4 ms·
The top comment here is very reasonable, but I still think the application of HIPAA has been a giant mess, reflecting a disdain toward patients similar to every
by macksd 3y ago
The top comment here is very reasonable, but I still think the application of HIPAA has been a giant mess, reflecting a disdain toward patients similar to everything else in the US healthcare system.
I've ranted on here plenty about how often I've dealt with incorrect bills, and HIPAA plays into that as well. My private information can be shared to "traveling doctors", it can be shared with woefully incompetent contractors who handle billing (or, pretend to), and I received a notice last year that my information had been involved in a data breach and I'm not expecting any compensation. When I had to get a very private and sensitive part of my body imaged, they'll gladly announce to the waiting room my name and what procedure I'm there for, even though it's a rather private and sensitive part of my body - very similar to the shared room concern. I don't care that the people in that room aren't likely to misuse my healthcare information, I don't want them knowing where I found a lump anyway.
And yet HIPAA is often cited to me over the phone as the reason why we can't seem to get incorrect bills figured out for my dependents. It doesn't seem to me that HIPAA actually does much to protect my privacy, but it sure gets used to obfuscate things when there's a problem.
- jliptzin 3y agoI once went to the dermatologist, the doctor left the room briefly and had the computer screen open with everyone’s full name and reason for the visit that day…could see who was there for genital warts, Botox, etc. I don’t think anyone should expect that their health info remains private at any point
- catchnear4321 3y agotwo seconds to clear the screen. a few dollars for a privacy shield. your doctor was more than a little careless and, knowingly or not, relied on you to not cross any lines. if that’s not concerning to you, fantastic… but for some reason you didn’t name the doctor, perhaps because you know others disagree. nor did you name the patients. huh. guess your doctor made a safe assumption about you. who else saw the warts list that day?
- DoreenMichele 3y agoWhat your doctor did is actually a HIPAA violation. He's a covered entity and securing computer screens is a standard precaution for such. In reality, a lot of doctor's offices are not well versed in HIPAA because many are de facto small businesses. Large hospitals and insurance companies generally have better knowledge of HIPAA and HIPAA compliance.
- jliptzin 3y agoI just wish we would all stop pretending that everyone's medical info is protected when it clearly isn't...so now we have the worst of both worlds. All the red tape of HIPAA compliance with no actual privacy anyway. And it's plenty of red tape. I have to now find a FAX machine to send test results to a doctor, because according to him that's the only HIPAA compliant method that he accepts, but the sending doctor doesn't have a fax machine.
- DoreenMichele 3y agoWhen I was in my teens, I chose to go on birth control pills when I became sexually active. Years later, I learned that the pharmacist was a friend of my mother's and told my mother I was on the pill. Fortunately, my mother bit her tongue and said nothing to me until years later and just was glad I was not being stupid and would not end up pregnant out of wedlock. It could have gone really bad places for me if my mother were inclined to be abusive about it. These days, a pharmacist is more likely to think twice before sharing that kind of info because it's illegal to do so and it could come back to bite them big time. HIPAA also helps protect people from discrimination who have medical issues like STDs -- which aren't always sexually transmitted or may be transmitted because someone was assaulted, but some people will just be judgy and not give you the benefit of the doubt and it's a nightmare to have to defend your virtue and tell random strangers "I'm not a whore. I don't sleep around casually. I was raped at gun point." or some such. Sorry it's such a pain in the ass for you. It's something that helps prevent casually ruinous oversharing for some people.
- meetingthrower 3y agoHad an emergency room visit for a somewhat bloody mishap with my son (he's ok.) The resident texted the on call surgeon pictures of the problem from his personal phone to determine if the surgeon should come in for a surgery. The pictures I saw on his phone of other patients as he set up the text were a hellscape of blood and gore!
- motohagiography 3y agoAgreed, the individual records are not specifically secret. The regulations are to prevent unauthorized disclosure and misuse. Unfortunatly that leaves a lot of leeway. The major EMR vendors are all aggregating patient data in cloud services and taking it across borders to where there is no transparency for what is being done with it. The regulations were written with a 90's understanding of technology. A more appropriate regulation today would be to create a category of legally privileged PHI that is strictly inadmissable in legal proceedings and with heavy fines for unauthorized use and disclosure. However, I don't see privacy legislation getting any better as the people inside govt and academia absolutely hate privacy as a concept because they are the specific targets of limiting their discretion about whose data they can snoop. We're in an era of institutional capture by people without ideals or principles, and it's probably unwise to expect altruistic public interest policy like 90's-style privacy legislation from any of them anytime soon.
- potatoman22 3y agoIn the medical field, the academics who "snoop" your data are doing so to conduct analyses and build models to improve your care.
- motohagiography 3y agoAsk them how they feel about having their names and the names of the people they hire attached to queries of PHI in aggregated health information repositories, and whether those people have had the level of background checks that public service staff who typically do this have had. Then ask them whether they will bear any accountability for losing the data they are entrusted with, have their REB decisions subject to freedom of information, or be subject to consent directives by patients, and why they engage big-N consulting firms to misrepresent system design on their behalf. Then ask them whether the research is restricted to clinicial and biological research, or if their "research" includes providing data people in the social sciences. Technically, they are building models to publish or perish, establish data feifs in their institutions for attracting grant money, and to support policy objectives for the revolving door between gov and academia and some troubling third party NGOs, with "care," being a distant abstraction. The academics I encountered doing privacy work for PHI data sets seemed to be interested in everything except responsibility and stewardship. My care indeed.
- deleted 3y ago[deleted]
- jancsika 3y ago> And yet HIPAA is often cited to me over the phone as the reason why we can't seem to get incorrect bills figured out for my dependents. That's actually a great reason to refrain from discussing someone else's medical data with you. That it is inconvenient for you is certainly bad, but that is a non sequitur. > It doesn't seem to me that HIPAA actually does much to protect my privacy, but it sure gets used to obfuscate things when there's a problem. If we allowed Bill Handler, Inc. try their hand at securely implementing "for the purposes of this call, pretend I'm someone else," you're going to have TWO_PROBLEMS * NO_OF_DEPENDENTS