News
3/17/2008
10:45 PM
Terry Sweeney
Terry Sweeney
Commentary
50%
50%

Not As Dumb As Eliot Spitzer

Don't get me wrong -- I think Chris Crocker would make a crap spokesperson for HIPAA. But the medical staff of the UCLA Health System facing discipline or dismissal for snooping in Britney Spears' medical records deserve everything coming to them.

Don't get me wrong -- I think Chris Crocker would make a crap spokesperson for HIPAA. But the medical staff of the UCLA Health System facing discipline or dismissal for snooping in Britney Spears' medical records deserve everything coming to them.The Los Angeles Times wrote about this breach/medical voyeurism over the weekend. As if the 19 staffers on this most recent go-round weren't bad enough, the Times reported several workers were disciplined in September 2005 for looking at Spears' records after she gave birth to her first son.

A few years ago, we might have called this bad form, unethical even. But thanks to the personal privacy protections in state and federal laws, this kind of snooping is now officially illegal.

I can imagine being tempted to look. I can probably even imagine being boneheaded enough to open up unauthorized files. I can't imagine being so stupid to believe that some log file or audit trail wouldn't eventually betray my burning need to know.

Is dismissal or suspension an appropriate response? Those punishments don't really fit the crime, do they? What if the culprits were required to publish their own medical records in a couple major daily newspapers? Or maybe some community service, in which they form human shields around some celeb to confound the paparazzi?

I'm curious if you think the UCLA staff deserves more than a slap on the hand. E-mail me with your thoughts or leave a comment below.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Latest Comment: nice one
Current Issue
Flash Poll
10 Recommendations for Outsourcing Security
10 Recommendations for Outsourcing Security
Enterprises today have a wide range of third-party options to help improve their defenses, including MSSPs, auditing and penetration testing, and DDoS protection. But are there situations in which a service provider might actually increase risk?
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-1235
Published: 2015-04-19
The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in the HTML parser in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy via a crafted HTML document with an IFRAME element.

CVE-2015-1236
Published: 2015-04-19
The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy and obtain sensitive audio sample values via a cr...

CVE-2015-1237
Published: 2015-04-19
Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/render_frame_impl.cc in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger renderer IPC messages ...

CVE-2015-1238
Published: 2015-04-19
Skia, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors.

CVE-2015-1240
Published: 2015-04-19
gpu/blink/webgraphicscontext3d_impl.cc in the WebGL implementation in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebGL program that triggers a state inconsistency.

Dark Reading Radio
Archived Dark Reading Radio
Join security and risk expert John Pironti and Dark Reading Editor-in-Chief Tim Wilson for a live online discussion of the sea-changing shift in security strategy and the many ways it is affecting IT and business.