The value of personal health information is very high inside and outside of the US healthcare system. At the same time, the US healthcare industry as a whole does a terrible job of protecting health data security. Most health data holders (hospitals and insurers) put health data security protection dead last on the list for tech upgrades.
Besides the lack of effective, comprehensive data security protections, thousands of low-level employees can snoop in millions of people’s health records in every US hospital using electronic records.
- -The latest celebrity example is the Kardashian hospital data breach firings: http://www.huffingtonpost.com/2013/07/14/workers-fired-kim-kardashian_n_3592841.html
The public expects that only their doctors and staff who are part of their treatment team can access their sensitive health records, but that’s wrong. Any staff members of a hospital or employees of a health IT company who are your neighbors, relatives, or stalkers/abusers can easily snoop in your records.
In Austin, TX the two major city hospital chains each allow thousands of doctors and nurses access to millions of patient records.
All this will get much worse when every state requires our health data to be “exchanged” with thousands more strangers. The new state health information exchanges (HIEs) will make data theft, sale, and exposure exponentially worse.
Tell every law maker you know: all HIEs should be REQUIRED by law to ask you to agree or OPT-IN before your health data can be shared or disclosed.
- -many states do not allow you to ‘opt-out’ of HIE data sharing
- -most states do not allow you to prevent even very sensitive health data (like psychiatric records) from being exchanged
There is no way to trust electronic health systems or HIEs unless our rights to control who can see and use our electronic health data are restored.