What? Isn't this exactly the sort of thing HIPAA is supposed to ban? What happened to doctor-patient confidentiality? Why do employers even have that information?
What? Isn't this exactly the sort of thing HIPAA is supposed to ban? What happened to doctor-patient confidentiality? Why do employers even have that information?
> The financial trajectory of MarketScan was perhaps unimaginable in 1981, when a former insurance executive named Ernie Ludy founded the company. His idea was to simply collect patients’ data and parcel it out to big companies that were seeking to control costs by getting a more granular view of their employees’ health care use.
> The Health Insurance Portability and Accountability Act of 1996
Hopefully, some security researchers will get their hands on it, de-anonymize the data set, and then regulators will burn the industry to the ground.
Although I'd point out that very little is needed to un-deidentify medical records if you want to. For example, see some of the work Latanya Sweeney has done.
http://latanyasweeney.org/ https://arstechnica.com/tech-policy/2009/09/your-secrets-liv...
Who does this benefit, though?
“Hot” conditions with high conversions are tracked in near real-time. I learned this when we received via FedEx a box of Enfamil on what should have been the due date of of daughter. Unfortunately, we miscarried.
Sorry to hear about your daughter. That is really tough.
There's a weird thing going on where everyone pronounces it as if it were spelled "hippa", and then everyone believes it must be spelled that way because of how it's pronounced.
It doesn't seem to have occurred to anyone to pronounce it in a way that's compatible with the spelling.
English has barely any words with "aa", so you can't differentiate the vowel in a normal way.
There's no standard way to exaggerate a vowel that would work either. The closest I can think of would be an extra-long pronunciation or sticking a glottal stop in to make it sound like two vowels, but those would both be confusing and sound too unlike a real word.
And no matter what you do it's going to sound like hippo.
Personally, I read it in my head as /hipɑːː/, with the artificially lengthened vowel that you note. But if you wanted to wear that down into a form that was easier to say, /hipɑ/ is still very distinct from /hɪpə/, and /haɪpɑ/ would be too.
I don't. But people aren't going to say out the letters for something that could be easily pronounced.
1. HIPAA can't be easily pronounced; it is obviously incompatible with the normal rules of English spelling.
2. People pronounce CIA letter by letter.
Most people don't seem to agree with you.
> People pronounce CIA letter by letter.
It's only three letters, it's hard to know what sound the C would make, and pronouncing an acronym with only one consonant is a bit iffy for clarity. Those are small factors but they add up.
HIPAA has the double A acting against pronouncing it, but everything else pushes toward pronouncing and not worrying about that part.
URL?
I can't keep this up, but I'm being limited more by my acronym vocabulary than by any tendency for people to avoid pronouncing them letter by letter.
>> HIPAA can't be easily pronounced
> Most people don't seem to agree with you.
This is how we started the thread, by observing that people have enormous problems spelling HIPAA because they believe the spelling should correspond to the pronunciation.
A precondition for this observation is that the spelling isn't being pronounced.
People who read HIPAA have no problem pronouncing it.
People who hear hɪpɑː sometimes have trouble spelling it, coming up with “HIPPA” instead of “HIPAA” (this often isn’t because it is the most natural read of the phonetics, but because they back-figure the acronym from the best-known focus of the law as “Health Insurance Privacy Protection Act” rather than “Health Insurance Portability and Accountability Act”.)
This is the second time you've claimed that people say /hɪpɑː/. But they don't.
Thus, there is no adding up to be done.
And I very occasionally hear people pronounce it, so it seems like URL is somewhat borderline.
Compared to URL, HIPAA is pretty close on effort to pronounce, and double the effort to say the letters.
It can be easily pronounced, it is easily pronounced, and its not at all incompatible with the “rules” of English spelling.
I mean, not a lot, but enough:
https://scrabble.merriam.com/words/with/aa
The most common pronunciation of “aa”, especially when its not in initial position, seems to be IPA ɑː
Which is how pretty much everyone in the field pronounces it in “HIPAA”.
> Which is how pretty much everyone in the field pronounces it in “HIPAA”.
Something's gone wrong. People in the field pronounce it /ə/, as in the second syllable of "comma". This is a fairly common pronunciation of "aa", but only as in "Isaac". It doesn't match Aaron, aardvark, baa, aah, argh, waah, bazaar, salaam, or Quaalude.
Your list mostly consists of words that cannot reasonably be said to exist in English. But of the real ones:
START / PALM [ɑ]: ah [spelling variable; attested in the list as 'aah'], argh [spelling variable; attested in the list as 'aargh', 'aarrgh', and 'aarrghh'], bazaar, aardvark, aardwolf. Also salaam, which is a foreign word that is common enough to have a conventional spelling. (So is "niqab", which appears on the list as "niqaab"...)
TRAP [æ]: baa, waah.
FACE [eɪ]: Quaalude, which is a proper noun. Why is it in a list of Scrabble words? Isaac and Aaron aren't there.
So if any of them or their business associates got the information and sold it that would be a violation. But if say Target figured it out because she was buying a lot more orange juice and lotion (true story, Target‘s ability to figure out who’s pregnant is legendary) and sold that into it would not be covered under HIPAA
But I can assure you that your pregnancy was not revealed to a marketing organization by your doctor or insurance company. HIPAA prohibits that kind of information transfer, and the consequences of violating the law are severe enough that physicians and insurers are highly unlikely to risk it, for the little bit of dough they'd get by selling the fact of a pregnancy.
However, HIPAA only protects information about you gathered by your doctor or insurance company in the course of providing medical care. It does not protect you against data aggregators inferring your condition based on non-medical activities. In the case of pregnancy, it's not unlikely that your condition was inferred from credit card activity or online retail activity. (There is a well known case of a retailer - Target - building a model that inferred a pregnancy in a household based on retail activity; they started sending flyers/adverts to households they had identified as pregnant, and in the process revealed pregnancies of wives or daughters in the household to others who had not been in read in to the news; it did not end well for Target).
My wife’s pregnancy and expected due date were available on a list sold by zip code, which I know because I purchased it after it was identified by Enfamil. I also learned that my neighbor has type-2 diabetes and another has a child with ADHD, among other things.
In my wife’s case, she suffered from an ectopic pregnancy that resulted in a near death experience, and subsequent admission to the OB floor of the hospital. The admission and drugs prescribed are sold/reported in near real-time to various data aggregators, who in turn are able to link them to the ob/gyn who performed the emergency surgery. We think that the admission to the obstetric floor, duration of hospital stay and certain prescriptions trigged a false hit of “pregnant”.
This data is poorly anonymized and can be trivially reconstructed. Both an attorney I hired and an investigator from the state health department confirmed that. There was no retail behavioral tracking because the events happened before my wife was aware that she was pregnant.
Insurance company and medical data is used for all sorts of practices. The state of Georgia, for example, has a anti-opioid surveillance system that uses Medicaid, private insurance, and behavioral data to identify pregnant women at risk of delivering an opioid addicted child. (Which will cost state Medicaid $1M or more)
What did the lawyer say?
Edit: I see now that technically they say it’s anonymized. I’m assuming that’s the answer.
So basically HIPAA is privacy theater, the same as we have security theater at the airport now and financial accountability theater and the latest: data privacy theater via GDPR.
The redaction does not mean that data cannot under some circumstances be re-identified, of course. But it's not trivial.
This is a good example of the law and popular conception of a concept being badly out of date, to the advantage of industry and disadvantage of regular people. Therefore industry has a vested interest in keeping the public perception focused on "de-identified" with a narrow definition of PII.
We need to understand that “knowing someone’s identity” is not coextensive with “knowing their name”, and that in fact knowing someone has a rare medical condition may be more identifying[0] than knowing their name.
[0] Or k-deanonymising, for anyone who’s pedantic about identity being an absolute.
For the kind of data in this particular database (mostly insurance claims data), it's highly unlikely that you could learn much through re-identification of the data.
It was cast by the wayside long ago. First it was the "mental health" exemptions, then various law enforcement provisions, then third-party "office solutions", then transcriptionist services, then private medical databases...
You might as well assume that anything you tell your doctor is going to be recorded and (eventually) used against you.
And then, as was alluded to earlier, there's the problem of incorrect information in those databases... and your only recourse is to give them more-accurate information to sell.
All the dice are loaded against the patient. And as anyone online for long knows, data is forever.
It's not made entirely clear in the article, but most of this data is insurance claims data, not medical records per se. That's why employers have it. If your employer underwrites your medical claims directly - which most do nowadays - when you or your doctor submits an insurance claim, they are submitting it to your employer. It may go through a health insurance company - since most employers hire one to administer their plans - but that insurance company is collecting the information on behalf of the plan owned by your employer. The fact that it's insurance claims and not raw medical records is one of the challenges IBM had in making a business out of analyzing it. There is a lot less and less quality, medical data in insurance claims than IBM hoped.
De-identification is unreliable. If you have enough context, then the patients can be re-identified.
The companies that came seeking medical records (I was until recently Chief Technology Officer for a clinic/hospital system with 10M active patient records) were satisfied with de-identified data, because they were looking for insights to develop new, or re-purpose existing, therapies and technologies, or to create marketing strategies for their tech. They had no need or desire to know who a particular patient was, because they were looking for broader insights.
1. Only applies to covered entities.
2. Data can be given to another covered entity as long as certain rules are followed.
Very easy to have a web of people giving each other data because of this.
In net - hipaa doesn’t protect medical information generally - only the subset that’s usually visible to doctors. And even then, it stops working as soon as the info is outside a covered entity.