Hacker News new | ask | show | jobs
by socalgal2 44 days ago
I'm sure someone smarter than me has a solution. Those papers you're required to sign are generally the result of regulation. Some law got passed that say "you can't share info unless you get signed permission". The person dreaming up the law thought that would be enough to stop getting them to share info. But, even if they cared about privacy, they don't want to increase all their expenses and run their own IT department so they contract out for 3rd party billing, 3rd party document infra, etc etc. Like if they wanted to store your appointment in MS Word 365 or Google Docs, suddenly the regulation kicks in. They're not going build a document sharing platform to get their job done just so they can meet the regs. They're just going to get you to sign that they can do what they need.

As one example, I went to a doctor, he ordered an x-ray. I went over to the x-ray company then back to my doctor. He pulled up the x-ray immediately. He's only able to do that because I signed that he can share my info with the x-ray company and visa-versa.

Again, I don't have a solution. No regulation = he'd probably share my data. But regulation = he gets me to sign so he can legit provide the service, and still shared my data (Because I signed). So all the regs did is make visiting the doctor more annoying, and add $$$$ to push all the paperwork around.

4 comments

Regarding information sharing, not quite. Covered entities (term of art in HIPAA), which include providers (and also payers!) including both the lab and your doctor, do not need your permission to share information between them for the purposes of treatment, payment, or operations (commonly, "TPO"). A BAA between a covered entity and a vendor (like an EHR or PACS [viewer for your imaging]) also does not require any patient consent.

There are sometimes things you might not like hidden in the releases you're signing, beyond the run of the mill acceptance of financial responsibility / assignment of benefits, notice of privacy policy acknowledgment, consent to treat.

> do not need your permission to share information between them for the purposes of treatment, payment, or operations (commonly, "TPO")

In fact, for the purposes of treatment, providers can share that information, even if you explicitly refuse, as needed.

> They're not going build a document sharing platform to get their job done just so they can meet the regs.

What is so hard in respecting the spirit of the law?

There are many dollars in between.
Like with criminal fraud?
Becauae "spirit of the law" doesnt exist. It is a saying used by people when they want to do something that isnt in the law. You dont see lawyers, judges or law makers use the phrase.
> Becauae "spirit of the law" doesnt exist. It is a saying used by people when they want to do something that isnt in the law. You dont see lawyers, judges or law makers use the phrase.

This is dependent on jurisdiction. Some countries (e.g. the USA) do not consider spirit/intent (anymore), as the judiciary has repeatedly ruled that the letter of the law, as written, is what matters, regardless of whether it meets the intent of what the law was written to achieve.

There are other countries in the world, outside of the USA, that do not work this way.

Intent is expressed through drafter's notes or explanations. "Spirit" is somerhing else, something made up later by people who had nothing to do with th3 creation of the law.
> The letter of the law and the spirit of the law are two ways of interpreting rules or laws. To obey the "letter of the law" is to follow the literal reading of the words of the law, whereas following the "spirit of the law" is to follow the intention of why the law was enacted.

https://en.wikipedia.org/wiki/Letter_and_spirit_of_the_law

It is always a good sign of modernity and relevance when the half an article's citations are to either the bible or the Talmude. And who can forget the legal touchstone that was the 1975 Systems Engineering Conference ... in Vegas.
Yes they obviously do use it?
I agree but please, provide citations instead of a question mark, to make what you believe is obvious actually in fact obvious.
> New combinations of circumstances — that is, new cases — constantly call for the application, which means in truth the extension of old principles; or, it may be, even for the thinking out of some new principle, in harmony with the general spirit of the law, fitted to meet the novel requirements of the time.

Law And Public Opinion In England, page 361 -> https://archive.org/details/in.ernet.dli.2015.40146/page/n38...

I think the question mark is good enough for such an absurd claim. If the author cares they can find quotes with no effort
I don't think so?
I don’t see any?
Are you even legally signing anything if they can't show you the document you are signing?

I am not familiar with the nitty gritty of US law, but under German law that signature would be worthless. Even signing a document you have but are unwilling to read is legally a bit iffy (which is why for things like real estate a notary will read the paperwork to you and ask if you understood it, or why surprising clauses in terms of service are unenforceable). Signing something without being able to know what you are signing would be worth exactly nothing, because you didn't actually knowingly consent to any particular thing, and neither did you have the "meeting of minds" required to form a contract.

It probably would be unenforceable in the US too, given you have no opportunity to know what you're signing, but you'd probably have to drag it before a court to settle that, and US companies know that no* individual is actually going to do that over what ultimately is (likely to only be) a minor inconvenience.

* Within margin of error

Many people now have devices with secure storage with them at all times. Maybe it’s time we owned our data and decided who gets it and when.

Obviously this doesn’t work in all situations and for all people, but it’s a start.

I do wish this was an option for some data, but emergency care would be an absolute shit show. People can't even remember passwords let alone keep track of keys and devices.
Zero trust device, with emergency channels pre-trusted. Like, the ambulance service is known to your device and can already suck your blood type and whatnot. And the police your name and emergency contacts. Or whatever schema with a similar idea. There's the technology to do this already, but we're lacking awareness and initiative.
> And the police your name and emergency contacts.

Hell no. The fuzz ain't getting my info without reasonable, articulable suspicion that I have committed, am committing, or am about to commit a crime, or if I'm pressing charges and need to ID for that process.

The parent comment was about an accident where you're unable to give any details yourself. Maybe when you're under a truck you'd like your folks to know what happened to you, right? But again, such are implementation details. First let's have that zero trust device, then we can be negotiate who gets to see what and when.
The problem is that it creates a vector for illicit access to the information, and if that vector exists, it will be abused.

I'd rather have society deal with the problems that come with not knowing who's under the truck than the problems that come with state surveillance.