4 ms·
HIPPA rules are easily circumvented unless you as a patient are paying attention: I can't tell you how many forms I've opted out of that wanted to explicitly ex
by technofiend 2y ago
HIPPA rules are easily circumvented unless you as a patient are paying attention: I can't tell you how many forms I've opted out of that wanted to explicitly export my data to third parties and partners that are not HIPPA compliant. And at least for my healthcare providers that use MyCharts, they like to make it part of the echeckin workflow, with no option to refuse. So you're forced to go up to the desk to check in and explicitly reject it each and every time. It's a healthcare dark pattern.
And then there are online providers like better health that don't have the option to opt out at all. So you just have to avoid them entirely.
- ipython 2y ago100% this. I just visited an urgent care center yesterday for some strep tests. I was given an electronic signature pad and told to sign for "consent to care". No documentation was given to me on what I was signing - just that I needed to sign. I had to ask for a paper copy of the form I was signing, which was handed to me. That document said that "I acknowledge receiving the privacy notice ..." Was that given to me? Of course not. Asking for that - well let's just say I think I was the first person to ever ask for any of this documentation. I'm sure my information has been shared with 30 other entities - for a strep test. It's insane and unenforceable as a patient who just wants to get shit done.
- andsens 2y agoThe fact that it is even legal to ask patients to sign away their right to privacy boggles the mind.
- hollerith 2y agoThere are already too many restrictive law and rules in the US around healthcare, and here you want to add another restriction.
- alsetmusic 2y agoOk, I’ll bite. List some concrete examples. Otherwise, I have to land on the default that regulation is good and works better than a free-for-all.
- hollerith 2y ago>Ok, I’ll bite. List some concrete examples. How generous of you
- kwhitefoot 2y agoHitchen's Razor: what can be asserted without evidence can also be dismissed without evidence.
- tiahura 2y agoIn the US, adults are generally considered competent to make their own decisions.
- sxg 2y agoIt's mind boggling because I highly doubt it's actually true. I'm not sure where the OP is getting that info. Patients can't waive away HIPAA privacy/security rights. I think the OP is assuming that when healthcare institutions partner with third parties, those third parties are not required to uphold HIPAA. If that's his/her belief, it's 100% false. Third parties associating with healthcare institutions have to sign business associate agreements (BAAs) that require them to uphold the same standard of privacy/security regarding patient data as the first party healthcare institution. There are severe financial penalties for violating HIPAA, and every healthcare institution I've been a part of takes this extremely seriously.
- ipython 2y agoBefore I start, I'm not singling you out- I am happy that you're participating in this discussion and sharing your first hand knowledge. The thing for me is that if HIPAA truly does provide me privacy of my personal information and health care information, why are all of these privacy and consent forms required? Whenever I am handed a form that says "privacy policy" my sense is immediately raised - what is it that they're trying to hide from me through mountains of legalese? When I don't receive one (as was the case in my doctors visit) then I am REALLY on edge. For example, with my health care visit, this thread prompted me to call the listed numbers on the website for the health care provider to discuss their privacy policy. The provider's number dumps you into an IVR that has zero way to reach a human - you must dial an extension, and there is no option for an operator. I ended up calling their headquarters to get a callback from a human. If there are standard mechanisms and policies in place, then we should be able to understand the rules once and never have to sign another form again, because the rules would be clear, unambiguous, and applicable to every health care interaction. If the rules are clear about not waiving HIPAA privacy/security rights, then why have a privacy policy that's three pages of inscrutable legalese that gives a bunch of weasel room for them to "share" information?
- sxg 2y agoNo problem—glad to participate! There's a lot of cynicism that leads to misinformation about how healthcare works, so I'd like to clean that up. Let's attack and fix the broken parts of the system, but we should praise the working parts. I think patient privacy/security is one of the few things the US gets mostly right about healthcare. Regarding the privacy policies: these are created by the legal department and physicians in the department are told to distribute them and get signatures when necessary in order to do things by the book. However, your rights are inalienable and protected regardless of whether you actually receive the policy and sign the appropriate box. If you don't receive the policy, the healthcare institution is on the hook and could face a fine if reported to the DHHS. Things could absolutely be done more efficiently and clearer for patients, but there's a fear in changing things ("if it ain't (horribly) broke, don't fix it"). Trying to improve how privacy policies are disseminated and patients informed could result in an inadvertent violation of HIPAA that results in large fines. So healthcare institutions are disincentivized from trying to improve things here. I reviewed the patient privacy policy for a few large institutions in the US, and it all seems to support what I'm saying. For example, here's NYU's policy on business associates: https://nyulangone.org/files/business-associates.pdf https://nyulangone.org/files/business-associates.pdf NYU has additional policies here: https://nyulangone.org/policies-disclaimers/hipaa-patient-privacy https://nyulangone.org/policies-disclaimers/hipaa-patient-pr.... UCLA Health has similar policies here: https://www.uclahealth.org/privacy-practices https://www.uclahealth.org/privacy-practices. Every institution has essentially the same policies as they're all just a reflection of HIPAA. The only ways in which patient data can be shared with others are if (1) they're involved in your treatment (e.g., your doctor at another hospital), (2) payment purposes (e.g., insurance), (3) health care operations (e.g., third party vendor software like EMRs, PACS, etc.) All are required to be HIPAA compliant if they're covered entities (i.e., healthcare institutions) or sign a BAA with a covered entity that essentially puts the same HIPAA requirements on them. A violation again results in massive fines, C-suite level firings, and expensive legal fallout.
- sxg 2y agoWait—this doesn't make any sense. I'm a physician and have a lot of experience dealing with protected health information. Third parties are required to sign a HIPAA BAA and obligated to uphold privacy/security standards equal to that of your physician and hospital. Can you provide some specific examples of the third parties you're talking about? MyChart itself is a component of Epic (the EMR) and is absolutely HIPAA compliant. Every healthcare institution I've worked with has taken HIPAA and privacy/security regarding patient data extremely seriously. Non-HIPAA compliant vendors are an immediate non-starter and don't even enter discussions when looking at new products.
- technofiend 2y agoSure, next time I find one of the forms I'll snag it for you. It was rather eye catching because it explicitly stated "You're allowing us to share data with third parties and service providers that are not HIPPA compliant." How do I get it to you? I wasn't claiming that MyCharts isn't HIPPA compliant: I was complaining as part of a MyCharts workflow I was presented with a form that wanted me to grant someone the right to send my data to non-compliant organizations, and as I said above explicitly stated so.
- sxg 2y agoMy email is in my profile page. And if you have truly found that the institution is sharing protected health information (e.g., even just names and date of birth) with third parties who have not signed BAAs, that is a lawsuit worth tens of millions plus government fines of $50,000 per piece of compromised data per patient. I highly suspect that there's some misunderstanding or miscommunication here.
- tbyehl 2y agoThe annual HIPAA training I was subjected to for nearly a decade on the EMR provider side of things never brought up these scenarios, but the Privacy Rule does have carve-outs that allow PHI to be transmitted to entities that would not be considered Business Associates, if the patient consents.