Don't Just Protect Me, Put Me in Charge!

June 1, 2005 -- Privacy will always be a major concern regarding medical data. One of the ways in which patients will be empowered by EMRs/PHRs is by having explicit control over access. While HIPAA goes a long way toward protecting privacy, it leaves the actual enforcement in the hands of the caregivers and their institutions. Under today's system, the patient is protected but not in control. This must change.

Here are the aspects of personal health records generally considered most sensitive:

  • Alcohol and substance abuse
  • Biometric information
  • Child or adult abuse or neglect, including sexual assault
  • Communicable diseases
  • Genetic information
  • HIV/AIDS
  • Mental health
  • Minors' information
  • Prescriptions
  • Reproductive health including pregnancy
  • Sexually transmitted diseases

With the electronic medical record system we need, the patient will be the owner of the data (see What Do You Mean I Don't Own My Own Medical Data? above) and will have complete control over who sees it and which parts are withheld from whom. In other words, don't just protect me. HIPAA does that and that's good but it's not enough. Put me in charge! Let me decide where that data goes... and doesn't go.