More than one privacy regime
HIPAA sets a federal floor for health plans, most health care providers, and their business associates, but it is not the whole picture. Records from many federally assisted substance use disorder programs carry their own stricter federal rules, which have been revised to align more closely with HIPAA. New York adds protections of its own, including heightened confidentiality for HIV-related information and a data security law that reaches private information held by businesses generally. Companies outside HIPAA, such as many consumer health apps, can still face Federal Trade Commission rules on health data breaches and deceptive privacy claims. Healthcare privacy compliance starts with mapping which of these apply to which data.
Where the gaps usually show up
Tracking technologies on websites and patient portals have drawn regulatory attention and class action litigation, because they can send information about patients to advertising platforms. Vendors and data flows multiply quickly, and an organization may not know which outside services touch patient data. Text messaging, personal devices, and shared logins create risks that formal policies often fail to mention. Patient requests for their own records are another area where providers fall behind, and federal regulators have treated delayed access as a violation in its own right. An inventory of systems, vendors, and data types is the base for every other decision.
What an initial privacy review covers
We usually start with the types of data you hold, the systems and vendors that hold it, and the laws that attach to each. Then we look at your notices, authorizations, and consent forms to see whether they describe what really happens to the data. If a specific incident or complaint prompted the review, we address that first, including whether any notification obligations may already be running. You come away with a picture of where the organization stands and the order in which gaps should be closed.