Hacker News new | ask | show | jobs
by ilikehurdles 2282 days ago
Zoom has allegedly HIPAA-compliant BAAs with users in the health space. If any PHI data is making it over to Facebook without a similar agreement from Facebook, Zoom is in for some trouble.
2 comments

IP address, telephone number, city and other identifying information is ALL considered PII.

I work with (adjacent industry) HIPAA protected data, which is considered PII by virtue of knowing Bob Smith is in the system. If they're under a BAA and sending that information to Facebook they're in violation.

If one of my sub-processors did this my lawyer would be livid. But hey, it's Silicon Valley, don't harsh their buzz man.

How do you even report something this technical to non technical folks who oversee HIPAA? Would you have to do a case study style write up?
As if it's binary definition - technical and non technical, unless they're amish I don't see why it can't be reported in plain terms
There are plenty of technical people overseeing HIPAA.
I am working on adding a Zoom client to a medical device right now :)