4 ms·
When writing medical software, HIPAA was an ever-present monster forcing me to consider all potential ways we'd be under a company-ending event. Once your fine
by pixelbath 7y ago
When writing medical software, HIPAA was an ever-present monster forcing me to consider all potential ways we'd be under a company-ending event. Once your fine totals exceed $100,000, you're required to issue a press release detailing how bad the damage is, in addition to the fines that stack for each violation (each patient's record would be considered one "violation").
I'm surprised any company keeping health information would be willing to sell that data without extensive legal protection, whether or not that data is protected explicitly under HIPAA. Seems to me like this should be treated like any other PHI breach.
- zik 7y agoWhat about those DNA companies that collect even more sensitive medical information - your DNA - and then straight up sell it to companies who'll use it against you (health insurance)? Why are these guys not facing billions in fines and being dissolved for egregious violations? Edit: It seems that none of these are HIPAA violations because these companies aren't classified as medical organisations.
- kube-system 7y agoThey wouldn't be subject to HIPAA, but they would be subject to GINA. https://en.wikipedia.org/wiki/Genetic_Information_Nondiscrimination_Act https://en.wikipedia.org/wiki/Genetic_Information_Nondiscrim...
- ncallaway 7y agoIt's unfortunate, but as another commenter noted these applications are not subject to HIPAA.