- Feature Articles
- CodeSOD
- Error'd
- Forums
-
Other Articles
- Random Article
- Other Series
- Alex's Soapbox
- Announcements
- Best of…
- Best of Email
- Best of the Sidebar
- Bring Your Own Code
- Coded Smorgasbord
- Mandatory Fun Day
- Off Topic
- Representative Line
- News Roundup
- Editor's Soapbox
- Software on the Rocks
- Souvenir Potpourri
- Sponsor Post
- Tales from the Interview
- The Daily WTF: Live
- Virtudyne
Admin
1st
Admin
OMG OMG OMG OMG!!!! I would be calling layers at that point! OMG!
Admin
new XMLHTTPRequest(window.layers); ?
Admin
Okay... where are my steel boots? Need to kick some a**
This is a really good WTF.....
Would like to know if someone got sued
Admin
Seriously they should be reported. Not only for trying to pull a fast one on the software company but for such a gross violation. Not only is medical information on there, but Social Security Numbers!
Admin
Sounds like it's time to sue them for their gross negligence.
all around big WTF
Admin
Wow. I sincerely hope this one goes up to the Feds and the client gets nailed to the wall on this.
Admin
Is there a way to log in to the application and actually GET drugs?
And if so, can I have the URL?
Admin
Fecking forum software.
Anyway, layers or lawyers, I do hope someone reports them; not just for being sneaky about trying to steal the software, but for the privacy violations. Seriously. Civil penalties, criminal charges and penalties, loss of accreditation. This is a cluster fuck on so many different levels, it borders on not funny. Plus, the double-whammy of it being CD treatment.
Wow. just, wow.
Admin
Hmmm .... i fail to see anything that HIPPA (or HIPAA) has to do with SOX.
HIPAA is a health information privacy act, SOX (Schema for Object-Oriented XML I assume) is computer related.
http://www.acronymfinder.com/af-query.asp?Acronym=HIPPA&Find=find&string=exact
WTF?
Admin
No, you can only POST them.
Admin
Names, social security numbers, diagnosis and treatment information for drug addicts across the state.
Q: And which state are we talking about?
A: A major one.
Admin
<FONT color=#0000cc>Summary of Sarbanes-Oxley Act of 2002</FONT> anyone?
Admin
SOX in this case is the Sarbanes-Oxley Act. It was passed in 2002, partly in response to the Enron scandal and similar corporate malfeasance.
Among other things, it mandates how companies record and store financial information, so that said information might be easily audited and/or subpoenad in case said company is doing anything dodgy. It spawned a cottage industry of IT experts and consultants who would make sure your data storage facilities were SOX compliant.
jf
Admin
No, because the application was coded by someone who wants to avoid the Spider of Doom problem. Instead, you have to log in and POST drugs.
Admin
This goes to show that no matter how secure your technology may be, it can be completely circumvented by the simplest (and dumbest) of human actions.
If you are writing an application and your client asks for the source, that is a sign they are going to do something with it. Sell, modify or get someone else to work on it. Never release your source code unless you agreed upon it before working on a project.
And why did they give their customer access to backup the production database? Wouldn't that have been a breach of privacy regulations?
Admin
It's hard to say who the WTF was...the person who sent the source code, etc or the people who took it on the sly. Everyone would get busted for this...badly.
Admin
SOX in this case is the Sarbanes-Oxley (http://en.wikipedia.org/wiki/Sarbanes-oxley ) Act that deals with public company's accounting, auditing, privacy and corporate responsability.
It imposes a lot of compliance checks that need to be enforced by IT systems.
Admin
Screwing up code that only makes the application $*#& up internally is one thing, but intentionally posting medical records and worse, SS numbers, should be a federal crime (assuming it isn't - dunno).
Can we create a new category of WTF - perhaps: Supreme-WTF for stuff like this?
Admin
So, the moral of the story is that you should just not bother seeking treatment for drug addiction, right?
<font size="2">(Don't do drugs kids because you could end up in jail, and drugs are much more expensive in jail.)</font>
Admin
Brillant!
captcha: enterprise
Admin
Are you saying the forum software ate your w's? I'm skeptical.
I think we have the same briefcase.
Admin
Admin
I'm such a non-spell-checking f00l! I meant lawyers ;-)
Admin
Government clients often have full rights to everything, per contract. Not much you can do about it. Trying to tell them what to do with it would likely fall on either the wrong ears or deaf ears.
But yes, they should know better.
Admin
When I see things like this I get a real urge to contact the responsible autority and get those idiots removed from the IT genepool. This is actually as scarey as it is funny. There could be muppets like this working at your bank!
Admin
Pretty sure he's just angry that he can't edit his post.
Also, this is ridiculous. I really hope heads rolled after this.
Admin
Any computer-literate drug dealer in that state could have had himself a huge new client list. I've seen some pretty gross malfeasances in information security before, but this has to be the worst.
Admin
Committee - A group of people who, individually can do nothing and collectively agrree that nothing can be done.
Admin
The real WTF here is that it didn't include Drivers License numbers or total family income amounts.
Admin
If whomever submitted this WTF reports it to the appropriate state medical board, heads WILL roll - they take stuff like this seriously!
Admin
Waitaminnit.
You (apparently) used acronymfinder.com for HIP[PA]A, but didn't think to use it for SOX before posting?
Yeeks.
Admin
Being in the natural farming business, I can tell you that none of my layers would be the slightest bit interestred in anything involving drugs.
Admin
Um - I hope it is whistle-blowing time...
This company really needs a lesson in not doing this kind of stupid illegality.
Admin
It's HIPAA, no HIPPA about it.
Admin
Hungry HIPPA? Why did I have to read this after reading this?
Admin
I am a HIPAA consultant and a programmer.
There is a reason why HIPAA consults make so much money, they are basically cheaper than lawyers (those are much more expensive).
Anyone familiar with the Tier I--Privacy and Tier-II Administrative Simplification (probably the most complex part) can attest to. I am an expert in tier II, which is basically the groundwork for the EDI process for medical billing and enrollment. It's not a picnic.
You got a hundred thousand different healthcare providers and over a thousand payors. That's a SH** load of business partners and is much more complex than Wal-Mart EDI with invoices/POs and electronic bill of lading.
HIPAA projects should never be touched by junior people in your administration. The company that allowed this to happen should be reported. Anyone can file a HIPAA complaint about any medical company at this website:
http://www.hhs.gov/ocr/privacyhowtofile.htm <-- this is for filing complaints about a violation just like the one that occured here (you can file anonymously to protect yourself from being fired by your employer. Your employer CANNOT take retribution on you for filing such complaints)
https://htct.hhs.gov/aset/ <--- this is for filing a complaint about Tier II violations (in regards to EDI business transactions between medical partners)
Admin
Maybe he's using a computer at the White House.
http://www.boston.com/news/daily/23/letter_w.htm
Admin
Oh boy! Gross privacy violations and blatant theft!
At least this programmer('s company) is going to come out on top; NOT telling the government that they just boldly violated HIPPA has got to be worth $$$
Admin
Actually, it was a pre-emptive strike, induced by my general dislike for Community Server, a failed attempt to insert an emoticon to help express my complete disgust (as one who has worked not only in healthcare but specifcally CD/Substance Abuse) at the layers of WTF-ery here, and a gentle poke at how this had affected GoatCheez so badly that he swallowed a 'w.' Plus, there was a pathological fear that something would get eaten if I didn't have the correct fingers and toes crossed while hitting the 'Post' button.
It's never easy to convey emotions and humor in a forum. Community Server seems to take 'difficult' and mung it to 'effing impossible.'
Fingers Crossed ...
Admin
HIPAA, HIPAA, HOORAY
Admin
Please tell me this is ending in criminal prosecution.
Admin
[8-)]
Admin
Well, if it was just anonymized and not actually anonymous, then theoretically anyone who was included in this list could sue for mad cash...and could probably name this site as complicit in not reporting the incident. That's gotta be worth a few thousand, right?
Mmm...filing suit against everyone who had any contact with this WTF...mmm...
Admin
Crap happens all the time, unfortunately. I was working for a state social services organization once, and the stuff I used to see there would turn your hair gray.
They routinely threw away hardcopy social security numbers, their "databases" (not my responsibility thankfully) were a complete disaster, and poorly secured at best. They'd download stuff from the state's secured databases, import it into their own, internet available, insecure databases, fiddle with the data, then UPLOAD IT BACK INTO THE SECURED DATABASE. Want to do welfare fraud? Want to "pay" your child support? Want to track down your estranged spouse and kill 'em?
I even reported some of the stuff to the state, but nothign came of it. People just don't understand security. The stuff that gets released into the open boggles the mind.
Admin
That reminds me of this despair poster:
Meetings - None of us is as dumb as all of us.
Admin
Admin
Not surprising. At my previous employer we were brought in to support a website for a popular herpes medication. It had a form where people could enter their name/phone/address to request more information on the product. Turns out the form handler was just appending the data to an unprotected text file in the website's root. It was literally as bad as: http://www.herpes????.com/formdata.txt and you could see several hundred people's name/phone/address + personal questions about the product as it related to their condition.
The best part was that the maker of the drug whose initials are S, G and K in some other order, had no idea that this potential customer data was being collected. Despite the client and the account team not understanding the magnitude of the problem and not budgeting any fixes, I went in and did some moving of files and slight recoding to try and get some security. Still... horrifying.
BG
Admin
It is a federal crime. Now, what law was that under....? Oh, right. HIPAA.
Admin
I propose that the IT folks who know what they are doing, when spotting a major WTF in someones' code, be required to insert the following as a warning to others: