Live data from Hacker News

Why do shared hospital rooms not violate HIPAA?

law.stackexchange.com

91–100 of 150 posts

Re: Why do shared hospital rooms not violate HIPAA?

#91
post #17

My friend spent the night in the hospital recently, for observation. She didn't sleep a wink. With all the beeping and alarms and periodic checks and procedures. Mostly involving her roommate. The next morning she was mentally and physically wrecked. the first thing she told the nurse was, "I want to go home so I can get some sleep. The nurse laughs and replies, "I hear that all the time. Nobody ever sleeps here". No…

I was in the hospital for about two weeks at the beginning of 2022. It was awful. The nurse would come in for evening meds and checks around 10-11 PM. When I was lucky enough to have neighbors who weren't trying to die all night it was usually relatively quiet from midnight to 4 AM. Then things would start to pick up. Phlebotomists making rounds to draw blood before 5 AM. Morning meds between 5-6 AM. Nursing shift change at 7 AM. Doctors doing rounds mid morning. Breakfast mixed in there somewhere. Of course I couldn't actually _do_ anything all day except try to read or play around on my phone, so I spent a lot of time dozing.

I wasn't so lucky for the first week of my stay. I was on IV meds that pushed my BP up significantly, to the point where every time the automatic hourly BP reading was taken it would set off alarms. During the day the charge nurse would usually silence the alarm (from the nursing station) immediately but at night they were understaffed (this was during a covid wave) and the nursing station often wasn't manned. So sometimes the alarm would sound for 20+ minutes. Every hour... all night... Eventually I found a sympathetic nurse who actually knew how to adjust the settings on the machine and disabled the alarm entirely.

At least I didn't have to share a room. That would have been misery.

Re: Why do shared hospital rooms not violate HIPAA?

#92
post #90

Earlier quoted context omitted.

Which sucks because there is tremendous value in anonymized collections of health records, yet we can’t use these health records for research at all. I realize it was out of scope for the bill, but damned if it didn’t stymie medical research to a ridiculous degree.

Anonymization is hard. Unless you have very accomplished cryptographers defining and implementing anonymization, I do not trust it. That basically means not trusting anyone but large governments and FAANG companies. That said I do think agencies like NIST should define anonymization standards.

And medical issues are such that even fully anonymous you can probably identify who is whom.

Re: Why do shared hospital rooms not violate HIPAA?

#93
Similarly, it really irks me how little privacy there is at the chemist/pharmacist/drugstore (listing all synonyms for an international audience).

If I have any questions, they're at the counter with 20 other patrons hearing everything about my medication. Then I take my medication to a separate counter for payment, which is staffed, usually, by a teenager working part-time. Great, now they know what medication I'm on.

Imagine if I were picking up medication for a teenage son or daughter, and the teenager at the counter went to school with them?

Re: Why do shared hospital rooms not violate HIPAA?

#94

How does HIPAA compare to FERPA? My understanding is that FERPA is similar to HIPAA, except for college scores and enrollment information instead of medical records. But there’s a rule in FERPA where you explicitly can’t leave a stack of exams and let students pick them, because it exposes students to others’ scores. Another rule is that you can’t associate a students exam with their student ID even if it’s a sequenc…

> you explicitly can’t leave a stack of exams and let students pick them, because it exposes students to others’ scores. Another rule is that you can’t associate a students exam with their student ID

As a comparison, at my Uni in the 1970s individual grades were posted along with corresponding social security numbers.

Re: Why do shared hospital rooms not violate HIPAA?

#95

Similarly, it really irks me how little privacy there is at the chemist/pharmacist/drugstore (listing all synonyms for an international audience). If I have any questions, they're at the counter with 20 other patrons hearing everything about my medication. Then I take my medication to a separate counter for payment, which is staffed, usually, by a teenager working part-time. Great, now they know what medication I'm o…

At my local Walgreens they're pretty strict about this- they make people stand about 10ft back from the window while waiting. I have seen them ask people to move back if they start encroaching.

Re: Why do shared hospital rooms not violate HIPAA?

#96
post #17

My friend spent the night in the hospital recently, for observation. She didn't sleep a wink. With all the beeping and alarms and periodic checks and procedures. Mostly involving her roommate. The next morning she was mentally and physically wrecked. the first thing she told the nurse was, "I want to go home so I can get some sleep. The nurse laughs and replies, "I hear that all the time. Nobody ever sleeps here". No…

Likewise, l hospitals serve food portioned nutritionally for a healthy adult when people who are sick or healing from injury may very well need more calories and protein to fuel their bodies healing.

The last time I was in the hospital (2022) the portions weren't terrible, the main problem was that the food was so damned bland. The first few days it doesn't seem like it's that bad, but by the time you've been eating it a week you just lose your appetite because the food is so unappealing. Not to mention that if you have a test or procedure at the wrong time and miss placing your order (IIRC they stopped taking orders at like 4 PM) you're going to get whatever the cafeteria feels like sending you and it will have been sitting at the nurses station for hours. Yummy.

Re: Why do shared hospital rooms not violate HIPAA?

#97
Once, and never again, I declared my desire to a front-desk nurse that I wished to record my session in an Urgent Care facility.

She said no, that is prohibited, because it is a HIPAA violation. She was clearly smoking crack.

Now I simply record surreptitiously.

Re: Why do shared hospital rooms not violate HIPAA?

#98
post #83

Speaking of that, hospitals still use tons of POCSAG (pagers) and splatter medical everything over those. Course it's illegal to listen due to a bullshit 1987 law... but trivial to do so with a RTL-SDR. One idea my nefarious side had was to get the med records of individuals and get the address's house cost, and send scary calls/text/messages shaking relatives down with scare-calls. (Or, get the info and get in leagu…

I've had a career in hospital IT and operations. The challenge is finding a replacement that is as reliable and accessible as a pager. The replacement communications products out there have some nice features (managing on-call scheduling, interfacing with electronic health records, etc), but it only takes a handful of outages to get everyone to switch back to pagers "just in case."

Re: Why do shared hospital rooms not violate HIPAA?

#99
post #90

Earlier quoted context omitted.

Which sucks because there is tremendous value in anonymized collections of health records, yet we can’t use these health records for research at all. I realize it was out of scope for the bill, but damned if it didn’t stymie medical research to a ridiculous degree.

Anonymization is hard. Unless you have very accomplished cryptographers defining and implementing anonymization, I do not trust it. That basically means not trusting anyone but large governments and FAANG companies. That said I do think agencies like NIST should define anonymization standards.

> Anonymization is hard. Unless you have very accomplished cryptographers defining and implementing anonymization, I do not trust it. That basically means not trusting anyone but large governments and FAANG companies.

Huh that is pretty solid point, so anonymization is useless to those who are the most interested in privacy?

Re: Why do shared hospital rooms not violate HIPAA?

#100
post #47

Earlier quoted context omitted.

A paper that says "I agree to a sub minimum wage" is illegal. One that says "I agree to share my medical info with XYZ" is not. Every hospital already makes you sign this when you are admitted, otherwise they wouldn't be able to function.

Such a voluntary waiver is legal, yes. Refusing to treat you if you want to keep your rights, less so. The thing they have you sign is an agreement that you received a notice of their privacy practices (laying out your HIPAA rights). It isn’t a waiver. Hospitals don’t need a waiver to operate. HIPAA already permits them to share internally, with billers, etc.

In the context of hospitals waivers are not that voluntary, at least in the US and Canada, since doctors and nurses can't be forced to treat people if they really don't want to.

And there is a decent chance in many hospitals that they will at least drag their feet, since they would be exposed to much greater liability.

I know this situation specifically is not quite a waiver, but it will likely have some effect on hospital staff's attitudes.

Post reply on HN