Live data from Hacker News

What HHS has to say about tracking technologies in latest HIPAA guidance

freshpaint.io

31–34 of 34 posts

Re: What HHS has to say about tracking technologies in latest HIPAA guidance

#31

As someone who has been in the "healthtech" area for several years now, none of this looks at all new to me. Am I missing something, or do companies typically play much more "fast and loose" with data than I've seen? In my experience, you don't send data anywhere you don't have a BAA. Period, full stop.

> In my experience, you don't send data anywhere you don't have a BAA. Period, full stop. This really depends on what you consider health data, which itself varies based on how big the marketing team is and the company's desire to obtain "growth & engagement". The below is from an EU perspective, but I'm sure the same would apply in the US. I have been involved in a EU-based HealthTech that had the Facebook SDK (and…

> I have been involved in a EU-based HealthTech that had the Facebook SDK (and maybe others too) in the app that fingerprinted the device and pinged Facebook on each run, without user consent nor adequate disclosure (buried in the privacy policy doesn't apply, nor was the privacy policy granular enough about the fingerprinting because Facebook itself doesn't publish any details on it).

Name and shame?

Re: What HHS has to say about tracking technologies in latest HIPAA guidance

#33

Earlier quoted context omitted.

> In my experience, you don't send data anywhere you don't have a BAA. Period, full stop. This really depends on what you consider health data, which itself varies based on how big the marketing team is and the company's desire to obtain "growth & engagement". The below is from an EU perspective, but I'm sure the same would apply in the US. I have been involved in a EU-based HealthTech that had the Facebook SDK (and…

> I have been involved in a EU-based HealthTech that had the Facebook SDK (and maybe others too) in the app that fingerprinted the device and pinged Facebook on each run, without user consent nor adequate disclosure (buried in the privacy policy doesn't apply, nor was the privacy policy granular enough about the fingerprinting because Facebook itself doesn't publish any details on it). Name and shame?

I'd name and shame if this was a one-off (frankly if it was I'd raise it internally and they'd fix it) but given that all apps are like this my best advice would be to avoid all "healthtech" apps to begin with and use them through a browser (with good ad-blocker) if really necessary.

Re: What HHS has to say about tracking technologies in latest HIPAA guidance

#34

Earlier quoted context omitted.

> I have been involved in a EU-based HealthTech that had the Facebook SDK (and maybe others too) in the app that fingerprinted the device and pinged Facebook on each run, without user consent nor adequate disclosure (buried in the privacy policy doesn't apply, nor was the privacy policy granular enough about the fingerprinting because Facebook itself doesn't publish any details on it). Name and shame?

I'd name and shame if this was a one-off (frankly if it was I'd raise it internally and they'd fix it) but given that all apps are like this my best advice would be to avoid all "healthtech" apps to begin with and use them through a browser (with good ad-blocker) if really necessary.

If nobody makes the first move, the status quo is maintained.

Name and shame.

Post reply on HN