sfba.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Mastodon instance for the San Francisco Bay Area. Come on in and join us!

Server stats:

2.3K
active users

#privacy

944 posts628 participants115 posts today

For years, I have filed a HIPPA complaint with the privacy office of every website I go to that has a Google Analytics tag that serves my protected health information, like my doctor, MyChart, labs, pharmacies, home health, case management etc. I get brushed off. It just makes me uncomfortable.

🔗 'Read the Manual': Misconfigured Google Analytics Led to a Data Breach Affecting 4.7M

Personal health information on 4.7 million Blue Shield California subscribers was unintentionally shared between Google #Analytics and Google #Ads between April 2021 and January 2025 due to a misconfiguration error.

#hippa #Privacy #GoogleAds #Google #MedMastodon

it.slashdot.org/story/25/04/26

🔗 BCBS NOTICE OF DATA BREACH: news.blueshieldca.com/notice-o

"On February 11, 2025, Blue Shield discovered that, between April 2021 and January 2024, Google Analytics was configured in a way that allowed certain member data to be shared with Google’s advertising product, Google Ads, that likely included protected health information. Google may have used this data to conduct focused ad campaigns back to those individual members. We want to reassure our members that no bad actor was involved, and, to our knowledge, Google has not used the information for any purpose other than these ads or shared the protected information with anyone."

Continued thread

"The amendments provide multi-channel access for data subjects to object to processing their information, or request the correction or deletion of their personal information free of charge.

This can be done by hand, fax, post, email, SMS, WhatsApp, or any other convenient method for the data subject."

#POPIA #SouthAfrica #DataProtection #Privacy

mybroadband.co.za/news/cellula

🛡️ #Privacy + Security folks, I'm looking for resources and recommendations!

Is there a favorite checklist, toolbox, or process that you like to use when assessing an individual's personal security posture?

I'm looking for a pre-made, practical framework that I can bring to a 1-hour sit-down with someone while we look at their phone or laptop to help focus and organize the process. Things like updating the OS and changing passwords can take a significant amount of time - it'd be nice if the tool recognized and accommodated for this!

I started jotting down critical settings to check on iOS in a text note, and it's really starting to sprawl as I branch out to different operating systems and think of more attack paths. I'm prepared to turn this into a finished product, but do have significant knowledge gaps about Android and MacOS devices and may need external references anyway.