Live data from Hacker News

Why do shared hospital rooms not violate HIPAA?

law.stackexchange.com

101–110 of 150 posts

Re: Why do shared hospital rooms not violate HIPAA?

#101
post #85
post #76

Earlier quoted context omitted.

No, that's not the actual reason! The reason the rule exists is because, when HIPAA was passed, electronic patient health records were a new thing, and they were desired both for cost savings (electronic records as a way to drive administration costs down were a huge thing in the 1990s) and so the USG could combat Medicare fraud. The confidentiality rule was designed to ease the acceptance of electronic records; that…

You’re correct regarding historical procedure, but with regards to the privacy rule, which was added shortly after its creation and at least online is much of why the act is known and discussed today, the rule exists to, quoting the government’s description, > The Rule requires appropriate safeguards to protect the privacy of protected health information and sets limits and conditions on the uses and disclosures that…

HHS was authorized by statute to make a specific set of rules to address a specific issue. When we refer to "The Rule", we're referring to HHS's rulemaking process, which is governed by the statute, which spells out what the rule is about.

Re: Why do shared hospital rooms not violate HIPAA?

#102
post #92
post #90

Earlier quoted context omitted.

Anonymization is hard. Unless you have very accomplished cryptographers defining and implementing anonymization, I do not trust it. That basically means not trusting anyone but large governments and FAANG companies. That said I do think agencies like NIST should define anonymization standards.

And medical issues are such that even fully anonymous you can probably identify who is whom.

Latanya Sweeney demonstrated how hard it is to anonymize health data back in the late 1990s as part of her dissertation work:

https://arstechnica.com/tech-policy/2009/09/your-secrets-liv...

"At the time GIC released the data, William Weld, then Governor of Massachusetts, assured the public that GIC had protected patient privacy by deleting identifiers. In response, then-graduate student Sweeney started hunting for the Governor’s hospital records in the GIC data. She knew that Governor Weld resided in Cambridge, Massachusetts, a city of 54,000 residents and seven ZIP codes. For twenty dollars, she purchased the complete voter rolls from the city of Cambridge, a database containing, among other things, the name, address, ZIP code, birth date, and sex of every voter. By combining this data with the GIC records, Sweeney found Governor Weld with ease. Only six people in Cambridge shared his birth date, only three of them men, and of them, only he lived in his ZIP code. In a theatrical flourish, Dr. Sweeney sent the Governor’s health records (which included diagnoses and prescriptions) to his office."

This same article also mentions one of her more famous findings too: "in 2000, she showed that 87 percent of all Americans could be uniquely identified using only three bits of information: ZIP code, birthdate, and sex."

Re: Why do shared hospital rooms not violate HIPAA?

#103
post #7

Why do the paper thin walls between exam rooms at my doctor's office that allow me to hear entire conversations while I am waiting (and waiting) not violate HIPAA?

Clinics that deal with the most sensitive medical needs tend to be more careful. HIV testing, reproductive health, psychiatry, hospice.

[flagged]

Re: Why do shared hospital rooms not violate HIPAA?

#104
post #53

It's easier to make sense of when you remember the original purpose of HIPAA, which was cost control and portability (that's what the 'p' stands for!). The confidentiality rules in HIPAA are part of (IIRC, I think, etc?) the "Administrative Simplification" section, which was about standardizing electronic health care records and making them available to the government for combating Medicare fraud. The law wasn't a sw…

Retracted

Re: Why do shared hospital rooms not violate HIPAA?

#105
post #83

Speaking of that, hospitals still use tons of POCSAG (pagers) and splatter medical everything over those. Course it's illegal to listen due to a bullshit 1987 law... but trivial to do so with a RTL-SDR. One idea my nefarious side had was to get the med records of individuals and get the address's house cost, and send scary calls/text/messages shaking relatives down with scare-calls. (Or, get the info and get in leagu…

I've had a career in hospital IT and operations. The challenge is finding a replacement that is as reliable and accessible as a pager. The replacement communications products out there have some nice features (managing on-call scheduling, interfacing with electronic health records, etc), but it only takes a handful of outages to get everyone to switch back to pagers "just in case."

I'm sure Oracle nee Cerner would develop Pager Millennium if you asked nicely enough.

Re: Why do shared hospital rooms not violate HIPAA?

#106

Earlier quoted context omitted.

Such a voluntary waiver is legal, yes. Refusing to treat you if you want to keep your rights, less so. The thing they have you sign is an agreement that you received a notice of their privacy practices (laying out your HIPAA rights). It isn’t a waiver. Hospitals don’t need a waiver to operate. HIPAA already permits them to share internally, with billers, etc.

In the context of hospitals waivers are not that voluntary, at least in the US and Canada, since doctors and nurses can't be forced to treat people if they really don't want to. And there is a decent chance in many hospitals that they will at least drag their feet, since they would be exposed to much greater liability. I know this situation specifically is not quite a waiver, but it will likely have some effect on ho…

Hospitals are under zero potential HIPAA liability for sharing information internally for the purposes of providing care. It's expressly permitted by the law, without any authorization required.

https://www.hhs.gov/hipaa/for-professionals/privacy/laws-reg...

> Permitted Uses and Disclosures. A covered entity is permitted, but not required, to use and disclose protected health information, without an individual's authorization, for the following purposes or situations: (1) To the Individual (unless required for access or accounting of disclosures); (2) Treatment, Payment, and Health Care Operations; (3) Opportunity to Agree or Object; (4) Incident to an otherwise permitted use and disclosure; (5) Public Interest and Benefit Activities; and (6) Limited Data Set for the purposes of research, public health or health care operations.18 Covered entities may rely on professional ethics and best judgments in deciding which of these permissive uses and disclosures to make.

The thing you sign all the time is acknowledging receipt of the provider's privacy practices. It's an entirely different thing; it is by no means a waiver of any rights. https://www.hhs.gov/hipaa/for-professionals/faq/notice-of-pr...

> Yes. The HIPAA Privacy Rule requires that a covered health care provider with a direct treatment relationship with individuals make a good faith effort to obtain written acknowledgments from those individuals that they have received the provider’s notice, regardless of whether the provider also chooses to obtain the individuals’ consent.

You can refuse to sign that. They'll document the refusal, which changes nothing. It's like your Miranda rights when you get arrested; they tried to inform you of your rights under HIPAA. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance...

Re: Why do shared hospital rooms not violate HIPAA?

#107
post #53

It's easier to make sense of when you remember the original purpose of HIPAA, which was cost control and portability (that's what the 'p' stands for!). The confidentiality rules in HIPAA are part of (IIRC, I think, etc?) the "Administrative Simplification" section, which was about standardizing electronic health care records and making them available to the government for combating Medicare fraud. The law wasn't a sw…

Retracted

[deleted]

Re: Why do shared hospital rooms not violate HIPAA?

#108

Earlier quoted context omitted.

In the context of hospitals waivers are not that voluntary, at least in the US and Canada, since doctors and nurses can't be forced to treat people if they really don't want to. And there is a decent chance in many hospitals that they will at least drag their feet, since they would be exposed to much greater liability. I know this situation specifically is not quite a waiver, but it will likely have some effect on ho…

Hospitals are under zero potential HIPAA liability for sharing information internally for the purposes of providing care. It's expressly permitted by the law, without any authorization required. https://www.hhs.gov/hipaa/for-professionals/privacy/laws-reg... > Permitted Uses and Disclosures. A covered entity is permitted, but not required, to use and disclose protected health information, without an individual's auth…

I meant it in a more prosaic sense, for example the receptionist could put those who refuse in the bucket of 'potentially troublesome patients'. And receptionists talk a lot with other staff.

Or various other scenarios.

Re: Why do shared hospital rooms not violate HIPAA?

#109
post #83

Speaking of that, hospitals still use tons of POCSAG (pagers) and splatter medical everything over those. Course it's illegal to listen due to a bullshit 1987 law... but trivial to do so with a RTL-SDR. One idea my nefarious side had was to get the med records of individuals and get the address's house cost, and send scary calls/text/messages shaking relatives down with scare-calls. (Or, get the info and get in leagu…

I've had a career in hospital IT and operations. The challenge is finding a replacement that is as reliable and accessible as a pager. The replacement communications products out there have some nice features (managing on-call scheduling, interfacing with electronic health records, etc), but it only takes a handful of outages to get everyone to switch back to pagers "just in case."

Well, I was being rather absolutist when I said to destroy pager infra.

It should be messages like "Code red to room xyz with patientID #####"

That would remove anything really actionable.

Whereas I was seeing over FLEX: full name, address, room#, child abuser status, why they're there, medicines. It was fucking stupid, like fuck no.

Re: Why do shared hospital rooms not violate HIPAA?

#110

Earlier quoted context omitted.

Agreed, the individual records are not specifically secret. The regulations are to prevent unauthorized disclosure and misuse. Unfortunatly that leaves a lot of leeway. The major EMR vendors are all aggregating patient data in cloud services and taking it across borders to where there is no transparency for what is being done with it. The regulations were written with a 90's understanding of technology. A more approp…

In the medical field, the academics who "snoop" your data are doing so to conduct analyses and build models to improve your care.

Ask them how they feel about having their names and the names of the people they hire attached to queries of PHI in aggregated health information repositories, and whether those people have had the level of background checks that public service staff who typically do this have had. Then ask them whether they will bear any accountability for losing the data they are entrusted with, have their REB decisions subject to freedom of information, or be subject to consent directives by patients, and why they engage big-N consulting firms to misrepresent system design on their behalf. Then ask them whether the research is restricted to clinicial and biological research, or if their "research" includes providing data people in the social sciences.

Technically, they are building models to publish or perish, establish data feifs in their institutions for attracting grant money, and to support policy objectives for the revolving door between gov and academia and some troubling third party NGOs, with "care," being a distant abstraction.

The academics I encountered doing privacy work for PHI data sets seemed to be interested in everything except responsibility and stewardship. My care indeed.

Post reply on HN