Showing posts with label HIPAA. Show all posts
Showing posts with label HIPAA. Show all posts

Tuesday, March 04, 2008

How Private is Private? Is Google a covered entity?

Back in 1996, the Health Insurance Portability and Accountability Act (HIPAA) was enacted by Congress for the purposes of ensuring continuity of healthcare benefits for workers changing or losing their jobs (Title 1) and to establish national standards (Title 2) for electronic health care transactions, maintenance of privacy about so-called protected health information (PHI) and security of that information maintained in electronic repositories (e.g. hospital information systems and other data bases).

Since the actual implementation of the Privacy and Security Rules in 2003, there have been considerable efforts on the part of healthcare organizations (providers, health plans and so-called healthcare clearing houses) to develop policies and procedures which adhere to federal law while still carrying out patient care effectively as well as managing clinical research productively. Of course, nothing is perfect and there have been a plethora of papers and media articles on the barriers to patient care (Gross 2007) and to important large population based clinical research (Armstrong, Kline-Rogers et al. 2005; Wolf and Bennett 2005; Wilson 2006). Further, the security of PHI is not so great either (Freudenheim and Pear 2006).

Therefore, health insurance might be portable for some workers, but PHI is not!

With all the recent hoopla about Microsoft wanting to purchase, somewhat hostilely, Yahoo in order to “corner” the market on search engines, it might have been easy to overlook 10 second sound bites on the morning radio news, or the little technology tidbit in the New York Times (Lohr 2008) which was NOT on the front page.

So it seems that Google actually will scoop Microsoft in implementing a web based interface with a major healthcare system, in this case the Cleveland Clinic with its some 100,000 patients. The deal is, if one has a Google e-mail account, one can use the same sign-in and password to access and transmit one’s medical records. Apparently, the pilot phase will involve only some “innocuous” data such as allergies and prescription records. However, prescription records can certainly allow inferences about underlying health conditions for specific patients which, if leaked, could have problematic consequences. Funny how Google mail accounts are encryption proof (Stone 2007) to corporate electronic security walls. Does that provide some clues as to how undone PHI privacy could become?

And what about HIPAA? There is some debate about whether Google could be considered a healthcare clearing house or other entity which information repositories containing people’s PHI would be considered protected and would have an obligation to protect under current federal regulations. The World Privacy Forum (Gellman 2008) thinks not.

Other dicey questions: will Google patients be subject to advertising spam or other intrusive advertisement adduced from their prescription lists? What guarantees that the “client” (read patient lists) won’t be sold to Pharma companies as yet another means of developing data bases about physician prescribing patterns? Who is going to regulate these issues? Google is a great search engine—I use it all the time! But I’m not sure I want to use it to manage my healthcare information. I’d rather continue to keep it on my PDA!


Armstrong, D., E. Kline-Rogers, et al. (2005). "Potential impact of the HIPAA privacy rule on data collection in a registry of patients with acute coronary syndrome." Archives of Internal Medicine 165(10): 1125-1129.
Freudenheim, M. and R. Pear (2006). Health hazard: computers spilling your history. New York times. New York.
Gellman, R. (2008). Personal health records: why many PHRs threaten privacy, The World Privacy Forum.
Gross, J. (2007). Keeping patients' details private, even from kin. New York Times. New York.
Lohr, S. (2008). Google Health begins its preseason at Cleveland Clinic. New York Times. New York.
Stone, B. (2007). Firms fret as office e-mail jumps security walls. New York Times. New York.
Wilson, J. F. (2006). "Health insurance portability and accountability act privacy rule causes ongoing concerns among clinicians and researchers." Annals of Internal Medicine 145(4): 313-316.
Wolf, M. S. and C. L. Bennett (2005). "Local perspective of the impact of the HIPAA privacy rule on research." Cancer 106(2): 474-479.

Monday, February 25, 2008

Are Those Workplace Wellness Programs a Good Idea?

Are Those Workplace Wellness Programs a Good Idea?

It happened yesterday in our department head meeting. The nice lady who represents our “WOW” council, “Works on Wellness”, was presenting yet again about the benefits of signing up, and encouraging/coercing our staffs to do so. It is “perfectly safe and confidential,” she said. Then she said, “Chris, as our Privacy Officer, what do you think?”

Well, I had already decided I was going to take the moral low ground and not opine publicly about my reservations. I had attended some of these presentations before, read Arthur Caplan’s great piece (which a colleague forwarded to me) about these programs (http://blog.bioethics.net/2007/08/art-caplan-on-msnbc-privacy-is-true-price-of-healt/) and had shared with my boss, the CFO, my concerns. This is a big initiative involving at least 15 hospitals, and I knew our CEO was heavily invested in our participation. I still have some interest in avoiding professional suicide. But now I was on the spot. I tried to hedge with, “you don’t really want to know”, making a joke, but she insisted.

For those of you who aren’t familiar, and many of you soon will be if you are not, this program, like many others nationally, has the stated goal of making employees more healthy. Employees are encouraged to go on line to a website, enter in their personal information, sign up for classes, even get a wellness coach. They enter in when their last physical was, and get points for doing all those screenings we should all be doing—cholesterol, mammograms, colonoscopies, etc. etc. They get points (and discounts) for exercise classes and joining Weight Watchers. Why? Aside from all the free/discounted education and the chance to track your health “quotient” in comparison to your peers, participants get a reduction in their insurance premiums for participating, and the more they participate, the more dollar credits they get. Not only that, but the organization gets an overall premium reduction too, based on the percentage of employees who participate. No wonder the top management sends regular emails encouraging staff to sign up, and now wants to enlist the department heads in doing the same type of 'encouraging'. Discounts for health insurance are a pretty powerful incentive.

“Perfectly safe and confidential”. Mmmm…. That is a tough one. Not a month goes by that there isn’t some famous security breach concerning PHI (Protected Health Information in HIPAA-speak) involving some pretty big organizations--- VA, Pentagon, Anthem—who you would expect to be current on technological ways to protect privacy. And, as Dr. Caplan points out, some organizations are already substituting a stick for the financial carrot—now you may have to pay more than your colleague if you are unlucky (or is it really your fault?) enough to have a high cholesterol level, still be addicted to nicotine, or, perhaps, carry a gene that will predispose you to expensive cancer treatment at some point in the future.

You might argue, and some in the room did, that it is only fair that those of us who don’t work to be healthy pay more than our exercising non red meat eating colleagues. What about those who don’t wear helmets or seat belts? Surely we shouldn’t have to pay for your care when you get into that wreck that could have been avoided. And of course our organization, even though a non profit, needs to stay afloat and provide care for our patients. Why not “tax” our employees to our benefit. The whole concept is, in a way, a bit like “sin taxes”--- taxes on alcohol and cigarettes and those other things we know we shouldn’t be doing. And what about if we elect to have children knowing that they may have an inherited disorder? Well, who wants to pay for that?

So, I looked around the room at my colleagues, some of whom are friends, and put in my two cents, quoting the Caplan article. As a result, I have been trading emails with the WOW coordinator all morning to defend/explain my position. So far, I haven’t gotten into any real trouble with my bosses.

HIPAA has been cursed and touted for all kinds of things. Even though it was not the intent of the federal law, which originally had to do with moving insurance from one employer to another, Privacy and Security became two of the three pillars of the statute, which at least requires “covered entities” to notify patients about what is happening to their PHI (Notice of Privacy Practices). Yet, even I, who do this for a living, toss these flyers in the trash when I get them, and quickly “agree” to explanations about the security of the websites I visit without reading the fine print. The law hasn’t really helped much, since there are so many loopholes that allow the courts and others to get information without the permission of patients.

A friend of mine’s mother was recently diagnosed with breast cancer, and all of the daughters sought genetic counseling. The doctor performing the testing and counseling advised my friend not to go through her insurance to get it paid for, warning her that the repercussions could be anything from refusal to provide life insurance to some future employer just deciding that another candidate, without the potential illness ahead, is better qualified. Studies show that 1 out of 4 docs deliberately exclude sensitive information from patient records at their request, and I would guess that number to be higher in truth.

For now, I am going to forgo the extra dollars in my paycheck and take care of my health because it is right for me and my family, not because my employer wants me to. And, I am going to advise anyone who asks me to do the same.