<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://nafonline.net/blog" xmlns:dc="
http://purl.org/dc/elements/1.1/">
<channel>
 <title>Privacy</title>
 <link>http://nafonline.net/blog/topics/privacy</link>
 <description>The taxonomy view with a depth of 0.</description>
 <language>en</language>
<item>
 <title>HEALTH IT: California Cracks Down on Health Cyber-Snoops</title>
 <link>http://nafonline.net/blog/new-health-dialogue/2008/health-it-california-cracks-down-health-cyber-snoops-6612</link>
 <description>&lt;p&gt;&lt;img border=&quot;5&quot; vspace=&quot;5&quot; align=&quot;right&quot; src=&quot;/blog/files/binoculars.jpg&quot; hspace=&quot;5&quot; /&gt;What do Britney Spears and Farrah Fawcett have in common with California First Lady Maria Shriver? How soon we forget: someone snooped in their medical files. The California state Senate hasn&#039;t forgotten. It just passed legislation that would require health care providers to monitor employees to ensure that they do not violate patients&#039; medical rights, the &lt;a target=&quot;_blank&quot; href=&quot;http://www.latimes.com/features/health/la-me-legis27-2008aug27,0,4367960.story&quot;&gt;&lt;em&gt;LA Times&lt;/em&gt; reports.&lt;/a&gt; California Gov. Arnold Schwarzenegger—Shriver&#039;s husband—supports the bill, which still must pass the state Assembly.&lt;/p&gt;
&lt;p&gt;Much of the language in the California bill sounds like the federal HIPAA Privacy law. It would require health care providers to have clear and appropriate safeguards to protect patient privacy and &amp;quot;reasonably safeguard confidential medical information from unauthorized or unlawful access, use or disclosure.&amp;quot; &lt;/p&gt;
&lt;p&gt;But the California initiative differs from HIPAA in several ways. First, it  would allow an individual to sue the person who negligently released confidential medical information. The federal law, in contrast, only allows the Secretary of Health and Human Services to investigate complaints and assess penalties. California would also impose fines up to $25,000—but this pales in comparison to the possible monetary damages available in a civil lawsuit. &lt;/p&gt;
&lt;p&gt;Second, the California bill would establish a new Office of Health Information Integrity in the state health department to enforce confidentiality laws and assess fines. This is a clear signal that the California legislature is not interested in waiting for the federal government to investigate whether hospitals are properly protecting health information. &lt;/p&gt;
&lt;p&gt;A pending companion bil in the state Senate would allow for fines against health care providers themselves, although opponents say such violations are already investigated by the Medical Board of California. Still, these bills are more evidence that the privacy of health information isn&#039;t just a concern for movie stars and first ladies.  Protecting privacy is a hot button issue that will be a factor as we move to expand health IT, as we must, as part of health care reform.  It will be interesting to see whether other states follow California&#039;s lead.&lt;/p&gt;
</description>
 <comments>http://nafonline.net/blog/new-health-dialogue/2008/health-it-california-cracks-down-health-cyber-snoops-6612#comments</comments>
 <category domain="http://nafonline.net/blog/which-blog/new-health-dialogue">New Health Dialogue</category>
 <category domain="http://nafonline.net/blog/topics/health-it">Health IT</category>
 <category domain="http://nafonline.net/blog/topics/privacy">Privacy</category>
 <pubDate>Wed, 27 Aug 2008 20:58:00 -0400</pubDate>
 <dc:creator>Joanne Kenen</dc:creator>
 <guid isPermaLink="false">6612 at http://nafonline.net/blog</guid>
</item>
<item>
 <title>HEALTH IT: The Not-So-Private View from HHS</title>
 <link>http://nafonline.net/blog/new-health-dialogue/2008/health-it-not-so-private-view-hhs-3779</link>
 <description>&lt;p&gt;Earlier this week we posted our interview about the future of health IT with Carol Diamond of the Markle Foundation. (&lt;a href=&quot;/blog/new-health-dialogue/2008/health-3684&quot; target=&quot;_blank&quot;&gt;Part one&lt;/a&gt;, and &lt;a href=&quot;/blog/new-health-dialogue/2008/part-two-markle-3688&quot; target=&quot;_blank&quot;&gt;part two&lt;/a&gt;). Today we&#039;d like to point you to &lt;a href=&quot;http://thehill.com/business--lobby/qa-with-mike-leavitt-2008-05-07.html&quot; target=&quot;_blank&quot;&gt;&lt;i&gt;The Hill&lt;/i&gt; &#039;s interview with Health and Human Services Secretary Mike Leavitt &lt;/a&gt;on the same topic. &lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/blog/files/leavitt_original.jpg&quot; align=&quot;left&quot; hspace=&quot;5&quot; vspace=&quot;5&quot; /&gt;Two points struck us. First, neither the article nor the full Leavitt transcript mentions the word &amp;quot;privacy&amp;quot;—a big issue both for policymakers and for the public who keep reading about nosy hospital staff, researchers who do sloppy things like leave laptops with patient records in the car, and thieves who steal credit card numbers and other financial identity information from medical records. Not insurmountable but essential if we&#039;re going to get the country on board with health IT. Second, Leavitt really depicted the health IT challenge primarily as a technology question involving interoperability (letting different computer systems talk to each other) while Markle&#039;s &lt;a href=&quot;http://www.connectingforhealth.org/&quot; target=&quot;_blank&quot;&gt;Connecting for Health&lt;/a&gt; program and conversations with some other experts have made us think about a far broader range of policy challenges that won&#039;t be solved only by the computer geeks. &lt;/p&gt;
&lt;p&gt;We did like that Leavitt pointed out that the electronic medical records (with appropriate privacy safeguards) won&#039;t just improve care for individual patients. Properly designed, they will provide a huge data pool for researchers to track public health threats, emerging trends or epidemics, drug side effects and the like as well as do research into what treatments work best for patients. But first we&#039;ve got to get there. Leavitt sounds optimistic, but we&#039;ve heard that health IT is just around corner for some time. Let&#039;s hope he&#039;s right sooner rather than later.&lt;/p&gt;
</description>
 <comments>http://nafonline.net/blog/new-health-dialogue/2008/health-it-not-so-private-view-hhs-3779#comments</comments>
 <category domain="http://nafonline.net/blog/which-blog/new-health-dialogue">New Health Dialogue</category>
 <category domain="http://nafonline.net/blog/topics/health-it">Health IT</category>
 <category domain="http://nafonline.net/blog/topics/health-reform">Health Reform</category>
 <category domain="http://nafonline.net/blog/topics/privacy">Privacy</category>
 <pubDate>Thu, 08 May 2008 18:10:00 -0400</pubDate>
 <dc:creator>Joanne Kenen</dc:creator>
 <guid isPermaLink="false">3779 at http://nafonline.net/blog</guid>
</item>
<item>
 <title>HEALTH IT: Crime and Punishment (Please) </title>
 <link>http://nafonline.net/blog/new-health-dialogue/2008/health-it-crime-and-punishment-please-3546</link>
 <description>&lt;p&gt;The &lt;em&gt;Wall Street Journal&lt;/em&gt; had a &lt;a target=&quot;_blank&quot; href=&quot;http://online.wsj.com/public/article/SB120941048217350433.html?mod=2_1566_leftbox&quot;&gt;great piece&lt;/a&gt; and blog &lt;a target=&quot;_blank&quot; href=&quot;http://blogs.wsj.com/health/2008/04/29/nosy-hospital-staffers-plague-patients-files/&quot;&gt;item &lt;/a&gt;yesterday about Health IT and privacy breaches — we would have blogged about it then had we not, coincidentally, been out much of the day with some other think-tankers and foundation folks educating ourselves about that very topic. Among other things, the &lt;em&gt;Journal&lt;/em&gt; article made the key point that privacy breaches are rarely prosecuted. That&#039;s not the right way to build public confidence in electronic health records. &lt;/p&gt;
&lt;p&gt;Some 35,000 reports of privacy violations have been reported to the Department of Health and Human Services under HIPAA (Health Insurance Portability and Accountabilty Act) since 2003, but not a single civil fine has been levied,&lt;em&gt; WSJ&lt;/em&gt; reported. HHS says several hundred reports of violations have been referred to the Department of Justice for criminal prosecution; about 200 cases have been filed although it&#039;s not clear how many of them were under HIPAA.&lt;/p&gt;
&lt;p&gt;So we were pleased to see the&lt;em&gt; &lt;/em&gt;&lt;a target=&quot;_blank&quot; href=&quot;http://www.latimes.com/news/local/la-me-ucla30apr30,1,2997318.story&quot;&gt;&lt;em&gt;LA Times&lt;/em&gt; report &lt;/a&gt;today (Charlie Ornstein&#039;s done a lot of good work on this whole phenomenon of &lt;a target=&quot;_blank&quot; href=&quot;http://www.latimes.com/news/local/la-me-records-sg,0,7797684.storygallery&quot;&gt;Hollywood sneaky peeky&lt;/a&gt;) that an alleged celebrity snoop at UCLA Medical Center had been indicted for allegedly selling information from medical records of celebrities to the media (apparently the &lt;em&gt;National Enquirer&lt;/em&gt;).&lt;/p&gt;
&lt;p&gt; The paper reported that Lawanda Jackson, 49, could face up to 10 years in prison if convicted of the charge of obtaining individually identifiable health information for commercial advantage. The paper had earlier reported that Jackson had allegedly pried into the private medical records of California First Lady Maria Shriver, Farrah Fawcett, and 60 others. In an April 8 interview with the newspaper, Jackson denied that she had leaked the information or otherwise profited from it.&lt;/p&gt;
&lt;p&gt;Hospitals can (and should) take multiple steps to make records more secure; for instance, walling off parts of the computerized records so that people can access only what they need to know. But the feds (or state governments) have responsibilities too. Getting electronic records right, from technical, economic, and privacy standpoints, is hard enough. If all the public hears about is breach after breach, snooping, spying, and carelessness (medical records left on a laptop in someone&#039;s car trunk...) they aren&#039;t going to buy into Health IT. And we need them to; Health IT may not save as much as quickly politicians are promising but it is essential for quality, for coordinated care, for efficiency and for research. So when there&#039;s a crime, let&#039;s see some punishment.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
</description>
 <comments>http://nafonline.net/blog/new-health-dialogue/2008/health-it-crime-and-punishment-please-3546#comments</comments>
 <category domain="http://nafonline.net/blog/which-blog/new-health-dialogue">New Health Dialogue</category>
 <category domain="http://nafonline.net/blog/topics/health-it">Health IT</category>
 <category domain="http://nafonline.net/blog/topics/privacy">Privacy</category>
 <pubDate>Wed, 30 Apr 2008 19:18:00 -0400</pubDate>
 <dc:creator>Joanne Kenen</dc:creator>
 <guid isPermaLink="false">3546 at http://nafonline.net/blog</guid>
</item>
</channel>
</rss>

