DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Her case shows why healthcare privacy laws exist

Posted on January 4, 2012 by Dissent

Michael Hiltzik writes:

Of all the personal information that you might want to keep private, your medical records are the most important. That’s why federal and state laws carry stiff penalties, up to and including jail time, for healthcare providers who let such data loose into the wild.

So you should be aghast at how free and easy Prime Healthcare Services and two executives at Prime-owned Shasta Regional Medical Center have been with the medical chart of a patient named Darlene Courtois. They showed the entire chart to an editor of her hometown newspaper, and Prime’s corporate office divulged some of her medical examination results to me (though I didn’t ask for them). They didn’t have her permission for those disclosures, her daughter says.

Their justification is that Courtois implicitly waived her medical privacy by sharing a portion of her records with a different news organization. But that doesn’t wash. No matter what Courtois said or did, without her specific consent Shasta still doesn’t have the legal right to disclose her file on its own, say the experts I’ve talked to.

Read more on Los Angeles Times.

This situation might be a good one to include in HIPAA privacy training – either specifically or in the more general form of whether doctors or providers can defend themselves against public statements made by patients if they do not have the patient’s explicit consent to discuss their case. It’s not clear from the report whether the hospital executives were relaying their own understanding (or misunderstanding) of HIPAA or if they had consulted with lawyers and lawyers had advised them that they did not need consent. But based on the circumstances described in the report, if they are accurate, the executives could find themselves facing HIPAA violation charges on top of their other problems.

Category: Health Data

Post navigation

← NY: Bronx cops in file flub
[CORRECTED AND UPDATED]: “Anonymous Dumps Bank of America client credit card info in #OpBank” – Fiction! →

1 thought on “Her case shows why healthcare privacy laws exist”

  1. Anonymous says:
    January 5, 2012 at 10:17 am

    One of the biggest barriers for people like me (health information system researchers focusing on privacy and security) in understanding EHR/PHR/HIE functionality and how it differs across institutions is that it’s impossible for a provider to allow me to see how physicians use these tools without some disclosure of PHI. I’m not saying I need to be accommodated, but I wish there were an easier way to allow tinkering with real systems in a safe way. Of course, this case is beyond egregious and is a great example of a case that cries out for HIPAA civil enforcement. (right?)

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Masimo Manufacturing Facilities Hit by Cyberattack
  • Education giant Pearson hit by cyberattack exposing customer data
  • Star Health hacker claims sending bullets, threats to top executives: Reports
  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
  • 60K BTC Wallets Tied to LockBit Ransomware Gang Leaked
  • UK: Legal Aid Agency hit by cyber security incident
  • Public notice for individuals affected by an information security breach in the Social Services, Health Care and Rescue Services Division of Helsinki
  • PowerSchool paid a hacker’s extortion demand, but now school district clients are being extorted anyway (3)
  • Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • US Customs and Border Protection Plans to Photograph Everyone Exiting the US by Car
  • Google agrees to pay Texas $1.4 billion data privacy settlement
  • The App Store Freedom Act Compromises User Privacy To Punish Big Tech
  • Florida bill requiring encryption backdoors for social media accounts has failed
  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim
  • Privacy matters to Canadians – Privacy Commissioner of Canada marks Privacy Awareness Week with release of latest survey results
  • Missouri Clinic Must Give State AG Minor Trans Care Information

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.