Related Experiment Videos
Hacking HIPAA: "Best Practices" for Avoiding Oversight in the Sale of Your Identifiable Medical Information
Insights
HIPAA de-identification standards offer robust patient privacy protections, unlike permissive guidelines which fail to adequately safeguard identifiable health information. Understanding these differences is crucial for regulators and the public.
Area of Science:
- Health Law
- Information Security
- Patient Privacy
Background:
- Confusion exists regarding the term "de-identified" when applied to patient information that can still identify individuals.
- The Health Insurance Portability and Accountability Act (HIPAA) has specific standards for de-identifying health information.
- Permissive "de-identification guidelines" differ significantly from HIPAA's stringent requirements.
Purpose of the Study:
- To clarify the critical differences between HIPAA's de-identification standards and permissive guidelines.
- To examine the legislative intent behind HIPAA's broad definition of identifiable health information.
- To evaluate the effectiveness and vulnerabilities of current permissive de-identification approaches.
Main Methods:
- Comparative analysis of HIPAA's de-identification requirements versus permissive guidelines.
- Examination of historical context and motivations for HIPAA's patient data protections.
- Assessment of methods used in permissive de-identification and their outcomes.
Main Results:
- HIPAA's de-identification standards were designed to prevent harms from the sale of medical records.
- Permissive guidelines often label identifiable information as "de-identified" without sufficient safeguards.
- Current permissive de-identification guidelines are deemed ineffective and vulnerable for data protection.
Conclusions:
- Permissive de-identification guidelines present significant vulnerabilities, rendering them inadequate for protecting patient privacy.
- There is a critical need for regulators, compliance professionals, and advocates to ensure accountability and transparency in health information utilization.
- Distinguishing between HIPAA standards and permissive guidelines is essential for protecting identifiable patient information.
Abstract:
In light of the confusion invited by applying the label "de-identified" to information that can be used to identify patients, it is paramount that regulators, compliance professionals, patient advocates and the general public understand the significant differences between the standards applied by HIPAA and those applied by permissive "de-identification guidelines." This Article discusses those differences in detail. The discussion proceeds in four Parts. Part II (HIPAA's Heartbeat: Why HIPAA Protects Identifiable Patient Information) examines Congress's motivations for defining individually identifiable health information broadly, which included to stop the harms patients endured prior to 1996 arising from the commercial sale of their medical records. Part III (Taking the "I" Out of Identifiable Information: HIPAA's Requirements for De-Identified Health Information) discusses HIPAA's requirements for de-identification that were never intended to create a loophole for identifiable patient information to escape HIPAA's protections. Part IV (Anatomy of a Hack: Methods for Labeling Identifiable information "De-Identified") examines the goals, methods, and results of permissive "de-identification guidelines" and compares them to HIPAA's requirements. Part V (Protecting Un-Protected Health Information) evaluates the suitability of permissive "de-identification guidelines," concluding that the vulnerabilities inherent in their current articulation render them ineffective as a data protection standard. It also discusses ways in which compliance professionals, regulators, and advocates can foster accountability and transparency in the utilization of health information that can be used to identify patients.