Never forget those who have died because of various sex offender laws.
Showing posts with label ( .News-HIPAA. Show all posts
Showing posts with label ( .News-HIPAA. Show all posts

June 16, 2014

Google's after your health data with 'Google Fit' service

Interesting, these Apps may be at odds w/federal law HIPPA; read on...
6-16-2014 National:

Google's about to jump into the growing fitness data marketplace - a mosh pit that consumer advocates are already calling a privacy nightmare - to wrestle with Apple and Samsung for the data created by fitness trackers and health-related apps.

Sources told Forbes that Google's planning to launch its new health service, called Google Fit, at its Google I/O developers conference, held on 25 and 26 June 2014.

Google Fit will reportedly collect and aggregate data from popular fitness trackers and health-related apps via open APIs.

One source familiar with Google’s plans told Forbes that Google Fit would allow a wearable device that measures data such as steps or heart rate to interface with Google’s cloud-based services and to become part of the Google Fit ecosystem.

Google has been working not just on wearable tech such as the much-loved, much-loathed Glass, but also on medical products, such as contact lenses for diabetics that read tears to ascertain glucose levels, according to the Washington Post.

The data-rich landscape being created by the proliferation of this type of fitness app has tech heavyweights drooling.

Earlier in June, Apple launched HealthKit, a system that pulls together health metrics from exercise, nutrition and medical apps such as blood pressure.

Samsung last month unveiled Sami, another biometric data platform that likewise gobbles up health information from devices and apps.

Deborah Peel, the executive director of Patient Privacy Rights, has called this growing fitness data marketplace a "privacy nightmare", given that the vast majority, if not all, of the health data these apps collect has "effectively zero" protection.

But while the fitness and health apps makers might have dropped the ball on protecting the data, the mega-data handlers who want to aggregate it all - Google, Apple and Samsung, so far - are tiptoeing around the landmines of privacy and security.

Sources told Forbes that creating these health platforms has been tough going for Google and Apple, given the delicacy required to deal with privacy issues and how best to process information as sensitive as health data - data that's protected with legislation such as the US's Health Insurance Portability and Accountability Act (HIPAA), which can carry onerous fines for medical data bungling. ..Continued.. by Lisa Vaas

Read More of Article...

July 9, 2013

Some US states strengthen data breach notification laws, others ignore them

7-9-2013 National:

Vermont and North Dakota have both decided to improve data breach notification (DBN) laws in their respective states in recent months. To a degree, this is exactly how the American system of government is designed to work.

Flesh out an idea at the state level, implement it, go back a little while later and close the loopholes and reiterate. Eventually a solid methodology becomes a general consensus across the 50 states and a Federal law can supersede them with some uniformity.

Vermont's original bill, Security Breach Notice Act, 9 V.S.A. § 2435 (rolls off the tongue, doesn't it?), had a bizarre exclusion for financial institutions. It is not unusual for loopholes to make it into early revisions of law, which seems to be the case here.

On May 13th Governor Peter Shumlin signed the revision into law. It now states:
"A data collector or other entity regulated by the Department of Financial Regulation under Title 8 or this title shall provide notice of a breach to the Department. All other data collectors or other entities subject to this subchapter shall provide notice of a breach to the Attorney General."
orth Dakota has taken a second look at its DBN law, 51-30-01, and amended it effective August 1st in House Bill 1435.

Previously North Dakota considered PII or Personally Identifiable Information to include:

Social Security Number, Driver's license number, state ID card, financial account details (credit card, bank account, etc), date of birth, mother's maiden name, employee ID number or a copy of your signature (digital or otherwise).

The state has added two important items to this list for non-HIPAA covered entities: medical information and health insurance information.

This plugs a federal loophole allowing organizations that are not "covered entities" to ignore the rules under the HIPAA act.

Which brings me to my home state of Michigan. Last week, the Michigan Department of Community Health contacted more than 49,000 individuals to warn them they were at risk of identity theft.

A server belonging to the Michigan Cancer Consortium, containing unencrypted names, Social Security numbers, birthdates and cancer screening results, was hacked.

This would appear to be the exact situation the HIPAA law was designed to discourage. A clear violation, one might say.

Nope. Not according to the state of Michigan. The hacked organization isn't a "covered entity."

Under HIPAA, the Cancer Prevention and Control Section of the Department of Community Health, which shared the data with the Cancer Center, doesn't meet the specific definition put forth by Health and Human Services.

According to a Health Data Management article, the state's spokesperson said the data in question:
"were not medical records and therefore, no notification under HIPAA was sent to individuals. However, because the reports contained Social Security numbers, the Identity Theft Protection Act did apply."
Looks like I did the right thing by moving away. Clearly the letter of the law in Michigan is much more important than the spirit.

While it is likely they are avoiding admitting to a HIPAA violation to avoid fines and an investigation, perhaps that is exactly what is needed here to ensure this type of accident doesn't occur again.

My name, birthdate and cancer screening results are not considered part of my "medical records?" Perhaps you ought to consult with your cousins Vermont and North Dakota for a peek at their dictionaries.

Lastly, my blog posts are never complete without some unsolicited advice. Here is some for both the state of Michigan and anyone else involved in handling *ANYTHING* related to health records.

It is all important. All of it. Every last scrap. Stop storing it on unprotected web servers. Encrypt everything.

As we have no choice but to entrust you with our information, please start treating it as if it were your own. ..Source.. by Chester Wisniewski

Read More of Article...

April 25, 2013

With HIPAA Compliance, Cloud Storage Platform Box Makes A Big Push Into Healthcare; Invests In Drchrono

Given that advocates handle many issues with respect to former offenders, is there any chance that the offender's private information (Medical or Psychological) supplied to an Advocate, is required to be kept confidential according to HIPAA? Do Advocates need a HIPAA form -similar to what Doctors offices use- before sharing offender supplied information (Medical or Psychological) with others? Food for thought today, just remember, there can be substantial fines and possible imprisonment for HIPAA violations.
4-25-2013 National:

Cloud storage company Box is making a big push into the healthcare sector today. Not only has Box received HIPAA compliance, but the company has announcing a new set of partners in the space, as well as an equity investment in drchrono, a startup that simplifies the professional lives of doctors by bringing electronic health records and much more to the iPad.

Healthcare is an enterprise vertical for Box, and is growing fast, says co-founder and CEO Aaron Levie. The company even hired Missy Krasner, who helped found Google Health, as a healthcare advisor.

In the past year, Box’s sales in the healthcare industry grew more than 81 percent, with clients including Henry Ford Health System, Beaumont Health System, HealthTrust Europe, Johns Hopkins HealthCare Solutions, Wake Forest Baptist Health, San Juan Regional Medical Center and Garden City Hospital.

The company is also announcing that a number of new healthcare startups are using Box’s API and platform including Umbie DentalCare, TigerText, Doximity, Medigram, PostureScreen Mobile, iMedViewer, iPaxera, Medi-Copy, and Healthtap. And Box has made an undisclosed investment in drchrono through the Box Innovation Network.

Part of making this big push into healthcare is getting the certifications that allows healthcare providers and companies to store medical information in the cloud. Box says it is now HIPAA compliant and is considered a secure and trusted platform for protected health information (PHI), personal health record files (PHRs), and is able to securely serve clinical researchers, ...continued... by Leena Rao

Read More of Article...