5 ms·
It's surprising that many medical providers don't understand this side of HIPAA. I recently spoke to a department head of oncology who seemed to think patient c
by aabaker99 5y ago
It's surprising that many medical providers don't understand this side of HIPAA. I recently spoke to a department head of oncology who seemed to think patient consent was required for sharing data and was not comfortable sharing their patients' data. What they don't realize is that HIPAA doesn't require consent if the data is de-identified and so their organization can or is sharing their patients' data anyway.
- SkyPuncher 5y agoThe problem is risk. HIPAA allows for a lot of things that feel like exceptions to the core principles of HIPAA. Many things are vaguely defined as "reasonable" - which changes over time. MD5 was a reasonable password hash - until it wasn't. SHA1 was - until it wasn't. Etc. An article like this can arguably prove that there is no reasonable means of de-identification since multiple data sources can be combined. Combine that with the fact that HIPAA puts pretty high limits on the minimum cohort size that can be associated with a unique identifier and low ROI from actually sharing this data. Many places end up in a position where it's simply not worth the risk to share.
- pitaj 5y agoArguably SHA1 is still reasonable as a password hash, but of course not recommended.