Healthcare providers, from the smallest clinic to the largest healthcare provider system, need to be concerned about the technologies (tech) they have implemented within their webpages. Many organizations do not realize that their contracted third parties hosting and managing their websites, or their own internal staff, have implemented tracking tech into their webpages, even within their patient portals. They often do so at the request of their marketing and sales departments, or at the urging of third parties who are supplying the provider organizations with supplies or services.
Tracking tech on healthcare websites, particularly within authenticated patient portals, can result in impermissible disclosures of protected health information (PHI) where data is transmitted to third parties without a valid HIPAA basis. Such data often includes not only identifiers, URLs, appointment information, health data, chat transcripts with doctors or nurses, user activity, lab results and more, they also often include data about the patient. Such data can include, but not be limited to, the type and version of computer or phone they are using, their location, date and time of activities, and even other websites they have visited. While tracking pixels on public-facing webpages can gather hundreds of personal data elements, within a patient portal that exposure increases exponentially, and so does the risk of HIPAA noncompliance.
HIPAA permits disclosures of PHI for treatment, payment, and healthcare operations (TPO), or with an explicit and valid authorization from each of the associated individuals. In practice, most advertising and marketing technology vendors do not qualify as business associates (BAs) and will not execute business associate agreements (BAAs). As a result, transmitting PHI to such vendors is typically high risk and often prohibited by HIPAA.
In an authenticated portal, typically most of the accessible data may constitute PHI depending on what is exposed or transmitted. Tracking tech incorporated into the webpage code can be configured to dynamically capture and transmit sensitive details without a valid HIPAA basis and send the data on to the large tech companies providing the tracking tech, from where they then often share it with other entities as a paid service to them.
Because the ad-tech entities generally refuse to execute BAAs or limit their data usage strictly to TPO, transmitting this data without explicit and valid patient authorization creates immense legal and regulatory risk. And regulatory enforcement and class-action litigation surrounding online tracking in healthcare are at an all-time high.
Every U.S. healthcare organization, and the BAs who support or manage their websites in some way, need to know where all the tracking tech is located within each webpage of a healthcare provider’s website, and then take appropriate actions to remove the tracking tech that is on the login page of the patient portals, and within each of the portal pages, unless legal counsel and executive management indicate it is acceptable on specific webpages.
Here are the recommended actions for you to take if you’ve just been notified that tracking tech are likely to be within your online webpages.
Tracking tech on healthcare websites, particularly within authenticated patient portals, can result in impermissible disclosures of protected health information (PHI) where data is transmitted to third parties without a valid HIPAA basis. Such data often includes not only identifiers, URLs, appointment information, health data, chat transcripts with doctors or nurses, user activity, lab results and more, they also often include data about the patient. Such data can include, but not be limited to, the type and version of computer or phone they are using, their location, date and time of activities, and even other websites they have visited. While tracking pixels on public-facing webpages can gather hundreds of personal data elements, within a patient portal that exposure increases exponentially, and so does the risk of HIPAA noncompliance.
HIPAA permits disclosures of PHI for treatment, payment, and healthcare operations (TPO), or with an explicit and valid authorization from each of the associated individuals. In practice, most advertising and marketing technology vendors do not qualify as business associates (BAs) and will not execute business associate agreements (BAAs). As a result, transmitting PHI to such vendors is typically high risk and often prohibited by HIPAA.
In an authenticated portal, typically most of the accessible data may constitute PHI depending on what is exposed or transmitted. Tracking tech incorporated into the webpage code can be configured to dynamically capture and transmit sensitive details without a valid HIPAA basis and send the data on to the large tech companies providing the tracking tech, from where they then often share it with other entities as a paid service to them.
Because the ad-tech entities generally refuse to execute BAAs or limit their data usage strictly to TPO, transmitting this data without explicit and valid patient authorization creates immense legal and regulatory risk. And regulatory enforcement and class-action litigation surrounding online tracking in healthcare are at an all-time high.
Every U.S. healthcare organization, and the BAs who support or manage their websites in some way, need to know where all the tracking tech is located within each webpage of a healthcare provider’s website, and then take appropriate actions to remove the tracking tech that is on the login page of the patient portals, and within each of the portal pages, unless legal counsel and executive management indicate it is acceptable on specific webpages.
Here are the recommended actions for you to take if you’ve just been notified that tracking tech are likely to be within your online webpages.
