Hacker News new | ask | show | jobs
by bcg1 3797 days ago
I think this is a good approach. I'm not familiar with HITRUST so maybe this is part of it... but I wonder if there is a way for the lawyers to build something into the policy that makes it so that if a backup exists (for instance on the devs machine, Dropbox, etc) then everything on that machine/cloud account/whatever is also legally discoverable in the event of a leak.

This could potentially make it so that the developer would effectively be leaking their own private data if they tried any shenanigans.