Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The US has HIPAA which while not perfect would cover any medical data sharing and does have decently sized fines behind it.


> The US has HIPAA which while not perfect would cover any medical data sharing and does have decently sized fines behind it.

Because HealthEngine looks like it has business relationships with providers, it would probably be covered by HIPAA through provider BAAs in the US.

But if it only had a business relationship with the consumer, ala Google Duplex, and handled medical bookings on the consumer's behalf that would not be the case. So even though the specific case would enjoy covered by HIPAA in the US, it is illustrative of a problem HIPAA may not be adequate to address.

HIPAA may actually be dangerous here, because what lay awareness of it exists seems to see it as protecting health data generally, when it only protects health data held by certain entities, and consumer-facing entities that don't have a business relationship with your health provider or insurer aren't covered, and there are plenty of them trying to vacuum up health data.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: