3 ms·
Can you provide a link the statute or other ratified text that you're basing your "health data" categorization on? By the way, HIPAA privacy rules regulate the
by modriano 4y ago
Can you provide a link the statute or other ratified text that you're basing your "health data" categorization on?
By the way, HIPAA privacy rules regulate the use and disclosure of Protected Health Information (PHI) in healthcare treatment, payment and operations by covered entities.
Per this CDC FAQ [0]:
"""
What information is protected?
All medical records and other individually identifiable health information used or disclosed by a covered entity in any form, whether electronically, on paper, or orally, are covered by the final rule.
For what disclosures and uses must consent be obtained by a provider?
The Privacy Rule states that:
In general, “[a] covered health care provider [with a direct treatment relationship] must obtain the individual’s consent,…prior to using or disclosing protected health information to carry out treatment, payment, or health care operations.” (See section [§] 164.506, 65 Federal Register [F.R.] p. 82810, for complete requirements.)
"""
Non-covered entities, like commercial data brokers, are free to sell PHI-containing data (assuming they aren't contractually prevented from doing so), and unless the data said broker sells is from a covered entity, no plausible interpretation bars the CDC from buying data available to anyone.
> Would you be okay if the CDC purchased data from period-tracking apps to track periods? Or how many bottles of soap I purchase in a year? Or how much booze everyone buys?
Legally? Yes, unambiguously. Morally? Depends on what they're do with their analysis. If it's for disease control and/or harm prevention, that seems to fall squarely within their scope.
[0] https://www.cdc.gov/nhsn/hipaa/index.html https://www.cdc.gov/nhsn/hipaa/index.html