3 ms·
That's incorrect. HIPAA compliance only requires consent between patient and provider. Provider can choose to share that data with other providers. This is how
by darkpicnic 7y ago
That's incorrect. HIPAA compliance only requires consent between patient and provider. Provider can choose to share that data with other providers. This is how Google purchased medical records by partnering with Ascension.
If you are covered under 42 CFR Part 2, then it would not be allowed because the patient has to give consent to ALL parties.
- missosoup 7y ago> Provider can choose to share that data with other providers Not without express consent. The default is 0 hops. Same rules applies for banking info. You want to share with someone else? You have to ask for consent again. A lot of people did unknowingly sign up to have their data shared like you say though, which I think is a regulatory failure more than anything else.
- JohnFen 7y agoIn the US, HIPAA allows your medical data to be shared without your express consent as long as certain conditions are met. Generally, they are that the data must be used to help your provider meet a legitimate medical or business need, and they have to have a contract with the entities they share with that constrains their use of that data.
- darkpicnic 7y agoHIPAA compliance has a lot of ambiguity. You are correct if, say, your employer requested medical records from your doctor. However, any entity that works with your provider that is facilitating its business can still get your data without your consent. JohnFen's comment is correct. This is why 42 CFR Part 2 was created; HIPAA was too loose with patient data.