logoalt Hacker News

gen220last Wednesday at 6:45 PM2 repliesview on HN

FYI, there's a .gov-maintained portal where healthcare companies in the U.S. are legally obliged to publish data breaches. It's an interesting dataset!

https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf


Replies

fhsmlast Thursday at 1:03 AM

This is a suboptimal characterization of this site.

I think it would be less wrong to say this is where covered entities that discover reportable breaches of PHI (whether their own or that of a BA) that trigger the immediate reporting obligation report them.

This is a narrower scope of coverage and shallower depth of epistemic obligation than you implied.

mexicocitinluezlast Thursday at 11:32 AM

One of my favorite HIPAA stories is about a doctor who utilized his patient list when sending out campaign-related information when he was running for local office. Over 2 decades of schooling and still didn't understand how stupid this was.