News: 1707765308

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Dutch insurers demand nudes from breast cancer patients despite ban

(2024/02/12)


Dutch health insurers are reportedly forcing breast cancer patients to submit photos of their breasts prior to reconstructive surgery despite a government ban on precisely that.

That sounds pretty bad but it gets worse: These insurers keep losing their copies of these highly intimate pictures, one way or another.

Some insurers don't use secure websites and/or other means of electronic communications to transfer these very sensitive photos, according to the Netherlands public broadcaster NOS. Patients reported that their insurance companies have [1]lost their photos , and denied their requests for reconstructive surgeries following a breast-cancer diagnosis.

[2]

In addition to being intrusive and humiliating — and, we're told, [3]not a requirement for any other types of cancer-related surgeries — cancer patients' photos have been [4]stolen by ransomware crews in the past, and then used to [5]extort victims . Some of these images ended up published online in data dumps, and now patients are suing the healthcare provider for allowing the "preventable" and [6]"seriously damaging" leak .

[7]

[8]

While the initial reconstruction is reimbursed by health insurers, if the patients require a follow-up surgery insurers generally require photos to determine whether they will cover it.

After a media outcry about the situation in 2021 the Dutch Health Minister [9]required that these photos be taken in a hospital, with the rules coming into effect on January 1, 2023. Some hospitals have since refused to do this, citing the sensitive nature of the images and potential privacy nightmares.

[10]

Meanwhile, health insurance orgs aren't necessarily following this rule, and are still asking patients directly for photos. One patient interviewed by NOS and insured by CZ was asked to send the nudes via email before the insurer would reimburse a second procedure after a botched first operation.

So she did, "with great reluctance," and was later told by CZ that the photos had been lost.

[11]Cancer patient sues hospital after ransomware gang leaks her nude medical photos

[12]Now BlackCat extortionists threaten to leak stolen plastic surgery pics

[13]After injecting cancer hospital with ransomware, crims threaten to swat patients

[14]Ignore Uncle Sam's 'voluntary' cybersecurity goals for hospitals at your peril

When asked about the patients' claims, a CZ spokesperson told The Register : "Dutch health insurer CZ does not ask breast cancer patients to submit photos."

The insurer, however, told NOS that it does request photos from the patients "if the plastic surgeon doesn't want to send photos," and described the lost pic as "very annoying."

Other patients, including those insured by health corporation VGZ, also reported being asked to to submit images of their breasts and then losing them. One reported being told to send the images via unsecured email and an employee telling her they had been passed "from one counter to another."

[15]

That insurance group told NOS that "only in the event of a complaint can policyholders be asked for photos."

The Register could not reach VGZ for comment, and the Health Minister did not immediately respond to our questions including if the agency planned to take action. ®

Get our [16]Tech Resources



[1] https://nos.nl/artikel/2508510-verzekeraars-vragen-nog-steeds-naaktfoto-s-aan-borstkankerpatienten

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZcqjGWW47fMNOW@9pnTragAAAA8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://nos.nl/artikel/2496890-juristen-borstreconstructies-niet-standaard-vergoeden-is-discriminatie

[4] https://www.theregister.com/2023/03/15/cancer_lvhn_sues_hospital/

[5] https://www.theregister.com/2023/06/22/blackcat_ransomware_plastic_surgery_clinic/

[6] https://www.theregister.com/2022/09/14/ransomware_medical_groups/e

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZcqjGWW47fMNOW@9pnTragAAAA8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZcqjGWW47fMNOW@9pnTragAAAA8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://zoek.officielebekendmakingen.nl/kst-29689-1140.html

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZcqjGWW47fMNOW@9pnTragAAAA8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://www.theregister.com/2023/03/15/cancer_lvhn_sues_hospital/

[12] https://www.theregister.com/2023/06/22/blackcat_ransomware_plastic_surgery_clinic/

[13] https://www.theregister.com/2024/01/05/swatting_extorion_tactics/

[14] https://www.theregister.com/2024/02/05/us_voluntary_cybersecurity_goals_hospitals/

[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZcqjGWW47fMNOW@9pnTragAAAA8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[16] https://whitepapers.theregister.com/



KillStuffMount

A constant stream of boobs.

In every sense.

James O'Shea

So... when will the, umm, vigorous action, involving torches, pitchforks, cutlasses, and nooses, going to take place? Personally, I'd string whoever is responsible for this up by his balls and prod his buttocks with a pitchfork a few times, but I have a bad attitude. Oh, and take pix. Lots of pix. And pass them to another counter. Or two. Or three.

As with the Horizon case, there is an obvious solution.

Tron

Put those responsible, all the way up the chain of command, in prison.

We really need to be putting more executives and CEOs behind bars for stuff like this. Pour discourager les autres.

Are these companies subject to GDPR?

Ken Hagan

Just wondering out loud here...

Seems like a fairly egregious loss of personal information and moreover of personal information that they were specifically not permitted to collect in the first place.

Runt packets