Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Although non-compliant activity with regards to e.g. spreadsheets containing patient data is extraordinarily widespread [+], you're correct, putting a spreadsheet with PHI on iCloud (whether you intended to or not) is a reportable breach.

(Not a lawyer, but I have to care about this, for professional reasons.)

[+] Say, emailing in the clear about PHI. This is extraordinarily common even among people who theoretically know better.



From what I can tell, I think a lot of people in healthcare view HIPAA as poorly written, and more or less a bureaucratic obstacle to doing their jobs effectively. Part of it also is that all the EMR solutions are so terrible that to try and do patient care entirely within a given EMR is so painful, people do the dropbox/email route to get around their limitations.


Are organizations that are caught emailing PHI in the clear not punished for this? Or are the damages insufficient to change the behavior?


Yes.

Odds of an enforcement action are minimal (940 complaints for Security Rule violations in 5 years divided by one sixth the economy), given that enforcement is complaint-driven and CSV files rarely complain. If you're big enough you budget for fines like retail budgets for employee theft -- sure, don't seek it out, but you won't be heartbroken when it happens.


My experiences on this suggest that any company that both produces something classifiable as PHI and large enough to have dedicated IT / Legal staff have fairly draconian policies that include "every attachment that is mailed to a mail server that is not ours is stripped".

When individuals work around these policies, there tends to be some level of legal shielding for the larger business entity when it is investigated.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: