SlideShare une entreprise Scribd logo
1  sur  21
Télécharger pour lire hors ligne
1
© 2022 TrustArc Inc. Proprietary and Confidential Information.
Level-Up Your Healthcare Privacy Program
2
Speakers
Sharon Kamowitz
Senior Privacy Consultant
TrustArc
Meaghan McCluskey
Associate General Counsel, Research
TrustArc
3
Agenda
● The state of privacy management in healthcare
● Enforcement trends
● Risks the industry is likely to face in 2022
● An approach to address the current environment
● Q&A
4
State of Privacy: What is Healthcare?
● Traditional healthcare providers and payers
● Medical device and equipment
● Digital innovation
○ Patient Portals
○ Virtual healthcare / telehealth
○ Health apps
● Medical Cannabis Dispensaries
● Genealogy platforms (23&Me; Ancestry; Vitagene; etc.)
● One size compliance does not fit all.
5
State of Privacy: Dobbs v Jackson
● No Constitutional right to privacy that protects abortions
● Post-Dobbs Activity:
○ HHS Guidance to both CEs and individuals
○ Letters to Data Brokers and Health Apps
○ EO on Protecting Access to Reproductive Healthcare Services
○ FTC Statement on Enforcement
○ SB 4408, the Health and Location Data Protection Act
6
State of Privacy: U.S. Regulatory Challenges - HIPAA
● Privacy Rule - 2003; Security Rule - 2005; Breach Rule - 2009
○ Did not contemplate today’s digital world
● Applies to covered entities and business associates, as defined
○ Lack of understanding among business associates
○ Confusion regarding release of information
○ Numerous questions re digital apps
■ See OCR Guidance
○ Grey areas for medical devices
7
State of Privacy: HIPAA (cont.)
● Proposed amendments to Privacy Rule
○ Comments requested - Dec. 2020 - May 2021
● Amendments to HITECH - Jan. 2021
○ Requires HHS to consider “recognized security practices” during
investigation.
● OCR Enforcement Discretion and Guidance during Covid Public
Health Emergency
○ Still in effect for now
8
State of Privacy: Other U.S. Regulatory Requirements
● Information Blocking Rules
○ Applies to Healthcare providers, Certified Health IT developers
○ Prohibits practices that are likely to interfere with, prevent or
materially discourage exchange or use of electronic health
information.
○ Several exceptions.
○ Overlap with HIPAA Right to Access provisions and definition of
EPHI.
9
State of Privacy: Other U.S. Requirements (cont.)
● FTC Health Breach Notification Rule
○ Applies to vendors of personal health records (PHR), related entities, and
third party services providers.
○ Does not apply to HIPAA covered entities or business associates (acting as
BAs)
○ PHR definition: electronic record of Individually identifiable health
information (as defined by HIPAA) that can be drawn from multiple
sources and is managed, shared, and controlled by or primarily by an
individual
○ Applies to developers of mobile health apps or connected devices as long
as app or devices are capable of drawing from multiple sources.
10
State of Privacy: American Data Privacy & Protection Act
● DRAFT Federal Legislation.
● Would apply to healthcare data collected, processed or transferred by
organizations that are not HIPAA covered entities, business associates,
and/or do not comply with HIPAA.
● HIPAA covered entities and business associates deemed to comply to
extent that they comply with HIPAA but only for data regulated by
HIPAA.
11
State of Privacy: U.S. Patchwork of State Laws
● Varying requirements re:
○ Breach reporting and notification
○ Medical record release
○ Minors
● New CA, CT, CO & VA privacy laws
○ Various exemptions re health data
○ Different definitions of sensitive information
○ B-to-B and employee data
● Laws on genetic and biometric information - ex. CA & IL.
● Security requirements - ex. MA
12
State of Privacy: Don’t forget there are other countries
● Germany Patient Data Protection Act
● Draft European Health Data Space Regulation
● Bill 19 in Quebec, Canada
● Cybersecurity laws in Asia
13
Enforcement and Litigation Trends
US:
● OCR - Right to Access initiative and continued focus on security
● FTC and Attorney General actions: Flo Health,
● Private Right of Action - CA
Canada:
● Individual enforcement
● Class action litigation - or not
Europe:
● DPA orders stem from misuse & data breaches
● Fines vary by volume of data, # of data subjects involved
14
Risks in the Healthcare Industry
● Ransomware attacks
● Difficulty in obtaining cyber-liability insurance
● Multiple legal requirements and inconsistent definitions
● Human error
15
Privacy Management in Healthcare
● Why is data privacy management particularly important for
the healthcare industry?
● A Framework approach to compliance:
○ TrustArc or Nymity frameworks;
○ NIST Privacy Framework
○ ISO 27701 or 27001/27002
○ GDPR, HIPAA
16
Privacy Management: A Framework Approach
17
Privacy Management: A Framework Approach
Devil is in the details: the more granular you break your topics down, the better able to identify gaps.
Individual Rights:
18
A Framework Approach: Build on what you have
19
A Framework Approach: Enforcement Approach
20
A Framework Approach: Bang for your buck
21
Thank You!
See http://www.trustarc.com/insightseries for
the 2022 Privacy Insight Series and past
webinar recordings.
If you would like to learn more about how TrustArc can support
you with compliance, please reach out to sales@trustarc.com for a
free demo.

Contenu connexe

Similaire à TrustArc Webinar: Level-Up Your Healthcare Privacy Program

[DSC Adria 23]Josema Cavanillas How To Mitigate the Exposure Risk in Clinical...
[DSC Adria 23]Josema Cavanillas How To Mitigate the Exposure Risk in Clinical...[DSC Adria 23]Josema Cavanillas How To Mitigate the Exposure Risk in Clinical...
[DSC Adria 23]Josema Cavanillas How To Mitigate the Exposure Risk in Clinical...DataScienceConferenc1
 
Data Privacy and consent management .. .
Data Privacy and consent management  ..  .Data Privacy and consent management  ..  .
Data Privacy and consent management .. .ClinosolIndia
 
Data privacy and consent management (K.sailaja).pptx
Data privacy and consent management (K.sailaja).pptxData privacy and consent management (K.sailaja).pptx
Data privacy and consent management (K.sailaja).pptxkandalamsailaja17
 
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...Burton Lee
 
Third-Party Relationships and Your Confidential Data
Third-Party Relationships and Your Confidential DataThird-Party Relationships and Your Confidential Data
Third-Party Relationships and Your Confidential DataGrant Thornton LLP
 
HIPAA Rights Privacy and Enforcements RD.pptx
HIPAA Rights  Privacy and Enforcements RD.pptxHIPAA Rights  Privacy and Enforcements RD.pptx
HIPAA Rights Privacy and Enforcements RD.pptxRAJIV RANJAN DAS
 
Telemedicine Law: Going from Startup to Enterprise
Telemedicine Law: Going from Startup to EnterpriseTelemedicine Law: Going from Startup to Enterprise
Telemedicine Law: Going from Startup to EnterpriseVSee
 
HIPAA and HITECH : What you need to know
HIPAA and HITECH : What you need to knowHIPAA and HITECH : What you need to know
HIPAA and HITECH : What you need to knowShred-it
 
Confidentiality & privacy
Confidentiality & privacyConfidentiality & privacy
Confidentiality & privacykendale
 
Confidentiality & privacy
Confidentiality & privacyConfidentiality & privacy
Confidentiality & privacykendale
 
Health Information Privacy: Asia's Viewpoint
Health Information Privacy: Asia's ViewpointHealth Information Privacy: Asia's Viewpoint
Health Information Privacy: Asia's ViewpointNawanan Theera-Ampornpunt
 
CHAPTER LAWS AND ETHICS
CHAPTER LAWS AND ETHICSCHAPTER LAWS AND ETHICS
CHAPTER LAWS AND ETHICSEarlene McNair
 
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...Diana Maier
 
Medicalchain - ECO 15: Digital connectivity in healthcare
Medicalchain - ECO 15: Digital connectivity in healthcareMedicalchain - ECO 15: Digital connectivity in healthcare
Medicalchain - ECO 15: Digital connectivity in healthcareInnovation Agency
 
mHealth Israel_Ellen Janos_Healthcare Partner_Mintz Levin_ US Regulatory Envi...
mHealth Israel_Ellen Janos_Healthcare Partner_Mintz Levin_ US Regulatory Envi...mHealth Israel_Ellen Janos_Healthcare Partner_Mintz Levin_ US Regulatory Envi...
mHealth Israel_Ellen Janos_Healthcare Partner_Mintz Levin_ US Regulatory Envi...Levi Shapiro
 
Case Study “HIE Consumer & Stakeholder Engagement: Privacy and Security of Pa...
Case Study “HIE Consumer & Stakeholder Engagement: Privacy and Security of Pa...Case Study “HIE Consumer & Stakeholder Engagement: Privacy and Security of Pa...
Case Study “HIE Consumer & Stakeholder Engagement: Privacy and Security of Pa...Health IT Conference – iHT2
 
Gdpr and usa data privacy issues
Gdpr and usa data privacy issuesGdpr and usa data privacy issues
Gdpr and usa data privacy issuesStefan Schippers
 

Similaire à TrustArc Webinar: Level-Up Your Healthcare Privacy Program (20)

[DSC Adria 23]Josema Cavanillas How To Mitigate the Exposure Risk in Clinical...
[DSC Adria 23]Josema Cavanillas How To Mitigate the Exposure Risk in Clinical...[DSC Adria 23]Josema Cavanillas How To Mitigate the Exposure Risk in Clinical...
[DSC Adria 23]Josema Cavanillas How To Mitigate the Exposure Risk in Clinical...
 
Nicolas Terry, "Big Data, Regulatory Disruption, and Arbitrage in Health Care"
Nicolas Terry, "Big Data, Regulatory Disruption, and Arbitrage in Health Care"Nicolas Terry, "Big Data, Regulatory Disruption, and Arbitrage in Health Care"
Nicolas Terry, "Big Data, Regulatory Disruption, and Arbitrage in Health Care"
 
Data Privacy and consent management .. .
Data Privacy and consent management  ..  .Data Privacy and consent management  ..  .
Data Privacy and consent management .. .
 
Data privacy and consent management (K.sailaja).pptx
Data privacy and consent management (K.sailaja).pptxData privacy and consent management (K.sailaja).pptx
Data privacy and consent management (K.sailaja).pptx
 
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
 
Third-Party Relationships and Your Confidential Data
Third-Party Relationships and Your Confidential DataThird-Party Relationships and Your Confidential Data
Third-Party Relationships and Your Confidential Data
 
HIPAA Rights Privacy and Enforcements RD.pptx
HIPAA Rights  Privacy and Enforcements RD.pptxHIPAA Rights  Privacy and Enforcements RD.pptx
HIPAA Rights Privacy and Enforcements RD.pptx
 
Overview on data privacy
Overview on data privacy Overview on data privacy
Overview on data privacy
 
Protection of patient data in EU vs. US
Protection of patient data in EU vs. USProtection of patient data in EU vs. US
Protection of patient data in EU vs. US
 
Telemedicine Law: Going from Startup to Enterprise
Telemedicine Law: Going from Startup to EnterpriseTelemedicine Law: Going from Startup to Enterprise
Telemedicine Law: Going from Startup to Enterprise
 
HIPAA and HITECH : What you need to know
HIPAA and HITECH : What you need to knowHIPAA and HITECH : What you need to know
HIPAA and HITECH : What you need to know
 
Confidentiality & privacy
Confidentiality & privacyConfidentiality & privacy
Confidentiality & privacy
 
Confidentiality & privacy
Confidentiality & privacyConfidentiality & privacy
Confidentiality & privacy
 
Health Information Privacy: Asia's Viewpoint
Health Information Privacy: Asia's ViewpointHealth Information Privacy: Asia's Viewpoint
Health Information Privacy: Asia's Viewpoint
 
CHAPTER LAWS AND ETHICS
CHAPTER LAWS AND ETHICSCHAPTER LAWS AND ETHICS
CHAPTER LAWS AND ETHICS
 
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
 
Medicalchain - ECO 15: Digital connectivity in healthcare
Medicalchain - ECO 15: Digital connectivity in healthcareMedicalchain - ECO 15: Digital connectivity in healthcare
Medicalchain - ECO 15: Digital connectivity in healthcare
 
mHealth Israel_Ellen Janos_Healthcare Partner_Mintz Levin_ US Regulatory Envi...
mHealth Israel_Ellen Janos_Healthcare Partner_Mintz Levin_ US Regulatory Envi...mHealth Israel_Ellen Janos_Healthcare Partner_Mintz Levin_ US Regulatory Envi...
mHealth Israel_Ellen Janos_Healthcare Partner_Mintz Levin_ US Regulatory Envi...
 
Case Study “HIE Consumer & Stakeholder Engagement: Privacy and Security of Pa...
Case Study “HIE Consumer & Stakeholder Engagement: Privacy and Security of Pa...Case Study “HIE Consumer & Stakeholder Engagement: Privacy and Security of Pa...
Case Study “HIE Consumer & Stakeholder Engagement: Privacy and Security of Pa...
 
Gdpr and usa data privacy issues
Gdpr and usa data privacy issuesGdpr and usa data privacy issues
Gdpr and usa data privacy issues
 

Plus de TrustArc

TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc
 
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc
 
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc
 
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...TrustArc
 
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...TrustArc
 
Nymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesNymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesTrustArc
 
CBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceCBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceTrustArc
 
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfEverything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfTrustArc
 
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...TrustArc
 
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsPrivacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsTrustArc
 
Building Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsBuilding Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsTrustArc
 
The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...TrustArc
 
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdfTrustArc
 
Artificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceArtificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceTrustArc
 
How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023TrustArc
 
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act:  Using Consumer Data and Maintaining TrustThe Ultimate Balancing Act:  Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act: Using Consumer Data and Maintaining TrustTrustArc
 
The Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To KnowThe Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To KnowTrustArc
 

Plus de TrustArc (20)

TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
 
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI Innovations
 
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
 
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
 
Nymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesNymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 States
 
CBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceCBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy Compliance
 
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfEverything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
 
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
 
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsPrivacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
 
Building Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsBuilding Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy Certifications
 
The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...
 
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
 
Artificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceArtificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI Governance
 
How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023
 
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act:  Using Consumer Data and Maintaining TrustThe Ultimate Balancing Act:  Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
 
The Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To KnowThe Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To Know
 

Dernier

AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAndrey Devyatkin
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUK Journal
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?Antenna Manufacturer Coco
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Enterprise Knowledge
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CVKhem
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...apidays
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024The Digital Insurer
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...DianaGray10
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 

Dernier (20)

AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 

TrustArc Webinar: Level-Up Your Healthcare Privacy Program

  • 1. 1 © 2022 TrustArc Inc. Proprietary and Confidential Information. Level-Up Your Healthcare Privacy Program
  • 2. 2 Speakers Sharon Kamowitz Senior Privacy Consultant TrustArc Meaghan McCluskey Associate General Counsel, Research TrustArc
  • 3. 3 Agenda ● The state of privacy management in healthcare ● Enforcement trends ● Risks the industry is likely to face in 2022 ● An approach to address the current environment ● Q&A
  • 4. 4 State of Privacy: What is Healthcare? ● Traditional healthcare providers and payers ● Medical device and equipment ● Digital innovation ○ Patient Portals ○ Virtual healthcare / telehealth ○ Health apps ● Medical Cannabis Dispensaries ● Genealogy platforms (23&Me; Ancestry; Vitagene; etc.) ● One size compliance does not fit all.
  • 5. 5 State of Privacy: Dobbs v Jackson ● No Constitutional right to privacy that protects abortions ● Post-Dobbs Activity: ○ HHS Guidance to both CEs and individuals ○ Letters to Data Brokers and Health Apps ○ EO on Protecting Access to Reproductive Healthcare Services ○ FTC Statement on Enforcement ○ SB 4408, the Health and Location Data Protection Act
  • 6. 6 State of Privacy: U.S. Regulatory Challenges - HIPAA ● Privacy Rule - 2003; Security Rule - 2005; Breach Rule - 2009 ○ Did not contemplate today’s digital world ● Applies to covered entities and business associates, as defined ○ Lack of understanding among business associates ○ Confusion regarding release of information ○ Numerous questions re digital apps ■ See OCR Guidance ○ Grey areas for medical devices
  • 7. 7 State of Privacy: HIPAA (cont.) ● Proposed amendments to Privacy Rule ○ Comments requested - Dec. 2020 - May 2021 ● Amendments to HITECH - Jan. 2021 ○ Requires HHS to consider “recognized security practices” during investigation. ● OCR Enforcement Discretion and Guidance during Covid Public Health Emergency ○ Still in effect for now
  • 8. 8 State of Privacy: Other U.S. Regulatory Requirements ● Information Blocking Rules ○ Applies to Healthcare providers, Certified Health IT developers ○ Prohibits practices that are likely to interfere with, prevent or materially discourage exchange or use of electronic health information. ○ Several exceptions. ○ Overlap with HIPAA Right to Access provisions and definition of EPHI.
  • 9. 9 State of Privacy: Other U.S. Requirements (cont.) ● FTC Health Breach Notification Rule ○ Applies to vendors of personal health records (PHR), related entities, and third party services providers. ○ Does not apply to HIPAA covered entities or business associates (acting as BAs) ○ PHR definition: electronic record of Individually identifiable health information (as defined by HIPAA) that can be drawn from multiple sources and is managed, shared, and controlled by or primarily by an individual ○ Applies to developers of mobile health apps or connected devices as long as app or devices are capable of drawing from multiple sources.
  • 10. 10 State of Privacy: American Data Privacy & Protection Act ● DRAFT Federal Legislation. ● Would apply to healthcare data collected, processed or transferred by organizations that are not HIPAA covered entities, business associates, and/or do not comply with HIPAA. ● HIPAA covered entities and business associates deemed to comply to extent that they comply with HIPAA but only for data regulated by HIPAA.
  • 11. 11 State of Privacy: U.S. Patchwork of State Laws ● Varying requirements re: ○ Breach reporting and notification ○ Medical record release ○ Minors ● New CA, CT, CO & VA privacy laws ○ Various exemptions re health data ○ Different definitions of sensitive information ○ B-to-B and employee data ● Laws on genetic and biometric information - ex. CA & IL. ● Security requirements - ex. MA
  • 12. 12 State of Privacy: Don’t forget there are other countries ● Germany Patient Data Protection Act ● Draft European Health Data Space Regulation ● Bill 19 in Quebec, Canada ● Cybersecurity laws in Asia
  • 13. 13 Enforcement and Litigation Trends US: ● OCR - Right to Access initiative and continued focus on security ● FTC and Attorney General actions: Flo Health, ● Private Right of Action - CA Canada: ● Individual enforcement ● Class action litigation - or not Europe: ● DPA orders stem from misuse & data breaches ● Fines vary by volume of data, # of data subjects involved
  • 14. 14 Risks in the Healthcare Industry ● Ransomware attacks ● Difficulty in obtaining cyber-liability insurance ● Multiple legal requirements and inconsistent definitions ● Human error
  • 15. 15 Privacy Management in Healthcare ● Why is data privacy management particularly important for the healthcare industry? ● A Framework approach to compliance: ○ TrustArc or Nymity frameworks; ○ NIST Privacy Framework ○ ISO 27701 or 27001/27002 ○ GDPR, HIPAA
  • 16. 16 Privacy Management: A Framework Approach
  • 17. 17 Privacy Management: A Framework Approach Devil is in the details: the more granular you break your topics down, the better able to identify gaps. Individual Rights:
  • 18. 18 A Framework Approach: Build on what you have
  • 19. 19 A Framework Approach: Enforcement Approach
  • 20. 20 A Framework Approach: Bang for your buck
  • 21. 21 Thank You! See http://www.trustarc.com/insightseries for the 2022 Privacy Insight Series and past webinar recordings. If you would like to learn more about how TrustArc can support you with compliance, please reach out to sales@trustarc.com for a free demo.