Viral warning about period-tracking apps raises privacy concerns
Most period-tracking apps are not covered by HIPAA, leaving user health data vulnerable to legal requests.
2 min read
Kirsten Peremore
Oct 11, 2024 1:45:00 PM
HIPAA’s right of access allows individuals to take control of their health data even when it comes to research data. If their data is part of a designated record set, participants have the right to view and obtain it, though there are exceptions, such as during ongoing trials where access may be temporarily restricted.
HIPAA allows patients to inspect and obtain copies of the protected health information (PHI) held by covered entities or their business associates. The data accessible to patients includes information forming part of something called a designated record set. This designated record set includes any group of records used to make decisions about individuals like medical or billing records.
HHS guidance provides, “...it may be unlikely that a researcher would be maintaining a designated record set, any research records or results that are maintained by the covered entity as part of a designated record set would be accessible to research participants unless one of the Privacy Rule’s permitted exceptions applies.” When it comes to research data, the right of access only applies if the record data falls under this record set.
One of these permitted exceptions exists in cases like clinical trials, if a participant agrees, their right of access can be suspended while the trial is ongoing. Once the trials end, the right of access can be restored and participants once more can access their health information.
Research data can be accessed by the following individuals:
Verify the patient's identity
Confirm the data type
Use secure communication channels
Patients can also request corrections and control how their information is shared.
An institutional review board is a committee that reviews and approves research involving human subjects.
A healthcare organization can reject a request if the information is part of an ongoing clinical trial, poses a risk to the individuals or others, or falls under specific exceptions like psychotherapy notes.
Most period-tracking apps are not covered by HIPAA, leaving user health data vulnerable to legal requests.
Ultimately, de-identification remains a double-edged sword as it is necessary for privacy compliance, but is not a standalone solution. In clinical...
Balancing Facebook Ads with HIPAA compliance is achievable with the right approach. Healthcare providers can successfully use Facebook Ads while...