Health industry responds to data privacy crackdown
politico.com
politico.com
Surprised this is the lede. Seems the biggest news is "problematic and widespread" "telehealth companies...violating their customers’ privacy"
That means that pretty much every possible service that is commonly used is off-limits. JIRA is an especially frustrating, but not entirely uncommon, example: to get them to sign a BAA, you need a massive contact.
That means no bug reports can go into JIRA with anything resembling the actual bug other than very vague info, so your internal customers (i.e. clinicians and customer service) have to jump through extra hoops just to file an issue.
I would love a world where HIPAA level compliance was standard for all PII across all industries. Until then, people will keep making mistakes.
Imagine this: you have two websites, a marketing site and a separate subdomain for your actual "app". There's a login button on the marketing site that redirects the user to the subdomain login page. Marketing adds GA to the marketing site to track conversations.
Congratulations! You've just violated HIPAA, because the rules apply to "past, current and future users" meaning that Google could theoretically identify people who were interested in either creating an account or wanted to log into your website. "But our company has a BAA with Google! We use all sorts of their products, right?" Wrong! Analytics is the one essential business software that Google refuses to cover with a BAA, which alone should tell you why you ought never browse the internet without uorigin and co.
I'm not making excuses for anyone. This is really important stuff to understand. It's also not always entirely obvious just exactly how leaky the entire SAAS world is to business people making what, in any other job, are obvious decisions.
You put your PHI in one place and you encrypt it. Add all of the obvious controls like authentication, access control and monitoring.
Each record gets a UUID. Everywhere else you reference that record by UUID.
- Patient ABC123 called and requested modifications to their record
- Meds delivered to ABC123
- Insurance confirmed for patient ABC123
That’s how you ensure MINIMUM NECESSARY.
And if you want to go crazy there’s literally a crosswalk document published by HHS OCR and NIST:
https://www.hhs.gov/hipaa/for-professionals/security/nist-se...
For most non healthcare first SAAS providers you either do a major rebuild or you end up with a healthcare specific cluster which is missing some of your tools (although it's worth pointing out that many more vendors particularly in the observability space are now HIPAA compliant.)
HIPAA controls are pretty simple. I think any mature company (not startups) will have them or is working towards them.
Mature vendors just don’t want to abide by breach notification guidelines which is why they use it as leverage to ask for more $$$.
The other issue is people forget that PHI can be used for treatment, payment and operations. You can totally put PHI in your systems literally any system but you NEED to adhere to the mandated controls specified in your BAA unless you’re a CE.
https://www.hhs.gov/hipaa/for-professionals/privacy/laws-reg...
Vendors don’t want to adhere to breach notification requirements or actually (gasp) do security which is why they charge you extra just to sign a BAA.
'CE' = Covered Entity
see https://www.hhs.gov/hipaa/for-professionals/privacy/laws-reg...
Anything more specific is ripe for abuse and should just not be allowed. Comparatively that specificity would be roughly equivalent to traditional TV, Cable and 'Print' media.
This is specificity as consumer privacy protection. I'm against most types of ads generally from a mental health stance.
Making spyware illegal (whether it's for ad targeting, or analytics, or "improving your experience") and enforcing CFAA-like penalties on company executives that knowingly violate the law would fix this problem overnight and for good.
just one examples that I can't take out of my mind as the consequences are everywhere around me: war on drugs (and the original alcohol prohibition)
I entered a business where I pushed back for years, but at one point, you need to do it.
Marketing, in the limit, is a zero-sum game (negative-sum, if you put a non-zero price on all the resources and labor wasted).