4 ms·
I worked in three different healthcare technology companies (for doctors, pharma, and insurance). 1. In not a single case was compliance with HIPAA rules ever
by goopthink 4y ago
I worked in three different healthcare technology companies (for doctors, pharma, and insurance).
1. In not a single case was compliance with HIPAA rules ever a cost center beyond the initial project to implement controls, and that itself wasn’t a huge project. For most organizations, compliance with the guidelines is simply good data security. It’s like calling any internet security expensive and unnecessary.
2. Doctors can share data. They have tools to share it in their EMRs, and there are no restrictions to sharing it with other healthcare providers during the course of care.
3. The security and privacy rules are almost entirely about the preventive of public, accidental, or unauthorized disclosure, and also about giving patients access whatever data you hold on them.
4. Why would newspapers want to publish random people’s healthcare information? Unless it was part of a piece targeting a famous/influential person or medical practice, in which case yes, if they access and publish individuals’ healthcare information without consent, that’s a breach of privacy that can be challenged in court. The law isn’t about the damages per se, it’s about the breach of privacy and confidentially.
- Ferrotin 4y agoIf you were right, we wouldn’t see comments like this one: https://news.ycombinator.com/item?id=6619188 https://news.ycombinator.com/item?id=6619188
- goopthink 4y agoThat’s a comment from 2013, now 9 years ago. Since then, healthcare technology has really changed. Compliance and auditing are pretty standard with easy to follow playbooks, and there are plenty of off the shelf tools HIPAA-compliant as soon as you sign a BAA with them. If you’re in health tech, this is the floor, not a high bar. That said, there can be a few times when your comment accurately describes what’s going on: - a non health tech vendor needs to comply with a healthcare client’s needs and they are navigating HIPAA and HITECH for the first time. - this is often paired with a situation where the company never refactored their SaaS software past mvp prototype phase and so they have no logging or controls and effectively need to rebuild their entire system to be security first, and healthcare regulations are just one of the factors they need to consider as they expand markets they service. - a company is concurrently trying to get SOC and/or other certifications. Those get pretty intense. For situations 1 and 2, that’s when a lot of vendors will explicitly say they aren’t HIPAA compliant and choose not to serve healthcare partners (vendor evaluation in healthtech is a pain in the butt because of that). For situation 3, yes, that’s a pain. My own team went through that and it was a year-long process. That said, there is an initial upfront cost with regards to documentation. However what most people complain about are the requirements to retrain all employees semi-annually on data privacy and protection best practices, which kills a full day or two of company productivity.