Hacker News new | ask | show | jobs
by clarkevans 4617 days ago
(I'm not a lawyer, but) I doubt they are in the clear. Sounds like they injected a public survey in a communication channel previously reserved for private interaction with their doctor. Perhaps the patient (state privacy law), doctor (business associates agreement), and the government (via HIPPA) have standing.

Under 42 USC ยง 1320d-5, penalties for wilful neglect are $10k per occurrence, up to 1.5M. There are also criminal penalties for up-to ten years for those who "knowingly" disclose individually identifiable health information for commercial advantage.

2 comments

Ah, it's not willful, though. They apparently assumed that every single patient would read and understand the tiny, italicized grey print warning to not include personal information.
sidebar:

> HIPPA

HIPAA

very common mistake.