False Verkada HIPAA Compliance And Legal Risks Investigated

Published Mar 18, 2021 13:49 PM

Verkada has repeatedly and falsely claimed to be certified HIPAA Compliant, with a HIPAA consultant telling IPVM Verkada's actions are a "HIPAA disaster" while Verkada refused to provide any explanation for its HIPAA compliant claims.

IPVM Image

Inside this note, from the fallout of the Verkada breach/hack, we examine:

  • What Verkada has claimed
  • Verkada's response to IPVM
  • What HIPAA consultant Abner Weintraub says about the hack and their compliance
  • What issues exist for Verkada and its HIPAA covered client

Verkada's ***** ******

******* ***** ******** ****** ****** ** HIPAA **********. *** *******'*"******* ********** ****" ************ **** *** '*********' ** ** HIPAA *********:

IPVM Image

*** *****"********** & ******** ***********" **************** ******** **** *************:

IPVM Image

*** ***** ** *********** **** ******* ********** ************ *******:

IPVM Image

*** ******* ********** ****** ********* ********, ***** ******** "***** ********* ********" from *******:

IPVM Image

***** * ******** ******** * **** ****** *** ******* hack/breach:

IPVM Image

**** ******** * ********* ********************** ***** ********* **** *******:

IPVM Image

******,*******'* *** ***** ******** ********** *********** "********* ****** ***** ******* ** be ********* **** *****":

**’** ********** ******* ***** ******* *** cyber ******** — ** ****, ****’* part ** *** **’** **** ** successful. *** *******, ****** **** ** an ******** ******* *** ** ******* we ***conscious ****** ***** ******* ** ** ********* **** *****. [emphasis added]

Verkada = ***** ******** *********

*******, ********** ***** ********* **** *******,**** **** **** ********** **** ********* that **** **** * ***** ******** associate *** **** ****** **** *****:

IPVM Image

No ***** ** ******* *** ******* ***** ********** ******

******* ****** ** ****** *****, *******, source, **********, *************, ** ***** ********** for *** ***** ********* ******. ********, we ********** ***** ******* *** **** evidence *** ***** ******* *** ******* a ******* ********, **** ******* ** address *** **** ** *****.

** ********, ********* **** *** ************* * ******* **** *** * data ****** ********** ***** *************** ***** HIPAA *********, *******:

*** ******* ******* *********** ********* ** by *********** **** * ********** ****** or ***** ***** *** ******** ******’* information ********* *** ********** **** *** HIPAA’s ************.

Violations ** *****

**** *******'* ***"******** ***** *********"********, *** *********** ***** ********** *** a ***** *** ** ****

*****, ******* ****** ******** *** "******* necessary ***********", ** ***** *****:

IPVM Image

*******, *******'****-******** ***** ***** ********, ** **********, ********** ***** ***** of '******* *********' ***********.

********, ***** ******* ********** *** **** to ****** **** ** *********** ****** to *** ***** *******, ** ************** has ******** ** ***** ****** ** its *** ********* ****** ** ******** systems *** ***** *****:

IPVM Image

*******, ******* ****** **** ********* "************* audit ****" ******* **** ** ** HIPAA *********:

IPVM Image

*******, ***** ******* *** **** ***** logs **********, *** ~*** ** ** employees **** ***** ***** ******** **** could *** ** ** ****'* ******** were *** ******** ****** *** ********* to *****.

"A ***** ********"

********* **** *** ******* **** ** "a ***** ********" **** *** "****** at *** ***** ** ***** ********, the **** ********, ** ***** ****** admin ********."

**'* ** ********** *** * ******* to ** ******** ****** ***** *** sophistication *** ************* ******* ** ** doing **** **** *** *** ******** their ******* ** *** *** **** they ***. *** **** ****** *** media ******* **** *** ***** ******** abuse ** ***** ** ***** *** systems ******* ***** *** *********. **'* just * *******. ****, * ******'* trust **** **** ** ******** ** this *****, ** *** *** *****. I ******'* ***** **** ********.

*** ********** **** ******* *** *** track ****** ********** ********** ** *** *******'* *** employees******* ********** **** **** ****** **** breach *** *******:

** * ****** **** ******** *** been ****, *** **** ** ******* cameras ** ******* ***** ********* ** a ***** ***** *** *** ******* been ***** *** ***** ***** *** cameras ** ****** ***** *** ********* - ** ***** *****, * **** of ******** ** *** ****** *** obvious, *** *** ** *** ***** freely, ****** ********* ** ****** *** looked - *** **** ** ******* those ******* ** ******* ***** ******** an ******** **** **** ****** **** been ********** ** *** ********** **** analysis.

***********, ** **** "******* *** ************** ******* ******* **** ** ********, and ***** ** ****** ** ** penalized -- ********** ** *******."

**'* *** **** ******* **** ***** face ************, *** ***** ********* ** well. ********* ** *********, "** **** was ******** **********, ********* ** *** letter ** *** ***, ** ***** represent ******** ** ******* ** *****. And ***** **** **** ***** * few ************ ****** ********* ****** [*** HIPAA **********]."

Legal **** ** *******

***** *******'* ***** ********** *** ** substantial, *** *********** ** ***** ********* will ***** ** *** ******* **********'* current *********** ******. *** ****** ** Civil ****** (***) ** *** ********** of ****** *** ***** ******** ** responsible *** ****** ******* ***** *********; according ** *********, *** *********** *** been "**** *****" ** ****** *****.

*******, *** ***** ** ******* **** can ***** *****-******* ******* ** ***** has ******** ** ****** ***** ***. Not **** *** ***** ******** **** as *** *** ***** ******* *** HIPAA **********, *****-***** ********* ******* *** as ****.

Response **** *******

******* ******** * ******* ******** ** IPVM ***** ********* *********:

*** ************* ** *******. ** ******** our ********* ** *** ******** ******** and *** ******* **** ******** ********* to ********* ****, ** ***, ********* health *********** *** **** **** ******* in **** ******.

******* ******* ** ******* *** ** justified ** ***** *** ***** ********* marketing ******.

Comments (12)
JH
John Honovich
Mar 18, 2021
IPVM

*****, **** ****!

**** ** ** ********* ************* ** the"**** ** ****" ***** ** *******. **** **, **** *** ******** it ***** ** *** *** ****, even ** **** ** ******* ******** to ** ********* *** ***** ********** while ****** ****** ** ***** ********* access ** ***** *******.

(11)
(1)
U
Undisclosed #1
Mar 18, 2021

***** ** *** ******* ** *** security ***** * **** **** *** most ******* **** ** *** ***** article:

** * ****** **** ******** *** been ****, *** **** ** ******* cameras ********* ***** ********* ** * third ***** *** *** ******* **** noted *** ***** ***** *** ******* to ****** ***** *** ********* - in ***** *****, * **** ** controls ** *** ****** *** *******, and *** ** *** ***** ******, freely ********* ** ****** *** ****** - *** **** ** ******* ***** cameras ********* ***** ******** ** ******** risk **** ****** **** **** ********** in *** ********** **** ********.

** ******** *************, ** **** ****** our *********, *********, *** ***** ** supporting ********* **** *******. ** ** up ** ** ** ************* ** make ******* ******* *** ****** ********** power ** ********* *** ****** ** move **** **.

(10)
(4)
(1)
JH
John Honovich
Mar 18, 2021
IPVM

** ******** *************, ** **** ******

**'* * **** ***** *** * agree ****'* ** ***** **** ****** who ***** ** ************** ******** **** are **** "**** **** ******* ****** harassment ** ***** *** ********* ***** media ******** ****** *** ******* *** they **** **** ** **** *** sorry *** ** ***'* ****** *****. So ****** **** ** **".

(6)
(2)
U
Undisclosed #2
Mar 18, 2021

**** ** **** *** **** **.

(4)
UI
Undisclosed Integrator #3
Mar 18, 2021

**********: **** **** ** ** ***** a ****** ***

**** **** * ****** ***** **** not ******* ******** ** ***** *********. Even *** ***** ************** *** ****** (e.g. ***********) **** *** ******* ** endorsed ** *****. ***** ********* ** one *****, ********* ** *******.

(4)
(1)
CH
Conor Healy
Mar 18, 2021
IPVMU Certified

*** ******** ***** **** ** ***** correct, ***** ** ** ******** ***** certification. ***** *** *****-******* **** **** review * ******* *** ********** *** provide ***** *** ********** ************* *** customers. *** **** ** ***** ** be "*********" ** ***** ********* ** a *****-***** ** *********. *** ** far ** ** **** (** ***** Verkada, **** ****'* ******), ******* ** not ********* ** * *****-***** ****.

(1)
(5)
UM
Undisclosed Manufacturer #4
Mar 18, 2021

**** **** *'** ****, * *****. There's ** **** ***** ** ***** certification. ****** **** *** ** **.

*'* ** ***** ****** *** *** certain ** *** ******** ******** ** this ****** *** *** ******* **** -***** ****** *** *********: *******, ********, and ****** ************ *****- ******** **** ****** *** ***** compliance.

******* ****, **** ***** *** ***** to ******* ** ****** *** ***********(*) that ******** ******* ** *** "******** associate," (*******) ******.

(2)
UE
Undisclosed End User #5
Mar 18, 2021

** ** * ********** ** *** actual ********** ******** ** *********** *** maintaining ***** ********** *** ** ** that ******** *** *** ** **** liable *** ******* ** ******. ******** these ******* **** ******* **** ****** is * ********* *** *** ******** and ******* ** ** **** *** cameras *** ** ***** (** **** as *** *** ***** ******* ******** and ******** ** *** *****.)

(2)
UM
Undisclosed Manufacturer #6
Mar 19, 2021

*** ********/******* ************ *** **'* ********* are ** ****** ********** *********** ** protect *** **** ** ***** ******** in ********** **** *** ********** *** compliance ************, ********* *********** *** ***** by *****.

**** ******** *******, *** ******* *** user ********* ******* *** ****** ** not **** ******* ***** ********** ************, but ** **** *** ******* ******* them.

**** ** * ****** *** *** claim ***** **********, *** ********** *********** would ** **** ** ****** ** not ***** ** ********* ******* *** general ******* ** ** ************* ******* data. ******* ** ***** **** *** expect **** ****** ** ********* ********* Federal ******* **** *** ******* *** privacy ** *** "*********"!

******* ********* *** ********* ** *** end ***** ******** ********* *******, *** privacy ** ***** *********, *** ***** customers ** ******* **** ******* ***. But *** **** ****, **** **** improperly ******* **** *** ******** *** services **** ******* ********* ***** ** a *** ********** ** ***** *******. The ***** ** ****** ** *** of ***** **** ***** *** ***** mess ************ ** ** *******.

(3)
JH
John Honovich
Apr 16, 2021
IPVM

******: ******* *** ******* ********* *** HIPAA '*************'* ******, *.*.:

*** *******'*"********** & ******** ***********" ***************** ****** ***** ** * ******** that "******* ******* *** ********* *******":

IPVM Image

*** **** *** ****** ****** **** Verkada ** ********* **** ***** *********, but ***** *** ******* ** *************:

IPVM Image

(3)
UM
Undisclosed Manufacturer #7
Apr 16, 2021

****'* ****** ** *** **** *** compliant ******* **** ** *** ********* ... ********* ** *** *****. ***, when ***** ***** *** *** *** this...

(1)
JH
John Honovich
May 17, 2021
IPVM

******* ** **** ** ********* ***** compliance ** **** ******** **:

IPVM Image

(2)
(1)