3 ms·
Handling confidential patient data does not necessarily mean the organization is a covered entity under HIPAA. One of the organizations I work with receives, st
by techwizrd 4y ago
Handling confidential patient data does not necessarily mean the organization is a covered entity under HIPAA. One of the organizations I work with receives, stores, and uses significant amounts of confidential patient data, but they are not a covered entity under HIPAA (although they are covered separately under the Privacy Act).
- lmkg 4y agoYou are correct, but despite the article's misunderstanding of HIPAA they are covered by it. The incident is being investigated by HHS, as opposed to the FTC who dealt with the (non-HIPAA-covered) GoodRx incident from like yesterday. According to HHS incident listing[1], the are a Business Associate. This means they handle patient data because they are contracted to do so by a HIPAA-covered entity. I've never heard of Cerebral before (and hopefully I won't again), but that likely means that their customers are the hospitals. [1] https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
- jonathankoren 4y ago> I've never heard of Cerebral before (and hopefully I won't again), but that likely means that their customers are the hospitals. Cerebral is a mental health therapy app, but unlike most apps, they also prescribed medicine until very recently. They stopped after the FDA started investigating them for being a pill mill for schedule II controlled substances like adderall (ie amphetamine salts) https://www.theverge.com/2022/5/9/23063356/cerebral-telehealth-prescriptions-investigation-adhd-adderall-doj-dea https://www.theverge.com/2022/5/9/23063356/cerebral-teleheal...
- matheusmoreira 4y agoA corporation prescribing amphetamines? No doctors involved at all? How is that possible?
- prepend 4y agoDoctors were involved all right, thus the “pill mill” part.
- colechristensen 4y agoCovered entities are required to enter into BAA (Business Associate Agreement) contracts when they let other entities handle protected data. Those agreements basically say HIPAA rules and more have to be followed. You do this, for example, with AWS for your infrastructure, any other service that might be exposed to patient data, etc. With a broad perspective, these secondary entities are covered by HIPAA and it's rules, it's just technicalities with how this happens that makes a distinction. In other words you can't circumvent HIPAA by having a third party process your data. You can however, circumvent the spirit of HIPAA and what most people would expect for data privacy by "deidentifying" your data and monetizing it in one of many ways which are wholly inadequate and usually reversable without much effort.
- time0ut 4y agoRegarding de-identification, are you talking about the expert determination method?