State Farm uses payment signature for HIPAA disclosure authorization
twitter.com
twitter.com
I feel like the direction that the standard is going is that you are assumed to have signed something if you benefited from signing that document. So you can't slip through the cracks by not signing something, it's just assumed that you signed it now. This fake signature is just an acknowledgement that signatures are useless. "If we issued you insurance, you signed every form. Prove otherwise." And my feeling is they will probably prevail in court on that, because signatures died a long time ago.
Well, not really. If you e-sign a document, it's not like there's no traceable provenance to the signature to establish your identity. To what email were the documents delivered? What computer/device were they signed from? At what location were they signed?
Sure, all of those things can be "faked", but they really only matter if the signature is disputed. In this case, that's happened, and it will be quite easy to prove he didn't sign the documents.
>This fake signature is just an acknowledgement that signatures are useless
This is a bit of a reach. Signatures are not meant to be a secure identity measure. If the story is as explained in the Tweet, it's fraud, and that fraud can be proven thanks to what was or was not actually signed. The story doens't end with the insurance company pointing to the signature and saying, "Look, there it is".
You haven't 'e-signed' anything if you haven't used your ID for it. In some countries this is a requirement for almost all docs, including signing a mobile phone contract, or opening a bank account. You'll have the same if you get a fancy Estonian e-residence.
Was it? The tweet seems to be 8 months ago. This should have been resolved. Was there an update posted?
Where they fall apart is where there's disagreement as to whether one party actually agreed to certain things, but that's not actually particularly common. Most court cases about contracts do not hinge on "did you actually agree to this whole contract?", they're about edge cases, or wording of the contract, or a clear breach that hasn't been dealt with yet.
I wonder if the bank telling you to correct your signature was so that if you somehow claimed that you didn't want to withdraw that money after-all and that the bank did it without your permission, they could point out that you used your "serious business" signature, not your joke signature. Hopefully it wasn't really for authentication.
As for the bank... they really do allow and deny checks based on looking at the signature. My problem is that I can't consistently draw a signature. Different paper/pen/surface quality throws me off. And I don't really practice... I use a pen and paper like once a month.
I think she wanted it so she could start prepping my insurance submission. But it’s sad to me that trying to improve a burdensome administrative system makes it casual to have patients misrepresent. Similarly to being asked to sign a form saying I’ve read the medical privacy policy, but not being allowed to see the policy.
The assumption is that patients will sign anything, which kind of defeats the purpose of patients signing anything.
I always pause, make strong eye contact, and go "Oh, so you normally sign things without reading them first?"
That usually causes them to go quiet.
Buying my house was the same. They absolutely overload you with documents and not enough time to read everything. Luckily with e signing it makes it less stressful to read.
When I bought my house, we were taken into a room with the selling and buying agent, and they read the mortgage document aloud, and asked if we had any questions after each page that we had to sign.
They said that was the law in the area. It took about 3 hours, and every party went home with a copy with the 4th copy getting filed with the county.
The handful of other people at the signing were mildly annoyed that I was being so cautious but I didn't care. It's my money. I'm normally a polite and shy person but if I had a question and everyone else was making small talk, I would just start talking.
I was signing up for a phone and started reading the T&Cs. Two pages of super small text. The staff member was surprised and said "No one reads that, it's just standard stuff". After a few minutes he starts pressing me to sign it as their system will cancel a signup not completed within five minutes. I doubt that 5-min timeout was a deliberate attempt to coerce people to signing up without reading the terms, but it certainly shows just how little people care about that stuff if they don't account for reading time in their signup process.
In the US, at least in larger cities, one of the signatures is often to share your data on an ERM network with all doctors/hospitals in the network. I never sign this one and it's never been an issue.
Thirty minutes later they figured out how to print it (it took the whole office to work out how). Then I signed.
I don't think it's a relevant concept here, because even if the rest of the patients don't read the HIPAA documents, they also don't care whether you read them. The staff don't care either, even if they have to do a little extra work so you can.
Shouting loudly in the waiting room would be a good example of violating a social norm--people generally expect each other to speak normally/quietly in a medical office.
The office also ignores most HIPAA regulations, leaving workstations logged in in private rooms, no screen locks, and sharing a single account amongst all staff, no 2FA.
Health privacy regulation in the USA is a joke because it's mostly unenforced. Most people just sign away 100% of their rights, and if you don't, the office will simply refuse to serve you as the forms are all integrated and non-negotiable.
I usually sign a big ‘X’, or draw a smiley face.
If being made to sign a contract that you can't read doesn't go against the premise of a contract than what does?
And extra $20 bucks and I never have to think about this again? Yes, please. An extra 40? Okay. I’d have to think hard about $100 though.
When I applied for a policy, my agent provided me with an electronic signature pad at payment time. I understood that I was providing my consent to apply for coverage, and to pay for that policy. I do contract review as a part of my job, and read legal language carefully before signing.
Just before I left the building, they provided me with a folder full of informational material--a bunch of ads for state farm services and disability coverage in general, some policy overviews, etc. I set it on the counter when I got home, and planned to read it later--work was incredibly busy that week.
It turned out that State Farm had applied my payment signature to additional forms without my knowledge: a HIPAA authorization form and consent for State Farm to draw my blood and test it for HIV. I was provided neither verbal nor written information prior to signing that I was agreeing to either of these terms. I was not given a chance to review these agreements prior to signing. I didn't ask to see them, because I didn't know they were even a thing.
State Farm started pulling my health records from my old doctors. One of them thought it looked sketchy, and called me to confirm. My reaction was something like "What the fuck". They emailed me a copy of the forms, and that was the first time I learned I'd "agreed" to disclose my health records. Sure enough, they were in the folder: buried behind the ads and policy information. If I'd flipped through the folder in full before walking out the door, I could have run back in and insisted they cancel the authorization.
I immediately called State Farm, informed them they did not have my consent, and demanded they destroy any records they'd obtained. They said they'd do that. I've been waiting for them to confirm they've destroyed those records since, uh... May, I guess. The folder's still on top of my desk; I've been meaning to follow up with a HIPAA complaint. Started getting the state regulatory bodies involved, but haven't finished that process.
I had a detailed conversation with my agent at State Farm where we talked about the importance of informed consent and presenting people with paperwork prior to signing. He actually told me that not only was this standard procedure, but that he didn't actually know how to get a copy of the forms to show to customers so they could review before signing: the workflow State Farm designed didn't actually produce forms until the signature was already in place.
I don't fault my agent specifically for this; I fault State Farm's training and workflow. My understanding from talking with state regulators is that I'd have to initiate a complaint specifically against my agent, which is less than ideal. I like him and I don't want to fuck up his business, and he didn't understand that contracts require a meeting of the minds. This is, IMO, a systemic problem requiring better training and software design, and those are both State Farm corporate issues.
As a public service, they should file a grievance against this insurance agent, and include State Farm as well. Because, if this is true, is forgery along with various HIPAA violations.
I get what you're saying, but it's irrelevant, and draws attention away from the crime being committed.
However, my experience with those "payments" is closer to "I have read the contract, agree to terms, etc." I am given the oppritunity to see the contract to review before I sign it, and walk out with it signed.
Also, my point is common sense tells me that state farm would want to see my medical records to make sure I am not lying about previous disabilities (we are talking about disability insurance, not car or renters insurance), and usually you sign a contract for insurance.
From a flow standpoint, I can see why state farm would only do one signature if it is all digital versus making the person sign five times, when all it says is "I have reviewed form X and agree." But if someone doesn't actually review all of the documents, then something like this happens.
There aren't two sides to every story, and this appears to be a case where there is only one side to the story.
Do you think that anything you've said justifies State Farm forging signatures to fake consent to violate clients' privacy? If not, why are you polluting the conversation with irrelevant information?
Being blunt, I think the poster has no idea how insurance works, and didn't bother to read anything while signing up. Now they are upset because they actually read it.
Or being less charitable, they did understand the process, and wanted to create fake outrage about it.
But the story does not add up to me at all taken at face value.
I don't see much reason to disbelieve what the poster said, given this is just a logical next step from sneaky behavior I've already seen lots of companies engage in.
I suggest you try that sometime. I find life to be much better when I just don't go accusing people of bad intentions like you just did to me.
Is that what you think you were doing when you said,
> Being blunt, I think the poster has no idea how insurance works, and didn't bother to read anything while signing up. Now they are upset because they actually read it.
> Or being less charitable, they did understand the process, and wanted to create fake outrage about it.
> But the story does not add up to me at all taken at face value.
Let's unpack this gem:
> I suggest you try that sometime. I find life to be much better when I just don't go accusing people of bad intentions like you just did to me.
You realize I was just turning what you said back on you? My point is: it doesn't feel good does it? So maybe don't do that?
You're literally objecting to something you did.
They would be allowed to ask questions about your medical history, but medical records themselves are an absolute no go.
Omitting said conditions would be grounds for non-payment of benefits if what made you unable to work is in any way related to a condition they asked you about and you didn't reveal.
So I can refuse to share that information and then every long term insurance company will refuse to issue coverage.
It’s not allowed for insurance companies to pull information without consent.
Of course, just because they have attached your signature to an unseen document will likely still require a legal case to affirm that it was illegal or unethical (probably little to no case law in this area).
I say that because then a person could have a preexisting condition, sign up for insurance, then go on long term disability due to the preexisting condition.
I'm saying if I'm the insurance company, why would I offer disability insurance if I can't verify the existence or absence of a preexisting? condition
Furthermore, the insurance the person is asking for is disability insurance. Common sense dictates that they will ask for medical records, and therefore need a HIPAA disclosure document.
If what the poster alleges it true, I agree wholeheartly that it should have been more clear in signing up for it, but it seems odd that the poster didn't think that state farm would ask for medical release forms for disability insurance.
TL;DR, I think there's more to the story than what is alleged here.
Honestly, though, so many ads for insurance say you don't need a doctor visit, or health checkup, or whatever. I could easily see customers getting confused thinking they wouldn't need to give over health documents because the ads are deliberately misleading.
Just because a business's practice is obvious to itself and those in the know, doesn't mean customers can get fleeced because "they should have known better". Caveat Emptor is kind of bullshit with such high information asymmetry.
Being blunt, I think the poster has no idea how insurance works, and didn't bother to read anything while signing up. Now they are upset because they actually read it.
Or being less charitable, they did understand the process, and wanted to create fake outrage about it. You don't have to "be in the know" to get how insurance works. Nor to understand that an insurance company will want to do it's fact checking on someone as a condition to insure them.
If you are customer you shouldn't want it.
Every party can have different interest and should fight for their own interest.
Literally the only thing that is stopping insurance companies from doing that is a contract, so if an insurance company is forging consent for a contract, that should be somewhat worrying.
The insurance company is well within their right to not provide coverage without that consent. They are not within their right to forge that consent, which is the issue here.
I want a million dollars. Wanting a million dollars is perfectly reasonable, lots of people want a million dollars. It's not reasonable to walk into a bank and cash a check with Bill Gates' forged signature on it.
Which is exactly what State Farm did. That's not shady, it's fraud, and it's very illegal.
The only "shady" thing might be not sending the authorization form he signed with their HIPPA request to show the source of the signature, but revealing he's seeking a long term disability claim could also be a HIPPA violation itself...
Regardless, the form says he authorized state farm to do exactly what they did: request his medical records without further approval from him (otherwise he might have needed to fill out each additional requests manually, which perhaps was an option if he declined this, we don't know)
> the form says he authorized ...
You seem to be repeatedly missing the point: he claims to have never seen nor signed this form. The "signature" is decidedly pixellized. The claim is that the insurance company put his name on this form without showing it to him, which both defeats the point of the form and is a crime (forgery) in the US.
At the end of the day it would require that the US government issue an ID to every citizen, green card holder, visa applicant, long term visa holder, etc., illegals be damned...
Even if that somehow happened, we now have the single largest hacking target in the world... are you comfortable with that? I’m sure not.
No big hacking target because they keys can be locked up or reverted pretty easily and the HSM are on military bases or whatever.
Hardware keys being on military bases doesn’t really fix that, the weak link is still a crappy government server.
You also skipped over all the hurdles of recognizing a “person” that we will issue to anyway. Sure, we could ignore that... but then Montana doesn’t recognize signatures from Oregon.
Everything you said against using private keys, apply to physical signatures.
Sure hacks will surely happens, but they already do happens with signature. At least now you'll get much more traceability and be able to invalidate what needs to be.
> You also skipped over all the hurdles of recognizing a “person” that we will issue to anyway. Sure, we could ignore that... but then Montana doesn’t recognize signatures from Oregon.
Recognizing what? You are the only one here talking about this being a proof of citizenship. Does your physical signature prove that you are a US citizen? Does it need to? I certainly hope not.
For each subsequent argument, please just ask yourself whether this issue apply to physical signature too in a way first.
I think those signature pads are beyond creepy, especially with the way that they're being run by all these companies, where the order in which they give you the documents for examination and the order in which you actually sign them are basically reversed. I've dealt with a few of those pads myself (I think it was at a local municipality and a bank), prompting me to:
https://law.stackexchange.com/questions/2148/if-you-sign-a-s...
Unfortunately, we seem to have scaled way outside of the capacity for the typical act of contract signing to be anything but fraught with danger. At this point, If I don't have someone to talk with authorized to make and act on contractual amendments in the room, I'm reluctant to sign anything. Hell, even if they are there, I have doubts any amendments would actually be honored given the difficulty and scale of assumptions built into most forms of business automation systems.
There has to be a way to get things back on track, but I'm clueless on where to start. Legislation? Public Awareness? Education? What?
Doing some more searching it seems to be an insurance company in the US.
To head off the objections: no, it would never be perfect. Yes, there is some risk. But it could be way better for 99% of the population that doesn't read anything they sign.
There is a tremendous power imbalance between private people and large corporations with civil lawyers on staff.
If they did then there is no problem here.
It seems that people are getting hung up on the wrong issue. Filling in and signing endless pieces of paper at the doctor's office is the most annoying experience. I wish my signature was applied directly.
Of course, I would like to be informed of what I agree to in simple brief terms. Putting massive documents in front of me that will sign automatically anyway makes no difference.
There is actually a major problem. Signing is not (anymore, at least, hopefully ...) (JUST) an authentication mechanism. It's a legal / contractual device that embodies the notion of consenting to something at some point.
Importantly, when you sign anything, there's not just the text of the contract or agreement. It also features the date (and usually place) of the signing. How does that square with the insurance company using someone else's signature on their behalf? Ignoring all else, the mere presence of the date on the document presented on that tweet implies that it is a claim that soandso signed the document on 05-16-2019.
If there's intent to be discussed here, it's State Farm's intent to enforce a one-sided document as though it was a legally binding contract. If they pull that off, unfortunately the law starts caring an awful lot about the actual content.
So fuck them and fuck anyone who defends them. This is exactly what is wrong with the US health system and we don't talk about it enough.
Isn't this basically power of attorney? He signed a form that explicitly stated he authorized SF can get his medical information (along other things). What's the purpose of such a form except to NOT go back to him to sign 12 documents from different companies to release info one by one?