View Single Post
  #33   Report Post  
Posted to alt.home.repair
Kurt V. Ullman Kurt V. Ullman is offline
external usenet poster
 
Posts: 367
Default Google is not the only one who knows all about you.

On 12/23/15 12:27 PM, Mayayana wrote:
| It's unclear to me in all this what the exact law
| is related to doctors, CVS and permission. My
| understanding was that a doctor cannot sell data,
| but a non-medical business can. I may be wrong.
| If you know otherwise, or more, I'd be interested
| to see the links that explain it.
|
|
| The two major (federal) ones is the Health Isurance Portability and
| Accountability Act. (The best resource is
|
https://www.cms.gov/Regulations-and-...fo/index.html0
| and he Health Information Technology for Economic and Clinical Health
| Act (HITECH Act)
|
https://www.healthit.gov/policy-rese...it-legislation
|

Those links seem to be for vast plans to regulate
health plan medical records and digitization
standards. I was talking about specific information
about specific laws, or lack thereof, governing
the sale of medical data. I thought I had read
in one of the CVS articles that doctors could
not legally share data, but that other businesses
could get around that. As one can see from my links,
they are getting around it one way or another.
What's not clear from my links is whether they
can just sell the data directly in a legal way,
without getting permission.


All medically related privacy laws flow from one of the two at least
at the federal level. At least under HIPAA (I havent worked as much with
HITECH, although that would talk about data transmission from electronic
health records. The holy grail is Personal Health Information (PHI).

http://www.hipaa.com/hipaa-protected...s-phi-include/