Live data from Hacker News

Why do shared hospital rooms not violate HIPAA?

law.stackexchange.com

21–30 of 150 posts

Re: Why do shared hospital rooms not violate HIPAA?

#21
post #9

Because by walking into the hospital, you already gave away the info to any bystander. And all variations thereof.

If you're coming in for a disembowlement, sure, but even then you're only really revealing the condition; your name, history, insurance details etc. are still private information. (The hospital would also still be forbidden from, say, publishing "amelius came in today with with a minor disembowlement" without your permission, no matter how public it was in the waiting room.)

In the waiting room they usually don't shout out "Geoff, who's here for the cock wart, the doctor will see you now"... they just say "Geoff, the doctor will see you now."

Btw, my name's not Geoff.

(Just to be a bit more plain.)

Re: Why do shared hospital rooms not violate HIPAA?

#22

Because health privacy is not ALWAYS HIPAA. In fact, it's almost never HIPAA... except for the fact that some Karen's learned the term HIPAA and now they think it's always HIPAA [1]. Unless it's digital health record-related, then it's probably HIPAA. If you're really curious, you can read HIPAA [2] and HITECH [3]. Combined, they are about 600 pages of dense dense legalese. [1] https://www.hipaajournal.com/is-it-a-hi…

From https://www.hipaajournal.com/what-does-hipaa-cover/

> The HIPAA Privacy Rule applies to all forms of health information, including paper records, films, and electronic health information – even spoken information.

HIPAA is not as limited as you state.

Re: Why do shared hospital rooms not violate HIPAA?

#23
post #16

HIPAA is sort of a joke to me. My perspective being that of a patient. Any doctor's office just blindly asks you sign a HIPAA authorization release form. Most patients don't realize that you have a choice to "opt out" and not sign it. But even then it doesn't matter because under HIPAA the provider may still choose to share your personal information for their own reasons. Sure, I am doing a lot of "hand waving"- I'm…

> Any doctor's office just blindly asks you sign a HIPAA authorization release form.

I've never been asked to waive my rights. I have been asked to sign that I received their notice of privacy practices. (Almost always having not been actually given any to read, which is fairly infuriating.)

> But even then it doesn't matter because under HIPAA the provider may still choose to share your personal information for their own reasons.

Only in certain specific situations.

Re: Why do shared hospital rooms not violate HIPAA?

#24
post #18

Earlier quoted context omitted.

You can't agree to OHSA violations, or to a sub-minimum wage. A hospital conditioning treatment on a HIPAA waiver having been signed will quickly find itself the subject of regulatory scrutiny. I went to war with a doctors' office that claimed their non-compete clause meant I couldn't transfer my medical records to a doctor who'd left the practice I wanted to follow.

That a doctors office can have a non-compete boggles the mind

I assume the non-compete agreement was between the doctor and the practice, which seems somewhat reasonable.

Re: Why do shared hospital rooms not violate HIPAA?

#25
post #12

I have a domain name that's similar to a medical facility. Sensitive medical data gets emailed to the wrong recipient all the time and it's usually operator error.

I used to work for a company which made EHR systems, and there was one product which distributed client software updates via email. As in, they would attach an *.msi file and send it.

It was a weird conversation, where we both ended up looking at each other like the other one was a total moron.

Re: Why do shared hospital rooms not violate HIPAA?

#26
post #17

My friend spent the night in the hospital recently, for observation. She didn't sleep a wink. With all the beeping and alarms and periodic checks and procedures. Mostly involving her roommate. The next morning she was mentally and physically wrecked. the first thing she told the nurse was, "I want to go home so I can get some sleep. The nurse laughs and replies, "I hear that all the time. Nobody ever sleeps here". No…

The beeping and alarms and periodic checks and procedures are there to prevent worse things than a night's worth of lost sleep.

Re: Why do shared hospital rooms not violate HIPAA?

#27
How does HIPAA compare to FERPA?

My understanding is that FERPA is similar to HIPAA, except for college scores and enrollment information instead of medical records.

But there’s a rule in FERPA where you explicitly can’t leave a stack of exams and let students pick them, because it exposes students to others’ scores. Another rule is that you can’t associate a students exam with their student ID even if it’s a sequence of numbers, because the id is public information, but you wouldn’t expect someone to remember someone else’s id.

(I specifically remember some professors not following the exam rule, probably because they didn’t know or perhaps it didn’t exist yet. I don’t know if anything happened to them but I suspect if anything, they were simply asked to not do that in the future.)

Re: Why do shared hospital rooms not violate HIPAA?

#28
post #11

The top comment here is very reasonable, but I still think the application of HIPAA has been a giant mess, reflecting a disdain toward patients similar to everything else in the US healthcare system. I've ranted on here plenty about how often I've dealt with incorrect bills, and HIPAA plays into that as well. My private information can be shared to "traveling doctors", it can be shared with woefully incompetent contr…

Had an emergency room visit for a somewhat bloody mishap with my son (he's ok.) The resident texted the on call surgeon pictures of the problem from his personal phone to determine if the surgeon should come in for a surgery. The pictures I saw on his phone of other patients as he set up the text were a hellscape of blood and gore!

Re: Why do shared hospital rooms not violate HIPAA?

#29
post #24
post #18

Earlier quoted context omitted.

That a doctors office can have a non-compete boggles the mind

I assume the non-compete agreement was between the doctor and the practice, which seems somewhat reasonable.

Yes. They took the position that their non-compete (and our general "we agree to clinic practices") with their doc took precedence over our HIPAA rights, which NY... disabused them of.

Re: Why do shared hospital rooms not violate HIPAA?

#30
From the HHS.gov website:

The Privacy Rule permits certain incidental uses and disclosures that occur as a by-product of another permissible or required use or disclosure, as long as the covered entity has applied reasonable safeguards and implemented the minimum necessary standard, where applicable, with respect to the primary use or disclosure. See 45 CFR 164.502(a)(1)(iii). An incidental use or disclosure is a secondary use or disclosure that cannot reasonably be prevented, is limited in nature, and that occurs as a result of another use or disclosure that is permitted by the Rule. However, an incidental use or disclosure is not permitted if it is a by-product of an underlying use or disclosure which violates the Privacy Rule.

Post reply on HN