SlideShare una empresa de Scribd logo
1 de 1
Square Peg in a Round Hole: Data Privacy & Security Laws & Standards Meet Medicine 2.0

Más contenido relacionado

Más de David Harlow

Telemedicine challenges and opportunities slidecast
Telemedicine challenges and opportunities slidecastTelemedicine challenges and opportunities slidecast
Telemedicine challenges and opportunities slidecastDavid Harlow
 
Telemedicine: Challenges and Opportunities
Telemedicine: Challenges and OpportunitiesTelemedicine: Challenges and Opportunities
Telemedicine: Challenges and OpportunitiesDavid Harlow
 
Beyond HIPAA: Digital Health Opportunities & Regulatory Land Mines
Beyond HIPAA: Digital Health Opportunities & Regulatory Land MinesBeyond HIPAA: Digital Health Opportunities & Regulatory Land Mines
Beyond HIPAA: Digital Health Opportunities & Regulatory Land MinesDavid Harlow
 
Appointment Reminders, Patient Marketing, HIPAA and You
Appointment Reminders, Patient Marketing, HIPAA and YouAppointment Reminders, Patient Marketing, HIPAA and You
Appointment Reminders, Patient Marketing, HIPAA and YouDavid Harlow
 
Health Data Privacy (and a little FDA mHealth) Regulation
Health Data Privacy (and a little FDA mHealth) RegulationHealth Data Privacy (and a little FDA mHealth) Regulation
Health Data Privacy (and a little FDA mHealth) RegulationDavid Harlow
 
Keeping Your Edge: Managing Social Media While Protecting Privacy and Securit...
Keeping Your Edge: Managing Social Media While Protecting Privacy and Securit...Keeping Your Edge: Managing Social Media While Protecting Privacy and Securit...
Keeping Your Edge: Managing Social Media While Protecting Privacy and Securit...David Harlow
 
Dancing With HIPAA (HxRefactored 2014) David Harlow 05 14 2014 ...
Dancing With HIPAA (HxRefactored 2014) David Harlow 05 14 2014               ...Dancing With HIPAA (HxRefactored 2014) David Harlow 05 14 2014               ...
Dancing With HIPAA (HxRefactored 2014) David Harlow 05 14 2014 ...David Harlow
 
Digital Health: Apps, Analytics & Agencies
Digital Health: Apps, Analytics & AgenciesDigital Health: Apps, Analytics & Agencies
Digital Health: Apps, Analytics & AgenciesDavid Harlow
 
MCLE Health Law Basics Plus 2013 - Post-Acute Care
MCLE Health Law Basics Plus 2013 - Post-Acute CareMCLE Health Law Basics Plus 2013 - Post-Acute Care
MCLE Health Law Basics Plus 2013 - Post-Acute CareDavid Harlow
 
Patient Consent to the Use of Data: Are We Asking the Wrong Question?
Patient Consent to the Use of Data: Are We Asking the Wrong Question?Patient Consent to the Use of Data: Are We Asking the Wrong Question?
Patient Consent to the Use of Data: Are We Asking the Wrong Question?David Harlow
 
Accountable Care Organizations - The Camel's Nose Is In the Tent
Accountable Care Organizations - The Camel's Nose Is In the TentAccountable Care Organizations - The Camel's Nose Is In the Tent
Accountable Care Organizations - The Camel's Nose Is In the TentDavid Harlow
 
Health Care Social Media - Getting Started Without Getting In Trouble
Health Care Social Media - Getting Started Without Getting In TroubleHealth Care Social Media - Getting Started Without Getting In Trouble
Health Care Social Media - Getting Started Without Getting In TroubleDavid Harlow
 
Health Care Social Media - An Introduction to Engaging Intelligently and Legally
Health Care Social Media - An Introduction to Engaging Intelligently and LegallyHealth Care Social Media - An Introduction to Engaging Intelligently and Legally
Health Care Social Media - An Introduction to Engaging Intelligently and LegallyDavid Harlow
 
AHLA Annual Meeting 2011 Social Media for Lawyers by David Harlow
AHLA Annual Meeting 2011 Social Media for Lawyers by David HarlowAHLA Annual Meeting 2011 Social Media for Lawyers by David Harlow
AHLA Annual Meeting 2011 Social Media for Lawyers by David HarlowDavid Harlow
 
AHLA Annual Meeting 2011 Social Media Legal Marketing Resources by David Harlow
AHLA Annual Meeting 2011 Social Media Legal Marketing Resources by David HarlowAHLA Annual Meeting 2011 Social Media Legal Marketing Resources by David Harlow
AHLA Annual Meeting 2011 Social Media Legal Marketing Resources by David HarlowDavid Harlow
 
Health Care Social Media for Medical Device Manufacturers - FDA - Presentatio...
Health Care Social Media for Medical Device Manufacturers - FDA - Presentatio...Health Care Social Media for Medical Device Manufacturers - FDA - Presentatio...
Health Care Social Media for Medical Device Manufacturers - FDA - Presentatio...David Harlow
 
Social media-legal-marketing-harlow-bln-04272011
Social media-legal-marketing-harlow-bln-04272011Social media-legal-marketing-harlow-bln-04272011
Social media-legal-marketing-harlow-bln-04272011David Harlow
 
Payment Reform and ACOs
Payment Reform and ACOsPayment Reform and ACOs
Payment Reform and ACOsDavid Harlow
 
Atrius ACO Presentation
Atrius ACO PresentationAtrius ACO Presentation
Atrius ACO PresentationDavid Harlow
 
Health Care Social Media - The Lawyers Don't Always Say No
Health Care Social Media - The Lawyers Don't Always Say NoHealth Care Social Media - The Lawyers Don't Always Say No
Health Care Social Media - The Lawyers Don't Always Say NoDavid Harlow
 

Más de David Harlow (20)

Telemedicine challenges and opportunities slidecast
Telemedicine challenges and opportunities slidecastTelemedicine challenges and opportunities slidecast
Telemedicine challenges and opportunities slidecast
 
Telemedicine: Challenges and Opportunities
Telemedicine: Challenges and OpportunitiesTelemedicine: Challenges and Opportunities
Telemedicine: Challenges and Opportunities
 
Beyond HIPAA: Digital Health Opportunities & Regulatory Land Mines
Beyond HIPAA: Digital Health Opportunities & Regulatory Land MinesBeyond HIPAA: Digital Health Opportunities & Regulatory Land Mines
Beyond HIPAA: Digital Health Opportunities & Regulatory Land Mines
 
Appointment Reminders, Patient Marketing, HIPAA and You
Appointment Reminders, Patient Marketing, HIPAA and YouAppointment Reminders, Patient Marketing, HIPAA and You
Appointment Reminders, Patient Marketing, HIPAA and You
 
Health Data Privacy (and a little FDA mHealth) Regulation
Health Data Privacy (and a little FDA mHealth) RegulationHealth Data Privacy (and a little FDA mHealth) Regulation
Health Data Privacy (and a little FDA mHealth) Regulation
 
Keeping Your Edge: Managing Social Media While Protecting Privacy and Securit...
Keeping Your Edge: Managing Social Media While Protecting Privacy and Securit...Keeping Your Edge: Managing Social Media While Protecting Privacy and Securit...
Keeping Your Edge: Managing Social Media While Protecting Privacy and Securit...
 
Dancing With HIPAA (HxRefactored 2014) David Harlow 05 14 2014 ...
Dancing With HIPAA (HxRefactored 2014) David Harlow 05 14 2014               ...Dancing With HIPAA (HxRefactored 2014) David Harlow 05 14 2014               ...
Dancing With HIPAA (HxRefactored 2014) David Harlow 05 14 2014 ...
 
Digital Health: Apps, Analytics & Agencies
Digital Health: Apps, Analytics & AgenciesDigital Health: Apps, Analytics & Agencies
Digital Health: Apps, Analytics & Agencies
 
MCLE Health Law Basics Plus 2013 - Post-Acute Care
MCLE Health Law Basics Plus 2013 - Post-Acute CareMCLE Health Law Basics Plus 2013 - Post-Acute Care
MCLE Health Law Basics Plus 2013 - Post-Acute Care
 
Patient Consent to the Use of Data: Are We Asking the Wrong Question?
Patient Consent to the Use of Data: Are We Asking the Wrong Question?Patient Consent to the Use of Data: Are We Asking the Wrong Question?
Patient Consent to the Use of Data: Are We Asking the Wrong Question?
 
Accountable Care Organizations - The Camel's Nose Is In the Tent
Accountable Care Organizations - The Camel's Nose Is In the TentAccountable Care Organizations - The Camel's Nose Is In the Tent
Accountable Care Organizations - The Camel's Nose Is In the Tent
 
Health Care Social Media - Getting Started Without Getting In Trouble
Health Care Social Media - Getting Started Without Getting In TroubleHealth Care Social Media - Getting Started Without Getting In Trouble
Health Care Social Media - Getting Started Without Getting In Trouble
 
Health Care Social Media - An Introduction to Engaging Intelligently and Legally
Health Care Social Media - An Introduction to Engaging Intelligently and LegallyHealth Care Social Media - An Introduction to Engaging Intelligently and Legally
Health Care Social Media - An Introduction to Engaging Intelligently and Legally
 
AHLA Annual Meeting 2011 Social Media for Lawyers by David Harlow
AHLA Annual Meeting 2011 Social Media for Lawyers by David HarlowAHLA Annual Meeting 2011 Social Media for Lawyers by David Harlow
AHLA Annual Meeting 2011 Social Media for Lawyers by David Harlow
 
AHLA Annual Meeting 2011 Social Media Legal Marketing Resources by David Harlow
AHLA Annual Meeting 2011 Social Media Legal Marketing Resources by David HarlowAHLA Annual Meeting 2011 Social Media Legal Marketing Resources by David Harlow
AHLA Annual Meeting 2011 Social Media Legal Marketing Resources by David Harlow
 
Health Care Social Media for Medical Device Manufacturers - FDA - Presentatio...
Health Care Social Media for Medical Device Manufacturers - FDA - Presentatio...Health Care Social Media for Medical Device Manufacturers - FDA - Presentatio...
Health Care Social Media for Medical Device Manufacturers - FDA - Presentatio...
 
Social media-legal-marketing-harlow-bln-04272011
Social media-legal-marketing-harlow-bln-04272011Social media-legal-marketing-harlow-bln-04272011
Social media-legal-marketing-harlow-bln-04272011
 
Payment Reform and ACOs
Payment Reform and ACOsPayment Reform and ACOs
Payment Reform and ACOs
 
Atrius ACO Presentation
Atrius ACO PresentationAtrius ACO Presentation
Atrius ACO Presentation
 
Health Care Social Media - The Lawyers Don't Always Say No
Health Care Social Media - The Lawyers Don't Always Say NoHealth Care Social Media - The Lawyers Don't Always Say No
Health Care Social Media - The Lawyers Don't Always Say No
 

Último

Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxhariprasad279825
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clashcharlottematthew16
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsMiki Katsuragi
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machinePadma Pradeep
 
The Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdfThe Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdfSeasiaInfotech2
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationSafe Software
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
Training state-of-the-art general text embedding
Training state-of-the-art general text embeddingTraining state-of-the-art general text embedding
Training state-of-the-art general text embeddingZilliz
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsMemoori
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 

Último (20)

Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptx
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering Tips
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machine
 
The Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdfThe Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdf
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
Training state-of-the-art general text embedding
Training state-of-the-art general text embeddingTraining state-of-the-art general text embedding
Training state-of-the-art general text embedding
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 

Notas del editor

  1. Good morning.  My name is David Harlow. I am a health care attorney and consultant based here in Boston.  You can find me online as HealthBlawg.  I'm going to discuss in brief this morning questions about the US health care data privacy security and data breach notification regualtory scheme known as HIPAA, its application to the Medicine 2.0 environment, and how it might be re-imagined -- to give you a glimpse of what works, what doesn't - what's broken, what can be fixed, and how it might be fixed in a way that makes sense for the health care system and for patients.  Some of these observations will apply to the relevant EU directives as well ... but don't hold me to it ....
  2. When it comes to health care privacy and security ... we are caught betwixt and between -pulled in different directions.  The initial HIPAA regulations have been revised under the HITECH Act, but the final consolidated HIPAA regulation is now in the final stage of regulatory review -- ONC -- the Office of the National Coordinator for Health IT has signed off on it, and now OMB - the Office of Management and Budget - has the regulation for review . . .and apparently has had it for several months already.
  3. on the one hand we have organizations such as the Center for democracy & technology - and even the US GAO - government accountability Office - telling us that privacy and security protections under HIPAA are inadequate, that rules need to be changed to ensure adequate protection of health , or at the very least that guidance and oversight efforts need to be improved.  on the other, many patients would rather be able to share more than they can now --- folks who have shared data through websites such as patients like me, who want to share personal information about themselves, their conditions, in order to seek out help, management of their conditions, helping others, 
  4. I think we can all agree that the laws and regulations in quesiton are essentially out of date, because the pace of change in the technology of health IT easily outstrips our ability to regulate it. For example, in order to be considered deidentified, a patient record must have 18 specific types of information stripped out noame, address, etc.  Know what # 18 is ? ... Anything else that may be used to re-identify the de-identified data ... thus, since more and more data is published on line every day,  it becomes easier to reidentify every day 
  5. Example: TX recently adopted a more aggressive privacy law that covers more categories of records and people, and has higher fines than the feral rules.  This law also requires any business associate of any Texas-based covered entitity to conduct training to the TX stds 
  6. In addition, Our whole concept of privacy has evolved in the age of social media, but our legal system governing privacy o f health data  has not.Though there are situations where health care proivder organizations could be doing a better job of prtecting the provacy and security of health inforamtion ---  eg one of our local health care systems was in the paper recently because psych records were available to all clinicians in the system -- some folks don't want the rules tightedned up too mych, becasue them it makes dialytakss harder to comlpete.
  7. And frankly, many -- not all, but many -- of the data breaches reported under HIPAA/HITECH, and posted on the HHS/OCR 'wall of shame' have had no real world effect on patients -- the laptop stolen from a rental car is going to be fenced by a junkie and sold for parts, not hacked by a data thief who's going to sell identities on the black market,  
  8. Though there are situations where health care proivder organizations could be doing a better job of prtecting the provacy and security of health inforamtion ---  eg one of our local health care systems was in the paper recently because psych records were available to all clinicians in the system -- some folks don't want the rules tightedned up too mych, becasue them it makes dialytakss harder to comlpete.
  9. In other contexts we share so much information: photoswhere am I right nowbut in health care it's a small vanguard of patients, epatients, engaged, empowered, enabled patients, who are doing this sort of sharing. ... but numbers are growing.casting aside concerns about privacy can pay off by yielding informaiton -- 
  10. > If we are serious abt Medicine 2.0 helping patients and helping populations, we need to systematize the ability to share on a customized basis.address this either with better protections, clearer permission to share openly - controlled by pt
  11. what one researcher call'context-relative informatonal norms' what i tell me doctor I don't tell ny banker n vice versaNissenbaum argues that the real problem "is the inappropriateness of the flow of information due to the mediation of technology." In her scheme, there are senders and receivers of messages, who communicate different types of information with very specific expectations of how it will be used. Privacy violations occur not when too much data accumulates or people can't direct it, but when one of the receivers or transmission principles change. The key academic term is "context-relative informational norms." Bust a norm and people get upset.  >> So/ Plant a carrot,/ Get a carrot, Not a Brussels sprout./ That's why I love vegetables./ You know what you're about!
  12. So lets talk about modes of sharing-blue buttion VA flat ascii
  13.  --- green button, rainbow bttin-blue buttion VA flat ascii- green button - concept discussesd on e-patients.net ... patient controls sharing of data- rainbow button - – [turn around – rainbow-friendship-bracelet] - an individual should be bale to dial in a customized approach to sharing his or her own health data -- make it all open - like the harvard researcher who postted his medical record on line make part of it open, give part of it to a data repository that allows data to be mined --- donate the data, or sell the data ... thoird parties are monetizing the data, so why not patients?
  14. I'd like to see a robust market for personal health data with the pateitn at the center
  15. This approach lets the patient choose between the lockdown and the open door
  16. Thank you for your attention , and I will be happy to turn to questions and discussion.