And then there are online providers like better health that don't have the option to opt out at all. So you just have to avoid them entirely.
I had to ask for a paper copy of the form I was signing, which was handed to me. That document said that "I acknowledge receiving the privacy notice ..." Was that given to me? Of course not. Asking for that - well let's just say I think I was the first person to ever ask for any of this documentation. I'm sure my information has been shared with 30 other entities - for a strep test. It's insane and unenforceable as a patient who just wants to get shit done.
How generous of you
I think the OP is assuming that when healthcare institutions partner with third parties, those third parties are not required to uphold HIPAA. If that's his/her belief, it's 100% false. Third parties associating with healthcare institutions have to sign business associate agreements (BAAs) that require them to uphold the same standard of privacy/security regarding patient data as the first party healthcare institution. There are severe financial penalties for violating HIPAA, and every healthcare institution I've been a part of takes this extremely seriously.
The thing for me is that if HIPAA truly does provide me privacy of my personal information and health care information, why are all of these privacy and consent forms required?
Whenever I am handed a form that says "privacy policy" my sense is immediately raised - what is it that they're trying to hide from me through mountains of legalese? When I don't receive one (as was the case in my doctors visit) then I am REALLY on edge.
For example, with my health care visit, this thread prompted me to call the listed numbers on the website for the health care provider to discuss their privacy policy. The provider's number dumps you into an IVR that has zero way to reach a human - you must dial an extension, and there is no option for an operator. I ended up calling their headquarters to get a callback from a human.
If there are standard mechanisms and policies in place, then we should be able to understand the rules once and never have to sign another form again, because the rules would be clear, unambiguous, and applicable to every health care interaction. If the rules are clear about not waiving HIPAA privacy/security rights, then why have a privacy policy that's three pages of inscrutable legalese that gives a bunch of weasel room for them to "share" information?
Regarding the privacy policies: these are created by the legal department and physicians in the department are told to distribute them and get signatures when necessary in order to do things by the book. However, your rights are inalienable and protected regardless of whether you actually receive the policy and sign the appropriate box. If you don't receive the policy, the healthcare institution is on the hook and could face a fine if reported to the DHHS. Things could absolutely be done more efficiently and clearer for patients, but there's a fear in changing things ("if it ain't (horribly) broke, don't fix it"). Trying to improve how privacy policies are disseminated and patients informed could result in an inadvertent violation of HIPAA that results in large fines. So healthcare institutions are disincentivized from trying to improve things here.
I reviewed the patient privacy policy for a few large institutions in the US, and it all seems to support what I'm saying. For example, here's NYU's policy on business associates: https://nyulangone.org/files/business-associates.pdf
NYU has additional policies here: https://nyulangone.org/policies-disclaimers/hipaa-patient-pr.... UCLA Health has similar policies here: https://www.uclahealth.org/privacy-practices. Every institution has essentially the same policies as they're all just a reflection of HIPAA.
The only ways in which patient data can be shared with others are if (1) they're involved in your treatment (e.g., your doctor at another hospital), (2) payment purposes (e.g., insurance), (3) health care operations (e.g., third party vendor software like EMRs, PACS, etc.) All are required to be HIPAA compliant if they're covered entities (i.e., healthcare institutions) or sign a BAA with a covered entity that essentially puts the same HIPAA requirements on them. A violation again results in massive fines, C-suite level firings, and expensive legal fallout.
I had one question in case you’re still monitoring this thread. The compliance manager mentioned a “health information exchange” which I opted out of (since it was something I can control). Do you have experience with these? It seems benign from the searches I’ve done since the conversation but I would be curious if you had any insight as a medical professional
MyChart itself is a component of Epic (the EMR) and is absolutely HIPAA compliant. Every healthcare institution I've worked with has taken HIPAA and privacy/security regarding patient data extremely seriously. Non-HIPAA compliant vendors are an immediate non-starter and don't even enter discussions when looking at new products.
I wasn't claiming that MyCharts isn't HIPPA compliant: I was complaining as part of a MyCharts workflow I was presented with a form that wanted me to grant someone the right to send my data to non-compliant organizations, and as I said above explicitly stated so.
I'm not at all dismissing how terrible it is that healthcare tech companies can be lax with patient data. This absolutely needs to be better! But at the same time, this sounds more like incompetence than active malice. Practically speaking, a patient is extremely unlikely to experience actual harm because a developer accidentally took patient data home on a personal laptop. Although, I would love to hear more about what kinds of violations you've seen in your time in health tech? I work with third party vendors from a healthcare institution, and I absolutely want to figure out how to fix this.
Now, though, if a third party accidentally leaks your patient info, or lead pipes are involved
Depends on how you define "strict". They're pretty onerous to comply with, but they don't really provide patients with anywhere near the level of protection that most people think. It's better than nothing, but in reality, your data is being legally shared with an arbitrary number of entities, without your consent, and without any way for you to even know who has access to that data.
If that data is breached in any way, in theory the reports are supposed to trickle up the chain eventually. In practice? If it's more than one or two subcontractors deep, you'll probably never find out (unless the breached data is posted publicly and you stumble upon it that way).
Also, the cap on penalties is shockingly low: $2 million for all violations of a given provision per calendar year. And that's for willful neglect. If the cause of the violation is determined to be lower than willful neglect, the maximum violation is even lower.
For a very large and well-capitalized company, that might as well be a cost of business.
And ILLEGALLY shared via non-conformance with federal laws and data breaches.
Just look at the Boeing fiasco and the serious normalization of deviance. You think that doesn't happen when you outsource your entire IT operations offshore to a populace that literally has zero skin in the game.
Aha! I thought. HIPAA gives them 30 days(sortof). We'll sue, and surely there's an attorney fee provision in there. Easy money. GOOGLE Wait what? No private cause of action! All I can do is file a complaint with HHS!
That said, depending on your state, you may be able to make some sort of colorable common-law claim.
Maybe ChatGPT would have given you a more favourable answer?
(And I see that noone corrects you below. [edit -- actually a few people do, or the comments are continuing])
Gravity is a fairly strict law too. Maybe you should review what it covers, what it doesn't. The Act greatly expands the "sloshability" of your data, whether the sanctions are appropriate or sufficient to prevent patient harm is debatable.
I wouldn't expect right capitalization of FedRAMP. But JAVA vs. Java and HIPPA vs HIPAA just seem like you're not truly familiar.
What's unfair? Are random mistakes unfair (that's a very good philosophical question)? Are we forbidden from learning about other people from their mistakes or from mistakes generally?
The parent says:
> The HIPPA rules on health data are fairly strict
The followons variously say:
> I can't tell you how many forms I've opted out of that wanted to explicitly export my data to third parties and partners that are not HIPPA compliant.
> I wasn't claiming that MyCharts isn't HIPPA compliant
> The HIPPA rules may be strict
I'm more convinced that these people are making claims about the heart of what they presume HIPAA to be than I am about my parent poster's intent. According to part of your comment these people are "not truly familiar", but without that surfeit of "P" all over it we wouldn't know. My comment was based on an actual conversation heard in the field while working with what is potentially HIPAA data.
As for the parent post, the thought in my mind was is it a mistake? is it a troll? is it a mistake and they thought it was funny so they didn't correct it? I'm willing to give them a tip o' th' hat for the inadvertent glimpse into the bland certitude of inaccuracy.
"Patient X's head was caught in a drop forge, and now they need to get four CAT scans a day."
How does HIPAA apply to this statement, how would you anonymize it, and how effective would those measures be against de-anonymization given the obvious rarity of the situation? Or is something like this simply never to be discussed?