Medical provider does check in via SMS from parking lot. Initial exchange indicates SMS is not secure and not under HIPAA. No problem - I get it and accept the risk. Later in the check in they ask for a photo of my credit card after calling SMS a “secure line”. WTAF?!?!
Discussion with the manager on duty indicated this is a system for a large national provider. They’ll be asking upstream about PCI suitability & educating staff on the “secure line” misinformation. Hopeful they adjust to more accurately convey risk or avoid risky model entirely.
Seriously folks, don’t ever send anything over SMS that you don’t want on a billboard. It’s terrrrible
You can follow @PhilHagen.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled: