top | item 21014104

(no title)

maxheadroom | 6 years ago

This will probably seem very pedantic but aren't "Unauthorized Access/Disclosure" and "Hacking/IT Incident" pretty much the same things?

discuss

order

slowmovintarget|6 years ago

No. Unauthorized access or disclosure can happen when someone with legitimate access to the system gets access to more data than they should see. For example, a patient logs on to the system to view their own record and sees records for other patients. Logs would show this, and this would have to be disclosed.

Deliberate penetration of the system, or purposeful exfiltration of the data, are very different occurences.