Who owns digital health data? HIPAA privacy myths may put women at risk

For women, privacy and control over health information has never been more important, as the U.S. continues its abortion access fight and as some states criminalize the procedure. But beyond the political debate, knowledge gaps on the actual protections for and control of digital health data may lead to severe consequences.
Several reports within the last few months have furthered these digital health privacy concerns, including two showing Facebook’s Pixel tool allegedly scraping hospital data. The Novant Health ACE breach notice that soon followed the report seemed to confirm the dubious practices as 1.4 million patients were told of an “unintended disclosure” via the Meta tool.
During the same time period, reports out of Nebraska showed Facebook was issued a subpoena compelling it to release private communications with law enforcement over illegal abortion claims against a 41-year-old woman and her daughter.
Kayte Spector-Bagdady, an associate director at the University of Michigan Medical School’s Center for Bioethics and Social Sciences in Medicine, says it’s the latter scenario that should be of prime concern to women under the current abortion climate, in combination with misconceptions about digital health control and privacy.
Spector-Bagdady is a clinical ethicist and leads in other academic roles. She was also the former associate director for the Obama administration’s presidential Commission for the Study of Bioethics. She mused, “this is the moment.”
The Facebook scenarios bring up several different regulatory regimes. While Spector-Bagdady has no personal knowledge of the report on the company’s alleged data scraping, if appointment information, health concerns, and personal names were indeed pulled by the app, it could be a violation of the Health Insurance Portability and Accountability Act.
HIPAA regulates identifying data like names combined with health information, like the kind of appointment you need. She added that in a traditional sense it “should indeed be protected by HIPAA.”
In light of these reports, extensive nuances, and the criminalization of abortion in some states, SC Media spoke with Spector-Bagdady on the current state of digital health privacy and controls to disbunk key myths and find ways to protect providers, and their patients.
Those in healthcare are keenly aware of the limitations of HIPAA: that it only applies to specific covered entities and business associates and its outdated nature limits its controls over consumer-generated data and health app developers.
Meanwhile, the COVID-19 national emergency revealed the chasm between privacy perceptions around health data and actuality. Consumers tend to believe they have more control over their own health information than they actually do, said Spector-Bagdady. “Health information is only protected by federal law under very narrow and specific circumstances.”
For example, when stores were asking people to present their vaccination card before entering, people were concerned about their HIPAA rights. But it clearly wasn’t a violation as the rule applies only to healthcare entities and not private businesses and no one else.
In addition, if the health data lacks some very specific identifying information, like the full name or Social Security number, the information “can be shared pretty freely.” Spector-Bagdady stressed that HIPAA’s main protection is for clinical information.
“Even our de-identified clinical information doesn’t have HIPAA protection,” she said. De-identified data is still defined by the regulation, which was drafted in the 1990s. As a result, it “doesn’t at all govern commercial gathering or use of health information or health proxy information.
“There are almost no protections under HIPAA or any other data privacy regulation in the U.S.


