• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

破解《健康保险流通与责任法案》:出售可识别医疗信息时避免监管的“最佳实践”

Hacking HIPAA: "Best Practices" for Avoiding Oversight in the Sale of Your Identifiable Medical Information.

作者信息

Omar Riyad A

出版信息

J Law Health. 2020;34(1):30-105.

PMID:33449456
Abstract

In light of the confusion invited by applying the label "de-identified" to information that can be used to identify patients, it is paramount that regulators, compliance professionals, patient advocates and the general public understand the significant differences between the standards applied by HIPAA and those applied by permissive "de-identification guidelines." This Article discusses those differences in detail. The discussion proceeds in four Parts. Part II (HIPAA's Heartbeat: Why HIPAA Protects Identifiable Patient Information) examines Congress's motivations for defining individually identifiable health information broadly, which included to stop the harms patients endured prior to 1996 arising from the commercial sale of their medical records. Part III (Taking the "I" Out of Identifiable Information: HIPAA's Requirements for De-Identified Health Information) discusses HIPAA's requirements for de-identification that were never intended to create a loophole for identifiable patient information to escape HIPAA's protections. Part IV (Anatomy of a Hack: Methods for Labeling Identifiable information "De-Identified") examines the goals, methods, and results of permissive "de-identification guidelines" and compares them to HIPAA's requirements. Part V (Protecting Un-Protected Health Information) evaluates the suitability of permissive "de-identification guidelines," concluding that the vulnerabilities inherent in their current articulation render them ineffective as a data protection standard. It also discusses ways in which compliance professionals, regulators, and advocates can foster accountability and transparency in the utilization of health information that can be used to identify patients.

摘要

鉴于将“去标识化”标签应用于可用于识别患者的信息所引发的混乱,监管机构、合规专业人员、患者权益倡导者和公众必须了解《健康保险流通与责任法案》(HIPAA)所适用的标准与宽松的“去标识化指南”所适用的标准之间的重大差异。本文将详细讨论这些差异。讨论分为四个部分。第二部分(HIPAA的核心:为何HIPAA保护可识别的患者信息)探讨了国会将可单独识别的健康信息进行宽泛定义的动机,其中包括制止患者在1996年之前因医疗记录的商业出售而遭受的伤害。第三部分(从可识别信息中去除“我”:HIPAA对去标识化健康信息的要求)讨论了HIPAA对去标识化的要求,这些要求从未打算为可识别的患者信息逃避HIPAA的保护创造漏洞。第四部分(黑客攻击剖析:将可识别信息标记为“去标识化”的方法)研究了宽松的“去标识化指南”的目标、方法和结果,并将它们与HIPAA的要求进行比较。第五部分(保护未受保护的健康信息)评估了宽松的“去标识化指南”的适用性,得出结论认为,其当前表述中固有的漏洞使其作为数据保护标准无效。它还讨论了合规专业人员、监管机构和倡导者可以促进在使用可用于识别患者的健康信息时的问责制和透明度的方法。

相似文献

1
Hacking HIPAA: "Best Practices" for Avoiding Oversight in the Sale of Your Identifiable Medical Information.破解《健康保险流通与责任法案》:出售可识别医疗信息时避免监管的“最佳实践”
J Law Health. 2020;34(1):30-105.
2
HIPAA Privacy 101: essentials for case management practice.《健康保险流通与责任法案》隐私基础101:病例管理实践要点
Lippincotts Case Manag. 2003 Jan-Feb;8(1):14-23. doi: 10.1097/00129234-200301000-00004.
3
Challenges and Insights in Using HIPAA Privacy Rule for Clinical Text Annotation.使用《健康保险流通与责任法案》隐私规则进行临床文本注释的挑战与见解。
AMIA Annu Symp Proc. 2015 Nov 5;2015:707-16. eCollection 2015.
4
What litigators need to know about HIPAA.诉讼律师需要了解的《健康保险流通与责任法案》相关内容。
J Health Law. 2003 Summer;36(3):433-54.
5
HIPAA's here. How to comply with new rules that govern protected health information.《健康保险流通与责任法案》来了。如何遵守管理受保护健康信息的新规定。
Nurs Manage. 2001 Apr;32(4):32-4.
6
HIPAA--a real world perspective.《健康保险流通与责任法案》——现实视角
Radiol Manage. 2001 Mar-Apr;23(2):29-37; quiz 38-40.
7
Do you know your business associates?你了解你的商业伙伴吗?
Healthc Financ Manage. 2003 Jan;57(1):54-9.
8
First-ever HIPAA conviction highlights differing views of HIPAA's civil and criminal penalties.首次因违反《健康保险流通与责任法案》被定罪凸显了对该法案民事和刑事处罚的不同看法。
Med Health R I. 2005 Jan;88(1):33-4.
9
Documenting your compliance with HIPAA's privacy rule.记录你对《健康保险流通与责任法案》隐私规则的合规情况。
J AHIMA. 2001 Apr;72(4):16A-16D.
10
Update on HIPAA privacy: are you ready?《健康保险流通与责任法案》隐私条款更新:你准备好了吗?
Genet Med. 2003 May-Jun;5(3):183-6. doi: 10.1097/01.GIM.0000068625.72823.86.