5 ms·
For those bringing up HIPAA I hate to let you know that none of these apps are covered by HIPAA, and none of them can be fined under HIPAA. If your friend tell
by bound008 7y ago
For those bringing up HIPAA I hate to let you know that none of these apps are covered by HIPAA, and none of them can be fined under HIPAA.
If your friend tells you they have a disease, and you tell someone else, are you breaking HIPAA? No.
In order to break HIPAA you have to first be a covered entity. An example of a covered entity is a Doctor (or provider).
If you tell Google or Facebook that you have some kind of condition, that information is not covered by HIPAA because they are not a medical provider, and therefore have no legal obligation to keep that information private.
- freedomben 7y agoThank you. I have an app idea that I wondered if would be regulated by HIPAA. It's not going to share data, but it's always good to know what regulations apply. source for what OP is talking about: https://privacyruleandresearch.nih.gov/pr_06.asp https://privacyruleandresearch.nih.gov/pr_06.asp
- bound008 7y agoThis is a great resource. Especially the key points > The Privacy Rule applies only to covered entities. Many organizations that use, collect, access, and disclose individually identifiable health information will not be covered entities, and thus, will not have to comply with the Privacy Rule.
- baddox 7y agoThat's interesting. When I was in college I worked tech support for the residence halls, and we went through what I remember to be a short HIPAA compliance program in case we encountered any medical information while servicing another student's computer. Perhaps that was just a (reasonable) precautionary policy of the university rather than a strict legal requirement under HIPAA. Or perhaps I'm simply misremembering, and it was some other compliance program other than HIPAA.
- godelski 7y agoIf you're servicing a computer that person isn't exactly sharing that information with you. Well, probably not intentionally.
- deleted 7y ago[deleted]
- jstarfish 7y agoDoesn't always matter. Some states even impose mandatory reporting requirements on computer technicians (at least as far as victimization of minors is concerned).
- pessimizer 7y agoYour college might have been providing healthcare to students.
- testvox 7y agoIt gets strange with Schools, they are actually allowed to keep medical records on students that are exempt from HIPAA and instead are covered under FERPA.
- dragonwriter 7y agoUniversities are often employers, health insurers (via directly-run student health plans) and health care providers (via university health clinics) to students. As such, they may be HIPAA covered entities, and in any case are subject to FERPA and possibly state privacy laws, education-specific and otherwise.
- Despegar 7y agoMaking it abundantly clear why the US needs to pass a GDPR clone into law.
- alxlaz 7y agoI'm a big fan of the GDPR and it certainly improved things over here across the pond, but "pass a GDPR clone" isn't something that leads to progress. There's a lot of stuff that can be improved about the GDPR, and there are a lot of other options as well -- for example, in this case, the US could choose to extend the coverage of HIPAA regulations (or a subset of them) to commercial entities selling health-related services, not just medical providers. This would also have the advantage of requiring less legal effort and it would avoid introducing an entirely new framework. The GDPR is a very broad axe, for an organization that isn't a federation and doesn't have a real federal government, the way the US does. The US has legal options and a legal framework that we don't have.
- krageon 7y agoIf the US truly has that legal framework (or the options), then it has consistently shown reluctant to enforce those. A big, scary axe is the solution they need (as well as potentially a proper education campaign for it's citizens, so everyone is aware that they have rights and they need to stop thinking companies can take that away if that's convenient for them).
- blaser-waffle 7y agoCCPA is already a thing in California and is, nearest I can tell, actually stricter than GDPR. Not a national law -- far from it -- but a first step.
- sidlls 7y agoJust to be clear about this an entity doesn't have to be a provider or insurer to be bound by HIPAA or HIPAA-like regulations. Generally companies that contract with or for "covered entities" are going to be required to sign contracts that bind them to the same rules as the covered entity.
- bound008 7y agoI just wanted to provide one example to keep it simple. Nothing about HIPAA is ever simple, other than not being a covered entity ;)
- anaphor 7y agoBusiness associates are required to comply with HIPAA. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html https://www.hhs.gov/hipaa/for-professionals/privacy/guidance... If Google or Facebook were being used by your doctor's office or something, then they would need to comply with HIPAA, but it doesn't seem like this is the case here.