Live data from Hacker News

Why do shared hospital rooms not violate HIPAA?

law.stackexchange.com

121–130 of 150 posts

Re: Why do shared hospital rooms not violate HIPAA?

#121
post #7

Why do the paper thin walls between exam rooms at my doctor's office that allow me to hear entire conversations while I am waiting (and waiting) not violate HIPAA?

Clinics that deal with the most sensitive medical needs tend to be more careful. HIV testing, reproductive health, psychiatry, hospice.

You missed one of the biggest, one so important it has its own, separate, overriding privacy law: Substance use disorders. (Though perhaps you can argue it’s in psychiatry!)

Addiction treatment falls under 42 CFR II, colloquially known as “part 2”[0]

Part 2 data is significantly more encumbered than other medical data. If I want to get it I need to be explicitly allowed as a named entity by the patient to receive it. If the data is shared with me under a “general designation”whoever gave it to me has to record that and tell the patient on request. And I have no TPO carve outs, I have to get explicit consent to pass it along.

It is, often times, treated as radioactive data - my company deals in medical data but explicitly says in our contracts that we refuse any receipt of it.

0: https://www.ecfr.gov/current/title-42/chapter-I/subchapter-A...

Re: Why do shared hospital rooms not violate HIPAA?

#122

Earlier quoted context omitted.

This was not a productive, nor necessary comment. Please retract it and take it elsewhere. It has no place on HN.

[flagged]

I did use it.

From the HN Guidelines:

“Please don't use Hacker News for political or ideological battle. That tramples curiosity.”

You indeed have the right to your opinions. That does not mean that HN must accept and provide a venue for them.

Good luck to you.

Re: Why do shared hospital rooms not violate HIPAA?

#123
post #118

Earlier quoted context omitted.

Anonymised collections of health records are available to bona fide researchers.

The point is that "anonymized" data is frequently relatively straightforward to de-anomymize at least on a statistical basis.

That doesn’t make what I said any less true. Anonymised datasets have been available to researchers for decades.

Re: Why do shared hospital rooms not violate HIPAA?

#124
post #53

It's easier to make sense of when you remember the original purpose of HIPAA, which was cost control and portability (that's what the 'p' stands for!). The confidentiality rules in HIPAA are part of (IIRC, I think, etc?) the "Administrative Simplification" section, which was about standardizing electronic health care records and making them available to the government for combating Medicare fraud. The law wasn't a sw…

Which sucks because there is tremendous value in anonymized collections of health records, yet we can’t use these health records for research at all. I realize it was out of scope for the bill, but damned if it didn’t stymie medical research to a ridiculous degree.

I worked with de-identification of records - it was not only difficult, but also rewarding. The records were used in research, tied to other biomedical data.

Some of it was simply migration of encounter data +/- a date range, with removal of the obvious stuff, too.

Other was cool like NLP on doc notes to ensure stuff like “pt said the school shooting they got this wound from was..” (think: cohort sizes for major incidents are often small and therefore easy to re-id.)

Re: Why do shared hospital rooms not violate HIPAA?

#125

Earlier quoted context omitted.

[flagged]

I did use it. From the HN Guidelines: “Please don't use Hacker News for political or ideological battle. That tramples curiosity.” You indeed have the right to your opinions. That does not mean that HN must accept and provide a venue for them. Good luck to you.

[flagged]

Re: Why do shared hospital rooms not violate HIPAA?

#126

Earlier quoted context omitted.

I did use it. From the HN Guidelines: “Please don't use Hacker News for political or ideological battle. That tramples curiosity.” You indeed have the right to your opinions. That does not mean that HN must accept and provide a venue for them. Good luck to you.

[flagged]

[flagged]

Re: Why do shared hospital rooms not violate HIPAA?

#127

Once, and never again, I declared my desire to a front-desk nurse that I wished to record my session in an Urgent Care facility. She said no, that is prohibited, because it is a HIPAA violation. She was clearly smoking crack. Now I simply record surreptitiously.

A healthcare facility knowingly permitting recording on-premises may indeed be a HIPAA violation.

Re: Why do shared hospital rooms not violate HIPAA?

#128
post #90

Earlier quoted context omitted.

Which sucks because there is tremendous value in anonymized collections of health records, yet we can’t use these health records for research at all. I realize it was out of scope for the bill, but damned if it didn’t stymie medical research to a ridiculous degree.

Anonymization is hard. Unless you have very accomplished cryptographers defining and implementing anonymization, I do not trust it. That basically means not trusting anyone but large governments and FAANG companies. That said I do think agencies like NIST should define anonymization standards.

> That basically means not trusting anyone but large governments and FAANG companies.

that basically means not trusting… anyone?

Re: Why do shared hospital rooms not violate HIPAA?

#129

Once, and never again, I declared my desire to a front-desk nurse that I wished to record my session in an Urgent Care facility. She said no, that is prohibited, because it is a HIPAA violation. She was clearly smoking crack. Now I simply record surreptitiously.

A healthcare facility knowingly permitting recording on-premises may indeed be a HIPAA violation.

78% false. Please do not discourage patients from exercising our rights and accessing our own PHI, like this crack-smoking nurse did to me.

https://www.aetnainternational.com/en/about-us/explore/healt...

https://www.alight.com/blog/can-patients-record-doctors-offi...

https://www.verywellhealth.com/secretly-recording-your-docto...

You've got to understand: clinic visits are very stressful, time-limited, and high-pressure. Doctors don't write anything down, but it's crucial that the patient rememberd everything that was said, with high accuracy and confidence. Audio recording is our best tool to these ends.

I'm glad I don't live in California!

Re: Why do shared hospital rooms not violate HIPAA?

#130

Earlier quoted context omitted.

A healthcare facility knowingly permitting recording on-premises may indeed be a HIPAA violation.

78% false. Please do not discourage patients from exercising our rights and accessing our own PHI , like this crack-smoking nurse did to me. https://www.aetnainternational.com/en/about-us/explore/healt... https://www.alight.com/blog/can-patients-record-doctors-offi... https://www.verywellhealth.com/secretly-recording-your-docto... You've got to understand: clinic visits are very stressful, time-limited, and high-pres…

The problem isn't your PHI, nor is it a legal problem for you. The problem is them knowingly permitting you to record in a situation where you may capture someone else's PHI. (As in the "shared hospital rooms" example we're in a discussion thread of.)

You've also mixed up what's legal for you to do (record, in a single-party state) and what's legal for them to permit by policy (knowingly agreeing to recording). You won't get arrested in a single-party state for recording; it can still violate the clinic's policy, and they can make the decision not to continue doing business with you after.

No one's going to stop you from writing down a note, though. Thinking "doctors don't write anything down" is universal may indicate you need a better one; mine definitely does, and I get sent the summary shortly after my visits.

Post reply on HN