These links loaded when getting test results, when contacting my doctor, even when providing website feedback.
Round and roune and someone finally said "the website is a convenience".
Yet they wouldn't cancel my account.
21–30 of 34 posts
These links loaded when getting test results, when contacting my doctor, even when providing website feedback.
Round and roune and someone finally said "the website is a convenience".
Yet they wouldn't cancel my account.
As someone who has been in the "healthtech" area for several years now, none of this looks at all new to me. Am I missing something, or do companies typically play much more "fast and loose" with data than I've seen? In my experience, you don't send data anywhere you don't have a BAA. Period, full stop.
> In my experience, you don't send data anywhere you don't have a BAA. Period, full stop. This really depends on what you consider health data, which itself varies based on how big the marketing team is and the company's desire to obtain "growth & engagement". The below is from an EU perspective, but I'm sure the same would apply in the US. I have been involved in a EU-based HealthTech that had the Facebook SDK (and…
Nope - because I didn't say "health data". I said "data".
> But I'd argue that the simple fact that you use a health app [...] itself is a major breach
It absolutely is. There is a hypothetical case that's often shown in HIPAA training materials that covers this: a staff member posting a selfie on social media of themselves with a celebrity in a clinical setting (e.g., a waiting room).
Earlier quoted context omitted.
> In my experience, you don't send data anywhere you don't have a BAA. Period, full stop. This really depends on what you consider health data, which itself varies based on how big the marketing team is and the company's desire to obtain "growth & engagement". The below is from an EU perspective, but I'm sure the same would apply in the US. I have been involved in a EU-based HealthTech that had the Facebook SDK (and…
As far as HIPAA is concerned health information is pretty much anything associated with a patient and a provider. The definition of a provider is pretty broad, but basically all data points in an EHR or claims system are associated with a provider. So data from a fitness tracker or what you ate last night is health related but unless it’s being fed into an EHR (and associated with a provider) then it won’t be conside…
Correction:
As far as HIPAA is concerned protected health information is health information associated with a patient and held by covered entities, including providers, insurers, clearing-houses, and business partners acting on behalf of other covered entities.
Particularly, health information “associated with a patient and provider” but held by someone other than a covered entity is not PHI. Particularly, any information you provide about your health and care to anyone who is not your insurer, your health care provider (and online wellness services aren’t health care providers), or a business partner acting on their behalf is not PHI.
As someone who has been in the "healthtech" area for several years now, none of this looks at all new to me. Am I missing something, or do companies typically play much more "fast and loose" with data than I've seen? In my experience, you don't send data anywhere you don't have a BAA. Period, full stop.
I've been doing B2B IT for years, and I'm glad to hear that the tech part of the health industry takes this more seriously than the health part. There's not a single doctor's office or hospital I'm aware of that is HIPAA compliant, and the vast majority of doctors ask us what a BAA is when we try to get one set up with them.
That mirrors my experience.
My GP has a sign-in sheet at the receptionist's desk where you have to write your name when you arrive. They put a single line through your name when you're checked in.
Worse, it's usually a notebook that's just turned to a new page every day. If you grabbed that notebook you'd have a list of everyone who visited that office for the past month or so, complete with dates and times.
Earlier quoted context omitted.
As far as HIPAA is concerned health information is pretty much anything associated with a patient and a provider. The definition of a provider is pretty broad, but basically all data points in an EHR or claims system are associated with a provider. So data from a fitness tracker or what you ate last night is health related but unless it’s being fed into an EHR (and associated with a provider) then it won’t be conside…
> As far as HIPAA is concerned health information is pretty much anything associated with a patient and a provider. Correction: As far as HIPAA is concerned protected health information is health information associated with a patient and held by covered entities, including providers, insurers, clearing-houses, and business partners acting on behalf of other covered entities. Particularly, health information “associat…
That isn't uniformly true - or, to be more precise, the line between "online wellness services" and "online mental healthcare providers" is quite blurry to the average person.
My company today is in this space. Previously I've worked for primary care clinic chains, prescription discount providers, and direct pediatric care providers.
As someone who has been in the "healthtech" area for several years now, none of this looks at all new to me. Am I missing something, or do companies typically play much more "fast and loose" with data than I've seen? In my experience, you don't send data anywhere you don't have a BAA. Period, full stop.
It's the HHS reaffirming what the law says as written. way too many companies got loosey goosey with this stuff. The mental gymnastics we'd hear from healthcare companies "oh our legal team said it's okay to have Facebook installed here because [convoluted and totally not kosher reasoning]" was crazy when you'd review the law as written.
Startups, hospital systems, payers...doesn't matter how much resources or the company's particular compliance stance. You'd be amazed where these companies are sending data to Google and Facebook data without consent and without BAAs in place. HHS here is specifically going after larger health networks and hospital systems (typically way more compliance focused than your average healthtech startup).
Earlier quoted context omitted.
> Were they sending health data The recent guidance from the HHS[0] indicates in many cases installing Google Analytics or the Facebook SDK would be considered sending health data to Google or Facebook and therefore be considered a HIPAA violation. From the HHS[0]: > Tracking technologies on a regulated entity’s user-authenticated webpages generally have access to PHI. Such PHI may include, for example, an individual…
Does the guidance only apply to user-authenticated web pages? the article suggests 'the website' is all PHI, which I personally find to be an insane interpretation of HIPAA. edit: I found the answer. it's pretty reasonable. basically, no, HIPAA doesn't apply there.
Someone (anonymous) goes to the website and does a bunch of searches on e.g. cancer or AIDS or anything else they don't want marketing to know about. Afterwards they log in (turns out the person was an existing patient who had a login). But it's all in the same session so now you tied all that search info to a specific account and sent it to adspyware third parties. Solid HIPAA violation.
Not my field, but talking to friends in healthcare infosec, this is something that has caused them to be hit with fines in the past. Even in the absence of fines, clearly a privacy violation.
* Most importantly, and almost always overlooked, a clause in the privacy agreement that says, 'we can change the agreement at any time'. In other words, there is no agreement, there are no restrictions.
* The usual third parties, etc. obtaining the usual data.
It was alarming. I'm not sure what the psychiatrist did, but they did tell me 'everyone is using it'. Great.
A psychiatrist asked me to evaluate a remote video service marketed toward their profession for sessions with patients. I think it was early in the pandemic. The service promised confidentiality on the front page, etc., but was no different than any other website: * Most importantly, and almost always overlooked, a clause in the privacy agreement that says, 'we can change the agreement at any time'. In other words, t…
Earlier quoted context omitted.
> Were they sending health data The recent guidance from the HHS[0] indicates in many cases installing Google Analytics or the Facebook SDK would be considered sending health data to Google or Facebook and therefore be considered a HIPAA violation. From the HHS[0]: > Tracking technologies on a regulated entity’s user-authenticated webpages generally have access to PHI. Such PHI may include, for example, an individual…
Does the guidance only apply to user-authenticated web pages? the article suggests 'the website' is all PHI, which I personally find to be an insane interpretation of HIPAA. edit: I found the answer. it's pretty reasonable. basically, no, HIPAA doesn't apply there.