Who Owns Your Health Data?
porsche911 writes "The Wall Street Journal has an interesting article about how the data from Implanted health devices is managed and the limitations patients run into when they want to see the data. Companies like Medtronic plan to sell the data but won't provide it to the person who generated it. From the article: 'The U.S. has strict privacy laws guaranteeing people access to traditional health files. But implants and other new technologies—including smartphone apps and over-the-counter monitors—are testing the very definition of medical records.'"
HIPPA only applies to health care providers. Anyone else who gets your data by any means, is not restricted by HIPPA. Notable examples are life insurance companies. You sign a waiver to give them access to your health info to qualify for a policy. After that they can do whatever they want with the data. They can, and do, routinely pass it along to a medical information clearing house in Massachusetts (I forget the name of it), which is a third party. The clearing house dishes out the information (including personal identifying information) to anyone who wants to pay for it.
Americans imagine that they own their personal data. Data (information, facts) are not property and can not be owned. Intellectual property laws bestow some rights but not "ownership" You can own the rights but not the facts. If you could own facts, then you could prevent police and courts from using facts about your behavior against you.
Records, on the other hand are ordinary property. Whoever owns the records can treat them like any other property, regardless of the information they contain (exceptions for national security, for parties covered by HIPPA, records under subpoena and so on). There was once a notable case of a hospital in Las Vegas. They rented a warehouse to store paper patient records. They failed to pay the rent. The landlord sold all property stored in the warehouse to recover money owed to him. Neither the landlord, nor any subsequent owner of those paper records was restricted in any way as to what they could do with them.
They remove anything that can identify you before they share it. The aggregate is what everyone wants to see. That is how they would get around anything short of being expressly forbidden to do anything at all with the data.