Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I always find it funny how more money is spent on audit tools like this, and yet people get no training in HIPAA, so they e-mail spreadsheets of social security #s and medical records to 3rd parties, to say nothing of dropbox and pastebin. Most people would shit themselves if they knew all the violations that go unreported.


>and yet people get no training in HIPAA,

WHAT!?! I'm a physician, and to my lament I have to do HIPAA training over and over and over and over... Just like everyone else everywhere I've ever worked. Yes, we get plenty of HIPAA training. There are still breaches, of course, but your statement is just plain wrong.


Okay, perhaps they just blatantly ignore their training? In which case they probably need to fix the training, or something. Are you sure all the personnel that work for the hospital system (or private practice) gets HIPAA training? There's plenty that work with sensitive data that aren't physicians.


Yes, everyone that touches protected data gets the training. I'm sure there are some hospitals/offices that don't but that's got to be pretty rare. I imagine most of the breaches are not due to overt ignorance, but due to poor application like not understanding the level of security provided by some means of transmission, or knowing but doing it anyway because it's convenient.


Maybe it's just your hospital then. I know that even the receptionist at my hospital has to go through HIPAA training.

If you know your hospital staff lacks HIPAA training, it's probably time to find a new doctor at a different hospital.


It depends on where you are, and if your hospital has ever been sued before. There are still pockets that don't have adequate training. I also assume that a lot of private practices don't get a lot of good data-handling training on the subject.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: