Hacker News new | ask | show | jobs
by crankylinuxuser 3129 days ago
Doea medical data not talked about in a medical setting trigger HIPAA?

(Like me talking that I'm type 2 diabetic?)

3 comments

If you talk about it outside a privileged context, you're implicitly waiving the privacy protections.

For example, if you run into your physician in public, and say, "Hi Doc. Have you gotten my test results back yet?" you're the one pointing out that she's your doctor, not her. If she, unprompted, said something about your test results to you, she'd have violated HIPAA.

It's your privacy to waive as you please.

The P in HIPAA doesn't stand for Privacy.
No, it stands for "Portability."

HIPAA does, however, have a section explicitly governing the privacy of patient medical information, under Title II, generally known as "The Privacy Rule".

EDIT: Tone and specificity.

Probably.. any disclosure could potentially be regulated. This is a company creating a health care profile of you (possibly without your consent) and potentially sharing that information of you (without your consent or release) to other entities.. so maybe? I bet there will be several lawsuits to clarify things.
Unequivocally not. Posting to Facebook is a public disclosure Health data: no one, including your own physician, is obligated to protect that which you opt to publicly disclose.
We are talking about a Facebook AI program reading your posts and deciding if you are suicidal or not. I'm not even sure how you would clinically validate that and if it would require FDA clearance, but if you are forming a mental health opinion on a stream of data and contacting the government about it that is probably something that may need to be protected.
Whether or not one thinks it ought to be protected, there is no contortion of existing law that does so.
The medical school structured itnas a clinical trial with people volunteering to participate. Medical studies have different regulations than just reviewing public postings.

This is a reflection of the way they’ve chosen to go about things - no doubt in response to past kerfuffles - rather than an actual legal obligation on fb’s analysis of public materials.

HIPAA regs aren’t hidden from the public. Peruse at your leisure.

I can't speak to HIPAA, but medical data is covered by the EU's new GDPR framework.