DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

NYCLU Calls for Greater Privacy Protections as New York Transitions to Electronic Medical Records

Posted on December 9, 2010 by Dissent

At a joint hearing of two New York City Council committees  (on Tuesday), the New York Civil Liberties Union raised serious privacy concerns related to New York State’s ongoing transition to electronic medical records.

“Sharing health information among health care providers will likely benefit patients greatly, but to recognize this benefit we need to take steps to protect the right of New Yorkers to keep their most personal information private,” said NYCLU Executive Director Donna Lieberman. “Without commonsense privacy protections, easily shareable electronic records can create threats to patient privacy, including making patients’ most personal and confidential information susceptible to inadvertent disclosure and misuse.”

Electronic networks operated by regional health information organizations already allow health-care providers to share patient information among participating providers within those regions. Eventually, these regional networks will be linked by the New York State Health Information Network, which will allow health-care providers throughout the state to easily access patients’ medical records.

Testifying before the Technology Committee and the Health Committee, NYCLU Senior Public Policy Counsel Corinne Carey warned that, despite the network’s potential benefits to patient care, there are serious gaps in the privacy protections currently in place.

“Patients have little control over confidential and sensitive health information once it is entered into an electronic network,” Carey said. “If patients don’t trust the network, they will not use it, and there may be significant public backlash, as we’ve seen with periodic uproar over the level of privacy protection guaranteed by Facebook.”

Carey discussed three major concerns: (1) patient consent is not required for entering individual medical information into the network; (2) the state has adopted an “all-or-nothing” approach to sharing health information that gives everyone who accesses a patient’s electronic record all of that patient’s medical information, regardless of the need; and (3) the state has not engaged in sufficient public education about the network.

The state’s current policies require patient consent only when a provider wants to download a patient’s medical records from the network. In emergency situations, state policy allows providers to access a patient’s medical records without the patient’s knowledge or consent.  Patients should have a choice about whether they want their medical information to be linked to an electronic network that allows for easy sharing before it happens, the NYCLU testified, not simply when a provider wants to access that information.

Patients also should be able to choose what health information is shared and with which providers, including sensitive information such as history of substance abuse treatment, mental health conditions, abortion and other reproductive health care. Otherwise, the patients who most need help may refuse to participate for fear of negative consequences such as discrimination both within and outside of the medical system.

“There has been an astonishing lack of communication with the public about the development of health information networks,” Carey said. “Informed consent is a critical concept in health care.  Patients can’t give consent that is truly informed unless they understand the risks and benefits before making the decision to participate. The state must initiate a public outreach and educational campaign about the network that is more than simply a promotional tool.”

To read the NYCLU’s full testimony, visit www.nyclu.org/files/releases/e-health_Testimony_12-6.10.pdf.

Source: NYCLU


Related:

  • Maintenance Note
  • CISA Alert: Reported Supply Chain Compromise Affecting XZ Utils Data Compression Library, CVE-2024-3094
  • System Status Note
  • System Status Note
  • Fraudster's fake data breach claims should remind media to be careful what we report
  • "Pompompurin" taken into custody after violating conditions of pre-sentencing release on bond (1)
Category: Uncategorized

Post navigation

← AHS medical records of 2,700 children stolen with laptop: Privacy boss
Laptop stolen from Methodist Theological School in Ohio contained personally identifiable information →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.