Hacker News new | ask | show | jobs
by solarkraft 2737 days ago
> Epic has nearly every person in the US's medical history in their databases (since their usage is so widespread) so if you sign up to use Epic you get the medical history with it

Why is this legal?

3 comments

While Epic produces the database/electronic health record system, the hospital or health system ultimately owns the data. AFAIK patient data don’t sit on Epic’s own servers outside of some research/pilot initiatives.

(Source: my personal experience working extensively with EHRs, including Epic products.)

One of the first forms new patients sign at a hospital or private practice is a form releasing allowing their healthcare provider to request the patient's medical records from their other providers. Once that is filed, Epic provides a HIPPA compliant system to get those medical records from other linked databases.
Those records are protected by HIPAA which requires they be encrypted, and epic logs anytime a person views patient information.