I had a physical therapy appointment this morning. It was my first time at this place, so I had to complete some new patient paperwork. The last page asked me to sign my name acknowledging that I had received a copy of the practice’s privacy policies. But I hadn’t received one. So I didn’t sign. (This is common, actually—rarely am I given the opportunity to review the HIPAA notice or privacy policy before being prompted to sign that I have.)
I took the paperwork back up to the front desk and noted that I had not signed the last page because I had not received the notice. Very quickly, I was given a copy of the practice’s privacy policy. I signed, then returned to my seat to review.
The thing you’ll realize when you start reading what you say you’ve read is that privacy, like your health, is pretty fragile.1
Most people have probably heard of HIPAA and generally understand it to protect your health information from being shared. But did you know that HIPAA stands for Health Insurance Portability and Accountability Act? Privacy isn’t even in the name. And what it covers is surprisingly limited, given our collective perception about it.
Without getting too deep into the weeds (but check out this article from Consumer Reports for a modest amount of weeds), HIPAA does not cover a whole lot of entities, agencies, departments, and organizations that you probably assume it does.2 For example, if a police department or prosecutor office receives your health information, it is no longer covered by HIPAA because those agencies are not covered by HIPAA. And though healthcare providers are permitted but not required to turn over your information to law enforcement agencies without a court order, many do. Some of them even call the police if they speculate you may have committed a crime, like the nurse who told the police about patient Brittany Watts’s miscarriage, resulting in Watts’s arrest before a grand jury declined to indict her.
HIPAA also doesn’t cover the fitness or health apps you use to track things like your sleep, exercise minutes, and heart rate. When you connect those apps to a smart bike or treadmill, the potential for privacy breaches multiplies. You may be surprised by how much that compilation of information reveals.
“The companies giving themselves permission to collect all kinds of data on you, whether or not they have a way to collect it or…use it. And then also granting themselves like, very broad ability to share and use the data kind of however they want.” - Catherine Roberts, a health science journalist at Consumer Reports in an interview with Texas Standard
After Roe v. Wade was overturned, concerns were raised that period tracking apps were sharing data about menstrual cycles with third-parties and that law enforcement could request and obtain that data. But the disclosure of information about your reproductive healthcare doesn’t even need to be that explicit: As Evan Greer, director of the digital rights advocacy group Fight for the Future, told NPR, even sitting in the waiting room of an abortion clinic using an app that collects your location data is enough to pierce the privacy you may expect during such a sensitive visit.
Doctors are starting to use AI note-taking and translation tools during visits. You can opt out, but how many people do? If you care about your privacy, you should, or should at least ask more questions before consenting. Questions like:
Are you recording, and can I opt out?
Do you have a HIPAA contract with the A.I. scribe company?
Does anyone review the AI notes for accuracy?
And relatedly, how is AI changing my relationship with my doctor, and my doctor’s ability to diagnosis and deliver care?
This morning felt like an acute symptom of a chronic problem. We’ve traded efficiency for informed consent. Our conceptions of privacy mismatch our actual rights to privacy. And I fear that our willingness3 to allow our data to be sold to anyone who wants to make money off of it has desensitized us to the ways sensitive data—like our private health information—can be shared and exploited.
I find myself overwhelmed with questions and concerns as AI and algorithms become more entangled in our health systems. Where do you even start if you want to take back your privacy or protect what’s left of it? I don’t have those answers but I appreciate that organizations like Electronic Frontier Foundation, The Future of Privacy Forum, the Electronic Privacy Information Center, and 404 Media are trying to get them for us so we can all exercise more agency over our data, health, and privacy.
This privacy policy helpfully offered a whole list of examples of who might be given my information about my health. That list included (but is not limited to), the FDA, government oversight agencies, public health authorities, workers compensation agencies, “appropriate agencies or persons when we believe it is necessary to avoid a serious threat to health or safety or to prevent future harm,” organ procurement organizations, law enforcement when required or allowed by law, coroners, medical examiners, funeral directors, and “government officials when required for specifically identified functions such as national security.” If you are incarcerated, the practice may also disclose your private health information to the correctional institutional or a law enforcement official.
There may be other laws that would protect the information from disclosure, though, like the Family Educational Rights and Privacy Act or state laws that go beyond the federal protections.
Perhaps not willingness. More like resignation.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.