09 Jul 2024
15 points (100.0% liked)

Pulse of Truth

377 readers
61 users here now

Cyber Security news and links to cyber security stories that could make you go hmmm. The content is exactly as it is consumed through RSS feeds and wont be edited (except for the occasional encoding errors).

This community is automagically fed by an instance of Dittybopper.

founded 10 months ago
MODERATORS
 

Stolen Data Includes Patient Medical Information, According to Breach NotificationA Pennsylvania-based debt collector originally told regulators in April that a hacker compromised the personal identifiable information of 1.9 million people. Now the company says the data breach affected more than 4 million people and included patient medical information.

top 2 comments
sorted by: hot top controversial new old
[–] [email protected] 2 points 1 month ago* (last edited 1 month ago)

I upvote this sort if thing for visibility, but I'd rather it not be a thing.

[–] [email protected] 1 points 1 month ago

The real question is why a debt collector had patient medical information to begin with. That sounds like a massive HIPAA violation; Under HIPAA, debt collectors are only supposed to be given the bare minimum info to be able to collect the debt. Typically, that consists of the patient’s contact info, and how much is owed. They very rarely get any kind of supporting documents, because that would divulge too much info.

One of the fastest ways to get a medical debt collector to delete your debt entirely is to get them to slip up and mention that they have info regarding your diagnoses or treatments. As soon as they mention that they know what the bill is for, (for instance, saying it’s a bill for a heart surgery instead of simply saying it’s a bill from a heart surgeon’s office,) you can start threatening to sue and file HIPAA complaints. They’ll almost always agree to delete the debt if you agree not to sue. And even then, you should still make the HIPAA report regardless, because they can’t legally stop you from doing it and it’s one of the few ways to hold scummy debt collectors accountable.