Hacker News new | ask | show | jobs
by JshWright 1979 days ago
A HIPAA audit would certainly miss this, but I would be very surprised if a SOC2 auditor missed this (or that they would remain in business long with the damage that would do to their reputation).