By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Health Works CollectiveHealth Works CollectiveHealth Works Collective
  • Health
    • Mental Health
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: Practice Pointers in the Wake of the Johns Hopkins Hospital Privacy Settlement
Share
Notification Show More
Font ResizerAa
Health Works CollectiveHealth Works Collective
Font ResizerAa
Search
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > Business > Hospital Administration > Practice Pointers in the Wake of the Johns Hopkins Hospital Privacy Settlement
Hospital AdministrationPolicy & Law

Practice Pointers in the Wake of the Johns Hopkins Hospital Privacy Settlement

David Harlow
David Harlow
Share
4 Min Read
SHARE

Report-on-patient-privacy

Report-on-patient-privacy
An OB/GYN at Johns Hopkins was fired last year after a colleague reported her suspicions about a “pen-like device” that was always around his neck, and that turned out to be a camera. He had secretly photographed 7,000 patients over ten years while conducting pelvic exams. Ten days later he committed suicide. Last month, the hospital agreed to settle the class action lawsuit brought by patients whose privacy had been violated for $190 million.

My advice to health care providers (Covered Entities under HIPAA) in a story in Report on Patient Privacy in light of this case recognized the fact that there is no way to protect an organization against a determined bad actor, but there are ways to limit the damage that may be wrought by such an individual. Photography is clinically appropriate in a wide variety of situations, but given the attention that this case has been getting nationally, Covered Entities would be well-advised to review photography and recording policies and their implementation, and be sure to explain them carefully to patients.

Here’s an excerpt from the piece with some of my specific advice:

  • Ensure consent is appropriately received. For example,“obtaining informed consent for use of photography or other recording devices should be standard in both the research and treatment contexts. In the research context, institutional review board approval should be required in advance as well. Policies should mandate the documentation of informed consent before any recording may be made.”
  • Make it easy to complain. “If there is a strong culture of compliance, generally, in a practice or institution, then reporting of violations or suspected violations of whatever sort, via an anonymous tip line or other mechanism, may be promoted and used.”
  • Look beyond policies and procedures. “I don’t care how carefully you have plotted out your privacy and security compliance plan,” Harlow says. “It has to be implemented by the people in your organization, and if they have not bought in to the whole concept and taken the core principles to heart, then the plan can never truly be operationalized.”
  • Customize your approach. Make it homegrown, and provide training and education “not just with respect to the ‘shalts’ and ‘shalt nots’ in the privacy rulebook.”
  • Foster patient empowerment and “patient-centeredness.” When this is done, “patients speak up immediately if something seems amiss rather than harboring misgivings.”

CEs should take care to employ methods that fit “with a broader culture of compliance and patient-centeredness and patient empowerment throughout the institution,” Harlow concludes. “Unless this is done, an institution runs a greater risk of experiencing a local or general breakdown in the realm of patient privacy.”

There has been no announcement to date of an OCR investigation in this matter. As in the case of the recent story about “baby wall” photographs of newborns, some commentators note that the photographs in question are not identifiable as photographs of specific individuals and therefore do not raise HIPAA issues.

The damage done in this case to the trust of thousands of women is likely to be felt for years, as many members of the class — as well as other women — are likely to avoid the health care system in the future and therefore to bear a heightened burden of disease.

TAGGED:HIPAApatient privacy
Share This Article
Facebook Copy Link Print
Share

Stay Connected

1.5kFollowersLike
4.5kFollowersFollow
2.8kFollowersPin
136kSubscribersSubscribe

Latest News

a woman walking on the hallway
6 Easy Healthcare Ways to Sit Less and Move More Every Day
Health
September 9, 2025
Clinical Expertise
Healthcare at a Crossroads: Why Leadership Matters More Than Ever
Global Healthcare
September 9, 2025
travel nurse in north carolina
Balancing Speed and Scope: Choosing the Nursing Degree That Fits Your Goals
Nursing
September 1, 2025
intimacy
How to Keep Intimacy Comfortable as You Age
Relationship and Lifestyle Senior Care
September 1, 2025

You Might also Like

Debt Ceiling Negotiations on Health Care are Mere Cost Shifting

July 15, 2011

Medical Child Abuse: Making Sense of the Boston Globe Stories on Children’s Hospital

December 24, 2013
Newsletter_Pic2_08_20_2015
BusinessHospital AdministrationSocial Media

Have You Checked Your Hospital Yelp Listing Lately?

August 18, 2015
Global HealthcareMedical Education

How To Choose A Private Stem Cell Clinic Without Being A Fraud Victim

February 26, 2019
Subscribe
Subscribe to our newsletter to get our newest articles instantly!
Follow US
© 2008-2025 HealthWorks Collective. All Rights Reserved.
  • About
  • Contact
  • Privacy
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?