As one example, I went to a doctor, he ordered an x-ray. I went over to the x-ray company then back to my doctor. He pulled up the x-ray immediately. He's only able to do that because I signed that he can share my info with the x-ray company and visa-versa.
Again, I don't have a solution. No regulation = he'd probably share my data. But regulation = he gets me to sign so he can legit provide the service, and still shared my data (Because I signed). So all the regs did is make visiting the doctor more annoying, and add $$$$ to push all the paperwork around.
What is so hard in respecting the spirit of the law?
Law And Public Opinion In England, page 361 -> https://archive.org/details/in.ernet.dli.2015.40146/page/n38...
This is dependent on jurisdiction. Some countries (e.g. the USA) do not consider spirit/intent (anymore), as the judiciary has repeatedly ruled that the letter of the law, as written, is what matters, regardless of whether it meets the intent of what the law was written to achieve.
There are other countries in the world, outside of the USA, that do not work this way.
> the spirit of the law - noun phrase
> the aim or purpose of a law when it was written
https://www.merriam-webster.com/dictionary/the%20spirit%20of...
There are sometimes things you might not like hidden in the releases you're signing, beyond the run of the mill acceptance of financial responsibility / assignment of benefits, notice of privacy policy acknowledgment, consent to treat.
In fact, for the purposes of treatment, providers can share that information, even if you explicitly refuse, as needed.
Obviously this doesn’t work in all situations and for all people, but it’s a start.
Hell no. The fuzz ain't getting my info without reasonable, articulable suspicion that I have committed, am committing, or am about to commit a crime, or if I'm pressing charges and need to ID for that process.
I'd rather have society deal with the problems that come with not knowing who's under the truck than the problems that come with state surveillance.
I am not familiar with the nitty gritty of US law, but under German law that signature would be worthless. Even signing a document you have but are unwilling to read is legally a bit iffy (which is why for things like real estate a notary will read the paperwork to you and ask if you understood it, or why surprising clauses in terms of service are unenforceable). Signing something without being able to know what you are signing would be worth exactly nothing, because you didn't actually knowingly consent to any particular thing, and neither did you have the "meeting of minds" required to form a contract.
* Within margin of error
The flip side of this however is that it’s a very worthwhile pursuit to know consumer protections and what your rights are in the jurisdiction in which you live - and how to enforce them.
Where I live, I unfortunately quite frequently find myself having to go “ok so you want to do the formal process with the regulator then?”, which usually gets them to reconsider - but not always. Three times in the last month I have threatened regulatory action - and of those three, only one chose that path. I have just reported a government agency here to the domestic and EU regulators for failing to fulfil EU FoM treaty rights - and they were even kind enough to put it in writing that they’re ignoring their own domestic laws.
I have yet to lose a case I have brought before a regulator or justice of the peace, and businesses usually only need to do this once, if at all, as it can quite quickly turn a €1,000 dispute into tens or hundreds of thousands of euro of damages and fines. By doing this, following these processes through, I help not just myself but society as a whole.
So - sign away, but have teeth, and know where to bite.
Being a bank, this has nothing to do with HIPAA. Just a dark pattern.
Specifically, you're typically giving the office's providers and their marketing "affiliates" and your insurance company and its marketing "affiliates" the right to forward around (through any length chains of agreements) your entire medical history associated with enough (research proven as de-anonymizing) details to retarget you personally. And you're typically doing this by accepting a company insurance (in the US) or the provider's reception counter while you're in need of care.
This effectively forced consent is arguably illegal, but as far as I know, untested, so it's standard across the medical system and across omnibus insurance (e.g. company-provided healthcare "plan").
Of course, every touch point is another place your personal history will get stolen and rolled into modern digitally scripted exploitation of your identity and or targeted forms of phish-mongering (a term I made up meaning marketing so personalized you believe it's necessary to sign up for and pay for).
If you have any relationship with the team at your company that procures employee insurance packages, see if you can persuade them to start with the firm's insurance consultant (high end) or broker (low end) and systematically remove every step in the "we can pass along all your info to our affiliates for our own pinky-swear good reasons like making more money off your private info" chain.
In our experience, this added 3+ months to the procurement process as every single provider balked until interacted with by counsel -- and then instantly capitulated.
Our goal was always to give our employees a top tier benefits package, and we consider it a top tier hard-to-match employee benefit to not have random firms and government agencies pawing through your doctors notes, prescription histories, lab results, and enough biographical data to fake your digital twin.
Sadly, most employees -- though none of them are sheeple -- shrug at that for reasons in this thread: no time to fight such pervasive exploitation, especially when it hits them while needing a service as it hit you, or just plain weary of trying. So much easier, and psychically healthier, to just avoid thinking about it. Everyone is resigned.
If a company you consider working for claims "we take your privacy seriously" ask if they got privacy waivers removed on your behalf from all vendor contracts including payroll (does your salary go to 'work number'?) and insurance providers (can your data leave your doctor's EMR?). Odds are, they do not, in fact, take your privacy as seriously as they could.