By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Health Works CollectiveHealth Works CollectiveHealth Works Collective
  • Health
    • Mental Health
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: Hacking HIPAA
Share
Notification Show More
Font ResizerAa
Health Works CollectiveHealth Works Collective
Font ResizerAa
Search
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > Policy & Law > Hacking HIPAA
Policy & Law

Hacking HIPAA

David Harlow
David Harlow
Share
0 Min Read
SHARE
Hacking-hipaa_edited-1<div><a class=Hacking-hipaa_edited-1

Join me in attacking an endemic problem in health care today by Hacking HIPAA. I am crowdfunding the development of a new legal form to be used on and after September 23, 2013 to allow patients to opt-in to easier health care communications – a Common Notice of Privacy Practices that is patient-focused. (Text me, please! Email me, please! etc.) Depending on how much support this project garners, we can attack some related problems as well. Contributions at any level are welcome; contributions at the levels designated on the Hacking HIPAA Medstartr page get you a seat at the virtual table, voicing your concerns that need to be met in the CNPP and in follow-on projects.

I’m working on this project with two leading health care open source software developers, Ian Eslick and Fred Trotter. Check out Fred’s video intro to the project on the Medstartr page – you can find Ian and Fred online via the links on the project page, too.

Here’s an excerpt from the crowdfunding project page:

The Problem

Right now we have the worst of all worlds with regards to patient privacy in healthcare. Patients are frequently subject to sub-standard security and privacy practices AND healthcare innovators are unable to deliver solutions that would be useful to patients because their technical approaches are uncomfortably novel for health care bureaucrats. Patients end up getting poor security and no innovation, the worst of all options. This problem is going to get worse before it gets better, since the new Omnibus HIPAA Rule will make cloud hosting of health care projects untenable very soon.  

How to Solve it

We need a way to provide meaningful privacy choices to patients, while enabling technical innovators to offer services using modern technical infrastructures. In order to do that, we need to hack the document that dictates the core relationship between patients, clinicians and innovators. That document is the Notice of Privacy Practices (“NPP”) that patients sign when they first start engaging with a particular provider.

Our Project to Deliver a Solution

The goal of this project is to fund the creation of a universally accepted NPP for health care providers to share with patients — one that recognizes current realities of data storage and transfer, explains these realities to patients, and obtains their consent to use, transmit and store data in a private and secure manner using cloud storage and computing, secure email, email, two-way video systems and text messaging. These are all standard technology approaches that patients use to work with their own health care data every day. But regulatory compliance makes it difficult to work connect with their doctors using these technologies. HIPAA and the HITECH Act — the Federal health data privacy and security laws — govern the use, transmission and storage of personally identifiable health data, and define the parameters for the NPP. However, there is no standard form NPP in use. This means that technologists have to adapt to a plethora of scenarios created by multiple NPPs, none of which is drafted with technical requirements in mind. The law of unintended consequences yields problems for patients and providers as a result of this technology blind spot.

The CNPP will be delivered to project supporters at the $1000 level or above before the Omnibus HIPAA Rule compliance date (September 23). It will be made available under a Creative Commons license on or about November 1, 2013.

I encourage you to read the rest of the Hacking HIPAA project description, and to support this project.

Any comments or questions – Please use the commens section on the project page.

Finally, please share this post liberally with anyone who may be interested in this issue and may be interested in supporting our efforts to Hack HIPAA.

David Harlow
The Harlow Group LLC
Health Care Law and Consulting 

TAGGED:HIPAApatient privacy
Share This Article
Facebook Copy Link Print
Share

Stay Connected

1.5KFollowersLike
4.5KFollowersFollow
2.8KFollowersPin
136KSubscribersSubscribe

Latest News

photo of a woman with red hair holding a brown brush
How Long Does It Take to Recover from Hair Fall?
Fitness
June 12, 2026
a person putting a bandage on a woman s head
How a car accident can leave hidden injury patterns
Global Healthcare
June 12, 2026
emergency medical simulation with rescue team outdoors
How car accident injuries can reshape physical recovery and everyday health routines
Policy & Law
June 12, 2026
wellness app development
Why Proper Calculation Matters in Research and Wellness Applications
Health Technology
June 11, 2026

You Might also Like

Small Business Health Insurance Tax Credit: Cashews on the Hindenburg

February 18, 2012

Healthcare Professionals Occupy Wall Street With Make-Shift Clinic

October 27, 2011
nursing education
CareerMedical EducationNursing

Your Study Path in Nursing: Hardships in Education and How to Overcome Them

December 20, 2022

Be Inspired: 3 Ways to Originate the Content Your Patients Want

February 22, 2016
Subscribe
Subscribe to our newsletter to get our newest articles instantly!
Follow US
© 2008-2025 HealthWorks Collective. All Rights Reserved.
  • About
  • Contact
  • Privacy
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?