Live data from Hacker News

Pharmacies share medical data with police without a warrant, inquiry finds

washingtonpost.com

11–20 of 47 posts

Re: Pharmacies share medical data with police without a warrant, inquiry finds

#11

Earlier quoted context omitted.

The article covers this: The Health Insurance Portability and Accountability Act, or HIPAA, regulates how health information is used and exchanged among “covered entities” such as hospitals and doctor’s offices. But the law gives pharmacies leeway as to what legal standard they require before disclosing medical records to law enforcement.

Wow, that's a gaping privacy loophole.

The P in HIPAA stands for "Portability," not "Privacy."

Re: Pharmacies share medical data with police without a warrant, inquiry finds

#12

Earlier quoted context omitted.

Wouldn’t this be a massive HIPAA violation??

The article covers this: The Health Insurance Portability and Accountability Act, or HIPAA, regulates how health information is used and exchanged among “covered entities” such as hospitals and doctor’s offices. But the law gives pharmacies leeway as to what legal standard they require before disclosing medical records to law enforcement.

I work in this space, and your comment is completely wrong. Data covered by HIPAA is always covered by HIPAA. A covered entity would also include a health insurer, and all payment intermediaries, this is straight from the HHS faq (https://www.hhs.gov/hipaa/for-professionals/faq/covered-enti...)

Re: Pharmacies share medical data with police without a warrant, inquiry finds

#13

If you get a prescription filled using insurance, that medication goes on a report. * Collects prescription drug purchase history for quantifying the relative mortality risk of life insurance applicants and provides risk scores for underwriting decisions.* https://www.consumerfinance.gov/consumer-tools/credit-report... Even if you don’t use insurance, it may still be possible to wind up on this list.

Wouldn’t this be a massive HIPAA violation??

When you buy health insurance, you sign a temporary HIPAA release (limited duration) to cover the period that they are underwriting. They can only query your specific pharmacy records for the purposes of underwriting. So yes, this is a HIPAA violation when it is being used by the police. I work in this space with HIPAA data.

Re: Pharmacies share medical data with police without a warrant, inquiry finds

#14

Earlier quoted context omitted.

Wouldn’t this be a massive HIPAA violation??

The article covers this: The Health Insurance Portability and Accountability Act, or HIPAA, regulates how health information is used and exchanged among “covered entities” such as hospitals and doctor’s offices. But the law gives pharmacies leeway as to what legal standard they require before disclosing medical records to law enforcement.

HIPAA law and implementing regs include broad allowances for disclosure to law enforcement, some of which involve some degree of subjective judgement on the part of the covered entity (and most of which do not require a warrant), but, no, it does not allow pharmacies (or any other covered entities) "leeway as to what legal standard they require" (emphasis added) before such disclosure.

See, generally, https://www.hhs.gov/hipaa/for-professionals/faq/505/what-doe... and the regulations cited therein.

Re: Pharmacies share medical data with police without a warrant, inquiry finds

#15
post #8

Earlier quoted context omitted.

Wouldn’t this be a massive HIPAA violation??

I look forward to the lawsuits since HIPAA is Federal and abortion laws are state.

Unfortunately for that idea, the law enforcement disclosures allowed under HIPAA are not limited to disclosures related to violations of federal law, or disclosures only to federal law enforcement.

Re: Pharmacies share medical data with police without a warrant, inquiry finds

#16
post #10

Earlier quoted context omitted.

Wouldn’t this be a massive HIPAA violation??

I'm in Canada so HIPAA doesn't apply for me but when I was going into my second year of university the student union signed a contract with a health insurance company that provided some piddly policy for students that was mandatory unless you could provide proof of insurance with another company. Not only was there no way to refuse this but you were automatically enrolled unless you could provide that proof by a cert…

> I'm in Canada so HIPAA doesn't apply for me

But PIPEDA definitely applies to this situation, but PIPEDA only came into effect on April 2020 so it would depend upon when you were a student.

Re: Pharmacies share medical data with police without a warrant, inquiry finds

#17

If you get a prescription filled using insurance, that medication goes on a report. * Collects prescription drug purchase history for quantifying the relative mortality risk of life insurance applicants and provides risk scores for underwriting decisions.* https://www.consumerfinance.gov/consumer-tools/credit-report... Even if you don’t use insurance, it may still be possible to wind up on this list.

Wouldn’t this be a massive HIPAA violation??

You can fit an astounding number of elephants through the loopholes in HIPAA:

https://www.law.cornell.edu/cfr/text/45/164.512

And then there's the HHS interpretation of the above for providers, which is... porous:

https://www.hhs.gov/hipaa/for-professionals/faq/505/what-doe...

Of particular note are the exemptions in 45 CFR 164.512(k)(2) applicable to powers granted by executive order 12333 (on mass surveillance). When this exemption is used it makes discovering whether, when, how, or why your data was collected or used practically impossible.

Re: Pharmacies share medical data with police without a warrant, inquiry finds

#20
post #10

Earlier quoted context omitted.

Wouldn’t this be a massive HIPAA violation??

I'm in Canada so HIPAA doesn't apply for me but when I was going into my second year of university the student union signed a contract with a health insurance company that provided some piddly policy for students that was mandatory unless you could provide proof of insurance with another company. Not only was there no way to refuse this but you were automatically enrolled unless you could provide that proof by a cert…

> He was adamant that it was both legal and ethical, and that there was no privacy violation that occurred.

I could understand about it being legal, maybe even ethical (ethical codes can differ) -- but to argue that there is no privacy violation? That just seems completely delusional.

Post reply on HN