Earlier quoted context omitted.
No, that's not the actual reason! The reason the rule exists is because, when HIPAA was passed, electronic patient health records were a new thing, and they were desired both for cost savings (electronic records as a way to drive administration costs down were a huge thing in the 1990s) and so the USG could combat Medicare fraud. The confidentiality rule was designed to ease the acceptance of electronic records; that…
You’re correct regarding historical procedure, but with regards to the privacy rule, which was added shortly after its creation and at least online is much of why the act is known and discussed today, the rule exists to, quoting the government’s description, > The Rule requires appropriate safeguards to protect the privacy of protected health information and sets limits and conditions on the uses and disclosures that…
Why do shared hospital rooms not violate HIPAA?
101–110 of 150 posts
Re: Why do shared hospital rooms not violate HIPAA?
#102Earlier quoted context omitted.
Anonymization is hard. Unless you have very accomplished cryptographers defining and implementing anonymization, I do not trust it. That basically means not trusting anyone but large governments and FAANG companies. That said I do think agencies like NIST should define anonymization standards.
And medical issues are such that even fully anonymous you can probably identify who is whom.
https://arstechnica.com/tech-policy/2009/09/your-secrets-liv...
"At the time GIC released the data, William Weld, then Governor of Massachusetts, assured the public that GIC had protected patient privacy by deleting identifiers. In response, then-graduate student Sweeney started hunting for the Governor’s hospital records in the GIC data. She knew that Governor Weld resided in Cambridge, Massachusetts, a city of 54,000 residents and seven ZIP codes. For twenty dollars, she purchased the complete voter rolls from the city of Cambridge, a database containing, among other things, the name, address, ZIP code, birth date, and sex of every voter. By combining this data with the GIC records, Sweeney found Governor Weld with ease. Only six people in Cambridge shared his birth date, only three of them men, and of them, only he lived in his ZIP code. In a theatrical flourish, Dr. Sweeney sent the Governor’s health records (which included diagnoses and prescriptions) to his office."
This same article also mentions one of her more famous findings too: "in 2000, she showed that 87 percent of all Americans could be uniquely identified using only three bits of information: ZIP code, birthdate, and sex."
Re: Why do shared hospital rooms not violate HIPAA?
#103Why do the paper thin walls between exam rooms at my doctor's office that allow me to hear entire conversations while I am waiting (and waiting) not violate HIPAA?
Clinics that deal with the most sensitive medical needs tend to be more careful. HIV testing, reproductive health, psychiatry, hospice.
Re: Why do shared hospital rooms not violate HIPAA?
#104It's easier to make sense of when you remember the original purpose of HIPAA, which was cost control and portability (that's what the 'p' stands for!). The confidentiality rules in HIPAA are part of (IIRC, I think, etc?) the "Administrative Simplification" section, which was about standardizing electronic health care records and making them available to the government for combating Medicare fraud. The law wasn't a sw…
Re: Why do shared hospital rooms not violate HIPAA?
#105Speaking of that, hospitals still use tons of POCSAG (pagers) and splatter medical everything over those. Course it's illegal to listen due to a bullshit 1987 law... but trivial to do so with a RTL-SDR. One idea my nefarious side had was to get the med records of individuals and get the address's house cost, and send scary calls/text/messages shaking relatives down with scare-calls. (Or, get the info and get in leagu…
I've had a career in hospital IT and operations. The challenge is finding a replacement that is as reliable and accessible as a pager. The replacement communications products out there have some nice features (managing on-call scheduling, interfacing with electronic health records, etc), but it only takes a handful of outages to get everyone to switch back to pagers "just in case."
Re: Why do shared hospital rooms not violate HIPAA?
#106Earlier quoted context omitted.
Such a voluntary waiver is legal, yes. Refusing to treat you if you want to keep your rights, less so. The thing they have you sign is an agreement that you received a notice of their privacy practices (laying out your HIPAA rights). It isn’t a waiver. Hospitals don’t need a waiver to operate. HIPAA already permits them to share internally, with billers, etc.
In the context of hospitals waivers are not that voluntary, at least in the US and Canada, since doctors and nurses can't be forced to treat people if they really don't want to. And there is a decent chance in many hospitals that they will at least drag their feet, since they would be exposed to much greater liability. I know this situation specifically is not quite a waiver, but it will likely have some effect on ho…
https://www.hhs.gov/hipaa/for-professionals/privacy/laws-reg...
> Permitted Uses and Disclosures. A covered entity is permitted, but not required, to use and disclose protected health information, without an individual's authorization, for the following purposes or situations: (1) To the Individual (unless required for access or accounting of disclosures); (2) Treatment, Payment, and Health Care Operations; (3) Opportunity to Agree or Object; (4) Incident to an otherwise permitted use and disclosure; (5) Public Interest and Benefit Activities; and (6) Limited Data Set for the purposes of research, public health or health care operations.18 Covered entities may rely on professional ethics and best judgments in deciding which of these permissive uses and disclosures to make.
The thing you sign all the time is acknowledging receipt of the provider's privacy practices. It's an entirely different thing; it is by no means a waiver of any rights. https://www.hhs.gov/hipaa/for-professionals/faq/notice-of-pr...
> Yes. The HIPAA Privacy Rule requires that a covered health care provider with a direct treatment relationship with individuals make a good faith effort to obtain written acknowledgments from those individuals that they have received the provider’s notice, regardless of whether the provider also chooses to obtain the individuals’ consent.
You can refuse to sign that. They'll document the refusal, which changes nothing. It's like your Miranda rights when you get arrested; they tried to inform you of your rights under HIPAA. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance...
Re: Why do shared hospital rooms not violate HIPAA?
#107It's easier to make sense of when you remember the original purpose of HIPAA, which was cost control and portability (that's what the 'p' stands for!). The confidentiality rules in HIPAA are part of (IIRC, I think, etc?) the "Administrative Simplification" section, which was about standardizing electronic health care records and making them available to the government for combating Medicare fraud. The law wasn't a sw…
Retracted
Re: Why do shared hospital rooms not violate HIPAA?
#108Earlier quoted context omitted.
In the context of hospitals waivers are not that voluntary, at least in the US and Canada, since doctors and nurses can't be forced to treat people if they really don't want to. And there is a decent chance in many hospitals that they will at least drag their feet, since they would be exposed to much greater liability. I know this situation specifically is not quite a waiver, but it will likely have some effect on ho…
Hospitals are under zero potential HIPAA liability for sharing information internally for the purposes of providing care. It's expressly permitted by the law, without any authorization required. https://www.hhs.gov/hipaa/for-professionals/privacy/laws-reg... > Permitted Uses and Disclosures. A covered entity is permitted, but not required, to use and disclose protected health information, without an individual's auth…
Or various other scenarios.
Re: Why do shared hospital rooms not violate HIPAA?
#109Speaking of that, hospitals still use tons of POCSAG (pagers) and splatter medical everything over those. Course it's illegal to listen due to a bullshit 1987 law... but trivial to do so with a RTL-SDR. One idea my nefarious side had was to get the med records of individuals and get the address's house cost, and send scary calls/text/messages shaking relatives down with scare-calls. (Or, get the info and get in leagu…
I've had a career in hospital IT and operations. The challenge is finding a replacement that is as reliable and accessible as a pager. The replacement communications products out there have some nice features (managing on-call scheduling, interfacing with electronic health records, etc), but it only takes a handful of outages to get everyone to switch back to pagers "just in case."
It should be messages like "Code red to room xyz with patientID #####"
That would remove anything really actionable.
Whereas I was seeing over FLEX: full name, address, room#, child abuser status, why they're there, medicines. It was fucking stupid, like fuck no.
Re: Why do shared hospital rooms not violate HIPAA?
#110Earlier quoted context omitted.
Agreed, the individual records are not specifically secret. The regulations are to prevent unauthorized disclosure and misuse. Unfortunatly that leaves a lot of leeway. The major EMR vendors are all aggregating patient data in cloud services and taking it across borders to where there is no transparency for what is being done with it. The regulations were written with a 90's understanding of technology. A more approp…
In the medical field, the academics who "snoop" your data are doing so to conduct analyses and build models to improve your care.
Technically, they are building models to publish or perish, establish data feifs in their institutions for attracting grant money, and to support policy objectives for the revolving door between gov and academia and some troubling third party NGOs, with "care," being a distant abstraction.
The academics I encountered doing privacy work for PHI data sets seemed to be interested in everything except responsibility and stewardship. My care indeed.