As someone who has been in the "healthtech" area for several years now, none of this looks at all new to me. Am I missing something, or do companies typically play much more "fast and loose" with data than I've seen? In my experience, you don't send data anywhere you don't have a BAA. Period, full stop.
I’ve never worked anywhere it wasn’t taken extremely seriously either, but I think this is the big news story that HHS is responding to: https://themarkup.org/privacy/2022/12/13/out-of-control-doze... . Classic tale of VC-backed “startups” going the Uber/Airbnb route and deciding the established rules aren’t worth following.
As long as penalties are lower than the profits (and no execs go to jail), the rules aren't actually worth following.
Maybe the real innovation of the tech sector in the last decade is figuring out that established laws aren't actually enforced anywhere well enough so you may as well break them.