Live data from Hacker News

What HHS has to say about tracking technologies in latest HIPAA guidance

freshpaint.io

11–20 of 34 posts

Re: What HHS has to say about tracking technologies in latest HIPAA guidance

#11
post #9

As someone who has been in the "healthtech" area for several years now, none of this looks at all new to me. Am I missing something, or do companies typically play much more "fast and loose" with data than I've seen? In my experience, you don't send data anywhere you don't have a BAA. Period, full stop.

I’ve never worked anywhere it wasn’t taken extremely seriously either, but I think this is the big news story that HHS is responding to: https://themarkup.org/privacy/2022/12/13/out-of-control-doze... . Classic tale of VC-backed “startups” going the Uber/Airbnb route and deciding the established rules aren’t worth following.

> Classic tale of VC-backed “startups” going the Uber/Airbnb route and deciding the established rules aren’t worth following.

As long as penalties are lower than the profits (and no execs go to jail), the rules aren't actually worth following.

Maybe the real innovation of the tech sector in the last decade is figuring out that established laws aren't actually enforced anywhere well enough so you may as well break them.

Re: What HHS has to say about tracking technologies in latest HIPAA guidance

#12

As someone who has been in the "healthtech" area for several years now, none of this looks at all new to me. Am I missing something, or do companies typically play much more "fast and loose" with data than I've seen? In my experience, you don't send data anywhere you don't have a BAA. Period, full stop.

> In my experience, you don't send data anywhere you don't have a BAA. Period, full stop. This really depends on what you consider health data, which itself varies based on how big the marketing team is and the company's desire to obtain "growth & engagement". The below is from an EU perspective, but I'm sure the same would apply in the US. I have been involved in a EU-based HealthTech that had the Facebook SDK (and…

> Were they sending health data

The recent guidance from the HHS[0] indicates in many cases installing Google Analytics or the Facebook SDK would be considered sending health data to Google or Facebook and therefore be considered a HIPAA violation. From the HHS[0]:

> Tracking technologies on a regulated entity’s user-authenticated webpages generally have access to PHI. Such PHI may include, for example, an individual’s IP address, medical record number, home or email addresses, dates of appointments, or other identifying information that the individual may provide when interacting with the webpage.

[0] https://www.hhs.gov/hipaa/for-professionals/privacy/guidance...

Re: What HHS has to say about tracking technologies in latest HIPAA guidance

#13

Who thinks the US will ever have a single privacy/data regulation law, or if there will be this patchwork of regulations for individual industry sectors driven by disjoint agencies? Honestly don't know and can believe either way. Leaning towards the latter currently.

my guess is that EU/GDPR will eventually force us to come up with something, pay attention to the area, and assert our global dominance. the way we're continuing to fight/hate China seems like the first entry point into some kind of federal data laws.

Re: What HHS has to say about tracking technologies in latest HIPAA guidance

#14

Earlier quoted context omitted.

> In my experience, you don't send data anywhere you don't have a BAA. Period, full stop. This really depends on what you consider health data, which itself varies based on how big the marketing team is and the company's desire to obtain "growth & engagement". The below is from an EU perspective, but I'm sure the same would apply in the US. I have been involved in a EU-based HealthTech that had the Facebook SDK (and…

> Were they sending health data The recent guidance from the HHS[0] indicates in many cases installing Google Analytics or the Facebook SDK would be considered sending health data to Google or Facebook and therefore be considered a HIPAA violation. From the HHS[0]: > Tracking technologies on a regulated entity’s user-authenticated webpages generally have access to PHI. Such PHI may include, for example, an individual…

Does the guidance only apply to user-authenticated web pages? the article suggests 'the website' is all PHI, which I personally find to be an insane interpretation of HIPAA.

edit: I found the answer. it's pretty reasonable. basically, no, HIPAA doesn't apply there.

Re: What HHS has to say about tracking technologies in latest HIPAA guidance

#15

As someone who has been in the "healthtech" area for several years now, none of this looks at all new to me. Am I missing something, or do companies typically play much more "fast and loose" with data than I've seen? In my experience, you don't send data anywhere you don't have a BAA. Period, full stop.

> In my experience, you don't send data anywhere you don't have a BAA. Period, full stop. This really depends on what you consider health data, which itself varies based on how big the marketing team is and the company's desire to obtain "growth & engagement". The below is from an EU perspective, but I'm sure the same would apply in the US. I have been involved in a EU-based HealthTech that had the Facebook SDK (and…

As far as HIPAA is concerned health information is pretty much anything associated with a patient and a provider. The definition of a provider is pretty broad, but basically all data points in an EHR or claims system are associated with a provider.

So data from a fitness tracker or what you ate last night is health related but unless it’s being fed into an EHR (and associated with a provider) then it won’t be considered covered by HIPAA.

Re: What HHS has to say about tracking technologies in latest HIPAA guidance

#16
post #9

As someone who has been in the "healthtech" area for several years now, none of this looks at all new to me. Am I missing something, or do companies typically play much more "fast and loose" with data than I've seen? In my experience, you don't send data anywhere you don't have a BAA. Period, full stop.

I’ve never worked anywhere it wasn’t taken extremely seriously either, but I think this is the big news story that HHS is responding to: https://themarkup.org/privacy/2022/12/13/out-of-control-doze... . Classic tale of VC-backed “startups” going the Uber/Airbnb route and deciding the established rules aren’t worth following.

It's not just start ups here. Lots of hospitals and hospital groups have trackers like Google Analytics installed on their website. From the HHS[0] in many cases this is considered sharing health information with Google:

> For example, tracking technologies could collect an individual’s email address and/or IP address when the individual visits a regulated entity’s webpage to search for available appointments with a health care provider. In this example, the regulated entity is disclosing PHI to the tracking technology vendor, and thus the HIPAA Rules apply.

Re: What HHS has to say about tracking technologies in latest HIPAA guidance

#17
post #14

Earlier quoted context omitted.

> Were they sending health data The recent guidance from the HHS[0] indicates in many cases installing Google Analytics or the Facebook SDK would be considered sending health data to Google or Facebook and therefore be considered a HIPAA violation. From the HHS[0]: > Tracking technologies on a regulated entity’s user-authenticated webpages generally have access to PHI. Such PHI may include, for example, an individual…

Does the guidance only apply to user-authenticated web pages? the article suggests 'the website' is all PHI, which I personally find to be an insane interpretation of HIPAA. edit: I found the answer. it's pretty reasonable. basically, no, HIPAA doesn't apply there.

Oh the other hand, maybe it should apply, considering that the website is the entry point for the user to the service and that an attacker owning that can trivially redirect the user flow - the same reason why mixed HTTP & HTTPS is considered insecure.

Re: What HHS has to say about tracking technologies in latest HIPAA guidance

#18
post #14

Earlier quoted context omitted.

> Were they sending health data The recent guidance from the HHS[0] indicates in many cases installing Google Analytics or the Facebook SDK would be considered sending health data to Google or Facebook and therefore be considered a HIPAA violation. From the HHS[0]: > Tracking technologies on a regulated entity’s user-authenticated webpages generally have access to PHI. Such PHI may include, for example, an individual…

Does the guidance only apply to user-authenticated web pages? the article suggests 'the website' is all PHI, which I personally find to be an insane interpretation of HIPAA. edit: I found the answer. it's pretty reasonable. basically, no, HIPAA doesn't apply there.

> Does the guidance only apply to user-authenticated web pages?

It depends on if there's health related information on the page. The HHS includes examples of unauthenticated pages where the guidance applies such as pages about a specific health condition or find a doctor pages[0].

[0] https://www.hhs.gov/hipaa/for-professionals/privacy/guidance...

Re: What HHS has to say about tracking technologies in latest HIPAA guidance

#19

As someone who has been in the "healthtech" area for several years now, none of this looks at all new to me. Am I missing something, or do companies typically play much more "fast and loose" with data than I've seen? In my experience, you don't send data anywhere you don't have a BAA. Period, full stop.

The providers lean on you for the heavy lift. The weakness is always at the integration points.

It’s all pretty meaningless anyway, lots of real health data is legally leaked via insurance and pharmacy data feeds.

Re: What HHS has to say about tracking technologies in latest HIPAA guidance

#20

As someone who has been in the "healthtech" area for several years now, none of this looks at all new to me. Am I missing something, or do companies typically play much more "fast and loose" with data than I've seen? In my experience, you don't send data anywhere you don't have a BAA. Period, full stop.

Same, I'm kind of scared of what others have been doing up too now to warrant this.
Post reply on HN