Breaches of Unsecured Protected Health Information
ocrportal.hhs.gov
ocrportal.hhs.gov
At best mostly subjective observations, at worst full of outright errors, they're largely useless from a health care perspective let alone for research purposes.
With regards to the usefulness of medical records, I don't know enough on the topic to address that point.
That mostly increases the size of the bucket without much in terms of guarantees of the maintainers of that bucket getting it right.
FDA disbarred investigators
https://www.fda.gov/ICECI/EnforcementActions/FDADebarmentLis...
FDA compliance proceedings
https://www.accessdata.fda.gov/scripts/SDA/sdNavigation.cfm?...
Sounds like you consented...
I just started shopping for term life insurance recently and have an application that was emailed to me by a local agent. It looks very much like this one (http://www.adkissoninsurance.com/forms/grangelifeapp.pdf), EXCEPT someone has removed the Notice of Information Practices at the top
Page 5 contains the authorization details.
Here's what page 5 looks like on my application - https://imgur.com/a/zk9ZQ (also Grange)
This is from a top tier life insurance provider, who knows what kind of shenanigans are going on out in the wild.
Edit: Just sent an email to my agent asking for a copy of that Notice of Information Practices doc, we'll see what happens lol.
According to the Texas Medical Association[0],
> there are only two reasons a lost device may not have to be reported as a breach under the HIPAA Breach Notification Rule: (1) no PHI was on the device, or (2) the PHI is unusable - encrypted with FIPS 140-2 encryption
It’s more worrying to me that a doctor might not report a breach because the data is encrypted, but had the keys stolen along with the computer.
Well, I'm glad this random webpage is broadcasted into the internet and therefore everyone is properly informed about these breaches.
This is the same as Google providing that page somewhere deep in the account settings where you can view what data they have on you. It's beneficial for them to provide this, because 99.99% of users will never find it anyways. And those that are concerned can be calmed down by it.
The number of people interested in your health is tiny. The number of people interested in your money, and motivated to try to take it from you, is much higher.
https://www.reuters.com/article/us-cybersecurity-hospitals/y...
In other words, identity information.
Imagine breach notifications for a company like Facebook. FCC could disbar you from transmitting data over mobile networks.
HIPAA
Note: I have had hipaa training for prior jobs and no penalties were ever discussed
There are, in fact, actual penalties.
A summary: https://www.ama-assn.org/practice-management/hipaa-violation...
And there have been civil and criminal enforcement actions: https://www.hhs.gov/hipaa/for-professionals/compliance-enfor...
> Note: I have had hipaa training for prior jobs and no penalties were ever discussed
I've had HIPAA training for several jobs stretching back to 2001, and civil and criminal penalties, and the fact that the latter especially were available against individual employees as well as covered entities, were stressed every time.
Here’s a third-party explanation: https://www.hipaajournal.com/what-are-the-penalties-for-hipa...