Hacker News new | ask | show | jobs
by sailfast 303 days ago
Kinda incredible - even if they’re not covered providers they are still requesting medical records!
2 comments

HIPAA is not a privacy law, nor even a healthcare law. It's an insurance law. It does not cover medical records generally. It deals strictly with how doctors bill insurance companies, and mandates security for health information being billed about.

For the same reason, health & wellness apps are not generally covered by HIPAA, and in fact quite a few of those exist solely for the purpose of selling medical data to data brokers. Especially ones related to women's health.

They usually require records for compliance with state regulations (but the state does not require them to follow HIPAA).