4 ms·
hmmm, It made me realize that I may be on the verge of breaching the HIPAA laws. I'm developing an app on Google App Engine (which afaict won't sign a BAA), thi
by hippaway 13y ago
hmmm, It made me realize that I may be on the verge of breaching the HIPAA laws. I'm developing an app on Google App Engine (which afaict won't sign a BAA), this app will help users with storing and interpreting their data (some of which may be considered health data: like all the biometric data). Anyone knows if I have to comply to HIPAA in spite of not being an health provider myself?
- yannk 13y agoAccording to: http://www.cms.gov/Regulations-and-Guidance/HIPAA-Administrative-Simplification/HIPAAGenInfo/Downloads/CoveredEntitycharts.pdf http://www.cms.gov/Regulations-and-Guidance/HIPAA-Administra... As long as you don't accept payments you should be fine... But talk to your laywer? (Yeah I know...)
- hippaway 13y agoI wish legal counsel was more easily accessible.
- jason_wang 13y agoTake a look at this article: http://www.hhs.gov/ocr/privacy/hipaa/understanding/coveredentities/De-identification/guidance.html http://www.hhs.gov/ocr/privacy/hipaa/understanding/covereden... The definition of who needs to comply with HIPAA has more to do with who has contact with protected health information and less about who the company is (e.g., a hospital or not).
- hippaway 13y agoThis document has some bullshit example: Identifying users by zipcode and gender? huh? "Imagine that a covered entity is considering sharing the information in the table to the left in Figure 3. This table is devoid of explicit identifiers, such as personal names and Social Security Numbers. The information in this table is distinguishing, such that each row is unique on the combination of demographics (i.e., Age, ZIP Code, and Gender). Beyond this data, there exists a voter registration data source, which contains personal names, as well as demographics (i.e., Birthdate, ZIP Code, and Gender), which are also distinguishing. Linkage between the records in the tables is possible through the demographics. Notice, however, that the first record in the covered entity’s table is not linked because the patient is not yet old enough to vote."
- sp332 13y agoIt's not bullshit. Here's the paper from 2000: http://dataprivacylab.org/projects/identifiability/paper1.pdf http://dataprivacylab.org/projects/identifiability/paper1.pd... From the abstract: 87% (216 million of 248 million) of the population in the United States had reported characteristics that likely made them unique based only on {5-digit ZIP, gender, date of birth}.
- hippaway 13y agothe date of birth is not cited in the example. Only the age. Seems like a stretch of an example to me.
- yannk 13y agoThis document states: "HIPAA defines a covered entity as 1) a health care provider that conducts certain standard administrative and financial transactions in electronic form; 2) a health care clearinghouse; or 3) a health plan" which is explained by the flowchart in the document I linked in my other comment. So as long hippaway app doesn't take payments for health services (which you can't do unless you are a certified health provider), I guess she is fine. Yes?
- NovemberWest 13y agoIf the data is stored on their device and you have zero access to it, I do not see any problem. Individuals have the right to do as they see fit with their own PHI. Background: I paid insurance claims for over five years. Thus, I received HIPAA training annually. Feel free to email me.
- hippaway 13y agonah, data is stored in GAE. Thanks for your offer.