Skip to content

Comment on U.S. government worse than all major industries on cyber securityparent

Comments

I'd file a complaint with their bosses. Your privacy is important. If the tech staff won't take HIPAA seriously, their bosses better or they'll lose their job. Don't let this go, please, be proactive.

Absolutely. I have zero interest in letting this go. :)

I have zero interest in letting this go

Then file a HIPAA complaint [1].

[1] http://www.hhs.gov/hipaa/filing-a-complaint/index.html

Not sure if it needs to get to that point yet. I'd like to do this civilly first and more aggressively with complaints like that only if necessary.

The first response was civil. I'd go straight to the HIPAA complaint now. They had their chance. Being overly polite is a waste of your time. For all you know you're being filtered by a moron covering his own ass.

My only concern with that, from personal experience, is that groups like HIPAA tend to be about as dismissive, but often significantly more. But you're right. If I don't get a decent response by tomorrow mid-afternoon, I'll raise the issue higher and follow through. My lawyer is very good with these sorts of issues, so I can go to him if needed, too.

Oh, the rabbit holes...

Edit: also, for what it's worth, I wasn't polite at the end - far from it.

Filed. :)

I'm a little late to the party but I'm glad you filed. That's awesome. Standing up for yourself (and others) is always a rewarding thing. Great work!

I helped build a learning management tool for our med school, even set up SSO with their AD. They scanned the hell out of us. And we had flaws. But when the dean said he wanted it on the school's domain, on their server, IT did as told.

I don't know the answer. If you do interesting things, there will be bugs. And a university is full of people doing interesting things. If IT locks everything down you end up hamstrung, like the DoD often is. Another kind of pain I know all too well.

Oh trust me, I get it. There's definitely a middle ground, though.

If you want to know locked down, my last place locked down icmp between vlans for security reasons. Ironically, it's what got me to learn nmap. It was also hell. :)

We do lots of interesting things at Google. We are more secure than the average university, I believe.

Careful, people have been prosecuted for running unauthorised portscans before. It's probably easier for them to report you to the police than it is for them to fix the problems.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.