Anyone can file a health information privacy or security complaint. Your complaint must:
Be filed in writing by mail, fax, e-mail, or via the OCR Complaint Portal
Name the covered entity or business associate involved, and describe the acts or omissions, you believed violated the requirements of the Privacy, Security, or Breach
Notification Rules
Be filed within 180 days of when you knew that the act or omission complained of occurred. OCR may extend the 180-day period if you can show "good cause"
GDPR will only occasionally and coincidentally (if at all) be relevant to health data held by US health care providers and their business associates, whereas HIPAA will always be relevant.
That has no effect on the central theme of the story (which is health care firms partnering with Google as a Business Associate, and thereby sharing patient data).
Comments
So what do we do to stop this? What recourse do people directly affected by this have?
https://www.hhs.gov/hipaa/filing-a-complaint/complaint-proce...
Complaint Requirements
Anyone can file a health information privacy or security complaint. Your complaint must:
Be filed in writing by mail, fax, e-mail, or via the OCR Complaint Portal
Name the covered entity or business associate involved, and describe the acts or omissions, you believed violated the requirements of the Privacy, Security, or Breach Notification Rules
Be filed within 180 days of when you knew that the act or omission complained of occurred. OCR may extend the 180-day period if you can show "good cause"
But what would the complaint be? "I don't want my data transferred to Google, because.... Google?"
I mean, filing a complaint is free but I imagine it should have a grievance attached to be taken seriously.
GDPR should kick in long before medical data is on the table.
GDPR will only occasionally and coincidentally (if at all) be relevant to health data held by US health care providers and their business associates, whereas HIPAA will always be relevant.
laws protecting medical data are stricter and preceded gdpr by many years
Go to fitbit and delete your data. I just did; it's pretty painless.
login, click on the wheel, and the delete link is at the bottom.
That has no effect on the central theme of the story (which is health care firms partnering with Google as a Business Associate, and thereby sharing patient data).