Hacker News new | ask | show | jobs
by maxheadroom 2465 days ago
This will probably seem very pedantic but aren't "Unauthorized Access/Disclosure" and "Hacking/IT Incident" pretty much the same things?
1 comments

No. Unauthorized access or disclosure can happen when someone with legitimate access to the system gets access to more data than they should see. For example, a patient logs on to the system to view their own record and sees records for other patients. Logs would show this, and this would have to be disclosed.

Deliberate penetration of the system, or purposeful exfiltration of the data, are very different occurences.