DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

FDNY might sell your personal health info? Not so fast….

Posted on February 5, 2014 by Dissent

Gary Buiso and Susan Edelman report that a revised privacy policy by the Fire Department of New York (FDNY) has got some people concerned.

Find yourself lying in a city ambulance and your personal health information could be sold to the highest bidder.

The FDNY has issued a murky patient-privacy notice that says it may use a patient’s “protected health information (PHI),” including everything from address and phone number to prescriptions and medical history, for fund-raising and marketing — and maybe even for sale.

It’s enough to give patients’ advocates and privacy experts a coronary.

The reporters interview some health lawyers but do not seem to have reached out to HHS to get a definitive answer on whether such use would be legal under HIPAA.  Confusing the matter, they report:

Public-health agencies are exempt from a federal law that bars private health-care providers and contractors from releasing patient data.

But that’s not quite the whole story. Under the public health exemption, covered entities who are public health authorities are only allowed to release or disclose patient information for public health reasons, not for marketing or other financial purposes. And with only a few exceptions, “marketing” requires signed consent of the patients. It’s not even clear to me whether FDNY is a “public health authority” under HIPAA. If they are, it would be as a “hybrid” entity, I suspect. In any event, the NY Post (and HealthITSecurity.com, who repeats the misinformation) have just got that part substantially wrong.

Fundraising and sale of PHI are also covered by HIPAA. For fundraising, no authorization may be required as long as certain conditions are met. Bricker & Eckler cite the law in an alert they wrote for their clients:

Subject to the conditions of paragraph (f)(2) of this section, a covered entity may use, or disclose to a business associate or to an institutionally related foundation, the following protected health information for the purpose of raising funds for its own benefit, without an authorization meeting the requirements of Sec. 164.508:

  • Demographic information relating to an individual, including name, address, other contact information, age, gender, and date of birth;
  • Dates of health care provided to an individual;
  • Department of service information;
  • Treating physician;
  • Outcome information; and
  • Health insurance status.

[…]

A covered entity may not use or disclose protected health information for fundraising purposes as otherwise permitted by paragraph (f)(1) of this section unless a statement required by § 164.520(b)(1)(iii)(A) is included in the covered entity’s notice of privacy practices.

So FDNY might be able to use some information for its own fund-raising purposes without patient signed consent – but only if the patients are first given a notice of privacy practices that explains that. And from what the reporters learned, that generally doesn’t happen. Handing a patient something prior to providing emergency treatment that tells them they have to go to a web site to get more information just won’t fly with HHS. I would also suspect that if the patient is unconscious, FDNY has “implied consent” for treatment but no consent or notice for fund-raising purposes. How they might keep track of which patients can be part of fund-raising and which can’t for failure to provide notice or obtain consent should give everyone a huge headache.

As to the sale of PHI, the law firm of Bricker & Eckler has a nice recap of the provisions, here. They include:

The sale of PHI without a patient authorization was prohibited under the original Privacy Rule. The Final Rule adds an express prohibition on covered entities or business associates receiving direct or indirect remuneration in exchange for the disclosure of PHI, unless the covered entity first obtains patient authorization or an exception applies.

See their article for a summary of the different exceptions.

All in all, FDNY’s lawyers will have their hands full if FDNY should decide to pursue these options because at the scene of an emergency, providing notice and getting consent for marketing, fund-raising, or sale of PHI is the last thing most responders and patients are thinking about.


Related:

  • Maintenance Note
  • CISA Alert: Reported Supply Chain Compromise Affecting XZ Utils Data Compression Library, CVE-2024-3094
  • System Status Note
  • System Status Note
  • Fraudster's fake data breach claims should remind media to be careful what we report
  • "Pompompurin" taken into custody after violating conditions of pre-sentencing release on bond (1)
Category: Uncategorized

Post navigation

← New and very concerning developments following breach involving Disqus comments
Miami Resident Pleads To Tax Fraud And Identity Theft – But Where Did She Get the PII? →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.