3 ms·
My doctor. Or my hospital. Or pretty much anyone in healthcare.
by aneesh 18y ago
My doctor. Or my hospital. Or pretty much anyone in healthcare.
- TomOfTTB 18y agoHeh...Good Luck with that. I work in a facility that provides mental health care to clients. I am in charge of the computers and all the technology. Unfortunately, our primary customer is the county government and they simply will not budge on anything. I’ll give you an example of what I mean. I recently made a very simple proposal which was that we assign clients a confidential number (given to them in person) and have them generate their own password. They could then view their records online using that number and password. But...and this was the important part... no identifying information (such as name, SSN, etc...) would ever be transmitted over the web. None. The number would be transmitted to us, matched up internally, and then treatment data would be sent back without any identifying pieces of info. No name, SSN, etc... would ever leave our firewall. In addition we’d still use secure connections through SSL, valid certificates, etc... As you can probably guess I was shot down cold by the county. Transmitting data over the internet to private clients is not secure under any circumstances according to HIPAA (so they said, I don’t agree). These kinds of policies are why every medical professional fears transmitting data in any way. I mean, if the government says it’s insecure than you’re just opening yourself up for a lawsuit if you ever try to give access. Privacy is important and I’m not against err-ing on the side of caution to a certain extent. But when fear of lawyers and fear of the Government over power common sense it’s a tragedy and that is exactly where we are now.
- jgilliam 18y agoScrew privacy, I'd rather the whole world know what's wrong with me... maybe they can fix it! Make it searchable and put my email address at the bottom.
- rokhayakebe 18y ago+1. I think if most people had the same attitude about their own problems, specially in the matters of health and finance, we would only benefit from it.
- tptacek 18y agoThat would be true if most employers (or procurement departments) were enlightened. Most, in fact, aren't.
- ambition 18y agoWhat about embarrassing problems with already-known fixes? Or easily-diagnosed but hard-to-cure embarrassing problems? I can't imagine a patient would benefit from the world finding out they had syphilis.
- wyday 18y ago> maybe they can fix it! Millions of newbie programmers have this exact thought. This is why you see countless forum posts with chunks of code and a note like "Something's wrong, can you guys fix it?" No programmer with experience is going to waste their time. Similarly, no doctor is going to waste time doing pro bono work to fix your medical problems.
- smokey_the_bear 18y agoI find people on forums are usually amazingly helpful and giving of time.
- rokhayakebe 18y agoBut one programmer will fix his problem and share the solution with the rest of the world.
- teej 18y agountil you get diagnosed with somethig that makes you uninsurable, then you'll wish you had kept it private.
- jgilliam 18y agoyou mean like two bouts with cancer, radiation fibrosis, a bone marrow transplant, and a double lung transplant? http://checkonjim.com/ http://checkonjim.com/
- sam_in_nyc 18y agoYou have to understand that unless you've got a name like Bill Gates, they're probably not going to put in the effort to understand what you're pitching. You might describe the most perfect system, but all they hear is "complicated computer stuff that might get me in trouble later on"
- TomOfTTB 18y agoI was talking to the CIO of the County so I'd hope that's not the case. Though sadly I'm not confident enough to say that for sure.
- sam_in_nyc 18y agoThat stinks. It bothers me that this is the way the world works.
- tptacek 18y agoI think your employer is making the right call. First, assigning a confidential number is a step in the right direction, but it isn't secure; simple traffic analysis (for instance, via a database flaw) will correlate IDs to recent activity, or to a specific visit (say by a tailed car). Second, any number of other vulnerabilities anywhere on the Internet could coerce a browser to give up the unique IDs assigned to your site, as would any physical compromise of a user's computer, however brief (like, 5 seconds with a malicious USB stick). Third, your employer would face almost unlimited liability in the event of a mass compromise; they've probably insured themselves against HIPAA violations, but compromise of stigmatizing mental health information is easy to tie to material harm --- far more so than a credit card number, which can at least be revoked. Using SSL and firewalls doesn't mitigate the core problem, which is that any false step with the application that serves this information cost cost them tens of millions of dollars. This is a rare instance where I see a draconian regulation actually working to the benefit of consumers.
- TomOfTTB 18y agoThe problem with your logic is that it invalidates every security measure. The reality is this: If the client’s browser or the server’s infrastructure is compromised than there’s no security measure that will prevent a system from being compromised. Think about it. Login info has to get in somehow and if someone has unlimited access to either the system that enters that data or the system that authenticates it how would you possible prevent a security breach? So the end result of your concerns is that there’s just no way to share medical information.
- tptacek 18y agoSo, three responses: First, yes, there's no secure way to share medical information. We should recognize that, and by doing so, I think you'll see my argument about your employer being right is pretty strong. Second, my argument isn't the slippery slope you're making it out to be. In fact, there are likely scenarios in which an application flaw exposes your database, and likely scenarios in which XSRF/XSS flaws will coerce users into exposing medical information. My argument does not depend on some hypothetical killer zero-day bug. Finally, I'm not advocating a world in which we don't provide access to medical information. I'm just saying, there's no way to do it casually. Any project that does it is going to need a steering committee, and special insurance.
- menloparkbum 18y agoTransmitting data over the internet to private clients is not secure under any circumstances according to HIPAA (so they said, I don’t agree). Kaiser Permanente must not be worried about it, since I can see all my blood test results, appointments, correspondence with my doctor, prescriptions, etc when I log into members.kp.org.
- tlrobinson 18y agoMy hospital has an online portal where you can access test results and message doctors... so surely HIPAA doesn't completely prohibit such things?
- tlrobinson 18y agoGood luck... ever head of HIPAA?