Health Data Misuse Sparks Public Concern - health data
Health Data Misuse Sparks Public Concern

The Confidentiality Coalition and the Workgroup for Electronic Data Interchange have sent a letter to the secretaries of Commerce and Health and Human Services, expressing concerns about the potential misuse of patient health information by unregulated third-party applications. The groups are worried that the HIPAA law may not provide adequate protection for health information, as it only applies to traditional healthcare covered entities and their business associates.

Limitations of HIPAA

The HIPAA law has limitations when it comes to protecting health information, particularly when it comes to third-party applications. The groups told HHS Secretary Xavier Becerra and Commerce Secretary Gina Raimondo that patients may not have enough information to make informed decisions about the risks associated with using these apps. The letter, dated March 24, highlights the need for greater security and protection of patient information.

The Confidentiality Coalition includes a range of organizations, such as hospitals, medical teaching colleges, health plans, pharmaceutical companies, and medical device manufacturers. The Workgroup for Electronic Data Interchange, or WEDI, was formed to improve the efficiency of health data exchange. However, the groups note that healthcare providers are not responsible under HIPAA for verifying the security of a patient’s third-party app.

Related: CMS unveils $50 Medicare GLP‑1 bridge program

Recommendations for Improvement

The groups have offered several recommendations for the federal government to increase security and protect privacy. They suggest that the government take steps to address the potential vulnerability of patient information when sent to third-party apps. The letter also notes that the “safe harbor” provision in HIPAA does not address this vulnerability.

In December 2020, the Centers for Medicare and Medicaid Services issued a proposed rule aimed at improving the electronic exchange of healthcare data among payers, providers, and patients. The final rule requires HL7 FHIR-based APIs to support data exchange and prior authorization. It also includes an API standard for healthcare operations nationwide.

The rule builds on final rules around interoperability and patient access to fulfill provisions of the 21st Century Cures Act. During HIMSS22, CMS Administrator Chaquita Brooks-LaSure said that the rule didn’t go far enough, and that payers need to implement data exchange. She added that CMS would soon publish a rule on enhanced data exchange.

Related: Nature’s beauty boosts mental wellbeing

The issue of patient privacy is complex. Patient information protection requires a coordinated effort. The Confidentiality Coalition and WEDI are working to raise awareness about the issue and to promote solutions that will protect patient information.

According to the report, the Confidentiality Coalition and WEDI will continue to work with the federal government. Email the writer: [email protected]