What HHS has to say about tracking technologies in latest HIPAA guidance
1–10 of 34 posts
Re: What HHS has to say about tracking technologies in latest HIPAA guidance
#2Re: What HHS has to say about tracking technologies in latest HIPAA guidance
#3Honestly don't know and can believe either way. Leaning towards the latter currently.
Re: What HHS has to say about tracking technologies in latest HIPAA guidance
#4In my experience, you don't send data anywhere you don't have a BAA. Period, full stop.
Re: What HHS has to say about tracking technologies in latest HIPAA guidance
#5Who thinks the US will ever have a single privacy/data regulation law, or if there will be this patchwork of regulations for individual industry sectors driven by disjoint agencies? Honestly don't know and can believe either way. Leaning towards the latter currently.
At that point, the feds will make something happen and claim that it was their idea. Then we'll have a single protection law.
Until then we'll have various agencies interpreting existing laws in the context of new technologies, which are ultimately decided via lawsuits. You know, like we have had for a decade or so.
Edit; For those of you downvoting me, could you explain why? What I said is exactly what happens with federal law. Nothing groundbreaking occurs federally until states take it up on their own.
Re: What HHS has to say about tracking technologies in latest HIPAA guidance
#6As someone who has been in the "healthtech" area for several years now, none of this looks at all new to me. Am I missing something, or do companies typically play much more "fast and loose" with data than I've seen? In my experience, you don't send data anywhere you don't have a BAA. Period, full stop.
Not to mention, how many practitioners don't separate their guest network from their back of house - or just have a standard ISP provided Wifi Router.
The world operates on much trust.
Re: What HHS has to say about tracking technologies in latest HIPAA guidance
#7As someone who has been in the "healthtech" area for several years now, none of this looks at all new to me. Am I missing something, or do companies typically play much more "fast and loose" with data than I've seen? In my experience, you don't send data anywhere you don't have a BAA. Period, full stop.
There's not a single doctor's office or hospital I'm aware of that is HIPAA compliant, and the vast majority of doctors ask us what a BAA is when we try to get one set up with them.
Re: What HHS has to say about tracking technologies in latest HIPAA guidance
#8As someone who has been in the "healthtech" area for several years now, none of this looks at all new to me. Am I missing something, or do companies typically play much more "fast and loose" with data than I've seen? In my experience, you don't send data anywhere you don't have a BAA. Period, full stop.
I've been doing B2B IT for years, and I'm glad to hear that the tech part of the health industry takes this more seriously than the health part. There's not a single doctor's office or hospital I'm aware of that is HIPAA compliant, and the vast majority of doctors ask us what a BAA is when we try to get one set up with them.
FYI, my therapist is HIPAA compliant. I’m not sure he counts in your view though, because he is a former software engineer.
Re: What HHS has to say about tracking technologies in latest HIPAA guidance
#9As someone who has been in the "healthtech" area for several years now, none of this looks at all new to me. Am I missing something, or do companies typically play much more "fast and loose" with data than I've seen? In my experience, you don't send data anywhere you don't have a BAA. Period, full stop.
Classic tale of VC-backed “startups” going the Uber/Airbnb route and deciding the established rules aren’t worth following.
Re: What HHS has to say about tracking technologies in latest HIPAA guidance
#10As someone who has been in the "healthtech" area for several years now, none of this looks at all new to me. Am I missing something, or do companies typically play much more "fast and loose" with data than I've seen? In my experience, you don't send data anywhere you don't have a BAA. Period, full stop.
This really depends on what you consider health data, which itself varies based on how big the marketing team is and the company's desire to obtain "growth & engagement". The below is from an EU perspective, but I'm sure the same would apply in the US.
I have been involved in a EU-based HealthTech that had the Facebook SDK (and maybe others too) in the app that fingerprinted the device and pinged Facebook on each run, without user consent nor adequate disclosure (buried in the privacy policy doesn't apply, nor was the privacy policy granular enough about the fingerprinting because Facebook itself doesn't publish any details on it).
Were they sending health data? No. But I'd argue that the simple fact that you use a health app and when you use it (and from where, derived from IP address) itself is a major breach. Of course, regardless of the healthcare context, this was also an obvious GDPR breach, but good luck getting any kind of enforcement against that given that the vast majority of apps are equally contaminated by these spyware SDKs.
I have seen a similar issue on a UK-based patient portal (the system here is so that third-parties are used to allow patients to access their government-maintained health record and schedule appointments) - full of trackers which had complete access to the page and Javascript context.