Went to a new doctor. As part of the check-in process, I was asked to "sign" a little digital pad, so, as I was told, they could properly use my insurance. I asked to see the hard copy of what I was signing and they couldn't find one. Then, for some reason, they were unable to print one. I gave up and scribbled my sig with my finger and then was seen by a doctor. It's maddening.
I'm sure someone smarter than me has a solution. Those papers you're required to sign are generally the result of regulation. Some law got passed that say "you can't share info unless you get signed permission". The person dreaming up the law thought that would be enough to stop getting them to share info. But, even if they cared about privacy, they don't want to increase all their expenses and run their own IT department so they contract out for 3rd party billing, 3rd party document infra, etc etc. Like if they wanted to store your appointment in MS Word 365 or Google Docs, suddenly the regulation kicks in. They're not going build a document sharing platform to get their job done just so they can meet the regs. They're just going to get you to sign that they can do what they need.
As one example, I went to a doctor, he ordered an x-ray. I went over to the x-ray company then back to my doctor. He pulled up the x-ray immediately. He's only able to do that because I signed that he can share my info with the x-ray company and visa-versa.
Again, I don't have a solution. No regulation = he'd probably share my data. But regulation = he gets me to sign so he can legit provide the service, and still shared my data (Because I signed). So all the regs did is make visiting the doctor more annoying, and add $$$$ to push all the paperwork around.
Regarding information sharing, not quite. Covered entities (term of art in HIPAA), which include providers (and also payers!) including both the lab and your doctor, do not need your permission to share information between them for the purposes of treatment, payment, or operations (commonly, "TPO"). A BAA between a covered entity and a vendor (like an EHR or PACS [viewer for your imaging]) also does not require any patient consent.
There are sometimes things you might not like hidden in the releases you're signing, beyond the run of the mill acceptance of financial responsibility / assignment of benefits, notice of privacy policy acknowledgment, consent to treat.
Becauae "spirit of the law" doesnt exist. It is a saying used by people when they want to do something that isnt in the law. You dont see lawyers, judges or law makers use the phrase.
> Becauae "spirit of the law" doesnt exist. It is a saying used by people when they want to do something that isnt in the law. You dont see lawyers, judges or law makers use the phrase.
This is dependent on jurisdiction. Some countries (e.g. the USA) do not consider spirit/intent (anymore), as the judiciary has repeatedly ruled that the letter of the law, as written, is what matters, regardless of whether it meets the intent of what the law was written to achieve.
There are other countries in the world, outside of the USA, that do not work this way.
Intent is expressed through drafter's notes or explanations. "Spirit" is somerhing else, something made up later by people who had nothing to do with th3 creation of the law.
> The letter of the law and the spirit of the law are two ways of interpreting rules or laws. To obey the "letter of the law" is to follow the literal reading of the words of the law, whereas following the "spirit of the law" is to follow the intention of why the law was enacted.
It is always a good sign of modernity and relevance when the half an article's citations are to either the bible or the Talmude. And who can forget the legal touchstone that was the 1975 Systems Engineering Conference ... in Vegas.
> New combinations of circumstances — that is, new cases — constantly call for the application, which means in truth the extension of old principles; or, it may be, even for the thinking out of some new principle, in harmony with the general spirit of the law, fitted to meet the novel requirements of the time.
Are you even legally signing anything if they can't show you the document you are signing?
I am not familiar with the nitty gritty of US law, but under German law that signature would be worthless. Even signing a document you have but are unwilling to read is legally a bit iffy (which is why for things like real estate a notary will read the paperwork to you and ask if you understood it, or why surprising clauses in terms of service are unenforceable). Signing something without being able to know what you are signing would be worth exactly nothing, because you didn't actually knowingly consent to any particular thing, and neither did you have the "meeting of minds" required to form a contract.
It probably would be unenforceable in the US too, given you have no opportunity to know what you're signing, but you'd probably have to drag it before a court to settle that, and US companies know that no* individual is actually going to do that over what ultimately is (likely to only be) a minor inconvenience.
I do wish this was an option for some data, but emergency care would be an absolute shit show. People can't even remember passwords let alone keep track of keys and devices.
Zero trust device, with emergency channels pre-trusted. Like, the ambulance service is known to your device and can already suck your blood type and whatnot. And the police your name and emergency contacts. Or whatever schema with a similar idea. There's the technology to do this already, but we're lacking awareness and initiative.
> And the police your name and emergency contacts.
Hell no. The fuzz ain't getting my info without reasonable, articulable suspicion that I have committed, am committing, or am about to commit a crime, or if I'm pressing charges and need to ID for that process.
The parent comment was about an accident where you're unable to give any details yourself. Maybe when you're under a truck you'd like your folks to know what happened to you, right? But again, such are implementation details. First let's have that zero trust device, then we can be negotiate who gets to see what and when.
Usually, signing things like this won’t particularly hurt you - largely because your inalienable rights are… inalienable. You can’t sign them away, even if some contract says you have.
The flip side of this however is that it’s a very worthwhile pursuit to know consumer protections and what your rights are in the jurisdiction in which you live - and how to enforce them.
Where I live, I unfortunately quite frequently find myself having to go “ok so you want to do the formal process with the regulator then?”, which usually gets them to reconsider - but not always. Three times in the last month I have threatened regulatory action - and of those three, only one chose that path. I have just reported a government agency here to the domestic and EU regulators for failing to fulfil EU FoM treaty rights - and they were even kind enough to put it in writing that they’re ignoring their own domestic laws.
I have yet to lose a case I have brought before a regulator or justice of the peace, and businesses usually only need to do this once, if at all, as it can quite quickly turn a €1,000 dispute into tens or hundreds of thousands of euro of damages and fines. By doing this, following these processes through, I help not just myself but society as a whole.
So - sign away, but have teeth, and know where to bite.
I had a similar experience at a bank some time ago. To sign up, you had to sign a digital pad without seeing what you were signing first. You could get a copy mailed to you later. At that future time, I was told, you could you cancel the agreement if you found it objectionable.
Being a bank, this has nothing to do with HIPAA. Just a dark pattern.
What's interesting about those documents you asked to sign, at least at hospitals, it's not a requirement even though it may appear that way by the interaction. I suspect it's the same for other medical professions as well.
Many of them are just "CYA" for the facility/provider. HIPAA allows, for example, providers to share your medical information, for the purposes of treatment, regardless of your consent.
In general, in the US of A, that consent you sign waives your legislated-to-be-guaranteed HIPAA rights.
Specifically, you're typically giving the office's providers and their marketing "affiliates" and your insurance company and its marketing "affiliates" the right to forward around (through any length chains of agreements) your entire medical history associated with enough (research proven as de-anonymizing) details to retarget you personally. And you're typically doing this by accepting a company insurance (in the US) or the provider's reception counter while you're in need of care.
This effectively forced consent is arguably illegal, but as far as I know, untested, so it's standard across the medical system and across omnibus insurance (e.g. company-provided healthcare "plan").
Of course, every touch point is another place your personal history will get stolen and rolled into modern digitally scripted exploitation of your identity and or targeted forms of phish-mongering (a term I made up meaning marketing so personalized you believe it's necessary to sign up for and pay for).
If you have any relationship with the team at your company that procures employee insurance packages, see if you can persuade them to start with the firm's insurance consultant (high end) or broker (low end) and systematically remove every step in the "we can pass along all your info to our affiliates for our own pinky-swear good reasons like making more money off your private info" chain.
In our experience, this added 3+ months to the procurement process as every single provider balked until interacted with by counsel -- and then instantly capitulated.
Our goal was always to give our employees a top tier benefits package, and we consider it a top tier hard-to-match employee benefit to not have random firms and government agencies pawing through your doctors notes, prescription histories, lab results, and enough biographical data to fake your digital twin.
Sadly, most employees -- though none of them are sheeple -- shrug at that for reasons in this thread: no time to fight such pervasive exploitation, especially when it hits them while needing a service as it hit you, or just plain weary of trying. So much easier, and psychically healthier, to just avoid thinking about it. Everyone is resigned.
If a company you consider working for claims "we take your privacy seriously" ask if they got privacy waivers removed on your behalf from all vendor contracts including payroll (does your salary go to 'work number'?) and insurance providers (can your data leave your doctor's EMR?). Odds are, they do not, in fact, take your privacy as seriously as they could.