5 ms·
curious why you say that - wouldn't doctors (and thus patients by extension) using these tools stand to benefit as well? (in addition to Google who is definitel
by dzader 7y ago
curious why you say that - wouldn't doctors (and thus patients by extension) using these tools stand to benefit as well? (in addition to Google who is definitely getting the most upside here)
- not_a_cop75 7y agoInformation. Google is already like the privatized arm of the NSA in a sense. Most people don't like oversharing with any one company.
- dzader 7y agowouldn't medical data be covered under HIPAA? (I really don't know - it's possible anonymized data etc. might get around those restrictions). I would hope that when it comes to medical data laws would prevent some of the usual privacy concerns around googles data collection.
- enriquto 7y agoare you being sarcastic? If that is the case, you are a really good writer! you got me until I did a second lecture of your text.
- disabled 7y agoHIPAA anonymized data sets can be combined with any other data set(s) to reidentify the individual, and it is 100% legal to do so. In fact, data brokers (there are 4,000-8,000 of them in the US) will sell lists of people with, for example, 150 columns of data tied to them, with one of the columns being "presumed medical conditions". Social media companies and other marketers use these lists.
- dzader 7y agohuh TIL. Seems like HIPAA should changed to account for this type of situation as it seems like corporations can't be trusted to do the right thing
- dragonwriter 7y agoIn theory, HIPAA anonymized data sets should be nearly impossible to reidentify in combination with any other data set. In practice, that's probably still true for “safe harbor” deidentification, but less true for “expert determination” deidentification [0] that doesn't need the safe harbor rules. The latter option should be eliminated. [0] https://www.hipaajournal.com/de-identification-protected-health-information/ https://www.hipaajournal.com/de-identification-protected-hea...
- disabled 7y agoThis is naive. Read spooky23's posts and the links posted by him. It is a horror story and a huge violation of their privacy: https://news.ycombinator.com/item?id=20183968 https://news.ycombinator.com/item?id=20183968 You can find more details about the situation by just searching for: "Enfamil" site:news.ycombinator.com Then on the news.ycombinator.com URL ctrl/command + f "Spooky23" Anyways it is extremely bad.
- dragonwriter 7y agoThe practice spooky23 reports in the thread you cite appears to be blatantly illegal, and the assurance that it was not came from someone who was paid to protect the company; no complaint was made to anyone responsible for enforcing the law. That's probably the biggest problem with HIPAA, not the law or supporting regs (which have problems, like the one I address upthread), but that most people's first and only complaint of a problem will be to the wrongdoer themselves, not anyone with an interest in enforcing the law. (In Spooky23’s case, there was some effort to go beyond that, but not to an entity actually responsible for enforcing the law in question, or even an agency of the right sovereign entity.) In any case, while the practices spooky23 raises are, legal or not, a real concern, they in no way justify characterizing my criticism of the specific problems with HIPAA deidentificationn rules as naive in the context of a pre-existing discussion of reidentification of deidentified data (which is a completely different issue than sharing, legally or not, data which is not deidentified as is the issue in spooky23’s case.) Again, it's a real issue, just not a germane one to where it was agressively thrown into the discussion.
- dekhn 7y agoI am not so certain about this. SPecifically, the claim that HIPAA anonymous datasets can be used to reidentify- yes, we know this is technically possible. But, the implication that's it's legal- I don't think that is specifically correct. By the terms of the law (of which I am far too familiar), if you did this you would generate PHI, which would fall under the privacy rule (and could not be resold). I don'tknow the specifics about the data brokers you're describing, this is a huge and complicared area, but I think it's correct to say that companies cannot re-identify de-identified data and then resell it as identified data, legally, under HIPAA.
- deleted 7y ago[deleted]
- dragonwriter 7y ago> By the terms of the law (of which I am far too familiar), if you did this you would generate PHI You can't generate PHI if you aren't a covered entity. > By the terms of the law (of which I am far too familiar), if you did this you would generate PHI You are wrong. If an entity that is not a covered entity acquires deidentified data and reidentifies it, it can do whatever it wants with it under HIPAA.
- dekhn 7y agoWouldn't the entities you're describing be Health Clearinghouses? """Health Care Clearinghouse – A public or private entity, including a billing service, repricing company, community health management information system or community health information system, and “valueadded” networks and switches that either process or facilitate the processing of health information received from another entity in a nonstandard format or containing nonstandard data content into standard data elements or a standard transaction, or receive a standard transaction from another entity and process or facilitate the processing of health information into a nonstandard format or nonstandard data content for the receiving entity.""" My read is that the entities I'm describing would fall under this. If you can point to a specific example which you believes violates this (not an anecdote, I'm talking about investigative journalism or a court case or an academic with credentials in this area), I'd love to hear about it.
- fuzz4lyfe 7y agoThe constitution protects against warrantless search and seizure specifically against "their persons, houses, papers, and effects". Courts in overwhelming number interpreted that to mean cops can take paper money from you without a warrant. You trust them to do the right thing for HIPAA in regards to a multi billion dollar enterprise?
- dzader 7y agohope they would, yes. trust them to, no.
- roywiggins 7y agoHIPAA governs entities ("Covered Entities"), not data. If you have data but you're not a covered entity, you're probably not governed by HIPAA requirements. https://privacyruleandresearch.nih.gov/pr_06.asp https://privacyruleandresearch.nih.gov/pr_06.asp