4 ms·
How is this not a HIPAA violation??
by 1024core 1y ago
How is this not a HIPAA violation??
- runjake 1y agoWho says it's not? It looks like a HIPAA violation to me.
- SapporoChris 1y agoWhile I wish it was a HIPAA violation, I am not sure it qualifies. "The HIPAA standards apply to covered entities and business associates “where provided” by §160.102. Covered entities are defined as health plans, healthcare clearinghouses, and healthcare providers who electronically transmit PHI in connection with transactions for which HHS has adopted standards" https://www.hipaajournal.com/what-is-a-hipaa-violation/#whatishipaaandwhodoesitapplyto https://www.hipaajournal.com/what-is-a-hipaa-violation/#what... Covered California is a health insurance marketplace. It is not an Insurance Carrier or an Insurance Clearing house. Perhaps they're guilty of something else?
- spacemadness 1y agoSounds like HIPAA needs some adjustments made to cover marketplaces.
- AStonesThrow 1y agoHIPAA is not designed to protect consumer or patient privacy. That is a silly fiction that voters and constituents believe in order to prop up the legislation. HIPAA is designed to protect the privacy of providers, clinics, hospitals, and insurance carriers. HIPAA is designed to make it maximally difficult to move PHI from one provider to the next. HIPAA is designed to make it maximally difficult for plaintiff attorneys to discover incriminating malpractice evidence when suing those providers. HIPAA is a stepping-stone to single-payer insurance. HIPAA also makes it maximally difficult to involve other people, providers, and entities in your health care. No entity under HIPAA can legally divulge the slightest tidbit to your brother, your parents, or anyone who contacts them, unless an ROI is on file. Those ROIs are a thing you have to go pursue on your own -- they are never offered or suggested by the provider -- and those ROIs will expire at the drop of a hat -- and you never know if an ROI is valid until it is tested at the point of that entity requesting information.
- deathanatos 1y agoIANAL, but I work in healthcare, and a portion of my work is trying to ensure obligations under HIPAA are met. > HIPAA is designed to protect the privacy of providers, clinics, hospitals, and insurance carriers. No? I can practically quote the law directly here, though it is a bit dense: > A covered entity or business associate may not use or disclose protected health information, except as permitted or required by this subpart or by subpart C of part 160 of this subchapter. I.e., the privacy of your, the patient's PHI is protected. That's a privacy regulation, and it is talking about and protecting the privacy of patient data, not provider's, etc. > HIPAA is designed to make it maximally difficult to move PHI from one provider to the next. It does no such thing. But [1]. > HIPAA is designed to make it maximally difficult for plaintiff attorneys to discover incriminating malpractice evidence when suing those providers. Plaintiffs can divulge their own PHI directly to lawyers. Otherwise, no, lawyers don't get to access random people's PHI … but that's directly because the privacy of that PHI is protected. Further, one of the exceptions to HIPAA's protections is judicial order … so if plaintiffs can get a judge to agree, they can get a limited window into people's PHI. But … no, they don't just get to see? > HIPAA is a stepping-stone to single-payer insurance. … clearly not, or where is it? > HIPAA also makes it maximally difficult to involve other people, providers, and entities in your health care. People: you're always permitted to divulge whatever you want, to whomever you want, about your own PHI. But no, a doctor cannot divulge PHI to, e.g., an adult's parents without authorization. Again, this is to protect the patient's privacy: for example, so that a woman can keep something medically private from her husband if she chooses, or an (adult) patient can not have nosy parents learning things that are not their business, etc. (Parents/guardians of non-adult children are treated differently, of course. There are other exceptions, and exceptions to the exceptions, but generally, they follow pretty common sense lines.) Providers, entities: again, HIPAA only prevents this without your consent, and that's basically what privacy is. And … you know this: > unless an ROI is on file. (An ROI is a "release of information", for others.) Yes, if you consent, then your PHI can be divulged. This is like the very definition of patient privacy. > Those ROIs are a thing you have to go pursue on your own -- they are never offered or suggested by the provider -- and those ROIs will expire at the drop of a hat -- and you never know if an ROI is valid until it is tested at the point of that entity requesting information. This isn't true, either; I've had providers ask for ROIs, and nothing prevents a provider from taking initiative. (Perhaps you need a better provider.) Yes, to a large extent, you must own your own outcome in American healthcare, but I think this is more a function of other failing in HC than HIPAA. Also, … yes, ROIs are scoped: they're only good for a specific instance of releasing information, i.e., they're not carte blanche to the provider to release your information to the world. Again, that's a privacy protection. In the specific case covered by TFA, upstream is right: it is unfortunate that marketplaces might not be covered entities, and probably should be. This would be a common sense update to the law, so call your congressperson. Were they, HIPAA prohibits what occurred here, and other covered entities have been fined for exactly this type of error/behavior. I.e., HIPAA has prior examples of preventing exactly the badness here! [1] I empathize that moving data between providers is not easy, but this is hardly due to HIPAA, which permits such, assuming patient consent. I'd say this is more a function of providers not adhering to standards like they ought to; I've seen precious little use of FHIR (for others: standardized format for HC data) in my time in the industry, and the state of tech for inter-provider transfers is such that most providers probably do find it easier to just recollect the data they need. Heck, even within a provider, I've witnessed struggles to transfer data.
- Drunk_Engineer 1y agoHowever, it may violate the state's Electronic Communication Privacy Act. https://calmatters.org/health/2025/05/covered-california-linkedin-lawsuit/ https://calmatters.org/health/2025/05/covered-california-lin...
- jeron 1y agothe state will do an investigation on itself and find no wrongdoing
- deleted 1y ago[deleted]
- wrs 1y agoTwo reasons: The marketplace is not a covered entity (it doesn’t provide healthcare or process transactions), and the information is not a medical record (it’s typed in by the user, not generated by a healthcare provider). However, California has its own more general privacy law about using medical information for marketing purposes.
- kjkjadksj 1y agoSo if I fill out my medical record form at the doctors office its not a medical record because me the user filled it out before handing it over the front desk?
- wrs 1y agoBecause you filled it out in the context of interacting with a medical provider, then gave it to them for their records, that is a medical record. (Just like a conversation with your doctor about your history would be.) If you filled out the same form just to keep in your desk drawer for your family’s reference, it would not be. Also, if you ask for a copy of your record, as soon as you take personal possession of it, HIPAA no longer cares about it, because you aren’t a covered entity. (Source: I founded a startup that spent a lot of money on attorneys to confirm this.)
- autoexec 1y agoFilling out forms at the doctor's office is one way they trick you into authorizing them to sell your data and no matter how careful you are about it you can still end up having your data sold. https://www.statnews.com/2023/04/07/medical-data-privacy-phreesia/ https://www.statnews.com/2023/04/07/medical-data-privacy-phr...
- oops_all_buried 1y ago[dead]