Hacker News new | ask | show | jobs
by david_l_lin 1952 days ago
HIPAA applies to any circumstance around handling PHI. We handle your self-reported survey data, and microbiome data as PHI. We do NOT have to be a "covered entity" to apply HIPAA compliant protocols to our data handling. It's an additional security measure we take in handling your PHI.
1 comments

>HIPAA applies to any circumstance around handling PHI.

HIPAA does not apply at all as you are not a covered entity under HIPAA, stop lying.

>We do NOT have to be a "covered entity" to apply HIPAA compliant protocols to our data handling

Yeah, but that's just your current choice. You (more or less) claimed you were obligated to abide by HIPAA, but that's a lie, you are not.

I know you though nobody would call you out on this, but I am, because I understand the law. Please be upfront when asked, and stop lying.