4 ms·
Yeah, Name and DOB are covered under HIPAA as PHI.
by dallbee 5y ago
Yeah, Name and DOB are covered under HIPAA as PHI.
- dallbee 5y ago*Meant to say in the United States.
- vrde 5y agoAlberto here, I made the bot. I'm not a lawyer but "codice fiscale" is not PHI. The Italian Data Protection Authority puts codice fiscale under PII[0] and it's not mentioned in the PHI section[1,2,3,4]. [0] https://www.garanteprivacy.it/home/diritti/cosa-intendiamo-per-dati-personali https://www.garanteprivacy.it/home/diritti/cosa-intendiamo-p... [1] https://www.garanteprivacy.it/temi/dati-sanitari https://www.garanteprivacy.it/temi/dati-sanitari [2] https://www.garanteprivacy.it/faq/fascicolo-sanitario https://www.garanteprivacy.it/faq/fascicolo-sanitario [3] https://www.garanteprivacy.it/faq/referti-online https://www.garanteprivacy.it/faq/referti-online [4] https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/9091942 https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb... [edit: formatting]
- corytheboyd 5y agoNice. Really I was just curious, and not trying to throw a wrench in anything, thanks for taking the time to dig that up!
- vrde 5y agoNP! I was actually surprised that in the US a "codice fiscale" would be considered PHI :)
- sakawa 5y agoFirst off, good work! It is always nice to help people deal on this (sicked and badthought) platforms. Anyhow, you should check also if a "tessera sanitaria" is considered a PHI since it includes the "codice fiscale" (and if I recall correctly, it is used often in "fascicoli sanitari" to identify an individual). But well, I'm not a lawyer either.
- berdario 5y agoI'm not aware of how things work in the US, but... Surely if you are only handling Names and DOB you don't have to be HIPAA compliant? I mean, if you have to be HIPAA compliant (your application is medical-adjacent and/or is handling also other bits of data besides Name and DOB), then by correlating the DOB (or name) with the rest of the data, health information could be leaked, and thus you want to protect Name+DOB with the HIPAA standards (even just the fact that a certain name uses a certain app/is inside a certain system might be sensitive). But otherwise... almost every system under the sun is ingesting name+DOB. (there's a case to be made that the system described in the post is a medical app... but again: different jurisdiction)
- corytheboyd 5y agoYeah I think it only really matters if you are trying to be HIPAA compliant, like you said, because you’re also dealing with other health information about people.