Hacker News new | ask | show | jobs
by pm215 2556 days ago
Whether there are damages depends on the context. In 2015 an HIV clinic in London used the to: field instead of bcc: on a patient newsletter, thus exposing the names of 700 patients, many of whom knew each other due to the small geographic area being served (https://www.theguardian.com/technology/2016/may/09/london-hi...). They were fined GBP180K (under the pre-gdpr regime, incidentally, so this isn't a new risk for businesses).
1 comments

I think that is why my hospital network uses an online patient account for any messages instead of email. Easy to screw up this stuff if using email.