And then there are online providers like better health that don't have the option to opt out at all. So you just have to avoid them entirely.
MyChart itself is a component of Epic (the EMR) and is absolutely HIPAA compliant. Every healthcare institution I've worked with has taken HIPAA and privacy/security regarding patient data extremely seriously. Non-HIPAA compliant vendors are an immediate non-starter and don't even enter discussions when looking at new products.
I'm not at all dismissing how terrible it is that healthcare tech companies can be lax with patient data. This absolutely needs to be better! But at the same time, this sounds more like incompetence than active malice. Practically speaking, a patient is extremely unlikely to experience actual harm because a developer accidentally took patient data home on a personal laptop. Although, I would love to hear more about what kinds of violations you've seen in your time in health tech? I work with third party vendors from a healthcare institution, and I absolutely want to figure out how to fix this.
Now, though, if a third party accidentally leaks your patient info, or lead pipes are involved
I wasn't claiming that MyCharts isn't HIPPA compliant: I was complaining as part of a MyCharts workflow I was presented with a form that wanted me to grant someone the right to send my data to non-compliant organizations, and as I said above explicitly stated so.
I had to ask for a paper copy of the form I was signing, which was handed to me. That document said that "I acknowledge receiving the privacy notice ..." Was that given to me? Of course not. Asking for that - well let's just say I think I was the first person to ever ask for any of this documentation. I'm sure my information has been shared with 30 other entities - for a strep test. It's insane and unenforceable as a patient who just wants to get shit done.
I think the OP is assuming that when healthcare institutions partner with third parties, those third parties are not required to uphold HIPAA. If that's his/her belief, it's 100% false. Third parties associating with healthcare institutions have to sign business associate agreements (BAAs) that require them to uphold the same standard of privacy/security regarding patient data as the first party healthcare institution. There are severe financial penalties for violating HIPAA, and every healthcare institution I've been a part of takes this extremely seriously.
The thing for me is that if HIPAA truly does provide me privacy of my personal information and health care information, why are all of these privacy and consent forms required?
Whenever I am handed a form that says "privacy policy" my sense is immediately raised - what is it that they're trying to hide from me through mountains of legalese? When I don't receive one (as was the case in my doctors visit) then I am REALLY on edge.
For example, with my health care visit, this thread prompted me to call the listed numbers on the website for the health care provider to discuss their privacy policy. The provider's number dumps you into an IVR that has zero way to reach a human - you must dial an extension, and there is no option for an operator. I ended up calling their headquarters to get a callback from a human.
If there are standard mechanisms and policies in place, then we should be able to understand the rules once and never have to sign another form again, because the rules would be clear, unambiguous, and applicable to every health care interaction. If the rules are clear about not waiving HIPAA privacy/security rights, then why have a privacy policy that's three pages of inscrutable legalese that gives a bunch of weasel room for them to "share" information?
Regarding the privacy policies: these are created by the legal department and physicians in the department are told to distribute them and get signatures when necessary in order to do things by the book. However, your rights are inalienable and protected regardless of whether you actually receive the policy and sign the appropriate box. If you don't receive the policy, the healthcare institution is on the hook and could face a fine if reported to the DHHS. Things could absolutely be done more efficiently and clearer for patients, but there's a fear in changing things ("if it ain't (horribly) broke, don't fix it"). Trying to improve how privacy policies are disseminated and patients informed could result in an inadvertent violation of HIPAA that results in large fines. So healthcare institutions are disincentivized from trying to improve things here.
I reviewed the patient privacy policy for a few large institutions in the US, and it all seems to support what I'm saying. For example, here's NYU's policy on business associates: https://nyulangone.org/files/business-associates.pdf
NYU has additional policies here: https://nyulangone.org/policies-disclaimers/hipaa-patient-pr.... UCLA Health has similar policies here: https://www.uclahealth.org/privacy-practices. Every institution has essentially the same policies as they're all just a reflection of HIPAA.
The only ways in which patient data can be shared with others are if (1) they're involved in your treatment (e.g., your doctor at another hospital), (2) payment purposes (e.g., insurance), (3) health care operations (e.g., third party vendor software like EMRs, PACS, etc.) All are required to be HIPAA compliant if they're covered entities (i.e., healthcare institutions) or sign a BAA with a covered entity that essentially puts the same HIPAA requirements on them. A violation again results in massive fines, C-suite level firings, and expensive legal fallout.
I had one question in case you’re still monitoring this thread. The compliance manager mentioned a “health information exchange” which I opted out of (since it was something I can control). Do you have experience with these? It seems benign from the searches I’ve done since the conversation but I would be curious if you had any insight as a medical professional
How generous of you
Depends on how you define "strict". They're pretty onerous to comply with, but they don't really provide patients with anywhere near the level of protection that most people think. It's better than nothing, but in reality, your data is being legally shared with an arbitrary number of entities, without your consent, and without any way for you to even know who has access to that data.
If that data is breached in any way, in theory the reports are supposed to trickle up the chain eventually. In practice? If it's more than one or two subcontractors deep, you'll probably never find out (unless the breached data is posted publicly and you stumble upon it that way).
Also, the cap on penalties is shockingly low: $2 million for all violations of a given provision per calendar year. And that's for willful neglect. If the cause of the violation is determined to be lower than willful neglect, the maximum violation is even lower.
For a very large and well-capitalized company, that might as well be a cost of business.
Aha! I thought. HIPAA gives them 30 days(sortof). We'll sue, and surely there's an attorney fee provision in there. Easy money. GOOGLE Wait what? No private cause of action! All I can do is file a complaint with HHS!
That said, depending on your state, you may be able to make some sort of colorable common-law claim.
Maybe ChatGPT would have given you a more favourable answer?
And ILLEGALLY shared via non-conformance with federal laws and data breaches.
Just look at the Boeing fiasco and the serious normalization of deviance. You think that doesn't happen when you outsource your entire IT operations offshore to a populace that literally has zero skin in the game.
(And I see that noone corrects you below. [edit -- actually a few people do, or the comments are continuing])
Gravity is a fairly strict law too. Maybe you should review what it covers, what it doesn't. The Act greatly expands the "sloshability" of your data, whether the sanctions are appropriate or sufficient to prevent patient harm is debatable.
I wouldn't expect right capitalization of FedRAMP. But JAVA vs. Java and HIPPA vs HIPAA just seem like you're not truly familiar.
What's unfair? Are random mistakes unfair (that's a very good philosophical question)? Are we forbidden from learning about other people from their mistakes or from mistakes generally?
The parent says:
> The HIPPA rules on health data are fairly strict
The followons variously say:
> I can't tell you how many forms I've opted out of that wanted to explicitly export my data to third parties and partners that are not HIPPA compliant.
> I wasn't claiming that MyCharts isn't HIPPA compliant
> The HIPPA rules may be strict
I'm more convinced that these people are making claims about the heart of what they presume HIPAA to be than I am about my parent poster's intent. According to part of your comment these people are "not truly familiar", but without that surfeit of "P" all over it we wouldn't know. My comment was based on an actual conversation heard in the field while working with what is potentially HIPAA data.
As for the parent post, the thought in my mind was is it a mistake? is it a troll? is it a mistake and they thought it was funny so they didn't correct it? I'm willing to give them a tip o' th' hat for the inadvertent glimpse into the bland certitude of inaccuracy.
"Patient X's head was caught in a drop forge, and now they need to get four CAT scans a day."
How does HIPAA apply to this statement, how would you anonymize it, and how effective would those measures be against de-anonymization given the obvious rarity of the situation? Or is something like this simply never to be discussed?
Most of the pundits of Bitcoin and similar - an evolution of the finance industrial complex - seem to claim that the reason there isn't wider adoption is that the "first killer app" hasn't been developed yet. I'd argue it's because its adoption is motivated by profit-greed, which requires a wealth transfer from new adopters to the ones passing off hodling the bag.
Many of the core-fundamental values put forward, what many hope Bitcoin et al would solve, are virtuous and attempting-hoping to solve complex problems - but Bitcoin from a holistic systems perspective, where all consequences are integrated, doesn't fit the bill for what will become the next stable evolution of how society functions with technology. I'd argue similarly to privacy concerns, the solutions that Bitcoin hodlers are aiming for - if they care about such things other than profit from buying low-selling high during pumps and dumps - simply haven't had a viable non-hype and non-greed-driven solution made available yet.
This current wave as a result of industrial complexes forming to maximize their ROI at all costs, first-to-market and maximizing profits allows them to dominate - but for how long? Maybe a decade ago now I wrote a blog post on Facebook's governance, pointing out FB's attempt to maximize profit now will certainly increase annual revenues/profits in the short-term - but would you rather have lower profits for 20+ years or higher profits for 5+ years?
Mark not being an idea person, not a creative - where everyone in tech should know his story involving the ConnectU twins who had hired him - and so he wasn't able to navigate to design and evolve a system to fully harness the potential of having what's essentially a free marketing platform for him as the controller - instead mostly depending on network effect defense strategies including buying up feature sets like WhatsApp, Instagram, etc - who gained a critical mass that could begin to become a competitor with FB, so no real innovation.
The VC industrial complex has been a driver in selecting for all of this, and where acquisitions also suck up and eliminate any up and coming competition that gained enough market share and momentum to be a threat; the incumbent dating and food-delivery platforms-apps are the most obvious for this; the captured MSM is another less obvious version of this, where conglomeration from consolidation has put the power of information control in the hands of fewer and fewer people - why big pharma has been so successful suppressing the majority of negative sentiment about them, as one of multiple parties who are toeing the line and attempting to maintain control with what I call the censorship-suppression-narrative control apparatus; Elon buying Twitter-X created a #ZeroIsASpecialNumber problem in terms of no longer being able to as easily put their hand on the scale of free speech - a blow to their authoritarian-totalitarian and industrial complex dreams, that combination forming fascism.
Another example, I think the advertising industrial complex will collapse within the next decade.
Ads are probably tied at first with downvoting mechanisms for how detrimental of an effect they have on society - where I don't have time to dive into detailing reasons for either right now; they are not mimicking natural patterns for how information-attention was distributed prior to digital.
Business is war, and there are $ trillions at stake - and so who knows what all the various parties, millions to billions of people who most likely mostly blindly follow the status quo system because they believe that they will do better off - those who struggled to get where they are in the manufactured rat race, and holding on for dear life due to fear, when in fact tyranny and scarcity mindset is very expensive - and where the universe provides all the abundance we need, and we can all thrive with proper organization.
“Those who love peace must learn to organize as effectively as those who love war.” — Martin Luther King, Jr.
Thanks for the convo! Please continue if you're motivated or inspired to!
P.S. I had 2 neck surgeries last week, so my pain level is down a lot - and so words are flowing out of me a bit easier, and apparently you inspired me to say far more than I was expecting, so thank you again.