Skip to content

Comment on Ask HN: Security negligence by former employer, a health insurance co.?

Comments

This looks like terminal penny pinching. Management dreams they are competent = they are not, except in pay check deposition, running at 100% efficient. Are they public or owned by a reporting entity? = their auditor should be advised. If private, anonymously inform their lawyers, insurers and accountants/auditors. Not sure how they dealt with the recent ransomware, maybe just paid it? Any insurer engaged afterwards with ransomware coverage would have done a data management audit and would not tolerate the state they are in and would not cover them unless they were patched wall to wall. with those holes, loose lips in the hackerverse will soon lead to those holes being exploited - possible ruin to business?

If they are involved with medicaid, medicare, or many private health care insurers - as they must be, hunt for a whistle blower number/button on their web site - not for $$, but for the public good. When cans of worms are opened, bodies are found and it might cost the company a lot of $$ to rectify this, as it should.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.