https://twitter.com/CyberPlayGround/status/560620546359296000
Tag: technology
Healthcare.gov HIPPA VIOLATIONS sharing personal data
Government health care website quietly sharing personal data
HealthCare.gov security — ‘a breach waiting to happen’
HIPPA VIOLATION: #ObamaCare website sends your age, income level, pregnancy status etc. to advertising companies
https://www.eff.org/deeplinks/2015/01/healthcare.gov-sends-personal-data
Shocking http://healthcare.gov security problems remain 1 yr later! Got it
#Politics WINS! > over#HIPPA & patient privacy!
must be read to the very end proves that not only does the Obamacare website have major security issues, but that the incorruptible wonderful well-meaning folks in Washington who care so much about our health and running our lives knew this when the site was launched.Federal medical-privacy law frustrates ID theft victims
http://www.abajournal.com/magazine/article/federal_medical-privacy_law_frustrates_id_theft_victims
a victim of an Obamacare breach and the little known fact that well over half of all identity thefts now arise from information on the Healthcare.gov site. Once again, any individual in the health care industry that demonstrates the slightest carelessness with patient privacy will likely be bankrupted by HIPPA fines.
Hacker accesses 70,000 Healthcare.gov records, says website is 100% insecure
http://www.slashgear.com/hacker-accesses-70000-healthcare-gov-records-says-website-is-100-insecure-21313926/
In the source code of http://healthcare.gov is “no right to privacy” tt overrides HIPPA. But it’s hidden!
http://www.frontpagemag.com/2013/frontpagemag-com/no-privacy-for-obamacare-patients/
And watch how they lie about it: OCare Website Hidden Source Code Says Users “Have No Reasonable Expectation of Privacy”
The CEO isn’t the only hacker to publicly confirm the security issues, however, with Kevin Mitnick, Ed Skoudis, and more having issued warnings of an impending security breach if the problems are not corrected. Said Mitnick in a signed statement alongside fellow hackers: “It’s shameful the team that built the Healthcare.gov site implemented minimal, if any, security best practices to mitigate the significant risk of a system compromise or access to consumer proprietary information.” Despite these warnings, the government has maintained Healthcare.gov is secure and undergoes regular security testing. Whether this latest breach performed by Kennedy will spur a proper review and corrections of the issue at hand is yet to be seen (and a cynic might express ample doubt at this point), but all signs point towards a ticking clock counting down to a major — malicious — data breach.
HealthCare.gov is shuttling personal data to third parties
http://www.slashgear.com/healthcare-gov-is-shuttling-personal-data-to-third-parties-21365499/
Judicial Watch, a politically conservative government watchdog group, has filed a Freedom of Information Act lawsuit against the Department of Health and Human Services seeking the release of all records – including studies, memos, e-mails, and slide presentations – related to the security of the HealthCare.gov Web portal dating back to Jan. 1, 2012.
http://www.healthcareinfosecurity.com/healthcaregov-security-answers-sought-a-6700
Doesn’t that violate HIPPA? Among other privacy laws? -> http://Healthcare.gov website quietly sharing personal data
WASHINGTON (AP) — The government’s health insurance website is quietly sending consumers’ personal data to private companies that specialize in advertising and analyzing Internet data for performance and marketing, The Associated Press has learned.
The scope of what is disclosed or how it might be used was not immediately clear, but it can include age, income, ZIP code, whether a person smokes, and if a person is pregnant. It can include a computer’s Internet address, which can identify a person’s name or address when combined with other information collected by sophisticated online marketing or advertising firms.
The Obama administration says HealthCare.gov’s connections to data firms were intended to help improve the consumer experience. Officials said outside firms are barred from using the data to further their own business interests.
There is no evidence that personal information has been misused. But connections to dozens of third-party tech firms were documented by technology experts who analyzed HealthCare.gov and then confirmed by AP. A handful of the companies were also collecting highly specific information. That combination is raising concerns.
Leading lawmakers on Tuesday asked the administration to explain how it oversees the data firms to make sure no personally identifiable information is improperly used or shared.
The administration did not explain how it ensures that companies were following the government’s privacy and security policies.
Albright said HealthCare.gov comports with standards set by the federal National Institute for Standards and Technology. But recent NIST guidance cautions that collecting bits of seemingly random data can be used to piece together someone’s identity.
In a recent visit to the site, AP found that certain personal details — including age, income and smoking habits — were being passed along, likely without consumers’ knowledge, to advertising and Web analytics sites.
Third-party outfits that track website performance are a standard part of e-commerce. HealthCare.gov’s privacy policy says in boldface that “no personally identifiable information is collected” by these Web measurement tools.
“Personally, I look at this … and I don’t know what is going on between the government and Facebook, and Google, and Twitter,” said Mehdi Daoudi, CEO of Catchpoint Systems. “Why is that there?”
Third-party sites embedded on HealthCare.gov can’t see your name, birth date or Social Security number. But they may be able to correlate the fact that your computer accessed the government website with your other Internet activities.
Daoudi’s company, Catchpoint Systems, came across some 50 third-party connections embedded on HealthCare.gov. They work in the background, unseen to most consumers.
The AP replicated the results. In one 10-minute visit to HealthCare.gov recently, dozens of websites were accessed behind the scenes. They included Google’s data-analytics service, Twitter, Facebook and a host of online advertising providers.
“I think that this could erode … confidentiality when dealing with medical data and medical information,” said Cooper Quintin, a staff technologist with the Electronic Frontier Foundation, a civil liberties group.
http://bigstory.ap.org/article/31490a20926d4ed3b98ff2d0ed8fc81d/new-privacy-concerns-over-governments-health-care-website
Girls change the world and can do anything
Educational CyberPlayGround: Websites for Girls and Young Women who want to be involved with Technology
WEBSITES FOR GIRLS AND YOUNG WOMEN
How to help girls get into technology.
Real women engineers and other role models for girls.
Changing Girls’ Attitudes About Computers
“Don’t worry your pretty little head over it.”
Special Edition
Computer Wonder Women
National Women’s History Month
GIRLS WHO CODE: GIRLS CAN DO ANYTHING – GIRLS CAN CHANGE THE WORD
https://www.youtube.com/watch?v=dr6b4nwo-5k
e-mail privacy laws: You want privacy? Too Bad! Now Politicians get it!
It took a shakedown, it took a threat, take their privacy away and “now” they see the light! Doesn’t matter what is happening to us the 99% until the 1% are effected by it. And Microsoft was happy to let the 99% twist in the wind until politicians put pressure on Microsoft to hand over the “files”. Only after that do we the 99% get any privacy that we all deserved in the first place from the bad actors above!
‘Checking email from the beach, Washington?‘
“Checking email from the beach, Washington?” Microsoft says in the ad, which refers vacationers to a website it set up about the case. “Then you may be just as concerned as most Americans about who has access to your emails saved in the cloud.”
Starting Wednesday, the software giant is running full-page ads in the newspapers of a number of popular beach spots frequented by Washingtonians to make the case for why the company should not have to turn over emails stored on a foreign server. The ads are running in weekly newspapers in Rehoboth Beach, Del., Martha’s Vineyard and North Carolina’s Outer Banks.
The company noted that 83 percent of people in a recent poll it commissioned thought that the same protections should apply to information stored digitally as on paper.
“Microsoft believes you own your emails no matter where they are stored,” it said. “That’s why we’ve gone to court to ask the government to follow long-established, internationally agreed upon processes to obtain emails rather than forcing technology companies to turn them over.”
A federal judge recently ruled against the software company, though Microsoft has pledged to appeal.
Other major tech firms including Apple, Verizon and AT&T have signed on in support of Microsoft, as has the digital rights organization Electronic Frontier Foundation.
The ad comes in response to a federal judgement in which Microsoft was ordered to share the private email data of users with investigators as part of a criminal case.
Microsoft has been pushing for new privacy rules ever since a federal judge this summer ordered the company to turn over a customer’s e-mails from an overseas server to U.S. law enforcement. Microsoft and several privacy advocates argued that doing so would set a dangerous precedent that would allow the U.S. government to order firms to give up content regardless of where the data are stored.
Your government has an interest in gaining access to communications stored overseas without having to rely solely on cooperation from foreign law enforcement. Currently your email is treated as a company’s business records – Imagine That! My email is MINE!
Microsoft is squaring off against the Justice Department in a case that could have drastic ramifications for the protections on people’s data. Not to mention their bottom line. If microsoft can’t protect your privacy then what business around the world is going to want to do business with microsoft software <THINK CHINA>
legal protections for emails and documents stored in data centers abroad, turning the issue into a landmark battle over digital privacy is only about their 1% bottom line.
Who is going to want to do business with Microsoft products?
Microsoft challenged the warrant, claiming that the U.S. government does not have any authority to go after information stored in Ireland, without permission from the local government. Instead, Microsoft argues that the U.S. needs to go through a treaty process that allows it to get evidence from foreign countries.
Repairing the public’s trust? I don’t think so!!
After more than a year of disclosures from our hero Edward Snowden caused many to be wary of American tech products, and learning about the conflicting laws between different nations this is about microsoft losing market share as well. The European Union, for instance, which has taken a much stronger approach to privacy, might take issue with a company that shuttled data stored abroad back to the U.S. government.
Judge Loretta Preska agreed with the government that the question came down to who controls the data, not where it is stored. Preska also ruled that personal emails are considered a “business record” under the law.
Someone better take Loretta to school it’s 2014.
1986 Electronic Communications Privacy Act outlines rules for protecting digital information under the constitutional right to privacy, but does not provide a clear legal framework for dealing with the data stored on servers outside of U.S. territory, since the concept of multinational data centers.