this post was submitted on 23 Apr 2025
11 points (100.0% liked)

The Register

242 readers
38 users here now

Biting the hand that feeds IT — Enterprise Technology News and Analysis

founded 10 months ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 2 points 1 month ago (2 children)

First: the "Blue Cross" and "Blue Shield" are certifications that an insurance company can get that are defined by the Blue Cross and Blue Shield Association. So, this company only got the Shield, but not the Cross. It's a whole thing. I have experience with one who had both, and it's a pain to maintain, but it ensures a lot of quality if done well. It's not always done well.

Second: I've had to have this kind of conversation with a marketing person that you can't even advertise certain things on the member's site about what kinds of doctors or services would be available because you can't share information with others on the plan. If Mom goes to the doctor for fertility, that does not mean she wants Dad to know. Also, if daughter goes to get a procedure done, you can't, unless DIRECTLY AUTHORIZED, tell anyone else in the family. Because the logic for all of that is a bit complicated, we told him in no uncertain terms that it was impossible and we were going to work against him doing it.

I'm still surprised people in Insurance are making these kinds of dumb mistakes. It's not that hard to just protect the data. Yes, breaches happen, but this is them handing it over. Get a few good data analysts and you can develop some really good algorithms, OR develop your own LLM with the user's data. BUT KEEP IT INSIDE OF THE DATACENTER.

[–] [email protected] 1 points 1 month ago (1 children)

How is this not a massive HIPAA lawsuit, though? And why would Google open themselves up to that legal risk? I get that the company did this by misconfiguring their use of Google products, but "oops" isn't a valid legal stance to not get sued...

[–] [email protected] 2 points 1 month ago

Oh, this should be. HHS should be coming down on them hard for this, and the members should have a huge lawsuit. There are major regulations that are broken doing this kind of thing. BUT, that takes people who have money or care. RFK Jr seems to be more worried about autism and beef fat than actually holding insurers to account at this point. On a side-note. His hyperfixation on autism seems like weird stimming... Anyway, wait to hear about any kind of suits or follow-up to this.

More reading on HIPAA for those inclined.