4 ms·
Yeah, I'm surprised every healthcare related business doesn't either ban PowerPoint or block this "feature" somehow. HIPAA is a hell of a drug.
by real_dogbert 4y ago
Yeah, I'm surprised every healthcare related business doesn't either ban PowerPoint or block this "feature" somehow. HIPAA is a hell of a drug.
- colechristensen 4y agoHIPAA is tame compared to export control and classified information handling. Single occurrences can get you 7 or 8 digit fines and prison sentences.
- reaperducer 4y agoI'm surprised every healthcare related business doesn't either ban PowerPoint or block this "feature" somehow. I work in healthcare, and the legal department bars me from using Google Analytics for HIPAA reasons. Meanwhile, IT made Chrome the only browser the employees are allowed to use on every Windows machine in the org.
- happythebob 4y agoDid you read the article? I find your jaded sense of cynicism to be different than critical thought. I don't see any proof in the article posted about its claims. It's just very easy to get jaded, cynical people to support the right headlines on social media. Hacker News, be better.
- nocman 4y agoI don't find reaperducer's comment to be jaded or cynical. It sounds perfectly reasonable to me.
- MichaelCollins 4y agoPowerpoint is the raison d'etre of an entire class of middling bureaucrats. They'll fight tooth and nail to protect their turf and preserve their role in society.
- ohbtvz 4y agoCan you point to the provision of HIPAA that this is violating?
- AyyWS 4y agoYeah. The HIPAA data needs to be encrypted and you have to report everyone who has access and you need patient permission to share. HIPAA is bad, but ITAR violations put you in jail!
- SamuelAdams 4y agoIf you work in healthcare you know not to put HIPPA data in PowerPoint slides to begin with.
- criddell 4y agoWouldn't it be easier to ban putting HIPAA protected information into a PowerPoint? We don't ban telephones just because an employee can read patient records over the phone.
- kibwen 4y agoPowerPoint should be banned for other reasons, we're just looking for an excuse. :)
- real_dogbert 4y agoOf course putting ePHI in PowerPoint presentations should be against policy. The thing is, when it does happen, it's almost always inadvertent. Unfortunately, the "oops, my bad" defense isn't valid against violations of the HIPAA privacy rule.
- giaour 4y agoIf you're putting PHI in a presentation, you probably already have HIPAA problems.
- zmmmmm 4y agoDoctors routinely need to present cases to each other. It often involves pictures of the patient and other identifying information that is essential to describe the case in detail. They need some way to do this.
- jayknight 4y agoAny healthcare institution is going to have a Business Associate Agreement[1] with Microsoft. OneDrive is one of the allowed/suggested ways to transmit PHI where I work. [1] https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html https://www.hhs.gov/hipaa/for-professionals/covered-entities...
- zmmmmm 4y agoexactly .... people here suggesting that putting any PHI into an office document is intrinsically a HIPAA violation are bonkers.
- giaour 4y agoIsn't the "Design Ideas" request going to the same Sharepoint server that is storing your doctor's OneDrive? I didn't capture and inspect the traffic myself, but https://support.office.com/client/53c77d7b-dc40-45c2-b684-81415eac0617?NS=PPTIM https://support.office.com/client/53c77d7b-dc40-45c2-b684-81... makes the feature sound like it's built into M365 and not sending data to some centralized web service.
- californical 4y agoSure, but a Word document seems much more likely
- thereddaikon 4y agoHIPAA is prescriptive, not descriptive. It does not lay out specific standards to reach. Only overly vague and broad guidelines. Because of this the industry has more or less developed its own best practices that should be good enough. What this means is that healthcare providers have annual audits performed by third parties who check compliance with these "best practices" which may or may not have any relation to what the lawmakers intended. Its ultimately about checking boxes. yada yada security is hard. You can't write a law that describes a security posture and expect to be relevant for more than a year at most.
- autoexec 4y agoI can't believe how many companies in general are leaking massive amounts of sensitive data to Microsoft. With Outlook alone MS much have an incredible amount of data on nearly every business and an unprecedented amount of insight into what they are doing. Windows 10 has only made the problem worse. The last desktop PC I got from my company's IT department had windows 10 on it and it was configured to send every last keypress to MS. Why they had the Windows 10 keylogger enabled I'll never understand, but at least it was easy enough to disable.