Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Whether there are damages depends on the context. In 2015 an HIV clinic in London used the to: field instead of bcc: on a patient newsletter, thus exposing the names of 700 patients, many of whom knew each other due to the small geographic area being served (https://www.theguardian.com/technology/2016/may/09/london-hi...). They were fined GBP180K (under the pre-gdpr regime, incidentally, so this isn't a new risk for businesses).


I think that is why my hospital network uses an online patient account for any messages instead of email. Easy to screw up this stuff if using email.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: