Hacker News new | ask | show | jobs
by rayuela 2410 days ago
So what do we do to stop this? What recourse do people directly affected by this have?
3 comments

https://www.hhs.gov/hipaa/filing-a-complaint/complaint-proce...

Complaint Requirements

Anyone can file a health information privacy or security complaint. Your complaint must:

Be filed in writing by mail, fax, e-mail, or via the OCR Complaint Portal

Name the covered entity or business associate involved, and describe the acts or omissions, you believed violated the requirements of the Privacy, Security, or Breach Notification Rules

Be filed within 180 days of when you knew that the act or omission complained of occurred. OCR may extend the 180-day period if you can show "good cause"

But what would the complaint be? "I don't want my data transferred to Google, because.... Google?"

I mean, filing a complaint is free but I imagine it should have a grievance attached to be taken seriously.

GDPR should kick in long before medical data is on the table.
GDPR will only occasionally and coincidentally (if at all) be relevant to health data held by US health care providers and their business associates, whereas HIPAA will always be relevant.
laws protecting medical data are stricter and preceded gdpr by many years
Go to fitbit and delete your data. I just did; it's pretty painless.

login, click on the wheel, and the delete link is at the bottom.

> Go to fitbit and delete your data.

That has no effect on the central theme of the story (which is health care firms partnering with Google as a Business Associate, and thereby sharing patient data).