5 ms·
Most people don't worry about their data privacy, or else they wouldn't be on FB, take those buzzfeed quizzes, etc. The P in HIPAA stands for Portability. At
by laurenstill 12y ago
Most people don't worry about their data privacy, or else they wouldn't be on FB, take those buzzfeed quizzes, etc.
The P in HIPAA stands for Portability. At it's heart, the act was supposed to guarantee patients have access to their health information, not bring health data liquidity to it's knees.
This is Jonathan Bush, of Athena, testifying (read: ranting) a couple weeks ago about regulations and innovation in healthcare. The big take away is that healthcare specifically sets these rules with incredibly high barriers of entry, and then at the last minute does a complete 180. We've seen it every step of the way with the EHR incentive program, CEHRT, ICD-10, payment reimbursement, etc.
https://www.youtube.com/watch?v=CekfvGDiab8 https://www.youtube.com/watch?v=CekfvGDiab8
- tallanvor 12y agoHow many people do you see posting all of their conditions and the medications they're taking on Facebook? I can't think of any friend who is THAT open. Also, whether or not people care about their privacy doesn't mean it shouldn't be protected. Not just for themselves, but for their family as well. --Let's say I don't allow my medical information to be used, by my brother does. If he has a genetic disease and a potential employer finds out about it, they might decide not to hire me because there's a chance I may have it as well, which could cause problems if it ended up needing treatment. Laws that prevent discrimination are all well and good, but the problem can be proving the reason they decided not to hire you.
- laurenstill 12y agoNever said privacy shouldn't be protected, only that it's not exactly valued by BOTH sides of the equation (and of course, YMMV). Up until recently (Omnibus rule), HIPAA had little practical power in that department from both an audit perspective and a fine/mediation perspective. The largest fine levied? It was for inadequate patient access to their own health information, not a security breach. And even with the new rule, there are currently no regulations surrounding de-identified PHI being used for marketing purposes, research, or sold for whatever other purposes. So now you have data wharehousers like IMS spinning up software dev depts with the specific goal of harvesting patient data. As far as identity vs membership vs attribute disclosure, I linked to a good study below. I find it interesting that there are more comments in the average HN healthcare-related thread than on any of the recent NPRM. Hell, there are more comments here than people who actually showed up for FDASIA. I support regulation in a lot of cases, and feel that that FDA took a reasonable approach to the recent mobile medical device guidelines. What I, and pretty much everyone else (other than the AMA) rails against is the indiscriminate flip flopping of what regulations, standards, etc will be required, and on what time horizon.
- amirmc 12y ago> "Most people don't worry about their data privacy, or else they wouldn't be on FB, take those buzzfeed quizzes, etc." The first part of the sentence is flawed, so the latter doesn't follow. It implicitly assumes that people even understand how things work (they don't, imho) and therefore can make a sound judgment, based on that knowledge. For example, I could argue that people simply don't value their future selves (ie 30+yrs), otherwise they wouldn't be eating all this junk food now and never exercising. In some sense that's true, but it's mainly driven by ignorance.
- deleted 12y ago[deleted]
- rayiner 12y agoFrankly I'm okay with health data being illiquid. Everyone should be absolutely terrified of this data getting into the hands of the same people that try to predict if you are pregnant to sell you crap, or use your credit history or Facebook posts to deny you a job. The future in that direction is "Google Gattaca."
- mcculley 12y agoI'm not. The illiquidity is why different healthcare specialists can't share data about me without resorting to a ten finger interface that leads to transcription errors. I want my general practitioner and my spine specialist to be using the same database for records, test, and scans. I'm okay with being embarrassed if it means living longer and better.
- michaelt 12y agoI wish I believed we could make a database shared between my GP and my spine specialist without my records also being shared with all insurers, employers, marketing companies, security services, medical researchers, credit rating agencies, and anyone who slips any hospital employee a hundred bucks.
- rwallace 12y agoSo do I, but given the world as it is, wouldn't you much prefer some idiot marketing guy spamming you on the basis of your medical records, than a screwup in the chain of communication between your GP and spine specialist leaving you crippled or dead?
- jerf 12y agoYes, of course. But "idiot marketing guy" isn't the worst case scenario, nor is it even the worst plausible scenario. Job loss and inability to get health insurance aren't hypothetical concerns... laws have been written about this because they happen, at scale. While I'm inclined to think the regulations as they stand today are heavy-handed and more expensive than they need to be to get the job done, that doesn't negate the fact that they exist for a reason, a reason that isn't just hypothetical but happened a lot.
- homulilly 12y agoMost people don't understand how data privacy works. A huge number of people don't even realize their Facebook posts can be viewable to the public let alone how that data can be collected, analyzed and shared with third parties. Besides, even the most completely oblivious Facebook users generally don't throw their entire medical history on their wall.