The small box inside Amanda Hubbard's chest beams all kinds of data about her faulty heart to the company that makes her defibrillator implant.The article also discusses issues with health-data-collecting applications for smartphones.
Ms. Hubbard herself, however, can't easily get that information unless she requests summaries from her doctor—whom she rarely sees since losing her insurance. In short, the data gathered by the Medtronic Inc. implant isn't readily accessible to the person whose heartbeat it tracks.
"This is my health information," said Ms. Hubbard, 36 years old. "They are collecting it from my chest."
The U.S. has strict privacy laws guaranteeing people access to traditional health files. But implants and other new technologies—including smartphone apps and over-the-counter monitors—are testing the very definition of medical records.
Born, like other comic book characters, out of an otherwise trivial but life-changing animal bite, the Rabid Librarian seeks out strange, useless facts, raves about real and perceived injustices, and seeks to meet her greatest challenge of all--her own life.
Translate
Showing posts with label HIPAA. Show all posts
Showing posts with label HIPAA. Show all posts
Thursday, November 29, 2012
Of concern
Heart Gadgets Test Privacy-Law Limits
Thursday, October 11, 2007
If you haven't been to a doctor, a hospital, or pharmacy in quite awhile
then maybe you don't know about HIPAA. The rest of us get all those privacy procedures statements at least once and sometimes everytime we go. But those of us who work in those environments--even those of us who are non-clinical--gets lots of training on what HIPAA means for violations. I give you the Department of Health and Human Services' summary of HIPAA (a PDF):
So when I hear stories of Britney Spears' experiences in rehab, etc., I have to wonder where those leaks are coming from (supposed friends, or health workers hoping to make a quick buck?) Fast foward to George Clooney's recent brush with death in a motorcycle accident. The hospital where he was treated, Palisades Medical Centre, in response to leaks to the press regarding his condition, has suspended 27 of its workers for a month without pay and has admitted that as many as 40 staffers accessed his records for no reason related to his care. People are debating as to whether that was harsh; even Mr Clooney said he'd rather it be resolved without suspensions. But the hospital was put in a very bad situation by its employees, all of whom presumably had the training to know that what they were doing was both wrong and illegal. I don't know if the law requires the object of the privacy violation, the injured party if you will--no pun intended, to make a complaint to start the process of sanctions, or if it can be done if it becomes known that violations happened. (Certainly you can start the process through a complaint if your health information privacy has been violated; information for doing so is on that website). Theoretically anyway the hospital is facing a few thousand dollars in penalties if they don't correct the problem. This is how they are doing so, and they are right to. And in these days of electronic medical records, it's easier to track who had access and who abused it.
Curiosity is one thing, and I think it's natural that some might have taken a peek where they ought not have. But whoever leaked the information to the press should certainly be penalised--and that's easier to find out these days, too, even with reporters protecting their sources. If anyone is found to have wilfully imparted the information for money, the penalties to the individual become very, very bad. In other words, doing so is stupid, one of those things people do because they don't think they'll get caught at it. I don't know if any of those workers leaked the information for money--it might just have been hearsay through a grapevine as people told friends and family, for example. But HIPAA isn't anything to take chances with, and most medical professionals also have rules of ethics that should cover this without the need of sanctions. So I can't really feel sorry for those suspended unless they turn out not to have done it--and I'm afraid that they'll have to go to court to prove they didn't deserve it.
Civil Money Penalties. HHS may impose civil money penalties on a covered entity of $100 per failure to comply with a Privacy Rule requirement.88 That penalty may not exceed $25,000 per year for multiple violations of the identical Privacy Rule requirement in a calendar year. HHS may not impose a civil money penalty under specific circumstances, such as when a violation is due to reasonable cause and did not involve willful neglect and the covered entity corrected the violation within 30 days of when it knew or should have known of the violation.
Criminal Penalties. A person who knowingly obtains or discloses individually identifiable health information in violation of HIPAA faces a fine of $50,000 and up to one-year imprisonment. The criminal penalties increase to $100,000 and up to five years imprisonment if the wrongful conduct involves false pretenses, and to $250,000 and up to ten years imprisonment if the wrongful conduct involves the intent to sell, transfer, or use individually identifiable health information for commercial advantage, personal gain, or malicious harm. Criminal sanctions will be enforced by the Department of Justice.
So when I hear stories of Britney Spears' experiences in rehab, etc., I have to wonder where those leaks are coming from (supposed friends, or health workers hoping to make a quick buck?) Fast foward to George Clooney's recent brush with death in a motorcycle accident. The hospital where he was treated, Palisades Medical Centre, in response to leaks to the press regarding his condition, has suspended 27 of its workers for a month without pay and has admitted that as many as 40 staffers accessed his records for no reason related to his care. People are debating as to whether that was harsh; even Mr Clooney said he'd rather it be resolved without suspensions. But the hospital was put in a very bad situation by its employees, all of whom presumably had the training to know that what they were doing was both wrong and illegal. I don't know if the law requires the object of the privacy violation, the injured party if you will--no pun intended, to make a complaint to start the process of sanctions, or if it can be done if it becomes known that violations happened. (Certainly you can start the process through a complaint if your health information privacy has been violated; information for doing so is on that website). Theoretically anyway the hospital is facing a few thousand dollars in penalties if they don't correct the problem. This is how they are doing so, and they are right to. And in these days of electronic medical records, it's easier to track who had access and who abused it.
Curiosity is one thing, and I think it's natural that some might have taken a peek where they ought not have. But whoever leaked the information to the press should certainly be penalised--and that's easier to find out these days, too, even with reporters protecting their sources. If anyone is found to have wilfully imparted the information for money, the penalties to the individual become very, very bad. In other words, doing so is stupid, one of those things people do because they don't think they'll get caught at it. I don't know if any of those workers leaked the information for money--it might just have been hearsay through a grapevine as people told friends and family, for example. But HIPAA isn't anything to take chances with, and most medical professionals also have rules of ethics that should cover this without the need of sanctions. So I can't really feel sorry for those suspended unless they turn out not to have done it--and I'm afraid that they'll have to go to court to prove they didn't deserve it.
Subscribe to:
Posts (Atom)