Live data from Hacker News

Why do shared hospital rooms not violate HIPAA?

law.stackexchange.com

141–150 of 150 posts

Re: Why do shared hospital rooms not violate HIPAA?

#141
post #89

Earlier quoted context omitted.

Let's put it this way: something being a key part of a particular solution implementation, does not necessarily imply that it was a key part of the solution's design; nor that it was a key part of the problem domain. Compare/contrast: there's one ability a Pokemon can have, that just by existing, means that the games' battle-system logic has to be re-entrant, because the ability evaluates a hypothetical battle "withi…

Y'all are nit picking a single word in my comment whose removal doesn't affect the comment in any way. Key to the point, key in this circumstance, etc.

I understand what you mean. And for technologists, it's more than "key", it's like, the only thing in HIPAA. My point is just, however important that section to us, it's not remotely the point of HIPAA itself; it's not even really the point of the confidentiality rulemaking.

Re: Why do shared hospital rooms not violate HIPAA?

#142
post #53

It's easier to make sense of when you remember the original purpose of HIPAA, which was cost control and portability (that's what the 'p' stands for!). The confidentiality rules in HIPAA are part of (IIRC, I think, etc?) the "Administrative Simplification" section, which was about standardizing electronic health care records and making them available to the government for combating Medicare fraud. The law wasn't a sw…

Which sucks because there is tremendous value in anonymized collections of health records, yet we can’t use these health records for research at all. I realize it was out of scope for the bill, but damned if it didn’t stymie medical research to a ridiculous degree.

This is just incorrect. I've collaborated in studies using anonymized MRI scans and health data.

You don't get a blank check, but there are plenty of studies doing exactly this.

Re: Why do shared hospital rooms not violate HIPAA?

#143
post #137

Earlier quoted context omitted.

I’m sorry but I don’t buy that. From a practical stand point, what am I going to do if you hand me a sex, birthdate and zip code and tell me to find who owns them? I would have to talk to every person in that zip code who matched the sex (have to account for the possibility two people have the same birthday). At that point, I’m getting better records pounding the streets than I am from some database.

Knowing gender cuts down your sample space by half. Assuming you are looking at someone between the ages of 1-80, knowing birthdate further filters in just 1÷(80 * 365) of the sample space. Since they're 42000 ZIP codes in the US, knowing the ZIP code lets you filter in just 1÷42000 of the sample space. Together, 1÷2 x 1÷(80*365) x 1÷42000 = 0.00000041% With these three datapoints, you can identify roughly 1.3 US per…

Only if age, birthdate, and zip codes are uniformly distributed among the population.

Which they aren’t. At all.

Re: Why do shared hospital rooms not violate HIPAA?

#144

Earlier quoted context omitted.

A healthcare facility knowingly permitting recording on-premises may indeed be a HIPAA violation.

78% false. Please do not discourage patients from exercising our rights and accessing our own PHI , like this crack-smoking nurse did to me. https://www.aetnainternational.com/en/about-us/explore/healt... https://www.alight.com/blog/can-patients-record-doctors-offi... https://www.verywellhealth.com/secretly-recording-your-docto... You've got to understand: clinic visits are very stressful, time-limited, and high-pres…

Your argument is also misleading.

HIPAA is a baseline rule set. Providers are free to set more restrictive rules than what HIPAA defines. They often do so they have buffer room better their rules and HIPAA violations.

Further, HIPAA is not the only rule governing you and your providers interactions. A private institution is free to set its own rules (with its legal obligations) and can have you leave if you don’t follow them.

Re: Why do shared hospital rooms not violate HIPAA?

#145

Earlier quoted context omitted.

I'd actually come to the opposite conclusion here. Unless you think this violation of privacy is OK?

I think this violation of privacy strikes the correct balance. Hospitals (especially ERs) are already quite full on a regular basis; making every room private would do substantial physical harm to many patients who'd wait much longer for treatment or have to forgo it entirely. ( Perfect privacy would also require soundproofed rooms for phone calls, mantrap doors for patient rooms so you can't get an inadvertent peek…

Just make all rooms private and build more rooms or hospitals. It's not rocket science.

Relative to the already absurdly high health care costs, the construction costs should be pretty small.

Re: Why do shared hospital rooms not violate HIPAA?

#146
post #137

Earlier quoted context omitted.

Knowing gender cuts down your sample space by half. Assuming you are looking at someone between the ages of 1-80, knowing birthdate further filters in just 1÷(80 * 365) of the sample space. Since they're 42000 ZIP codes in the US, knowing the ZIP code lets you filter in just 1÷42000 of the sample space. Together, 1÷2 x 1÷(80*365) x 1÷42000 = 0.00000041% With these three datapoints, you can identify roughly 1.3 US per…

Only if age, birthdate, and zip codes are uniformly distributed among the population. Which they aren’t. At all.

Here's what I found for birthdates - https://www.panix.com/~murphy/bday.html. The variation between dates doesn't seem all that bad. So, for all practical purposes, we can assume that births across dates is uniform.

Given this, the only real issue is ZIP codes. If we assume that we know nothing about how populations are distributed across ZIP codes, given just the gender and date of birth, we can narrow down the cohort to just 5650 US persons (330M x 1/2 x 1/(80x365)).

According to this link - https://www.johndcook.com/blog/2019/08/21/zip-code-populatio... - 80% of the US population lives in 27% of her ZIP codes.

Assuming your target individual is in the 80%, given the gender, birthdate, and ZIP code, you can narrow down to the following - 0.8x330M x 1/2 x 1/(80x365) x 1/(0.27x42000) = 0.4 US persons per ZIP code.

Basically, these three data points can almost certainly uniquely identify specific individuals - the only remaining thing is to connect a name/phone number to each individual.

Re: Why do shared hospital rooms not violate HIPAA?

#147
post #146

Earlier quoted context omitted.

Only if age, birthdate, and zip codes are uniformly distributed among the population. Which they aren’t. At all.

Here's what I found for birthdates - https://www.panix.com/~murphy/bday.html . The variation between dates doesn't seem all that bad. So, for all practical purposes, we can assume that births across dates is uniform. Given this, the only real issue is ZIP codes. If we assume that we know nothing about how populations are distributed across ZIP codes, given just the gender and date of birth, we can narrow down the coh…

Obviously the data is not really anonymized.

Im just nitpicking your weirdly precise results of your fermi math. It would be easier to grab this from the census data, right? 40 year old males with a given birthdate, no zip code, narrows to ~7,154.

Re: Why do shared hospital rooms not violate HIPAA?

#148

Earlier quoted context omitted.

I think this violation of privacy strikes the correct balance. Hospitals (especially ERs) are already quite full on a regular basis; making every room private would do substantial physical harm to many patients who'd wait much longer for treatment or have to forgo it entirely. ( Perfect privacy would also require soundproofed rooms for phone calls, mantrap doors for patient rooms so you can't get an inadvertent peek…

Just make all rooms private and build more rooms or hospitals. It's not rocket science. Relative to the already absurdly high health care costs, the construction costs should be pretty small.

> build more rooms or hospitals. It's not rocket science

The hospitals near me have been expanding as fast as they can. Absolutely constant large-scale construction. It's not rocket science, but it's not a Thanos finger snap either.

Re: Why do shared hospital rooms not violate HIPAA?

#149
post #111

Earlier quoted context omitted.

Latanya Sweeney demonstrated how hard it is to anonymize health data back in the late 1990s as part of her dissertation work: https://arstechnica.com/tech-policy/2009/09/your-secrets-liv... "At the time GIC released the data, William Weld, then Governor of Massachusetts, assured the public that GIC had protected patient privacy by deleting identifiers. In response, then-graduate student Sweeney started hunting for th…

Yep. I've used that example in presentations. If you really want to de-anonymize a medical record, it's pretty easy to do so on the basis of other data which is arguably public for good reasons (and/or as a matter of law).

Even if you remove all location and date information from a medical record, you can likely work out quite a bit of information (certain procedures occur at certain times, etc).

And at that point you’re starting to destroy the value of the data.

Re: Why do shared hospital rooms not violate HIPAA?

#150

Earlier quoted context omitted.

Clinics that deal with the most sensitive medical needs tend to be more careful. HIV testing, reproductive health, psychiatry, hospice.

[flagged]

Posting like this will get you banned again. No more of it please, regardless of how right you are or feel you are.

https://news.ycombinator.com/newsguidelines.html

Post reply on HN