4 ms·
HIPAA is such an awesome law. I have to work with it daily as an engineer, and I'm continually amazed that the US government requires so much security. Normally
by blaisio 7y ago
HIPAA is such an awesome law. I have to work with it daily as an engineer, and I'm continually amazed that the US government requires so much security. Normally the US is extremely hands off when it comes to privacy and security. Congress almost never passes laws that have such far reaching scope. And HIPAA actually has teeth, with significant penalties for companies who don't comply (and of course people can sue as well over the violation).
I think aspects of it could definitely be improved. I see HIPAA violations at doctor's offices all the time - but they are usually still fairly minor, and doctors and nurses grow concerned quickly as soon as you mention a possible violation.
- t34543 7y agoYes, I am fond of HIPAA too. One project I worked on was physical infrastructure for a healthcare company. One cool thing I remember is that the phone lines within the building had to be in armored cable, so they couldn’t be tapped without leaving a huge mess.
- closeparen 7y agoYou can read the technical safeguards. They are pretty reasonable and not nearly that intense. There is definitely a cottage industry of security/compliance consultants giving maximalist interpretations to bill more hours, but there are also shops doing pretty average modern IT best practices (individual user accounts, TLS, screensaver passwords, etc) that do fine. https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/administrative/securityrule/techsafeguards.pdf https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/ad...
- corebit 7y agoHow are you fond of this law? It's so obviously a pointless waste of money. As a fellow engineer who has worked with it I cant wait ffg or its repeal - and I see that coming.
- chooseaname 7y agoI'll bite. What would be the options for keeping our PHI from being freely shared everywhere? You have to know that Facebook would love a piece of that.
- clinta 7y agoFirst of all, I don't think HIPPA actually prevents PHI from being shared. If Facebook were to become a business partner of a hospital, and maintain HIPPA compliance themselves, hospitals can share data with Facebook. To tackle the problem HIPPA tries to solve, that is making sure that data sharing is secure and only with the intended parties, I want to see stronger enforcement of liability. Granted, the US doesn't have a great track record on that, seeing Equifax get away with what their doing. But I think that's the system that needs to be improved. Instead of government dictating what "secure" means, different approaches can be experimented with on the market with strong enforcement of liability providing the necessary incentives.
- briandear 7y ago> hospitals can share data with Facebook Then Facebook would become a Business Associate and would have to protect information in a variety of very strict ways and could face a fine of up to $10,000 per patient record, per violation. If they had 25 million health records and decided to target advertising to those people on two separate occasions, then they are liable for a fine of up to $500 billion. So sure, let Facebook get into health, it wouldn’t take long for them to run afoul of the law given their move-fast-break-things attitude.
- clinta 7y agoIs targeting advertising based on health data a violation if the advertiser is a business associate and is not directly exposing the data to any non-covered entities?
- organsnyder 7y agoI work for a healthcare software company (and previously worked for a healthcare system). In my experience, these regulations tend to be high-level: they're less interested in exactly how you meet the regulations, as long as you're meeting them. They focus much more on business processes than low-level technical details. I've found that, for the most part, common-sense industry-standard practices go at least 90% of the way toward meeting the regulations.
- briandear 7y ago> I see HIPAA violations at doctor’s offices all the time.. It’s very likely your aren’t seeing actual violations. These “violations” are likely considered incidental uses and disclosures. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/incidental-uses-and-disclosures/index.html https://www.hhs.gov/hipaa/for-professionals/privacy/guidance...
- specialist 7y agoThe biggest exemption was for us working on the systems. The idea that whispering in the waiting room was an important attack vector while whitelisting us IT people is hilarious. (For lack of a better adjective.) For a middle ground example: My SO did clinical trials at the local research hospital. She went to ANOTHER hospital for some surgery, because she knows her coworkers look up people's records, and she didn't want them knowing about her troubles. Like the systems I created, of course there were access logs. But like our systems, no one ever reviewed or audited them. Hopefully things have gotten better.
- specialist 7y agoWhen did HIPAA grow teeth? I worked on some exchanges in the mid-2000s. 5 exchanges, 80 orgs, 100s of data feeds, including govts. We had to do HIPAA "training" every year. It was just corporate CYA. Those of us working on the systems resigned ourselves to the fact that disclosures were inevitable. Even if we could technically secure stuff (encrypt all data at rest, PKI for all access, RBAC, audits, etc), we'd never be able to get all our partners up to speed.