4 ms·
Your doctor already captures this data.
by blhack 6y ago
Your doctor already captures this data.
- sm4rk0 6y agoIn real time and willing and able to sell it to whomever bids more?
- blhack 6y agoWell yes in some cases it is in "real time", but do you know of doctors offices caught selling health data? That seems wildly unethical, and also very illegal. I'd imagine anybody caught doing that would be in jail.
- sm4rk0 6y agoMy point was that your data is safer with a doctor's office then with a "platform": > And while you might assume that this information is legally protected the same way your hospital and medical records are, that’s not necessarily the case. https://www.consumerreports.org/health-privacy/are-health-apps-putting-your-privacy-at-risk/ https://www.consumerreports.org/health-privacy/are-health-ap...
- blhack 6y agoCan you be specific about what you're trying to get at here? I don't understand why you think there is a difference between taking a health reading at your doctors office and having it included in your patient chart, or taking a reading at your house and having that included in your patient chart. I'm wondering if I'm missing something that is just being unsaid.
- everly 6y agoI think they are just saying the data is more likely to be secure if it is recorded at your doctor's office, which seems reasonable to me. Let's say it is a blood pressure reading taken by your Fitbit and uploaded to Google's servers. That data is not subject to HIPAA regulations. When your doctor takes your blood pressure and records it in your chart, it is subject to those regulations (as you say, it would be wildly unethical for them to sell it). Separately, even if the two scenarios were subject to the same regulations, I would still expect the doctor's office scenario to be more secure. I think that any given patient's home network/device/security practices are more lax than those of most healthcare organizations.
- swirepe 6y ago>That data is not subject to HIPAA regulations. You can be HIPAA compliant and on Google servers. https://cloud.google.com/security/compliance/hipaa/ https://cloud.google.com/security/compliance/hipaa/
- tssva 6y agoThe point wasn't that they couldn't be HIPAA compliant but that they don't have to be.
- caddemon 6y agoThere are downsides to this too though. I wanted a second opinion on an EEG, and after some hassle getting the original office to mail a disk (the only way they can transfer it), the new doctor said they can't view it because they use different software at their hospital for EEGs. These are two well ranked US hospitals, and EEG is a fairly common procedure. Perhaps this is not an inherent downside to the data security, but it's a reality with the current medical system and regulation does play a part in how we got here. And there is no financial incentive for hospitals to fix these sort of issues, in fact there is a disincentive (I'm doing another EEG now...). So I just don't see how it gets fixed without some outside disruption. It may not be a popular opinion on HN but I'm much more concerned with having access to my own medical information than how secure it is.
- tssva 6y ago"Separately, even if the two scenarios were subject to the same regulations, I would still expect the doctor's office scenario to be more secure. I think that any given patient's home network/device/security practices are more lax than those of most healthcare organizations." For the most part security for healthcare systems is like security for government systems. A lot of checkbox marking and little real security. Just look at the large number of successful ransomware attacks against healthcare organizations. Having at one time worked in health informatics and from observing the practices at my healthcare providers I am not confident my data is anymore protected at a doctor's office.
- 6y ago
- sm4rk0 6y agoMaybe I misunderstood you. I thought your point is that it doesn't matter if a third-party platform has patient's data because their doctor's office already has it.
- iso1631 6y agoA device that measures your blood pressure and sends the results directly via an encrypted connection to your health care provider can be very useful, certainly beats lying in a hospital bed with a printout that the doctor checks every few hours. They key thing is, as always, ensuring that your data remains your property. Europe is bigger on that than the US.
- wikibob 6y agoNot only do they sell it, your Insurance company aggregates and sells it, as does your pharmacy, and anybody else that can get their grubby little hands on it.
- deleted 6y ago[deleted]
- prepend 6y agoMany health systems sell “anonymized” health data that fits the HIPAA description and is completely legal. So if your doctor is part of a larger health system or uses an EMR system odds are that all your data is bundled up and sold. It’s not identifiable easily, but is still sold and used.