Live data from Hacker News

Why do shared hospital rooms not violate HIPAA?

law.stackexchange.com

51–60 of 150 posts

Re: Why do shared hospital rooms not violate HIPAA?

#51
post #11

The top comment here is very reasonable, but I still think the application of HIPAA has been a giant mess, reflecting a disdain toward patients similar to everything else in the US healthcare system. I've ranted on here plenty about how often I've dealt with incorrect bills, and HIPAA plays into that as well. My private information can be shared to "traveling doctors", it can be shared with woefully incompetent contr…

Agreed, the individual records are not specifically secret. The regulations are to prevent unauthorized disclosure and misuse.

Unfortunatly that leaves a lot of leeway. The major EMR vendors are all aggregating patient data in cloud services and taking it across borders to where there is no transparency for what is being done with it. The regulations were written with a 90's understanding of technology.

A more appropriate regulation today would be to create a category of legally privileged PHI that is strictly inadmissable in legal proceedings and with heavy fines for unauthorized use and disclosure. However, I don't see privacy legislation getting any better as the people inside govt and academia absolutely hate privacy as a concept because they are the specific targets of limiting their discretion about whose data they can snoop. We're in an era of institutional capture by people without ideals or principles, and it's probably unwise to expect altruistic public interest policy like 90's-style privacy legislation from any of them anytime soon.

Re: Why do shared hospital rooms not violate HIPAA?

#52
post #17

My friend spent the night in the hospital recently, for observation. She didn't sleep a wink. With all the beeping and alarms and periodic checks and procedures. Mostly involving her roommate. The next morning she was mentally and physically wrecked. the first thing she told the nurse was, "I want to go home so I can get some sleep. The nurse laughs and replies, "I hear that all the time. Nobody ever sleeps here". No…

Ricky Gervais had a line that stuck with me back on the podcast with Steve Merchant and Karl Pilkington - `How do people sleep in hospital? They'll wake you up to give a sleeping pill`

Re: Why do shared hospital rooms not violate HIPAA?

#53
It's easier to make sense of when you remember the original purpose of HIPAA, which was cost control and portability (that's what the 'p' stands for!).

The confidentiality rules in HIPAA are part of (IIRC, I think, etc?) the "Administrative Simplification" section, which was about standardizing electronic health care records and making them available to the government for combating Medicare fraud. The law wasn't a sweeping medical privacy bill; it added privacy rules to mitigate concerns people had about centralizing medical records as part of its major purpose.

Re: Why do shared hospital rooms not violate HIPAA?

#54
post #12

I have a domain name that's similar to a medical facility. Sensitive medical data gets emailed to the wrong recipient all the time and it's usually operator error.

Ditto, only my domain is unfortunately similar to a major (non-us) airline.

The tarmac reports can be oddly entertaining sometimes. I still wonder how an alcohol bottle became embedded in a runway a few years back.

Re: Why do shared hospital rooms not violate HIPAA?

#55

From the HHS.gov website: The Privacy Rule permits certain incidental uses and disclosures that occur as a by-product of another permissible or required use or disclosure, as long as the covered entity has applied reasonable safeguards and implemented the minimum necessary standard, where applicable, with respect to the primary use or disclosure. See 45 CFR 164.502(a)(1)(iii). An incidental use or disclosure is a sec…

I mean, they usually have a little curtain - I suppose that counts as reasonable.

Re: Why do shared hospital rooms not violate HIPAA?

#56

The P in HIPAA stands for Portability, not Privacy. The primary purpose of HIPAA is not to prevent the sharing of confidential patient data, it is to ENABLE the sharing of confidential patient data with anyone who has the right to see it. The issue is the number of entities who claim that they have right to see the data, and the lack of a mechanism for the individual to prevent their information from being shared. Sh…

I work in healthcare; these views are my own, and IANAL. > The P in HIPAA stands for Portability, not Privacy. … sure, that P stands for that. But one of the key sections is literally called the Privacy Rule: "The HIPAA Privacy Rule establishes national standards to protect individuals' medical records and other individually identifiable health information" > Should Facebook have a right to access your health data? Y…

It's only "key" in the sense that it's the part technologists and people building PHI-encumbered products have to care about. It's not a key section in the bill itself; in fact, I don't even think it's a key part of the section of the bill it's in (which, I think, is about Medicare fraud).

Re: Why do shared hospital rooms not violate HIPAA?

#57
post #48
post #41

Earlier quoted context omitted.

Go to the hospital healthy, come out sick. I don't have a medical degree or anything but that's crazy. (Also, the nurse said nobody sleeps here. Not just the people under observation.)

> Go to the hospital healthy, come out sick. This isn't whats happening. Being sleep deprived for a day is annoying, but hardly a health issue. I bet most people would rather have doctors respond to you suddenly dropping blood O2 levels to under 90% than not. > (Also, the nurse said nobody sleeps here. Not just the people under observation.) Yes, nobody sleeps because nurses and doctors are all working >14 hour shift…

Actually, sleep deprivation, even for one night, is definitely a health issue. And the only reason it's accepted is because it's so common. It's the modern equivalent of drinking out of lead cups.

(And of course a sleep-deprived medical professional is a health hazard to everybody involved. Only a fool thinks otherwise.)

Re: Why do shared hospital rooms not violate HIPAA?

#58
post #11

The top comment here is very reasonable, but I still think the application of HIPAA has been a giant mess, reflecting a disdain toward patients similar to everything else in the US healthcare system. I've ranted on here plenty about how often I've dealt with incorrect bills, and HIPAA plays into that as well. My private information can be shared to "traveling doctors", it can be shared with woefully incompetent contr…

I once went to the dermatologist, the doctor left the room briefly and had the computer screen open with everyone’s full name and reason for the visit that day…could see who was there for genital warts, Botox, etc. I don’t think anyone should expect that their health info remains private at any point

What your doctor did is actually a HIPAA violation. He's a covered entity and securing computer screens is a standard precaution for such.

In reality, a lot of doctor's offices are not well versed in HIPAA because many are de facto small businesses. Large hospitals and insurance companies generally have better knowledge of HIPAA and HIPAA compliance.

Re: Why do shared hospital rooms not violate HIPAA?

#59
post #57
post #48

Earlier quoted context omitted.

> Go to the hospital healthy, come out sick. This isn't whats happening. Being sleep deprived for a day is annoying, but hardly a health issue. I bet most people would rather have doctors respond to you suddenly dropping blood O2 levels to under 90% than not. > (Also, the nurse said nobody sleeps here. Not just the people under observation.) Yes, nobody sleeps because nurses and doctors are all working >14 hour shift…

Actually, sleep deprivation, even for one night, is definitely a health issue. And the only reason it's accepted is because it's so common. It's the modern equivalent of drinking out of lead cups. (And of course a sleep-deprived medical professional is a health hazard to everybody involved. Only a fool thinks otherwise.)

Then leave. They're not forcing you to stay. Generally no one puts you on observation unless you need it, and by "need it", it means "needs to be disturbed to take tests"

If you think sleep is a higher health factor than the reasons that the hospital want to put you under observation, then just refuse treatment.

If you don't want to be disturbed by patients in the same room, you can pay for that.

Re: Why do shared hospital rooms not violate HIPAA?

#60
post #43

Earlier quoted context omitted.

From https://www.hipaajournal.com/what-does-hipaa-cover/ > The HIPAA Privacy Rule applies to all forms of health information, including paper records, films, and electronic health information – even spoken information. HIPAA is not as limited as you state.

but it only applies to covered entities and business associates.

True. That covers the hospital rooms in this article. It doesn’t mean that your barber can’t ask to see your vaccination card.
Post reply on HN