Question: A hospital decided to use cloud computing for processing and storage in order to save costs. After several months it was discovered that the cloud

A hospital decided to use cloud computing for processing and storage in order to save costs. After several months it was discovered that the cloud provider's storage facilities were compromised and patient information was stolen. The hospital maintained that the cloud provider should be punished and fined for the breach, while the provider responded that it was still the hospital's responsibility under HIPAA to secure patient information and the hospital was ultimately responsible.

Conduct some research, or use examples from your personal experience, to discuss each of the following:

  1. Legally, who is responsible - the cloud provider or the hospital?
     
  2. If the cloud provider is responsible, then should software companies like Microsoft be held liable for a vulnerability in their software that results in a data breach on a Microsoft server in the LAN?
  3. Where does the responsibility for the user end and the vendor begin?


Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock

Determining legal responsibility in a situation like this can be complex and may depend on the terms of the contract between the hospital and the clou... View full answer

blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Computer Network Questions!