Unlike the general Internet where laws are so poor that an opt-out hidden checkbox is sufficient as "consent", HIPAA is quite specific on what is needed and who needs to get it.
Unlike the general Internet where laws are so poor that an opt-out hidden checkbox is sufficient as "consent", HIPAA is quite specific on what is needed and who needs to get it.
The Constitutional requirement for a common-law legal system only works to the degree that there is common agreement on basic premises. Once linguistic definitions come to be viewed as strategic legal territory to be captured, the system is bound to collapse under the weight of its own contradictions.
The data protection rules provided by HIPAA are actually pretty good, especially for a privacy-hostile country like the USA. I'd love see something like HIPAA act as the model for a generic (non-healthcare) data privacy protection law, if Congress could get their shit together and propose it.
The ideal contract has enforcement mechanisms that are really easy to predict, so that both parties can just settle around that predicted outcome, instead of actually having to go to court.
The actual mechanisms aren't that important, as long as they are predictable. If eg bankruptcy law in your jurisdiction predictably benefits creditor (or debtor) more, then the original agreement (when people still agree with each other) can adjust for that.
So yeah it should apply but they are just claiming they aren't a mental healthcare service to avoid it despite them being a literal mental health crisis hotline.
It probably won't hold up but it might be enough to lessen penalties since they can feign ignorance.
Or at least I was given this impression from my compliance trainings.