Showing posts with label HIPAA. Show all posts
Showing posts with label HIPAA. Show all posts

Saturday, June 08, 2013

The IRS, NSA, and Justice Department Scandals and What They Mean for HIPAA

As my head reels at the implications of the IRS scandal mushrooming in Washington, the IRS's recently disclosed ability to access e-mails without warrant, the intricacy of the NSA PRISM wiretap techiques that includes their ability to acquire tech firms' digital data, and even the Justice Department's ability to secretly acquire telephone toll records from the Associated Press, I wonder (as a doctor) what all this means for the privacy protections afforded by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) in our new era of mandated electronic medical records.  Are such privacy protections credible at all?

It doesn't seem so.

Now it seems everyone's health data is just as vulnerable to federal review as their Google search data.  This is not a small issue.  We have already seen that discovering "leaks" of personal health information has produced some very handsome rewards for the feds, so it is not beyond reason to think that HIPAA might also be a funding tool for our government health care administration disguised as a beneficent effort to protect the health care data of our populace.

But even more concerning is the role the IRS scandal has for America's health care system.  After all, the Affordable Care Act is ultimately funded by the IRS by administering some 47 tax provisions.  These include the right to levy a penalty against businesses and individuals who don't provide or acquire insurance and determining how to distribute annual subsidies to 18 million people who make less than $45,000 a year and thus qualify for subsidies in buying health coverage. In addition, the agency will collect taxes on medical devices and a surtax on people making more than $200,000 a year, as well as conducting compliance audits of tax-exempt hospitals.

We are left to wonder: given the IRS's recent actions in favor of one political party, could other aspects of our evolving health care system be similarly politically targeted?  What if the government agencies turn a disapproving eye on physician-run hospitals or independent concierge medical practices?  What if the market place emergence of a two-tier health care system is systematically crushed?  For these types of concerns we instinctually rely on a fair, beneficent government, but these latest revelations challenge that assumption.

To the political class, the ends always justifies the means.  Now, we're seeing that the means includes stealth digital tracking, e-mail browsing, and wiretaps.

Health care data protection by HIPAA?

Meh.

We should think about the far-reaching implications of what we're seeing from our government agencies as we turn the reins of health care financing over to them lock, stock, and barrel.  Perhaps Peggy Noonan said it best:
What does it mean when half the country—literally half the country—understands that the revenue-gathering arm of its federal government is politically corrupt, sees them as targets, and will shoot at them if they try to raise their heads? That is the kind of thing that can kill a country, letting half its citizens believe that they no longer have full political rights.

Those who think this is just business as usual are ahistorical, and those who think nothing can be done, or nothing serious should be done, are suffering from Cynicism Poisoning.
In the blink of an eye, HIPAA privacy protections now seem small.

Very, very small.

-Wes

Addendum: Thanks to @BillHart46 for pointing me to this: Suit Alleges IRS Improperly Seized 60 Million Personal Medical Records

Monday, November 28, 2011

When a HIPAA Security Breech Occurs

It wasn't the fact that pop-star Lindsey Lohan's father, Michael Lohan, was hospitalized that caught my eye, nor was it the splashy headline: Michael Lohan Struggling to Speak, Breathe. What caught my eye was the picture that accompanies the article that reportedly shows Mr. Lohan asleep in his hospital bed.

Is this picture of a man who is "short of breath" authentic? Since there is no oxygen tubing and no pulse oximeter applied to the pictured patient's finger, we are left to wonder.

But what if the picture IS authentic? What will happen as a result?

Will this photograph be ignored? For hospital administration and government regulators, this would pose an enormous problem.

If not ignored, will the perpetrators be brought to justice? What financial "lesson" will be levied against them?

It is frightening to consider how an investigation of such an obvious lapse in patient privacy might be conducted thanks to the implications to health care facilities imposed by HIPAA. Will all the nurses on the unit be placed on administrative leave until someone squeals? Or maybe the cleaning staff? Maybe the family themselves? Perhaps the whole hospital will have to attend HIPAA refresher courses. Perhaps the ward should be closed until the problem identified. And what about the hospital administration who have permitted such an egregious lapse in governmental policy? What fines will be levied against them as a result? Will hospital costs for future patients be adversely affected as a result of these fines?

What is clear is that the ability to maintain patient privacy is quickly becoming impossible to manage, thanks to the explosion of hand-held cell phones and miniature cameras, not to mention the requirement for electronic medical records for those receiving government-funded health care.

Real patient privacy remains a local challenge, not a universal, governmental one. Sadly, in our attempt to provide global governmental privacy protections, we forgot to protect those that are most affected when breeches occur: the innocent workers and patients themselves.

-Wes

Saturday, November 19, 2011

HIPAA, Case Reports, and the "Small Cell" Problem

It was an interesting tweet that referenced a soon-to-be-published case report from the Annals of Emergency Medicine (via @EmergencyDocs) that piqued my interest:
Thrilling case study: emergency doc cracked chest to save 42 y/o woman in cardiac tamponade after ablation therapy. http://bit.ly/umnydc
Details about the case are quite specific and the case reports heralds from a town in Minnesota. It describes, in very specific detail, the management of a patient who presented to the emergency room in shock from cardiac tamponade after a catheter ablation procedure for right ventricular outflow tract tachycardia.

Is this unique case report HIPAA compliant?

I would say, according to our current definition of HIPAA's "personal health information," such a case report is not HIPAA compliant. Nor could such a case be mentioned on a blog, for that matter, even though it presents important information for people dealing with these patients.

There is an important quality-of-care role in telling these clinical stories. In fact, HIPAA states there are just "18 little rules" that doctors are supposed to follow when they report important clinical cases. But details about cases may need to be very specific. Specific case reports can bring important specific clinical details to the attention of the medical community. For instance, if doctors had not been willing to describe several cases of pulmonary vein stenosis or two cases of esophageal perforation in a major medical journal years ago, how many more people might have been injured as a result?

But there's problem giving such details about clinical details about patient cases: "the small cell problem:"
Clinicians should be sensitive to the "small cell problem": the existence of individuals with such unique or unusual diagnoses or illnesses, that it might be possible for others (or patients and families themselves) to identify the individuals in case reports or medical text books based upon limited information, such as state or city of residence, age and diagnosis.
The "small cell" problem violates HIPAA and HIPAA means business: millions of dollars of business that gets released in press releases from the Department of Health and Human Services when they catch their prey.

But doctors should not be afraid of publishing case reports especially since there are good reasons for them clinically. Further, when doctors make good faith efforts to conceal patient's personal information in those reports, they should not be subject to threats of HIPAA's "small cell" problem. Simply put: the "small cell" problem is HIPAA's, not the doctors'. Extending the definition of personal health information as defined by HIPAA to include "any other unique identifying characteristic" about a patient's case limits doctors' ability to improve care to our patients while greatly increasing our legal culpability for that effort.

-Wes

Saturday, November 05, 2011

Smile! You're on Candid Camera!

They sat anxiously waiting for their loved one to enter the holding area after the procedure, one nervously clutching her purse, another today's paper, and a third, her cellphone. The air was tense as they awaited the news of how the procedure went. All the preparation, the concern, and the questioning come down to this moment when they learn if they made the right decision to go forward with the procedure. Will there be elation or despair?

So of course they want to videotape the moment.

The door opened, there was their loved one, looking no worse for wear, followed by the doctor. As he came forth to tell them the good news, the cellphone video recorder captured the discussion, the elation, the "thank you's," and the specifics about the case. It was done discretely and not noticed until the end of the conversation with the group. The doctor was caught completely off-guard.

In this case, the news was happy. All went well. But what should happen if the news weren't so good or even devastating?

I wonder.

We have entered an era where instantly-available photographs and video loops are becoming a way of life for many. YouTube, Facebook, and Twitter are everyday household words. More and more people own cellphones capable of uploading photographs and video content in seconds to the internet. And people bring these marvels of technology into hospitals and clinics every day. What this will mean to patient privacy, HIPAA compliance, and the sanctity of the doctor-patient relationship remains to be seen. But one thing's for certain, surveillance cameras are showing up everywhere and not likely to go away.

-Wes

Tuesday, March 08, 2011

How Medication Lists Define Your Health Issues

Give me your medication list and I'll tell you your health problems.

It happens every day in emergency rooms across the country as confused elderly patients present for an acute problem unable to describe their past medical history but equipped with a list of medications in their wallet.

Metformin = type II diabetes

Synthroid = hypothyroidism

Lipitor + Altace + Lasix + Slo-K = ischemic cardiomyopathy

Lexapro = He's a little anxious or depressed

Viagra = Well, you know...

I bet I'd be right better than 90% of the time.

Now, imagine you're a pharmaceutical company wanting to target people with those chronic diseases. Where might you find them?

No problem. Just pay the insurers to provide you patients drug lists. No names need be exchanged in keeping with HIPAA requirements. But the drugs list attached to folk's cable TV box?

Perfect. You're in. With no legal strings attached. Then just fire away with that targeted direct-to-consumer advertising on TV, courtesy of your local health care insurance provider.

No wonder our health care industry movers and shakers love the electronic medical record.

Health care privacy? What health care privacy?

-Wes

Sunday, January 09, 2011

An Internet ID for All Americans?

From CBS News:
President Obama is planning to hand the U.S. Commerce Department authority over a forthcoming cybersecurity effort to create an Internet ID for Americans, a White House official said here today.

It's "the absolute perfect spot in the U.S. government" to centralize efforts toward creating an "identity ecosystem" for the Internet, White House Cybersecurity Coordinator Howard Schmidt said.

That news, first reported by CNET, effectively pushes the department to the forefront of the issue, beating out other potential candidates including the National Security Agency and the Department of Homeland Security. The move also is likely to please privacy and civil liberties groups that have raised concerns in the past over the dual roles of police and intelligence agencies.

The announcement came at an event today at the Stanford Institute for Economic Policy Research, where U.S. Commerce Secretary Gary Locke and Schmidt spoke.

The Obama administration is currently drafting what it's calling the National Strategy for Trusted Identities in Cyberspace, which Locke said will be released by the president in the next few months. (An early version was publicly released last summer.)

"We are not talking about a national ID card," Locke said at the Stanford event. "We are not talking about a government-controlled system. What we are talking about is enhancing online security and privacy and reducing and perhaps even eliminating the need to memorize a dozen passwords, through creation and use of more trusted digital identities."
No, they're not talking about a national ID card, just an international internet ID.

Imagine. Anyone registered with such a cyber-ID who conferences with their doctor via a "secure server" can also be tracked by the government with such a mechanism.

And the issue of not needing more than one password? While convenient, the ramifications of multiple accounts being compromised if a data leak were to occur remains with such a mechanism.

But fear not:
Details about the "trusted identity" project are unusually scarce. Last year's announcement referenced a possible forthcoming smart card or digital certificate that would prove that online users are who they say they are. These digital IDs would be offered to consumers by online vendors for financial transactions.

Schmidt stressed today that anonymity and pseudonymity will remain possible on the Internet. "I don't have to get a credential if I don't want to," he said. There's no chance that "a centralized database will emerge," and "we need the private sector to lead the implementation of this," he said.
No doubt you won't have to be "credentialed" unless you want to use a government service. (They have to be sure you're a "trusted user," right?)

Like Medicare or Medicaid.

Privacy? Who needs privacy?

-Wes

Reference: Draft Document: "National Strategy for Trusted Identities in Cyberspace," (pdf) dated 25 June 2010.

Monday, August 16, 2010

Some Helpful Healthcare Advice for College-Bound Students

Call your lawyer first:
After a few clients ran into difficulty getting information about adult children who were ill, Sheila Benninger, an attorney in Chapel Hill, N.C., began recommending that clients' children designate a health-care power of attorney after they turn 18 to identify who can speak for them if they can't.

She also includes a Health Insurance Portability and Accountability Act, or HIPAA, release form that allows patients to determine who can receive information about their medical care and whether information about treatment for substance abuse, mental health or sexually transmitted diseases can be disclosed.

You don't have to use a lawyer. Generic health-care power-of-attorney forms can be found online. If the school has a HIPAA release online, it's best to use that more-tailored document.

Parents should keep a copy in an email folder, where it can be easily accessed in an emergency. And students should designate a general power of attorney so someone can pay bills or handle other issues if they go abroad.
It's good advice for those of us shipping one more child back to college this week.

-Wes

h/t: Instapundit.

Monday, November 30, 2009

Text Paging Health Information

I saw this in a recent nursing note:
Urine noted to be bloody without clots.
Text message sent to 2290 (trauma pager) about hematuria.
Patient denies any pain at this time.
No doubt patient identification or their room number, was sent to identify the patient (I'm not sure which). I suppose a record of the physician covering the trauma service that night is discoverable.

But I wonder, in the world of cyberspace with electronic communication carrying such an important role in health care delivery lately, is HIPAA really enforceable or will it just be used to extract huge fines from care providers now that the new HITECH policy expands HIPAA's reach.

Since text pages are neither encoded nor retained as an official audit trail of care delivered, it seems to me care providers are vulnerable, even when they are doing the right thing for the patient.

-Wes

Friday, October 09, 2009

"Body Computing" and the Right to Health Information

Fellow cardiac electrophysiologist Leslie Saxon, MD thinks patients should own their medical device information in the era of "body computing:"
But there are major obstacles standing in the way of people's rights to access their health care data. There are over 400,000 patients with implanted defibrillators that have networked capability. Up to 20 percent of people with defibrillators will be shocked from the device. While the shock is life-saving and one of the main reasons the device gets placed, patients feel something that is akin to a punch in the chest and it causes great concern and curiosity from the patient. Where does the vital information about the shock go?

It is transmitted to a secure server--managed by device manufacturers--and the information is then downloaded to a secure web site for the patient's physician. I think patients have a right to see the information, and be able to share it with family members and other physicians, but patients are given no opportunity to access it. Device manufactures tell me that they won't allow patients to access the data because they are worried about insulting the physician who implanted the device. Physicians aren't exactly excited to give up the data because they believe it will cause more work and put them at risk for lawsuits.
So what are those "major obstacles" to allowing patients access to their health information?

Privacy and Safety

You can never be too careful with health information - especially if its yours. Powerful governmental rules exist to make sure your cannot access your health information easily. In 1996, with the advent of electronic submission of claims to the US government, concerns over the privacy of electronically-encoded information surfaced and resulted in the development of HIPAA, enforced by the governmental Office of Civil Rights. After the Institute of Medicine's "landmark report" entitled "To Err is Human: Building a Safer Health System," (available for purchase only) which highlighted critical areas of research and activities needed to improve the safety and quality of health care delivery, Congress passed the Patient Safety and Quality Improvement Act of 2005 (PSQIA). PSQIA provides Federal privilege and confidentiality protections for patient safety information called "patient safety work product." Patient safety work product includes information collected and created during the reporting and analysis of patient safety events. These safety events then feed into the Agency for Healthcare Research and Quality (AHRQ) which has responsibility for listing patient safety organizations (PSOs), the external experts established by the Patient Safety Act to collect and analyze patient safety information. Who are Patient Safety Organizations? Well there's one for nearly every state. The data collected from these PSO's feed into a carefully contructed Network of Patient Safety Databases (NPSD). These NPSD's will receive, analyze, and report on de-identified and aggregated patient safety event information with the goal of facilitating aggregation and analyses of patient safety event information to help reduce adverse events and improve health care quality. All of this aggregated information is then protected by the PSO Privacy Protection Center.

But safety concerns don't stop there.

The FDA (pdf) must also regulate the devices themselves to assure their safety, managed adeptly by the Center for Devices and Radiological Health. They, in turn, manage a Medical Device Recall Database so consumers can find out which devices have or have not been recalled. Doctors also must maintain a registry of all patients who receive medical devices, some of which extend information to hospital information systems as well as a database of implant information tied to clinical variables. Companies can use these data to report potential safety problems. Doctors can use these data to protect their turf in the name of safety.

Legal Concerns

Despite all of the above safety and privacy safeguards, legal liability concerns loom large in the minds of health care providers and device manufacturers as violation of privacy laws can lead to jail time and hefty fines. With the increasing need to balance governmental budgets, we're seeing an increase in audits of health information, thanks, in part to the Health Information Technology for Economic and Clinical Health Act (HITECH Act):
American Recovery and Reinvestment Act of 2009 (ARRA) also includes a section that expands the reach of the Health Insurance Portability and Accountability Act (HIPAA) and introduces the first federally mandated data breach notification requirement.

Title XIII of ARRA, also known as the Health Information Technology for Economic and Clinical Health Act (HITECH Act), reserves $22 billion to "advance the use of health information technology" -- in large part so the U.S. will be able to move to e-health records by President Obama's 2014 deadline.

It also expands the reach of HIPAA data privacy and security requirements to include the "business associates" of those entities (health care providers, pharmacies, and the like) that are subject to HIPAA.
This act significantly expands the reach of the HIPAA Privacy Rule and Security Rule, along with the corresponding penalties. Subsection 13410(c) requires civil penalties that are collected under the HITECH Act to be funneled back into the Department of Health and Human Services' Office of Civil Rights enforcement budget, completing the funding "Circle of Life" for the system.

So if you're wondering why you can't get your health information I think it's pretty clear...

... you should probably thank our government.

-Wes

Tuesday, March 04, 2008

HIPAA's Worthless and Here's Why

Do you have disability insurance? Do you want to utilize it? Well, my friend, if you want to tap into the disability coffers, plan on surrendering your privacy and sign this "Medical Disclosure Authorization." It gives our special "Medical Disability Advisor" the right to transmit to the world your persoanl and medical history (including HIV status), HIPAA free!
I understand that any health information disclosed pursuant to this authorization will no longer be protected by the HIPAA Privacy Rule when received by Reed Group.

When relevant to my claim, Reed Group may re-disclose(without further authorization) this information to any of the following, (a)Any person or facility that attends, treats or examines me; (b) Any person or facility that impacts the determination of my claim or that coordinates my benefits, including without limitation the employer to the extent permitted by state or federal law; or (c) The Social Security Administration or a social security or vocational rehabilitation vendor. Reed Group and DePaul University may use information obtained pursuant to this authorization in any other claim matter they handle related to me. I understand that this authorization is necessary for the processing of my claim or reguest for medical restrictions and that failure to sign this authorization may impair or impede the processing of my claim or request for medical restrictions.

I understand my treatment provider will not base treatment, payment enrollment or eligibitity on the refusal to sign this authorization. However, I understand that such refusal may affect my eligibility for benefits under my employers disability policy.
I received this request to complete an "Attending Physician's Statement" for a patient to receive their disability insurance. It had this form attached (not yet signed by the patient). As we can clearly see, this patient's healthcare record will be "free and clear" from a HIPAA perspective if this patient signs this "Medical Disclosure Authorization." Everything and anything about their health is fair game... forever. Both this patient's employer and future insurers can use this information against this patient for any future claims (even if their health problem is resolved). Yet if this patient does not sign this form, then this patient will not likely receive the benefits for which this patient has paid for through deductions from their salary.

Welcome to the world of "Insurance Catch-22."

So why the heck do we even have HIPAA when insurers can play this game with our most private healthcare information?

-Wes

Saturday, February 09, 2008

Part III: The Opportunity

“If you change a patient’s appointment don’t forget to enter a reason why in the comment field. Do you know, is he a H.M.O., P.P.O. or P.O.S.?”

“Probably a P.O.S.” I thought, chuckling as I kept the double entendre to myself. With that, the receptionist looked up.

“Hi, may I help you?”

“Yes, I’m here for my 2:45 appointment.”

She looked at her computer screen again.

“Fisher?”

“Yes.”

“Bad weather out there today, huh? Did you hurt yourself shoveling?”

“Sure did. I’ll bet you’re seeing lots of people for that, huh?”

“You’re the first today,” she said matter-of-factly as if to want to make me feel even older. “Here are a few forms I’d like you to fill out. Would you like to sit down?”

“Uh, I’m sorry. It feels better if I keep standing right now.”

I looked at the clipboard she handed me. Six pages of fine print paperwork: one page for demographic information like my name, address, date of birth, insurer and so on and, what, my social security number? Hmm. I wonder what bank accounts they could open with all of this information? The opposite side of the page for brief background medical history – all meant to reassure that someone actually looks at this stuff, but more likely to entrap me for possible insurance fraud if I should lie or forget something, I thought.

The next four pages were ludicrous examples of the follies of bureaucracy: a “Privacy Statement” (2 pages) and explanation of the Health Insurance Portability and Accountability Act (HIPAA) and what it means to me – carefully juxtaposed to the pages containing my entire life and medical history, social security number, date of birth, etc. Bureaucracy to Content ratio: 3 to 1. What a waste, I thought. Pages and pages of text were provided just to explain an obscure and effectively meaningless document to the average Joe, just so my information can whir about cyberspace with nary a liability concern to the Great Third Party.

I stood in agony as I completed the forms; most of which had nothing to do with facilitating my care.

Rather, it was all about jostling for the few dollars afforded by my insurer because in the eyes of the rehab facility and our health care system, I had become an opportunity to collect.

And as I looked down to replace my insurance card back in my wallet, I saw it. Up in the upper right-hand corner of the card. Like a piece of beef and in bold letters for all to see:

"Plan Option 3 - Choice P.O.S."

-Wes

Friday, November 30, 2007

HIPAA, Guns, and Public Health

A while ago I was called to the Psych floor to see a patient with a cardiac arrhythmia. I thought I would check on the patient’s history via our fancy electronic medical record (EMR) before making the trek to an area rarely visited by this outsider, but I was surprised to see that I could not access charts electronically from outside the Psych ward. It seems there are some checks and balances installed in our EMR to avoid prying eyes. Although I was initially perturbed, I must admit I thought it was a smart move to limit access to psychiatric charts – especially since I might be up there as an inpatient myself given all the bureaucracy surrounding medicine these days.

But then this news appeared today about how the feds have miraculously increased their "Mental Defective File" database size to limit the sales of guns to goofy people. On first blush, I thought, “Thank God! I really don’t one of these crazy people with a gun.”

But then I looked into HOW the FBI expanded their database from 150,000 to over 400,000 people in the blink of an eye:
The vast majority of the individuals who were added to the FBI's list were identified by the state of California, which provided more than 200,000 names to the FBI in October, the Justice Department said. Ohio also provided more than 7,000 new names, and the number of states reporting mental health data to the FBI this year grew from 23 to 32, officials said.
So where did these states get these names from? Well it seems hospitals may have supplied the names:
A Virginia state court found (Seung Hui) Cho (remember, he caused the largest on-campus killing spree of anyone to date) to be dangerously mentally ill in 2005 and ordered him to receive outpatient treatment. But because Cho was not ordered into hospital treatment, the court's order was never provided to the FBI and incorporated in its database, which two gun dealers checked before selling Cho the 9mm Glock 19 and a Walther .22-caliber pistol used in the shootings.
The debate about this has been heated:
House Democrats reached an agreement earlier this year with the National Rifle Association on legislation meant to encourage states to submit timely background check data to the FBI, by offering monetary awards and threatening penalties.

"Our position has always been that those who have been adjudicated as mentally defective or a danger to themselves or to others or suicidal should not have access to firearms" and should be added to the FBI's list, said NRA spokesman Andrew Arulanandam.

The measure passed easily in the House, but it has stalled in the Senate due to a hold by Sen. Tom Coburn, R-Okla. He has said he opposes the legislation because its implementation would cost too much and because it lacks a mechanism to challenge inclusion on the list. He was joined by some veterans' groups, which argued that former soldiers might be denied gun-owning rights without due process.
Now, most of us assume such sensitive health records are protected in the interest of “privacy.” Isn’t that what we’ve been assured by HIPAA? So what’s the loophole that permits the feds access to sensitive hospital records to make their lists? What if I had an anxiety disorder or depression in my medical history requiring inpatient admission. Would I end up on the FBI’s “Mental Defective File?” Would I have any recourse to remove myself from that list if my condition improved? Who’s responsible for this information? If we take this a step further, what’s to stop the feds from forming another database in the interest of public health like, say, an “HIV Defective File” or other “Sexually-transmitted Disease Defective File?”

Probably nothing.

-Wes

Wednesday, June 20, 2007

Another Example of HIPAA Futility

Todd Stroger, the elected Cook County Commissioner here in Chicago, never wanted the public to know that he needed surgery for prostate cancer. He made it clear his health issues were a "personal matter." But the public wanted to know, so the public found out.

Is there any backbone to HIPAA? Does holding public office imply that individuals forfeit their rights to protection under this law?

Interesting questions, eh? What do you think?

-Wes

Thursday, April 26, 2007

Patient Blogs Make HIPAA Unenforceable

HIPAA, the Health Insurance Portability and Accountability Act of 1996, contains privacy provisions that provide "protection" of patient's health care information to assure that health care providers, health plans, and health care clearinghouses don't leak such sensitive information in a public forum. You see, our legislature felt that doctors and health care providers might use such information to the detriment of our patients, so they made this law to allow government to reassure others that Big Brother could do a better job at protecting your privacy.

But now comes another realization: patient's family members might leak the informaton instead.

Patient blogs are now the rage at local hospitals here in Chicago, detailing play-by-play accounts of health care delivery and histories on patients themselves. You see, patients aren't covered by HIPAA. They can say what ever they want about themselves. But sometimes the patient isn't the one posting on the patient's blog, family members were, dutifully updating the daily progress of their loved one to the world.
"Many people have been inquiring about him so I would like to share some information with everyone," said the first in a series of near-daily updates posted by Nequin's wife, Dawn.

She described in detail how her husband had slipped on ice March 6 while walking the family dog, hit his head on the sidewalk and, nearly three hours later, asked to be taken to the hospital, complaining of a headache and weakness in his leg.

"Within minutes he was having a CAT scan, and in a few more minutes we knew he had a brain bleed," she wrote.
And companies providing these patient weblogs and message boards are springing up like 17-year cicadas:
TLContact Inc., the Northwest Side company that oversees CarePages, has created more than 50,000 such pages, according to a spokeswoman. CaringBridge, a competing service based near Minneapolis, and theStatus.com, a third major competitor based in Anchorage, claim roughly the same numbers of pages, most of them generated in the last few years as word has spread about their availability.

"Most people don't find out about them until a friend goes into the hospital and starts one," said theStatus founder Mark Pierson.

Such sites have been around nearly 10 years, are free, easy to use and fairly secure -- families can control access to them via passwords and invitation lists. Though the companies contract with hospitals for branding and promotional purposes, any patient anywhere can sign up and use any of the services.

They relieve family members and patients of the tedious job of telling the same story over and over, while the accompanying message areas become a forum for encouragement and prayers.

They offer an advantage for health-care professionals as well. Having the family post updates online allows them to skirt the awkwardness and even legal peril that newly stringent medical privacy regulations have added to such simple questions as "How's he doing?"
So in the future, if doctors or insurers get accused of violating the HIPAA provisions, they'll just look stupid and say, "Hey, I just read what I know about him on his patient blog!"

-Wes

Monday, April 23, 2007

Post Virginia Tech: HIPAA Implications

Walter Olson reviews the implications of Health Insurance Portability and Accountability Act of 1996 (HIPAA) following the Virginia Tech massacre:
Under HIPAA’s terms, doctors and other covered persons who improperly release information about identifiable persons’ health care are subject to fines and even prison terms of up to ten years. That a disclosure is well-meaning rather than malicious is no defence: disclosures to patients’ own parents or roommates, as well as disclosures to other medical or custodial institutions, can very much trigger liability; and the exact scope of what is deemed proper disclosure is by no means precisely defined.

Unintended consequences soon blossomed, in large quantity. Frantic family members dialed emergency rooms in vain seeking confirmation that their unconscious loved ones were there. Preferring to play it safe, some hospitals removed patients’ names from doors. Clergy were ordered not to drop in on ill parishioners unless on specific request. Wider areas within clinics were closed off to unescorted visitors; Santa Claus could drop by only with a proper release form on hand for each ailing child.

Infringement of medical privacy is a lamentable thing, but experience soon suggested that other things can be even worse. After a Washington, D. C. pedestrian was fatally struck by a car, his family learned nothing of it for two weeks until a $17,000 hospital bill arrived in the mail. In rural Colorado, where ambulance dispatchers had been casually accustomed to naming the family whose home needed a run (get over to the Wilson ranch, Vern is having chest pains) it was thought advisable to rely on unfamiliar street addresses instead, leaving drivers to fumble.
In my experience, if a referring clinic knows me they will send a patient's records without requiring written authorization for release of records from the patient. Are they breaking the law by releasing this information to me without a "consent form" being signed?

Technically, I suppose they are.

Yet here we are, forced to comply with a mandate that isn't enforced, has significant limitations, and in many ways limits the quality of health care delivery.

-Wes