Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This isn't 100% accurate. While I can't say much about the case of the apple watch, I can say that there are a ton of tech companies which are not covered entities but which do fall under HIPAA guidelines.

For example, the company I work at is not a covered entity because we do have access to PHI we have certain regulations we have to follow. Further, we have to sign BAAs with any covered entity we work with defining who is responsible for what.

Any company which deals with heathcare information should always assume they fall under HIPAA until they've hired lawyers who tell them otherwise.



If you are signing BAAs, you're probably a service provider for a covered entity and are contractually obligated to follow HIPAA. Which is different than what the original question was.

For example, what is Apple's exposure here? I doubt any... they keep your data private because it's good for business (and they can then advertise how privacy conscience they are and get people to buy more watches). They aren't doing it because they have to follow HIPAA regulations.

A more interesting question is -- if the Apple watch was purchased as a medical device (maybe even with insurance or a prescription), does Apple's data processing need to change at all? What about if people got a watch as part of a medical study (not people that already had the watch). Would that be different?


Do the examples you have in mind work with data that originates with HIPAA covered entities? That, and/or doing work on behalf of a CE would likely be a situation in which you’d have to comply: https://www.techhealthperspectives.com/2012/09/25/when-does-...

In a future where smartwatch companies integrate with a health plan/hospital’s medical records system, I would expect HIPAA to cover them. But in a case where a company is generating the data (via user consent/input), it might not be the case.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: