HIPAA must have more strict rules to be able to charge companies which don’t comply with it. Now it has many details but it looks like a list of suggestions. When something goes wrong, companies negotiate around these rules and get huge discounts on charges. People may change their leaked username/password and live with it. But this isn’t the case with PHI data. So results must be more serious for the companies.
HHS published a draft of set of changes in HIPAA. It is scheduled to be published for public review on the next Monday. There will be 60-days public review period and then there is a suggested 240-days transition period.
This is a common mistake until the first incident. Even AWS did it. Static files in their status page were hosted on S3 and when they had a fat-finger issue, their status page went down as well.
Years ago, Turkish government made a law to force companies which develop crypto communication devices to share a copy of keys with government. Few years later, a group leaked call recordings of president and ministers. The same government complained about corruption in the system and power of bad guys. They couldn't accept they were hit by their own gun.
in UK, as conservatives screw everything up even with crypto devices, they may not be worried about these kind of leaks.