DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Would a federal data breach notification law be A Good Thing or not for healthcare?

Posted on July 20, 2013 by Dissent

Modern Healthcare covered a Congressional hearing this week to consider a federal data breach notification law.  Congress has been kicking the idea around for years, but one of the big stumbling blocks has been whether any such law would pre-empt state laws.

I have long been on record supporting a federal law that pre-empts state laws, but only if the federal law is at least as strong as the strongest state laws.  I think it is unnecessarily burdensome on businesses to try to sort out 46 different breach notification laws, and feel sorry for people who live in the states that do not have any breach notification laws at all.

We need a strong law that sets clear standards for what types of information are covered – including health-related information held by non-HIPAA-covered entities – and the trigger to notification needs to be an  “access or acquisition” standard without any “significant harm” threshold.  The notification letter needs to include what happened, when it happened, where it happened, and how it happened as well as what types of information were involved. I’ve outlined my thoughts on these points numerous times on DataBreaches.net, including the need for transparency and a public listing of breaches that consumers and researchers can access.

In combination with any data breach notification law, however, the federal government also needs to impose some privacy and data security standards, so that any entity that collects  PII or what should be PHI  clearly knows its obligations on data collection, data protection, and data sharing. This would be particularly helpful given the proliferation of so many apps and health-related sites that seem to be sharing information widely.

I realize many businesses will claim that such an approach will “stifle innovation.” My response is that it will also reduce identity theft and other harms that may result from privacy breaches, will foster greater consumer confidence in businesses, and will bring U.S. law more into alignment with EU data protection laws.

In the end, I think that stronger federal laws will be good for U.S. businesses and good for consumers.

Category: Uncategorized

Post navigation

← Hartselle man files complaint after Decatur hospital shares his mother's personal information with third-party vendor
OR: Samaritan Health investigates improper disposal of medical records →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
  • 60K BTC Wallets Tied to LockBit Ransomware Gang Leaked
  • UK: Legal Aid Agency hit by cyber security incident
  • Public notice for individuals affected by an information security breach in the Social Services, Health Care and Rescue Services Division of Helsinki
  • PowerSchool paid a hacker’s extortion demand, but now school district clients are being extorted anyway (3)
  • Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines
  • Call for Public Input: Essential Cybersecurity Protections for K-12 Schools (2025-26 SY)
  • Cyberattack puts healthcare on hold for hundreds in St. Louis metro
  • Europol: DDoS-for-hire empire brought down: Poland arrests 4 administrators, US seizes 9 domains

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim
  • Privacy matters to Canadians – Privacy Commissioner of Canada marks Privacy Awareness Week with release of latest survey results
  • Missouri Clinic Must Give State AG Minor Trans Care Information
  • Georgia hospital defeats data-tracking lawsuit
  • No Postal Service Data Sharing to Deport Immigrants
  • DOGE aims to pool federal data, putting personal information at risk
  • Privacy concerns swirl around HHS plan to build Medicare, Medicaid database on autism

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.