Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Ignorant question here. How is this not regulated through HIPAA? Shouldn't these board members of this company face prison? DNA, a prosecutor could argue is a unique health identifier.

"Access to equipment containing health information should be carefully controlled and monitored."

https://en.wikipedia.org/wiki/Health_Insurance_Portability_a...



People think of HIPAA as a generic cover-all medical privacy law for some reason.

It's not, not even close, It's a law that very narrowly applies mainly to insurance companies and healthcare entities that accept medical insurance.

As a general rule - if insurance is never involved HIPAA doesn't apply.

If you got a DNA test prescribed by your doctor for a diagnosis or even for genetic counseling then HIPAA applies. It's not the nature of the data, it's the nature of the organization dealing with the data.

I have no idea where this mass misunderstanding came from


"if insurance is never involved HIPAA doesn't apply."

No. This is just plain false.

HIPAA applies when personally identifiable health information is shared/exchanged. And it applies whether the data is electronic or physical (paper).

(I am NOT saying DNA falls within the HIPAA guidelines.)


No, personally identifiable health information can be shared/exchanged without HIPAA applying. For example if I email my grandma information about my cancer diagnosis, Gmail isn't HIPAA compliant and doesn't need to be just because some people might use it to talk about their health. Grandma is also free to share my health information with impunity, she is free to, say, forward it to my boss because grandma doesn't have to abide by HIPAA either because she's a grandma.


Correct, you can personally share whatever information you like.

But a covered entity may not. And there are many covered entities which are not insurance related. That is all I was trying to say.


The privacy rule only applies covered entities. If a covered entity works with cloud provider, they sign a BAA. The cloud provider is not a covered entity.


HIPPA only applies to a specific list of covered entities... health providers, insurance, etc.

DNA services are not currently considered covered entities.

They should be, IMO, but I believe Congress would have to act.


More accurately "Dna services for funsies" are not covered entities. Medical labs that sequence DNA in the realm of actual healthcare (and accept medical insurance) are covered entities.


if they construe their DNA data as not health information, but instead information like finger prints?


"I'm standing here in this chalk circle where HIPAA does not apply, can't touch me, nyah nyah!" Sounds like that would work against a 5-year-old sibling, but that's rarely the case...


It's not covered. The ones at which we should be most angry are law enforcement officers using this information. This is simply a first step to the state collecting DNA on all citizens (see what it's done with fingerprints as an example.)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: