DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Would a federal data breach notification law be A Good Thing or not for healthcare?

Posted on July 20, 2013 by Dissent

Modern Healthcare covered a Congressional hearing this week to consider a federal data breach notification law.  Congress has been kicking the idea around for years, but one of the big stumbling blocks has been whether any such law would pre-empt state laws.

I have long been on record supporting a federal law that pre-empts state laws, but only if the federal law is at least as strong as the strongest state laws.  I think it is unnecessarily burdensome on businesses to try to sort out 46 different breach notification laws, and feel sorry for people who live in the states that do not have any breach notification laws at all.

We need a strong law that sets clear standards for what types of information are covered – including health-related information held by non-HIPAA-covered entities – and the trigger to notification needs to be an  “access or acquisition” standard without any “significant harm” threshold.  The notification letter needs to include what happened, when it happened, where it happened, and how it happened as well as what types of information were involved. I’ve outlined my thoughts on these points numerous times on DataBreaches.net, including the need for transparency and a public listing of breaches that consumers and researchers can access.

In combination with any data breach notification law, however, the federal government also needs to impose some privacy and data security standards, so that any entity that collects  PII or what should be PHI  clearly knows its obligations on data collection, data protection, and data sharing. This would be particularly helpful given the proliferation of so many apps and health-related sites that seem to be sharing information widely.

I realize many businesses will claim that such an approach will “stifle innovation.” My response is that it will also reduce identity theft and other harms that may result from privacy breaches, will foster greater consumer confidence in businesses, and will bring U.S. law more into alignment with EU data protection laws.

In the end, I think that stronger federal laws will be good for U.S. businesses and good for consumers.


Related:

  • Maintenance Note
  • CISA Alert: Reported Supply Chain Compromise Affecting XZ Utils Data Compression Library, CVE-2024-3094
  • System Status Note
  • System Status Note
  • System Status Note
  • Fraudster's fake data breach claims should remind media to be careful what we report
Category: Uncategorized

Post navigation

← Hartselle man files complaint after Decatur hospital shares his mother's personal information with third-party vendor
OR: Samaritan Health investigates improper disposal of medical records →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Suspected Russian hacker reportedly detained in Thailand, faces possible US extradition
  • Did you hear the one about the ransom victim who made a ransom installment payment after they were told that it wouldn’t be accepted?
  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.