{"id":4502,"date":"2010-01-07T14:09:18","date_gmt":"2010-01-07T14:09:18","guid":{"rendered":"http:\/\/euvolution.com\/futurist-transhuman-news-blog\/hackers-hitech-and-hipaa-in-dtc-genomics-oh-my\/"},"modified":"2010-01-07T14:09:18","modified_gmt":"2010-01-07T14:09:18","slug":"hackers-hitech-and-hipaa-in-dtc-genomics-oh-my","status":"publish","type":"post","link":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/genetic-medicine\/hackers-hitech-and-hipaa-in-dtc-genomics-oh-my.php","title":{"rendered":"Hackers, HITECH and HIPAA in DTC Genomics, Oh My!"},"content":{"rendered":"<p><span><span>At our practice we run a pretty tight ship when it comes to security of patient records. Why do we do this? Well there are 2 big reasons.<\/span><\/span><\/p><div><span><span><br><\/span><\/span><\/div><div><span><span>1. It's the right thing to do.<\/span><\/span><\/div><div><span><span>2. The law will put you in the hurt locker if you don't<\/span><\/span><\/div><div><span><span><br><\/span><\/span><\/div><div><span><span>I want to talk about reason 2 a little bit. <\/span><\/span><\/div><div><span><span>Why? <\/span><\/span><\/div><div><span><span><br><\/span><\/span><\/div><div><span><span>With all of this protection of health information and <span>DTC<\/span> <span>genomics<\/span> companies going bankrupt, I begin to really wonder who a covered entity is. <\/span><\/span><\/div><div><span><span><br><\/span><\/span><\/div><div><span><span>Daniel <span>Vorhaus<\/span> over at<\/span><\/span><a href=\"http:\/\/www.genomicslawreport.com\/index.php\/2009\/10\/27\/federal-privacy-regulation-and-the-financially-troubled-dtc-genomics-company\/\"><span><span> <span>Genomics<\/span> Law Review has a pretty good break down of it, <\/span><\/span><\/a><span><span>but I think there may be some nuances not covered. As well as a notable lack of coverage of <span>HITECH<\/span> policies in the <span>ARRA<\/span>.<\/span><\/span><\/div><div><span><span><br><\/span><\/span><\/div><div><span><span><span>Wha<\/span>? <\/span><\/span><\/div><div><span><span><br><\/span><\/span><\/div><div><span><span>Yes the recovery act has stuff on Health care privacy in it. In <span>HIPAA<\/span> <span>DTC<\/span> <span>Genomics<\/span> may not be covered, but I think in <span>HITECH<\/span> they are.<\/span><\/span><\/div><div><span><span><br><\/span><\/span><\/div><div><span><span>Why have I been reading this stuff? Because it's my job.<\/span><\/span><\/div><div><span><span><br><\/span><\/span><\/div><div><span><span>According to <span>HITECH<\/span><\/span><\/span><\/div><div><span><div><span><span><br><\/span><\/span><\/div><div><span><span>H.R.1 150 Title XIII (<\/span><\/span><span><span><span><span>HITECH<\/span><\/span><\/span><\/span><span><span>)<\/span><\/span><\/div><p><span><span>SEC. 13404<\/span><\/span><\/p><div><span><span><br><\/span><\/span><\/div><div><span><span>For the purposes of compliance with privacy and security regulations, a \"covered entity\" and its \"business associate\" are equally liable as if each were itself was a covered entity. <\/span><\/span><\/div><p><\/p><\/span><\/div><div><span><span><br><\/span><\/span><\/div><div><span><span>Which means if I send a <span>DTC<\/span> genomic test off with a <span>doctor's<\/span> order, AKA <span>Illumina<\/span>, a breach in that data due to the lab or interpretive business associate THEY are just as liable as the physician.<\/span><\/span><\/div><div><span><span><br><\/span><\/span><\/div><div><span><span>This means that <span>DTC<\/span> Genomic tests ordered by physicians fall into a completely more risky category than those ordered by Joe Blow.<\/span><\/span><\/div><div><span><span><br><\/span><\/span><\/div><div><span><span>This one risk may be why <span>DTC<\/span> is dying not to make these tests gatekeeper specific. Once these tests become gatekeeper specific, <span>DTC<\/span> will <\/span><\/span><\/div><div><span><span><br><\/span><\/span><\/div><div><span><span>A. No longer be <span>DTC<\/span><\/span><\/span><\/div><div><span><span>B. No longer be free of <span>HITECH<\/span> and <span>HIPAA<\/span><\/span><\/span><\/div><div><span><span><br><\/span><\/span><\/div><div><span><span>Which means a big '<span>ol<\/span> nightmare for these companies as they want to emphasize the social networking part. You see, social networks have always balanced growth versus security and the same is true for any Internet Technology.<\/span><\/span><\/div><div><span><span><br><\/span><\/span><\/div><div><span><span>But let's say this is just one rogue hacker who has decided to hack a genome record ordered by a physician.......Via say a hacked email or website........<\/span><\/span><\/div><div><span><span><br><\/span><\/span><\/div><div><span><span>What is the penalty?<\/span><\/span><\/div><div><span><span><br><\/span><\/span><\/div><div><span><span><br><\/span><\/span><\/div><div><span><div><a href=\"http:\/\/frwebgate.access.gpo.gov\/cgi-bin\/usc.cgi?ACTION=RETRIEVE&amp;FILE=%24%24xa%24%24busc42.pt1.wais&amp;start=13864428&amp;SIZE=1670&amp;TYPE=TEXT\"><span><span>CITE 42<span>USC<\/span>1320-6<\/span><\/span><\/a><\/div><div><span><span><br><\/span><\/span><\/div><div><span><span>This is the scary part.<\/span><\/span><\/div><div><span><span><br><\/span><\/span><\/div><div><pre><span><span>Sec. 1320d-6. Wrongful disclosure of individually identifiable          health information           (a) Offense      A person who knowingly and in violation of this part--         (1) uses or causes to be used a unique health identifier;         (2) obtains individually identifiable health information      relating to an individual; or         (3) discloses individually identifiable health information to      another person,  shall be punished as provided in subsection (b) of this section.  (b) Penalties      A person described in subsection (a) of this section shall--         (1) be fined not more than $50,000, imprisoned not more than 1      year, or both;          (2) if the offense is committed under false pretenses, be fined      not more than $100,000, imprisoned not more than 5 years, or both;      and         (3) if the offense is committed with intent to sell, transfer,      or use individually identifiable health information for commercial      advantage, personal gain, or malicious harm, be fined not more than      $250,000, imprisoned not more than 10 years, or both. <\/span><\/span><\/pre><pre><span><span><br><\/span><\/span><\/pre><pre><span><span>So let's say someone hacked a record to get the one up on you, maybe you are a political candidate or maybe a business competitor, or maybe they want to sue you.......<\/span><\/span><\/pre><pre><span><span>If this rogue hacker performs an act of this on genomic information ordered by a doctor or that can be defined as PHI, these are the penalties. If it is not considered PHI, it is a far lesser offense.......<\/span><\/span><\/pre><pre><span><span>So the question is, do you want these protections if you are a customer\/patient? I would say Hell Yeah.<\/span><\/span><\/pre><pre><span><span>But do you want them as a covered entity? Uhhhhh.....Ahem.......Well........<\/span><\/span><\/pre><pre><span><span>As a doctor we have to follow these. Why shouldn't anyone else who has been given the responsibility of handling human samples?<\/span><\/span><\/pre><pre><span><span><b><span>The Sherpa Says: As a consumer <span>HITECH<\/span> is great. But as a start up company it can prove to be a nightmare. But those who have to risk the most are the huge companies making millions of dollars....can you say class action lawsuit for millions? I know a few lawyers who would be interested in that! I wonder if the <span>DTC<\/span> <span>Genomics<\/span> investors thought of that<\/span><\/b><\/span><\/span><\/pre><div><span><span><span><br><\/span><\/span><\/span><\/div><\/div><p><\/p><\/span><\/div><div><span><span><br><\/span><\/span><\/div><div><\/div><div><img loading=\"lazy\" decoding=\"async\" width=\"1\" height=\"1\" src=\"http:\/\/euvolution.com\/futurist-transhuman-news-blog\/wp-content\/plugins\/wp-o-matic\/cache\/c3be5_6173393362223742012-1294199245545079910?l=thegenesherpa.blogspot.com\" alt=\"\" style=\"padding-left:10px; padding-right: 10px;\"><\/div>","protected":false},"excerpt":{"rendered":"<p>At our practice we run a pretty tight ship when it comes to security of patient records. Why do we do this? Well there are 2 big reasons.1. It's the right thing to do.2. The law will put you in &hellip; <a href=\"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/genetic-medicine\/hackers-hitech-and-hipaa-in-dtc-genomics-oh-my.php\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"limit_modified_date":"","last_modified_date":"","_lmt_disableupdate":"","_lmt_disable":"","footnotes":""},"categories":[5],"tags":[],"class_list":["post-4502","post","type-post","status-publish","format-standard","hentry","category-genetic-medicine"],"modified_by":null,"_links":{"self":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts\/4502"}],"collection":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/comments?post=4502"}],"version-history":[{"count":0,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts\/4502\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/media?parent=4502"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/categories?post=4502"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/tags?post=4502"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}