Wearables raising possible policy concerns over privacy and security
Wearable fitness-monitoring devices are not only motivating Americans to exercise more. When combined with providers’ use of wearable computers and cloud-based storage, they’re also pushing the healthcare system to ask whether HIPAA lines are being crossed.
A former policy and planning official at the VA under the Obama administration took up the question in Government Health IT, a publication of HIMSS Media.
“It is not clear whether using patient data to improve products, as opposed to health outcomes, is allowed under this law (HIPAA),” wrote Julie Anderson, who now works as a consultant. “An even more concerning scenario could take shape if health information were combined with other personal, non-medical data for the purposes of user profiling.”
If wearable device manufacturers want to store health information in the cloud, they must bring their terms of service and privacy policies in line with HIPAA privacy and security requirements, argued Anderson.
Vendors supplying wearables, she added, should take several steps to guide the securing, sharing and analyzing of health data.
When it comes to HIPAA-mandated security controls, companies must protect health information with baseline access control and encryption measures, in addition to maintaining an “audit trail” of who has edited a patient’s information and when, wrote Anderson.
Meanwhile, companies need to grant patients and consumers greater transparency with regard to how their data is being used. “HIPAA would also require obtaining a patient’s consent before using their health information in any part of the advertising process,” Anderson pointed out.
Where privacy is concerned, companies must only analyze health data within the confines of what is permissible under HIPAA. “If companies want to mine customer data for other purposes, they should keep health information separate from non-medical data,” she wrote.
“[A]ny consumers, doctors and healthcare organizations using wearables in any capacity,” concluded Anderson, “should seek out vendors [who] will adhere to these tenets moving forward.”