3 ms·
> Were they sending health data The recent guidance from the HHS[0] indicates in many cases installing Google Analytics or the Facebook SDK would be considered
by malisper 4y ago
> Were they sending health data
The recent guidance from the HHS[0] indicates in many cases installing Google Analytics or the Facebook SDK would be considered sending health data to Google or Facebook and therefore be considered a HIPAA violation. From the HHS[0]:
> Tracking technologies on a regulated entity’s user-authenticated webpages generally have access to PHI. Such PHI may include, for example, an individual’s IP address, medical record number, home or email addresses, dates of appointments, or other identifying information that the individual may provide when interacting with the webpage.
[0] https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-online-tracking/index.html https://www.hhs.gov/hipaa/for-professionals/privacy/guidance...
- johndhi 4y agoDoes the guidance only apply to user-authenticated web pages? the article suggests 'the website' is all PHI, which I personally find to be an insane interpretation of HIPAA. edit: I found the answer. it's pretty reasonable. basically, no, HIPAA doesn't apply there.
- atkailash 4y ago[dead]
- malisper 4y ago> Does the guidance only apply to user-authenticated web pages? It depends on if there's health related information on the page. The HHS includes examples of unauthenticated pages where the guidance applies such as pages about a specific health condition or find a doctor pages[0]. [0] https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-online-tracking/index.html https://www.hhs.gov/hipaa/for-professionals/privacy/guidance...
- Nextgrid 4y agoOh the other hand, maybe it should apply, considering that the website is the entry point for the user to the service and that an attacker owning that can trivially redirect the user flow - the same reason why mixed HTTP & HTTPS is considered insecure.
- jjav 4y ago> Does the guidance only apply to user-authenticated web pages? the article suggests 'the website' is all PHI, which I personally find to be an insane interpretation of HIPAA. Someone (anonymous) goes to the website and does a bunch of searches on e.g. cancer or AIDS or anything else they don't want marketing to know about. Afterwards they log in (turns out the person was an existing patient who had a login). But it's all in the same session so now you tied all that search info to a specific account and sent it to adspyware third parties. Solid HIPAA violation. Not my field, but talking to friends in healthcare infosec, this is something that has caused them to be hit with fines in the past. Even in the absence of fines, clearly a privacy violation.