Live data from Hacker News

Why do shared hospital rooms not violate HIPAA?

law.stackexchange.com

41–50 of 150 posts

Re: Why do shared hospital rooms not violate HIPAA?

#41
post #32
post #17

My friend spent the night in the hospital recently, for observation. She didn't sleep a wink. With all the beeping and alarms and periodic checks and procedures. Mostly involving her roommate. The next morning she was mentally and physically wrecked. the first thing she told the nurse was, "I want to go home so I can get some sleep. The nurse laughs and replies, "I hear that all the time. Nobody ever sleeps here". No…

An overnight stay is for observation not comfort. The hospital wants to gather as many metrics as possible to keep you alive, respond ASAP to issues and dis-chargable to free up room for other sick patients. not give you a hotel bed.

Go to the hospital healthy, come out sick.

I don't have a medical degree or anything but that's crazy.

(Also, the nurse said nobody sleeps here. Not just the people under observation.)

Re: Why do shared hospital rooms not violate HIPAA?

#42
post #35
post #12

I have a domain name that's similar to a medical facility. Sensitive medical data gets emailed to the wrong recipient all the time and it's usually operator error.

My name and domain is similar to a huge transportation company so I frequently get quotes for big jobs, plus times and dates for large truck shipments.

This might be advantageous if you are also receiving inventory for these shipments if you're the type to make that information available to interested parties

Re: Why do shared hospital rooms not violate HIPAA?

#43

Because health privacy is not ALWAYS HIPAA. In fact, it's almost never HIPAA... except for the fact that some Karen's learned the term HIPAA and now they think it's always HIPAA [1]. Unless it's digital health record-related, then it's probably HIPAA. If you're really curious, you can read HIPAA [2] and HITECH [3]. Combined, they are about 600 pages of dense dense legalese. [1] https://www.hipaajournal.com/is-it-a-hi…

From https://www.hipaajournal.com/what-does-hipaa-cover/ > The HIPAA Privacy Rule applies to all forms of health information, including paper records, films, and electronic health information – even spoken information. HIPAA is not as limited as you state.

but it only applies to covered entities and business associates.

Re: Why do shared hospital rooms not violate HIPAA?

#44

Because health privacy is not ALWAYS HIPAA. In fact, it's almost never HIPAA... except for the fact that some Karen's learned the term HIPAA and now they think it's always HIPAA [1]. Unless it's digital health record-related, then it's probably HIPAA. If you're really curious, you can read HIPAA [2] and HITECH [3]. Combined, they are about 600 pages of dense dense legalese. [1] https://www.hipaajournal.com/is-it-a-hi…

> some Karen's

As an aside: I wish this meme would die.

> For the same reason, the Karen meme divides white women themselves. On one side are those who register its sexist uses, who feel the familiar tang of misogyny. Women are too loud, too demanding, too entitled. Others push aside those echoes, reasoning that if Black women want a word to describe their experience of racism, they should be allowed to have it. Hanging over white women’s decision on which way to jump is a classic finger trap, familiar to anyone who has confronted a sexist joke, only to be told that they don’t have a sense of humor. What is more Karen than complaining about being called “Karen”? There is a strong incentive to be cool about other women being Karened, lest you be Karened yourself.

https://www.theatlantic.com/international/archive/2020/08/ka...

Re: Why do shared hospital rooms not violate HIPAA?

#45

The P in HIPAA stands for Portability, not Privacy. The primary purpose of HIPAA is not to prevent the sharing of confidential patient data, it is to ENABLE the sharing of confidential patient data with anyone who has the right to see it. The issue is the number of entities who claim that they have right to see the data, and the lack of a mechanism for the individual to prevent their information from being shared. Sh…

I work in healthcare; these views are my own, and IANAL.

> The P in HIPAA stands for Portability, not Privacy.

… sure, that P stands for that. But one of the key sections is literally called the Privacy Rule: "The HIPAA Privacy Rule establishes national standards to protect individuals' medical records and other individually identifiable health information"

> Should Facebook have a right to access your health data? Your opinion does not matter, they wanted it, and they got it.

No. Wantonly sharing PHI with Facebook would almost certainly be a violation of HIPAA … and literally, it's already happened, this year even[1]: "The office warned that entities covered by HIPAA aren’t allowed to wantonly disclose HIPAA-protected data to vendors or use tracking technology" ("Vendors" here included Facebook and the like.) ¹

Now, HIPAA only applies to covered entities. In the context of the OP however, a hospital is a covered entity. Whether eavesdropping is permissible is a good question.

[1]: https://www.politico.com/news/2023/04/17/health-industry-dat...

¹I think regulatory agencies across the board have been giving pittances for fines, and these are no exception. There's a real question as to whether enforcement is actually meaningful, but that's separate question from whether there is a right.

Re: Why do shared hospital rooms not violate HIPAA?

#46
post #7

Why do the paper thin walls between exam rooms at my doctor's office that allow me to hear entire conversations while I am waiting (and waiting) not violate HIPAA?

Clinics that deal with the most sensitive medical needs tend to be more careful. HIV testing, reproductive health, psychiatry, hospice.

Re: Why do shared hospital rooms not violate HIPAA?

#47
post #5

It is legal because you are agreeing to it. Otherwise get up and leave.

You can't agree to OHSA violations, or to a sub-minimum wage. A hospital conditioning treatment on a HIPAA waiver having been signed will quickly find itself the subject of regulatory scrutiny. I went to war with a doctors' office that claimed their non-compete clause meant I couldn't transfer my medical records to a doctor who'd left the practice I wanted to follow.

A paper that says "I agree to a sub minimum wage" is illegal.

One that says "I agree to share my medical info with XYZ" is not. Every hospital already makes you sign this when you are admitted, otherwise they wouldn't be able to function.

Re: Why do shared hospital rooms not violate HIPAA?

#48
post #41
post #32

Earlier quoted context omitted.

An overnight stay is for observation not comfort. The hospital wants to gather as many metrics as possible to keep you alive, respond ASAP to issues and dis-chargable to free up room for other sick patients. not give you a hotel bed.

Go to the hospital healthy, come out sick. I don't have a medical degree or anything but that's crazy. (Also, the nurse said nobody sleeps here. Not just the people under observation.)

> Go to the hospital healthy, come out sick.

This isn't whats happening. Being sleep deprived for a day is annoying, but hardly a health issue. I bet most people would rather have doctors respond to you suddenly dropping blood O2 levels to under 90% than not.

> (Also, the nurse said nobody sleeps here. Not just the people under observation.)

Yes, nobody sleeps because nurses and doctors are all working >14 hour shifts with on-call rotations trying to keep people ALIVE. I have many medical professionals in my family, all of them are rest deprived, trying to keep track of the myriad of patients all demanding personal constant attention.

Re: Why do shared hospital rooms not violate HIPAA?

#49
post #47

Earlier quoted context omitted.

You can't agree to OHSA violations, or to a sub-minimum wage. A hospital conditioning treatment on a HIPAA waiver having been signed will quickly find itself the subject of regulatory scrutiny. I went to war with a doctors' office that claimed their non-compete clause meant I couldn't transfer my medical records to a doctor who'd left the practice I wanted to follow.

A paper that says "I agree to a sub minimum wage" is illegal. One that says "I agree to share my medical info with XYZ" is not. Every hospital already makes you sign this when you are admitted, otherwise they wouldn't be able to function.

Such a voluntary waiver is legal, yes.

Refusing to treat you if you want to keep your rights, less so.

The thing they have you sign is an agreement that you received a notice of their privacy practices (laying out your HIPAA rights). It isn’t a waiver.

Hospitals don’t need a waiver to operate. HIPAA already permits them to share internally, with billers, etc.

Post reply on HN