Live data from Hacker News

Why do shared hospital rooms not violate HIPAA?

law.stackexchange.com

131–140 of 150 posts

Re: Why do shared hospital rooms not violate HIPAA?

#131

Earlier quoted context omitted.

78% false. Please do not discourage patients from exercising our rights and accessing our own PHI , like this crack-smoking nurse did to me. https://www.aetnainternational.com/en/about-us/explore/healt... https://www.alight.com/blog/can-patients-record-doctors-offi... https://www.verywellhealth.com/secretly-recording-your-docto... You've got to understand: clinic visits are very stressful, time-limited, and high-pres…

The problem isn't your PHI , nor is it a legal problem for you . The problem is them knowingly permitting you to record in a situation where you may capture someone else's PHI . (As in the "shared hospital rooms" example we're in a discussion thread of.) You've also mixed up what's legal for you to do (record, in a single-party state) and what's legal for them to permit by policy (knowingly agreeing to recording). Yo…

What is the moral difference between me hearing someone's PHI, and writing it down in a note, and my phone hearing it? Let's stipulate that all smartphones are always and everywhere listening to everything, and sending it to someone; it may as well be me.

Re: Why do shared hospital rooms not violate HIPAA?

#133

Earlier quoted context omitted.

The problem isn't your PHI , nor is it a legal problem for you . The problem is them knowingly permitting you to record in a situation where you may capture someone else's PHI . (As in the "shared hospital rooms" example we're in a discussion thread of.) You've also mixed up what's legal for you to do (record, in a single-party state) and what's legal for them to permit by policy (knowingly agreeing to recording). Yo…

What is the moral difference between me hearing someone's PHI, and writing it down in a note, and my phone hearing it? Let's stipulate that all smartphones are always and everywhere listening to everything, and sending it to someone; it may as well be me.

> What is the moral difference between me hearing someone's PHI, and my phone hearing it?

In a court, hearsay is inadmissible; a recording (critically different than mere hearing) is far more likely to be admissible. That's for a good reason. (HIPAA compliance is also not a strictly moral question, but a legal one.)

> Let's stipulate that all smartphones are always and everywhere listening to everything, and sending it to someone...

Even if you're using something like "hey Siri" or "OK Google", that's not how they work.

Re: Why do shared hospital rooms not violate HIPAA?

#134
post #92

Earlier quoted context omitted.

And medical issues are such that even fully anonymous you can probably identify who is whom.

Latanya Sweeney demonstrated how hard it is to anonymize health data back in the late 1990s as part of her dissertation work: https://arstechnica.com/tech-policy/2009/09/your-secrets-liv... "At the time GIC released the data, William Weld, then Governor of Massachusetts, assured the public that GIC had protected patient privacy by deleting identifiers. In response, then-graduate student Sweeney started hunting for th…

I’m sorry but I don’t buy that. From a practical stand point, what am I going to do if you hand me a sex, birthdate and zip code and tell me to find who owns them? I would have to talk to every person in that zip code who matched the sex (have to account for the possibility two people have the same birthday). At that point, I’m getting better records pounding the streets than I am from some database.

Re: Why do shared hospital rooms not violate HIPAA?

#135
post #2

This is why "code is law" as a crypto meme was a little silly. Law is often intentionally flexible!

I'd actually come to the opposite conclusion here. Unless you think this violation of privacy is OK?

I think this violation of privacy strikes the correct balance. Hospitals (especially ERs) are already quite full on a regular basis; making every room private would do substantial physical harm to many patients who'd wait much longer for treatment or have to forgo it entirely.

(Perfect privacy would also require soundproofed rooms for phone calls, mantrap doors for patient rooms so you can't get an inadvertent peek while walking by, and probably dozens of other expensively impractical mitigations.)

HIPAA requires "reasonable safeguards" to permit this sort of balance to be struck.

Re: Why do shared hospital rooms not violate HIPAA?

#136

Earlier quoted context omitted.

Latanya Sweeney demonstrated how hard it is to anonymize health data back in the late 1990s as part of her dissertation work: https://arstechnica.com/tech-policy/2009/09/your-secrets-liv... "At the time GIC released the data, William Weld, then Governor of Massachusetts, assured the public that GIC had protected patient privacy by deleting identifiers. In response, then-graduate student Sweeney started hunting for th…

I’m sorry but I don’t buy that. From a practical stand point, what am I going to do if you hand me a sex, birthdate and zip code and tell me to find who owns them? I would have to talk to every person in that zip code who matched the sex (have to account for the possibility two people have the same birthday). At that point, I’m getting better records pounding the streets than I am from some database.

A key insight from anonymization is that you need to consider how easy it is to join that dataset together with some other freely available or cheaply available datasets. GP said the person spent $20 buying voter information. A moderate to big company will even prevent employees from joining data sets from different departments of the company, as a matter of policy.

Re: Why do shared hospital rooms not violate HIPAA?

#137

Earlier quoted context omitted.

Latanya Sweeney demonstrated how hard it is to anonymize health data back in the late 1990s as part of her dissertation work: https://arstechnica.com/tech-policy/2009/09/your-secrets-liv... "At the time GIC released the data, William Weld, then Governor of Massachusetts, assured the public that GIC had protected patient privacy by deleting identifiers. In response, then-graduate student Sweeney started hunting for th…

I’m sorry but I don’t buy that. From a practical stand point, what am I going to do if you hand me a sex, birthdate and zip code and tell me to find who owns them? I would have to talk to every person in that zip code who matched the sex (have to account for the possibility two people have the same birthday). At that point, I’m getting better records pounding the streets than I am from some database.

Knowing gender cuts down your sample space by half.

Assuming you are looking at someone between the ages of 1-80, knowing birthdate further filters in just 1÷(80 * 365) of the sample space.

Since they're 42000 ZIP codes in the US, knowing the ZIP code lets you filter in just 1÷42000 of the sample space. Together, 1÷2 x 1÷(80*365) x 1÷42000 = 0.00000041%

With these three datapoints, you can identify roughly 1.3 US persons (assuming a US population of 330M). Not too bad, imho.

Re: Why do shared hospital rooms not violate HIPAA?

#139
post #89

Earlier quoted context omitted.

Okay … sure. "Key" if you're like me, and working in healthtech, I suppose, as it's one of the sections they repeatedly try to cram into your head in the mandatory training sessions. (…and for good reason.) In the intersection of Facebook and PHI.

Let's put it this way: something being a key part of a particular solution implementation, does not necessarily imply that it was a key part of the solution's design; nor that it was a key part of the problem domain. Compare/contrast: there's one ability a Pokemon can have, that just by existing, means that the games' battle-system logic has to be re-entrant, because the ability evaluates a hypothetical battle "withi…

Y'all are nit picking a single word in my comment whose removal doesn't affect the comment in any way. Key to the point, key in this circumstance, etc.

Re: Why do shared hospital rooms not violate HIPAA?

#140
post #90

Earlier quoted context omitted.

Anonymization is hard. Unless you have very accomplished cryptographers defining and implementing anonymization, I do not trust it. That basically means not trusting anyone but large governments and FAANG companies. That said I do think agencies like NIST should define anonymization standards.

> Anonymization is hard. Unless you have very accomplished cryptographers defining and implementing anonymization, I do not trust it. That basically means not trusting anyone but large governments and FAANG companies. Huh that is pretty solid point, so anonymization is useless to those who are the most interested in privacy?

no its useless to people with several distinct data points

turns out that in this regard, everyone is special

Post reply on HN