redegelde, to random Dutch
@redegelde@mastodon.education avatar

#cookies kan dat nu niet anders.
Je komt niet verder dan dit bij #gpfans

jaboud, to random
puresick, to random

„Presents versus privacy“

Zerforschung doing a great job again at researching a startup promise and finding a simple but bad vulnerability.

#security #research #vulnerability #data #privacy #session #cookies https://zerforschung.org/posts/throne-en/

admin, to socialwork

TITLE: Confusion in Text Messaging, Encryption, and HIPAA

A therapist colleague of mine contacted Ring Central (a video and
telephone platform that provides HIPAA BAA subcontractor paperwork upon
request) with questions about their messaging capabilities and
encryption. They were looking for a compliant way to text message with
clients. The support staff directed them to this article:

https://support.ringcentral.com/article-v2/Intro-to-end-to-end-encryption-in-RingCentral-messaging.html?brand=RingCentral&product=MVP&language=en_US
<https://support.ringcentral.com/article-v2/Intro-to-end-to-end-encryption-in-RingCentral-messaging.html?brand=RingCentral&product=MVP&language=en_US>

At first glance, the article would seem to make messaging with clients
golden as a good level of encryption is described and the therapist has
a HIPAA BAA with Ring Central. Right?

Wrong.

A few different topics are getting confused here -- smart phone SMS text
messaging, messaging within Ring Central apps and websites, and HIPAA
BAA subcontractor agreements.

With SMS text messaging by phone it will never be HIPAA compliant (even
if the therapist sends it from within Ring Central) because the client
will get the SMS text message unencrypted on their smartphone.

Messaging within the Ring Central apps and website IS at an excellent
level of encryption -- but won't be covered by the therapist's HIPAA BAA
agreement unless the people messaged are also part of the therapist's
company account or are other therapists with their own Ring Central
accounts with HIPAA BAA subcontractor agreements. This will rarely if
ever cover therapy clients.

This gets confusing. So -- for example -- when I go into my Ring
Central account online and click on "Message" I'm invited to email a
messaging link to anyone I choose. So far so good. But when that
person (like a client for example) goes to that messaging link, Ring
Central REQUIRES them to sign up for their own FREE Ring Central
account. That FREE account WILL NOT be covered by a HIPAA BAA
agreement. So the messages sent to them (inside a Ring Central app or
website) will be encrypted but not HIPAA compliant.

Similar problem with Ring Central video conferencing. As long as the
client DOES NOT sign in with their own free account -- and instead goes
to my anonymous video link -- it will be covered under my BAA agreement
with Ring Central. However, Ring Central invites clients to sign up for
their own FREE account in order to video conference with me. If the
client makes that mistake, then its no longer a HIPAA compliant video
conference session because only one of our two Ring Central accounts is
covered by BAA.

I sometimes wonder why this all is left in such a confusing state?

Of course, I'm not a lawyer, so do your own research too.
*
Michael Reeder, LCPC
*
Hygeia Counseling Services : Baltimore / Mt. Washington Village location

#psychology #neurology #socialwork #psychiatry @psychology
@socialwork @psychiatry #mentalhealth
#psychotherapists @psychotherapists #pharmacy
#medicationchecker #drugs #druginteractions #cookies #tracking #hacking
#3rdpartytrackers #HIPAA #privacy #dataprivacy #webbeacons#RingCentral
#VoIP #telephony

admin,

I've said several times that the Signal messaging app may not be HIPAA compliant.

I was likely wrong.

From another thread (thank you Siderea): "You don't need a BAA from Signal to be in compliance with HIPAA. Signal is one of the very few platforms that meets the carrier standard not to need one, because they have no access to the contents of messages sent through them."

However, there is more to the story. You need to read this write-up from 2016 (so it may be dated):
https://personcenteredtech.com/vendorreview/signal/

Person Centered Tech says it best (above), but some factors include:

a) The need to keep copies of all communications in the client's chart. So you have to get messages out of Signal and into your chart. You also have to convince clients not to set their messages to self-destruct or you need to retrieve them before that happens! Signal messages (as of 2016) were not backed up automatically when your phone is backed-up. Lose your phone -- lose your messages.

b) You may need client phone numbers stored in your phone. Do you store them not under their names (initials maybe)? Do you need a BAA agreement with the vendor that backs-up your phone directory?

c) You may need to keep Signal from displaying client names on screen whenever you get a new pop-up alert of a new Signal message.

-- Michael

@siderea @psychology @socialwork @psychiatry @psychotherapists

#psychology #socialwork #psychiatry #mentalhealth
#psychotherapists #pharmacy
#cookies #tracking #hacking
#3rdpartytrackers #HIPAA #privacy #dataprivacy #webbeacons #Signal
#telephony #SMS #messaging

questlog, to programming
@questlog@mstdn.games avatar

For anyone that wondered why Questlog only links to YouTube videos like game trailers and doesn't just embed the No Cookie version.

There are many reasons but one of the biggest reasons was the privacy philosophy of Questlog. But didn't I say No Cookie version? Yes, but it is not what you expect.

This post describes it pretty well. https://cloudfour.com/thinks/youtube-no-cookies-adds-cookies/

I realized that at work a while ago and decided I don't want to use YouTube-Embeds ever again. #WebDev #Coding #Privacy #GDPR #Cookies

Chrishallbeck, to random
@Chrishallbeck@mastodon.social avatar
mastodonmigration, to internet
@mastodonmigration@mastodon.online avatar

April 30, 2023

Sure our Terms of Service taking ownership of your content are a crazy, says CEO Jay Gaber. It's the lawyers' fault, trust her...

Yahoo: Users Flock to Jack Dorsey’s Twitter Rival BlueSky, but Fine Print Gives Some Pause >>> https://www.yahoo.com/entertainment/users-flock-jack-dorsey-twitter-155832584.html

“It was not my intent for the legalese to end up so confusing and unfriendly... We’ve already been working on a second pass over the past few weeks.”

paul,
@paul@oldfriends.live avatar

@mastodonmigration

that link🔝 ⏫ is a must read

"#BlueSky Terms of Service gives Jack a 'perpetual' & 'irrevocable' license to all your content (posts, name, likeness, pics)

"#Privacy Policy says they'll stalk everything you do on the site, but also what you were doing before you got there & what you do after"

"...#Cookies, #pixel tags, & web beacons on app, web, & emails to stalk you all over the web. They'll use info for targeted #ads"

:nitter: https://nitter.net/ashleygjovik/status/1651686218319425570

amoroso, to random
@amoroso@fosstodon.org avatar

I'm using the Consent-O-Matic browser extension to autofill cookie consent pop-ups. It's a time saver as it seamlessly handles the pop-ups most of the times.

The extension, wich I use with Chrome but is available also for Chromium and derivatives, Firefox, and Safari, is an open-source tool by a European academic research project on privacy.

https://github.com/cavi-au/Consent-O-Matic

#cookies #privacy

icd, to random Polish
@icd@mastodon.internet-czas-dzialac.pl avatar

Czym jest Uzasadniony Interes Administratora? Warto wiedzieć, jak działa ta podstawa prawna, która często jest błędnie interpretowana zarówno przez administratorów, jak i osoby, których dane dotyczą.

Nieznajomość prawa szkodzi! ;)

@agnieszka przybliża ten temat w drugim odcinku ICD Express:

https://www.internet-czas-dzialac.pl/czym-jest-uzasadniony-interes-administratora-icd-express-2/

#prawo #rodo #uodo #cookies

Mastodon, to random
@Mastodon@mastodon.social avatar

A new update on our #Patreon: Hiring progress, 3 months in

https://www.patreon.com/posts/hiring-progress-81995545

nicol,
@nicol@social.coop avatar

@Mastodon #Patreon doesn't appear to let me reject or opt out of Tracking #Cookies to read that… #GDPR #OpenCollective

Downfroggy, to random

There’s some interesting results in the gingerbread decorating today. SMH at creative teenagers…. #gingerbread #cookies Curious which ones will be picked to leave out for Santa….

jace, to Calgary

Today's -40C #calgary weather called for some comfort desserts. Warm, chewy, chocolatey brownie #cookies.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • provamag3
  • mdbf
  • ngwrru68w68
  • modclub
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • JUstTest
  • GTA5RPClips
  • ethstaker
  • normalnudes
  • tester
  • osvaldo12
  • everett
  • cubers
  • tacticalgear
  • anitta
  • megavids
  • Leos
  • cisconetworking
  • lostlight
  • All magazines