TIL - HIPAA doesn't protect data from being shared between organizations without consent
It obviously protects against sharing data with e.g. your employer, but if a health provider chooses to make your data shareable, there are 2.2M authorized entities that can potentially access the data (identifiable health data).
Excerpt of the video description:
Most people think that HIPAA means that their medical records are kept private. But what if I told you that HIPAA doesn’t protect your privacy at all?
This is our first video in a series about medical privacy, specifically looking at legislation that stripped individuals of the right to consent to medical data sharing.
We focus on what HIPAA actually is, how it came to allow our data to be shared without us even knowing, how we’ve been tricked into thinking we have privacy, and steps we can take to reclaim control of our medical data.
00:00 The State of Medical Privacy is a Mess
02:29 What is HIPAA
07:39 How Your Data is Shared
12:10 The Illusion of Privacy
14:48 What Can We Do
22:16 We Deserve Medical Privacy
We deserve privacy in our medical system. Our health information is sensitive, and we should be allowed to protect it. Even while we fight for better medical privacy, please always prioritize your health.
Special Thanks to: Twila Brase, Rob Frommer, and Keith Smith for chatting to us!
I'm not watching the whole video series because I'm no longer paid to sit through "continuing education" lol.
But, while the title of the post is misleading, hipaa was never meant to improve privacy, and when it was originally passed, anyone paying attention to the news knew that. The idea that it's a law intended to do something about privacy as a primary goal came later.
And, in day to day levels, it was actually an improvement over the lack of privacy that existed before it. Where it fails is in privacy protections from the government itself, and from insurance corporations. But it wasn't really designed for that, despite people somehow coming to believe it did.
But for the average person? It made it much harder for you or me to access someone else's records, and slightly reduced exposure of records overall.
Now, again, this isn't based on the videos, only the title of the post. The title is inaccurate and misleading, though I hope that people do look into what hipaa does and doesn't do for them because of the title.
Changed the title, not sure how to balance "meant to make it easier to share between organizations (gov included)" and the misconception thay it is a privacy oriented regulation