4 ms·
I think you misunderstand HIPAA. As long as they have a business associate agreement with the pharmacies and serve some vaguely care-adjacent purpose, the pharm
by nosuchuser2 7y ago
I think you misunderstand HIPAA. As long as they have a business associate agreement with the pharmacies and serve some vaguely care-adjacent purpose, the pharmacy can share your data with them without your knowledge or consent.
- SamBam 7y agoI can't tell if you're being cynical or serious, but if the latter I can't see how this is correct. From "Pharmacy privacy Requirements here [1], I don't think "business associate agreement [with] some vaguely care-adjacent purpose" meets the standards for information-sharing. Rather the information must be being shared as part of specific treatment for a patient (discussing actual care) or payment. [1] https://www.uspharmacist.com/article/hipaa-privacy-security-and-pharmacy-information-technology https://www.uspharmacist.com/article/hipaa-privacy-security-...
- rlucas 7y agoGP comment is being deadly serious and not at all cynical or sarcastic. HIPAA is a fig leaf. Cardboard covers on clipboards to inconvenience the nurses and receptionists, but a unencumbered infobahn for anyone who touches the money to drive straight through. For decades, every visit, test, procedure, and medication you've ever had paid for by a health insurer in the US got dumped straight into MIB, where any insurer could look at it. HIPAA functionally changed this not a whit.
- jklein11 7y ago> HIPAA has a rule that permits disclosure of PHI for health care operations, treatment, and payment. I think this is what the GP was referring to. It's not just for care but for payment and operations too. A few operational examples, in the case of pharmacies, they must make sure that a patient doesn't fill the same prescription twice. Health insurance companies receive clinical data from health care providers for the purposes of HEDIS reporting. Don't forget, the second P in HIPPA is portability.