There has been considerable discussion lately about whether the new privacy provisions in the economic stimulus legislation (the American Recovery and Reinvestment Act or ARRA) extend the coverage of the HIPAA privacy and security regulations to commercial vendors of personal health records (PHRs) any time they contract with a HIPAA covered entity.
In a blog post today we argue that PHR vendors should be covered under HIPAA only under certain circumstances, such as when they are performing a function or activity on behalf of a hospital or physician. PHRs should be governed by a comprehensive framework of privacy and security protections, but HIPAA – which was designed to regulate the flow of information among entities in the traditional health care system – would provide inadequate privacy protection for records kept by or for individuals.
The blog post explains why the HIPAA privacy regulations, at least as they are currently structured, are inappropriate for protecting PHRs in most circumstances. The post also looks at other factors that should be taken into consideration in deciding when vendors of PHRs could (and perhaps should) be covered by HIPAA. The post is part of a three-party series co-authored by Vince Kuraitis, J.D., M.B.A., Principal and Founder of Better Health Technologies LLC and David C. Kibbe, M.D., M.B.A., Principal, The Kibbe Group LLC.
Coalition Urges Senate Not to Let Companies Waive Financial Regulations for AI
CDT joined AI Now Institute, American Civil Liberties Union, and several organizations dedicated to tech policy, consumer protection, and civil rights in a letter to Senate leadership and the Senate Banking, Housing, and Urban Affairs Committee opposing the “AI Innovation Labs” language in Sec. 10509 of the CLARITY Act.
CDT and Partners Urge Passage of the California Location Privacy Act of 2025 (AB 322)
Location data is particularly sensitive, and when collected across time it can reveal a broad range of intrusive insights such as medical conditions, sexual orientation, political activities, and religious beliefs.
CDT and Allies Urge FCC Not to Violate Privacy of Cell Phone Buyers
CDT and EPIC led a coalition of 15 organizations in urging the FCC not to require phone companies to collect government IDs, physical addresses, and alternate phone numbers from every phone subscriber in the country.