---
title: Why HIPAA and the UK Data Protection Act are bloody useless
date: 2006-06-09T20:17:27Z
modified: 2006-06-09T20:17:27Z
permalink: "https://redmonk.com/jgovernor/why-hipaa-and-the-uk-data-protection-act-are-bloody-useless/"
type: post
status: publish
excerpt: ""
wpid: 621
categories:
  - Uncategorized
timestamp: 2006-06-09T20:17:27Z
tags:
  - Uncategorized
---

If there is [no enforcement](http://www.washingtonpost.com/wp-dyn/content/article/2006/06/04/AR2006060400672.html?referrer=email&referrer=email) legislation provides no protection for consumers or citizens. Heathcare Insurance Portability and Accountability Act (HIPAA) just acts as a fig-leaf, a compliance tick-list item, but what is really needed is a _culture_ of security, a _culture_ of really caring for your customers’ information. (hat tip [Anton](http://chuvakin.blogspot.com/2006/06/using-hipaa-compliance-to-sell.html))

In the UK the data protection act is just as much of a [lame duck](http://www.ico.gov.uk/). Codes of practice and [enforcement notices](http://www.ico.gov.uk/eventual.aspx?id=5248) achieve nothing.

More California-style notification legislation please. Bring on that sunlight! Bring on that disinfectant. Bring on some jail sentences for negligence.

I have talked to many people in the security field that claim their clients are deeply worried about reputational damage concerning breaches. They always seem shocked when I tell them its nonsense. The share price hits, where there are any, don’t last more than a few days…Reputational problems mean nothing when all the companies in a sector don’t get it.

If organisations were serious about data governance, new breaches wouldn’t bubble up every week.

Customers and citizens are being screwed. [I am with Greg](http://www.greghughes.net/rant/IdentityTheftAListOfDataBreachesWhyImShockedAndAngryAndWhyYouShouldBeToo.aspx) when it comes to the problem description, but I disagree about the solution. I actually think stronger legislation around notification is called for. The market is failing to come up with a solution and complaining isn’t getting us anywhere. We need lawyers and police involved. Sad but true. Maybe [Elliot](http://www.oag.state.ny.us/) can step up once he gets this little case he’s working on finished.

Tags: [privacy](http://technorati.com/tag/privacy), [Data protection](http://technorati.com/tag/Data+protection), [data governance](http://technorati.com/tag/data+governance), [HIPAA](http://technorati.com/tag/HIPAA)