Health Privacy
About health privacy, World Privacy Forum key health privacy resources
The World Privacy Forum is extremely active in health privacy, with a long and successful track record of work in this area. We have done groundbreaking work in the area of medical identity theft, as well as substantive analysis and education on critical privacy aspects of health data such as medical research, genomics, and many other issues.
Some of our most frequently accessed health privacy resources include:
* A Patient’s Guide to HIPAA
* Medical Identity Theft Page (resources, reports, more)
* Health privacy tagged materials
* HIPAA tagged materials
* Electronic Health Records tagged materials
* Common Rule and Human Subject Research Protection tagged materials
* Genetic privacy tagged materials
We have many more publications and resources. For a full list of topics and publications, see our key issues page.
See below for health privacy news and content by date.
Thank you Chair and Commissioners. The profusion of health apps, websites and digital tools that provide consumers with assistance and insights about their health is a positive development. However, it has come at the cost of increasing privacy risks. One of these risks is that consumers are confused about when and where federal health privacy protections apply to their health information.
WPF recently reviewed and provided recommendations regarding a proposed AI Framework meant to apply to medical research involving human subjects. The issue of human subject research is a critically important one. In the US, The Common Rule (45 CFR subpart A) is a key regulation that protects people from unethical medical research. As research utilizing tools such as AI and SaMD — software as a medical device — grows in use, there is an urgent need to determine the proper ethical, legal, and regulatory framework for the use of these tools in the human subject research context. For this reason, WPF was pleased to review and provide recommendations to the Secretary’s Advisory Committee on Human Research Protections, SACHRP, on its proposed AI Framework.
One of the most common questions we receive is: what does HIPAA compliant mean? Well.. If a company or entity or health app is not covered by HIPAA, it may still say that it is “HIPAA compliant.” HIPAA compliant does not mean the same thing as being a HIPAA- covered entity. If you see the
The U.S. Occupational Safety and Health Administration (OSHA) has published its proposal regarding how employee vaccination information will be treated by employers. WPF’s analysis has found a meaningful loophole in privacy protections, and has proposed a remedy to OSHA.
In public testimony September 15, 2021, WPF’s Executive Director urged the Department of Health and Human Services National Vaccine Advisory Committee Committee to establish broadened protections for covid-19 vaccination data, including extending the existing CDC Guidance (from May 2021) prohibiting commercial marketing use of vaccination registration information or other vaccination data. The intersection between HIPAA privacy regulations