this post was submitted on 01 Nov 2023
440 points (99.3% liked)

Technology

59312 readers
4597 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

Drugmakers Are Set to Pay 23andMe Millions to Access Consumer DNA::GSK will pay the DNA testing company $20 million for non-exclusive access to genetic data.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 4 points 1 year ago (1 children)

Although I wonder if HIPAA would need to get involved in places like the US if that happens. If that data is used to diagnose, then it falls under HIPAA.

If they do that, there will definitely be giant legal battles. I wonder if that is a legal risk they’d want to take on.

[–] [email protected] 5 points 1 year ago (1 children)

HIPAA basically only covers healthcare providers and workers. I ran into this when the VA mailed my entire medical history to some random person. Since it wasn’t the healthcare branch of the VA, I had exactly zero recourse.

[–] [email protected] 5 points 1 year ago

That's not true. HIPAA covers anyone handling protected health information in a professional manner. If some office clerk at the VA is mailing out copies of HIPAA-protected information, they're bound by HIPAA. If a consulting IT firm has access to a hospital's servers as they're changing something about the EHR, they're bound by HIPAA. Protected information cannot make its way from a "covered entity" to a non-covered entity like a totally unrelated bakery who would not have an obligation to protect your information without either: 1) violating the law, 2) you personally disclosing the information to the non-protected party, or 3) you or someone authorized on your behalf signing a disclosure waiver permitting the covered entity to disclose