Why do shared hospital rooms not violate HIPAA?
law.stackexchange.com
law.stackexchange.com
The confidentiality rules in HIPAA are part of (IIRC, I think, etc?) the "Administrative Simplification" section, which was about standardizing electronic health care records and making them available to the government for combating Medicare fraud. The law wasn't a sweeping medical privacy bill; it added privacy rules to mitigate concerns people had about centralizing medical records as part of its major purpose.
That said I do think agencies like NIST should define anonymization standards.
Huh that is pretty solid point, so anonymization is useless to those who are the most interested in privacy?
turns out that in this regard, everyone is special
https://arstechnica.com/tech-policy/2009/09/your-secrets-liv...
"At the time GIC released the data, William Weld, then Governor of Massachusetts, assured the public that GIC had protected patient privacy by deleting identifiers. In response, then-graduate student Sweeney started hunting for the Governor’s hospital records in the GIC data. She knew that Governor Weld resided in Cambridge, Massachusetts, a city of 54,000 residents and seven ZIP codes. For twenty dollars, she purchased the complete voter rolls from the city of Cambridge, a database containing, among other things, the name, address, ZIP code, birth date, and sex of every voter. By combining this data with the GIC records, Sweeney found Governor Weld with ease. Only six people in Cambridge shared his birth date, only three of them men, and of them, only he lived in his ZIP code. In a theatrical flourish, Dr. Sweeney sent the Governor’s health records (which included diagnoses and prescriptions) to his office."
This same article also mentions one of her more famous findings too: "in 2000, she showed that 87 percent of all Americans could be uniquely identified using only three bits of information: ZIP code, birthdate, and sex."
And at that point you’re starting to destroy the value of the data.
Assuming you are looking at someone between the ages of 1-80, knowing birthdate further filters in just 1÷(80 * 365) of the sample space.
Since they're 42000 ZIP codes in the US, knowing the ZIP code lets you filter in just 1÷42000 of the sample space. Together, 1÷2 x 1÷(80*365) x 1÷42000 = 0.00000041%
With these three datapoints, you can identify roughly 1.3 US persons (assuming a US population of 330M). Not too bad, imho.
Which they aren’t. At all.
Given this, the only real issue is ZIP codes. If we assume that we know nothing about how populations are distributed across ZIP codes, given just the gender and date of birth, we can narrow down the cohort to just 5650 US persons (330M x 1/2 x 1/(80x365)).
According to this link - https://www.johndcook.com/blog/2019/08/21/zip-code-populatio... - 80% of the US population lives in 27% of her ZIP codes.
Assuming your target individual is in the 80%, given the gender, birthdate, and ZIP code, you can narrow down to the following - 0.8x330M x 1/2 x 1/(80x365) x 1/(0.27x42000) = 0.4 US persons per ZIP code.
Basically, these three data points can almost certainly uniquely identify specific individuals - the only remaining thing is to connect a name/phone number to each individual.
Im just nitpicking your weirdly precise results of your fermi math. It would be easier to grab this from the census data, right? 40 year old males with a given birthdate, no zip code, narrows to ~7,154.
that basically means not trusting… anyone?
Some of it was simply migration of encounter data +/- a date range, with removal of the obvious stuff, too.
Other was cool like NLP on doc notes to ensure stuff like “pt said the school shooting they got this wound from was..” (think: cohort sizes for major incidents are often small and therefore easy to re-id.)
You don't get a blank check, but there are plenty of studies doing exactly this.
Should Facebook have a right to access your health data? Your opinion does not matter, they wanted it, and they got it. What about the US Department of Transportation? They maintain the right to access the electronic medical records of any person who falls under their regulation, such as pilots and truck drivers. They have been know to go on fishing expeditions trolling through medical records in search of violations. Search for Operation Safe Pilot. I know several people who have either avoided medical treatment because of this issue, or obtained treatment in a foreign country.
> The P in HIPAA stands for Portability, not Privacy.
… sure, that P stands for that. But one of the key sections is literally called the Privacy Rule: "The HIPAA Privacy Rule establishes national standards to protect individuals' medical records and other individually identifiable health information"
> Should Facebook have a right to access your health data? Your opinion does not matter, they wanted it, and they got it.
No. Wantonly sharing PHI with Facebook would almost certainly be a violation of HIPAA … and literally, it's already happened, this year even[1]: "The office warned that entities covered by HIPAA aren’t allowed to wantonly disclose HIPAA-protected data to vendors or use tracking technology" ("Vendors" here included Facebook and the like.) ¹
Now, HIPAA only applies to covered entities. In the context of the OP however, a hospital is a covered entity. Whether eavesdropping is permissible is a good question.
[1]: https://www.politico.com/news/2023/04/17/health-industry-dat...
¹I think regulatory agencies across the board have been giving pittances for fines, and these are no exception. There's a real question as to whether enforcement is actually meaningful, but that's separate question from whether there is a right.
Compare/contrast: there's one ability a Pokemon can have, that just by existing, means that the games' battle-system logic has to be re-entrant, because the ability evaluates a hypothetical battle "within" the current battle in order to determine what it does. Insofar as you're being asked to code the Pokemon battle system, the existence of that ability is very important to you; but it's nevertheless not a key aspect of the game's design — the game would be the same game without it. :)
I searched for Operation Safe Pilot, and it looks like they matched up aviation medical clearances with social security disability claims, not with general medical records. If you're claiming for a disability, there's something seriously wrong and you shouldn't be flying, or you're lying about the disability and committing social security fraud. Am I missing anything?
The typical car salesman has 15 credit applications in his desk, 5 in his car in some folders he forgot about, 1 in the trash can he accidentally crinkled up instead of putting in the shred box. The managers office is even worse. The finance guys office is even worse. The 'business office' is half decent because the GM/owner is up there often.
On a side note, my friend subleased an office from a medical nurse temp agency/employment agency.
When he arrived (I helped him move in), there were thousands of unsecured files with people's socials and all info needed to get a job in file cabinets.
The office had cleaning service every night from a random cleaning company.
One idea my nefarious side had was to get the med records of individuals and get the address's house cost, and send scary calls/text/messages shaking relatives down with scare-calls. (Or, get the info and get in league with overseas scammers who masquerade as the hospital, and take a cut from that. Would be relatively risky free.)
Obviously I wouldn't do that. But it would be trivial to do.
(Long story short, pager infrastructure needs destroyed.)
It should be messages like "Code red to room xyz with patientID #####"
That would remove anything really actionable.
Whereas I was seeing over FLEX: full name, address, room#, child abuser status, why they're there, medicines. It was fucking stupid, like fuck no.
If I have any questions, they're at the counter with 20 other patrons hearing everything about my medication. Then I take my medication to a separate counter for payment, which is staffed, usually, by a teenager working part-time. Great, now they know what medication I'm on.
Imagine if I were picking up medication for a teenage son or daughter, and the teenager at the counter went to school with them?
She didn't sleep a wink. With all the beeping and alarms and periodic checks and procedures. Mostly involving her roommate.
The next morning she was mentally and physically wrecked. the first thing she told the nurse was, "I want to go home so I can get some sleep.
The nurse laughs and replies, "I hear that all the time. Nobody ever sleeps here".
Now that's messed up. Sleep is the great healer. No sleep is the great destroyer. Is this intentional or institutional insanity or what?
I mean why don't they just put strychnine in the water supply while they're at it?
I wasn't so lucky for the first week of my stay. I was on IV meds that pushed my BP up significantly, to the point where every time the automatic hourly BP reading was taken it would set off alarms. During the day the charge nurse would usually silence the alarm (from the nursing station) immediately but at night they were understaffed (this was during a covid wave) and the nursing station often wasn't manned. So sometimes the alarm would sound for 20+ minutes. Every hour... all night... Eventually I found a sympathetic nurse who actually knew how to adjust the settings on the machine and disabled the alarm entirely.
At least I didn't have to share a room. That would have been misery.
I don't have a medical degree or anything but that's crazy.
(Also, the nurse said nobody sleeps here. Not just the people under observation.)
This isn't whats happening. Being sleep deprived for a day is annoying, but hardly a health issue. I bet most people would rather have doctors respond to you suddenly dropping blood O2 levels to under 90% than not.
> (Also, the nurse said nobody sleeps here. Not just the people under observation.)
Yes, nobody sleeps because nurses and doctors are all working >14 hour shifts with on-call rotations trying to keep people ALIVE. I have many medical professionals in my family, all of them are rest deprived, trying to keep track of the myriad of patients all demanding personal constant attention.
That is not exactly defense of medical system. If it keeps workers sleep deprived they will make mistakes. This just means system itself sux.
(And of course a sleep-deprived medical professional is a health hazard to everybody involved. Only a fool thinks otherwise.)
You get used to the beeping after one night anyway. If not, you can ask the nurse for earplugs or even sleeping pills (although sleeping pills are harder to get).
If you think sleep is a higher health factor than the reasons that the hospital want to put you under observation, then just refuse treatment.
If you don't want to be disturbed by patients in the same room, you can pay for that.
The Privacy Rule permits certain incidental uses and disclosures that occur as a by-product of another permissible or required use or disclosure, as long as the covered entity has applied reasonable safeguards and implemented the minimum necessary standard, where applicable, with respect to the primary use or disclosure. See 45 CFR 164.502(a)(1)(iii). An incidental use or disclosure is a secondary use or disclosure that cannot reasonably be prevented, is limited in nature, and that occurs as a result of another use or disclosure that is permitted by the Rule. However, an incidental use or disclosure is not permitted if it is a by-product of an underlying use or disclosure which violates the Privacy Rule.
My understanding is that FERPA is similar to HIPAA, except for college scores and enrollment information instead of medical records.
But there’s a rule in FERPA where you explicitly can’t leave a stack of exams and let students pick them, because it exposes students to others’ scores. Another rule is that you can’t associate a students exam with their student ID even if it’s a sequence of numbers, because the id is public information, but you wouldn’t expect someone to remember someone else’s id.
(I specifically remember some professors not following the exam rule, probably because they didn’t know or perhaps it didn’t exist yet. I don’t know if anything happened to them but I suspect if anything, they were simply asked to not do that in the future.)
In my college people definitely remembered other people's IDs, since all you needed to badge into any door they had access to was to write their ID and a 00+(number of replacement badges) to the data track on a swipe card. This gave access to even dorms. This even worked for faculty or Deans who had full access to all academic and athletic facilities.
Clearly nobody would ever know anybody else's public ID, because that would take just going into a study session and looking at the sign in sheet of hundreds of them sitting in the back of the classroom. Or looking at the log of swipes of an event that a dean attended.
People are too focused on hiding results because someone might feel bad.
But you don’t get the grades of individuals.
As a comparison, at my Uni in the 1970s individual grades were posted along with corresponding social security numbers.
Addiction treatment falls under 42 CFR II, colloquially known as “part 2”[0]
Part 2 data is significantly more encumbered than other medical data. If I want to get it I need to be explicitly allowed as a named entity by the patient to receive it. If the data is shared with me under a “general designation”whoever gave it to me has to record that and tell the patient on request. And I have no TPO carve outs, I have to get explicit consent to pass it along.
It is, often times, treated as radioactive data - my company deals in medical data but explicitly says in our contracts that we refuse any receipt of it.
0: https://www.ecfr.gov/current/title-42/chapter-I/subchapter-A...
She said no, that is prohibited, because it is a HIPAA violation. She was clearly smoking crack.
Now I simply record surreptitiously.
https://www.aetnainternational.com/en/about-us/explore/healt...
https://www.alight.com/blog/can-patients-record-doctors-offi...
https://www.verywellhealth.com/secretly-recording-your-docto...
You've got to understand: clinic visits are very stressful, time-limited, and high-pressure. Doctors don't write anything down, but it's crucial that the patient rememberd everything that was said, with high accuracy and confidence. Audio recording is our best tool to these ends.
I'm glad I don't live in California!
You've also mixed up what's legal for you to do (record, in a single-party state) and what's legal for them to permit by policy (knowingly agreeing to recording). You won't get arrested in a single-party state for recording; it can still violate the clinic's policy, and they can make the decision not to continue doing business with you after.
No one's going to stop you from writing down a note, though. Thinking "doctors don't write anything down" is universal may indicate you need a better one; mine definitely does, and I get sent the summary shortly after my visits.
In a court, hearsay is inadmissible; a recording (critically different than mere hearing) is far more likely to be admissible. That's for a good reason. (HIPAA compliance is also not a strictly moral question, but a legal one.)
> Let's stipulate that all smartphones are always and everywhere listening to everything, and sending it to someone...
Even if you're using something like "hey Siri" or "OK Google", that's not how they work.
HIPAA is a baseline rule set. Providers are free to set more restrictive rules than what HIPAA defines. They often do so they have buffer room better their rules and HIPAA violations.
Further, HIPAA is not the only rule governing you and your providers interactions. A private institution is free to set its own rules (with its legal obligations) and can have you leave if you don’t follow them.
weird
When HIPAA was created, a large impetus was getting large health systems onto electronic records. Portability and accountability reigned high. And there's a lot of information and misinformation about this.
Attorney general letters help clarify a lot of it.
But sharing a hospital room doesn't violate anything related to HIPAA because that isn't what the law protects.
> “It would be extraordinarily inconvenient and expensive for it to work otherwise.”
Sprinkle on a little bureaucrat-ese and post-hoc justification and you get the “clarified guidance” the primary comment calls out
> What is the motivation behind keeping medical records confidential, why do we actually care?
A respect for the patient’s privacy is likely going to be one of the driving reasons, if not the primary reason itself.
> The Rule requires appropriate safeguards to protect the privacy of protected health information and sets limits and conditions on the uses and disclosures that may be made of such information without an individual’s authorization.
We allow a major hole here in that protected health information by willfully careful readings of “appropriate safeguards” and “limits and conditions”, essentially because doing otherwise would be a nightmarish expense and pain.
Btw, my name's not Geoff.
(Just to be a bit more plain.)
I've ranted on here plenty about how often I've dealt with incorrect bills, and HIPAA plays into that as well. My private information can be shared to "traveling doctors", it can be shared with woefully incompetent contractors who handle billing (or, pretend to), and I received a notice last year that my information had been involved in a data breach and I'm not expecting any compensation. When I had to get a very private and sensitive part of my body imaged, they'll gladly announce to the waiting room my name and what procedure I'm there for, even though it's a rather private and sensitive part of my body - very similar to the shared room concern. I don't care that the people in that room aren't likely to misuse my healthcare information, I don't want them knowing where I found a lump anyway.
And yet HIPAA is often cited to me over the phone as the reason why we can't seem to get incorrect bills figured out for my dependents. It doesn't seem to me that HIPAA actually does much to protect my privacy, but it sure gets used to obfuscate things when there's a problem.
In reality, a lot of doctor's offices are not well versed in HIPAA because many are de facto small businesses. Large hospitals and insurance companies generally have better knowledge of HIPAA and HIPAA compliance.
Fortunately, my mother bit her tongue and said nothing to me until years later and just was glad I was not being stupid and would not end up pregnant out of wedlock. It could have gone really bad places for me if my mother were inclined to be abusive about it.
These days, a pharmacist is more likely to think twice before sharing that kind of info because it's illegal to do so and it could come back to bite them big time.
HIPAA also helps protect people from discrimination who have medical issues like STDs -- which aren't always sexually transmitted or may be transmitted because someone was assaulted, but some people will just be judgy and not give you the benefit of the doubt and it's a nightmare to have to defend your virtue and tell random strangers "I'm not a whore. I don't sleep around casually. I was raped at gun point." or some such.
Sorry it's such a pain in the ass for you. It's something that helps prevent casually ruinous oversharing for some people.
your doctor was more than a little careless and, knowingly or not, relied on you to not cross any lines.
if that’s not concerning to you, fantastic… but for some reason you didn’t name the doctor, perhaps because you know others disagree. nor did you name the patients.
huh.
guess your doctor made a safe assumption about you. who else saw the warts list that day?
Unfortunatly that leaves a lot of leeway. The major EMR vendors are all aggregating patient data in cloud services and taking it across borders to where there is no transparency for what is being done with it. The regulations were written with a 90's understanding of technology.
A more appropriate regulation today would be to create a category of legally privileged PHI that is strictly inadmissable in legal proceedings and with heavy fines for unauthorized use and disclosure. However, I don't see privacy legislation getting any better as the people inside govt and academia absolutely hate privacy as a concept because they are the specific targets of limiting their discretion about whose data they can snoop. We're in an era of institutional capture by people without ideals or principles, and it's probably unwise to expect altruistic public interest policy like 90's-style privacy legislation from any of them anytime soon.
Technically, they are building models to publish or perish, establish data feifs in their institutions for attracting grant money, and to support policy objectives for the revolving door between gov and academia and some troubling third party NGOs, with "care," being a distant abstraction.
The academics I encountered doing privacy work for PHI data sets seemed to be interested in everything except responsibility and stewardship. My care indeed.
That's actually a great reason to refrain from discussing someone else's medical data with you. That it is inconvenient for you is certainly bad, but that is a non sequitur.
> It doesn't seem to me that HIPAA actually does much to protect my privacy, but it sure gets used to obfuscate things when there's a problem.
If we allowed Bill Handler, Inc. try their hand at securely implementing "for the purposes of this call, pretend I'm someone else," you're going to have TWO_PROBLEMS * NO_OF_DEPENDENTS
Sure, I am doing a lot of "hand waving"- I'm not an expert on the law. I'm merely sharing my perspective on this. Would love to understand more about this specific authorization...
I've never been asked to waive my rights. I have been asked to sign that I received their notice of privacy practices. (Almost always having not been actually given any to read, which is fairly infuriating.)
> But even then it doesn't matter because under HIPAA the provider may still choose to share your personal information for their own reasons.
Only in certain specific situations.
You are incorrect. You are being asked to acknowledge that you received a copy of their privacy policies. You can decline and it doesn't change very much (if anything), because they will still document that they informed you of them... which they did.
It's understandable that people don't read what they're signing; I often don't have time, either. But you are posting about that form having not paid much attention to it, which is less common, in my experience.
It was a weird conversation, where we both ended up looking at each other like the other one was a total moron.
The tarmac reports can be oddly entertaining sometimes. I still wonder how an alcohol bottle became embedded in a runway a few years back.
(Perfect privacy would also require soundproofed rooms for phone calls, mantrap doors for patient rooms so you can't get an inadvertent peek while walking by, and probably dozens of other expensively impractical mitigations.)
HIPAA requires "reasonable safeguards" to permit this sort of balance to be struck.
Relative to the already absurdly high health care costs, the construction costs should be pretty small.
The hospitals near me have been expanding as fast as they can. Absolutely constant large-scale construction. It's not rocket science, but it's not a Thanos finger snap either.
Next question please.
I went to war with a doctors' office that claimed their non-compete clause meant I couldn't transfer my medical records to a doctor who'd left the practice I wanted to follow.
One that says "I agree to share my medical info with XYZ" is not. Every hospital already makes you sign this when you are admitted, otherwise they wouldn't be able to function.
Refusing to treat you if you want to keep your rights, less so.
The thing they have you sign is an agreement that you received a notice of their privacy practices (laying out your HIPAA rights). It isn’t a waiver.
Hospitals don’t need a waiver to operate. HIPAA already permits them to share internally, with billers, etc.
And there is a decent chance in many hospitals that they will at least drag their feet, since they would be exposed to much greater liability.
I know this situation specifically is not quite a waiver, but it will likely have some effect on hospital staff's attitudes.
https://www.hhs.gov/hipaa/for-professionals/privacy/laws-reg...
> Permitted Uses and Disclosures. A covered entity is permitted, but not required, to use and disclose protected health information, without an individual's authorization, for the following purposes or situations: (1) To the Individual (unless required for access or accounting of disclosures); (2) Treatment, Payment, and Health Care Operations; (3) Opportunity to Agree or Object; (4) Incident to an otherwise permitted use and disclosure; (5) Public Interest and Benefit Activities; and (6) Limited Data Set for the purposes of research, public health or health care operations.18 Covered entities may rely on professional ethics and best judgments in deciding which of these permissive uses and disclosures to make.
The thing you sign all the time is acknowledging receipt of the provider's privacy practices. It's an entirely different thing; it is by no means a waiver of any rights. https://www.hhs.gov/hipaa/for-professionals/faq/notice-of-pr...
> Yes. The HIPAA Privacy Rule requires that a covered health care provider with a direct treatment relationship with individuals make a good faith effort to obtain written acknowledgments from those individuals that they have received the provider’s notice, regardless of whether the provider also chooses to obtain the individuals’ consent.
You can refuse to sign that. They'll document the refusal, which changes nothing. It's like your Miranda rights when you get arrested; they tried to inform you of your rights under HIPAA. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance...
Or various other scenarios.
Unless it's digital health record-related, then it's probably HIPAA.
If you're really curious, you can read HIPAA [2] and HITECH [3]. Combined, they are about 600 pages of dense dense legalese.
[1] https://www.hipaajournal.com/is-it-a-hipaa-violation-to-ask-... [2] https://www.govinfo.gov/content/pkg/PLAW-104publ191/pdf/PLAW... [3] https://www.govinfo.gov/content/pkg/PLAW-111publ5/pdf/PLAW-1...
As an aside: I wish this meme would die.
> For the same reason, the Karen meme divides white women themselves. On one side are those who register its sexist uses, who feel the familiar tang of misogyny. Women are too loud, too demanding, too entitled. Others push aside those echoes, reasoning that if Black women want a word to describe their experience of racism, they should be allowed to have it. Hanging over white women’s decision on which way to jump is a classic finger trap, familiar to anyone who has confronted a sexist joke, only to be told that they don’t have a sense of humor. What is more Karen than complaining about being called “Karen”? There is a strong incentive to be cool about other women being Karened, lest you be Karened yourself.
https://www.theatlantic.com/international/archive/2020/08/ka...
> The HIPAA Privacy Rule applies to all forms of health information, including paper records, films, and electronic health information – even spoken information.
HIPAA is not as limited as you state.
“Yes, Dunkin Donuts can give you a free donut if you show your Covid vaccination card. No, the donut shop is not a covered entity or a business associate, so they aren’t bound by HARPO.”