Friday, February 7, 2014

Privacy in the Toilet

So I cannot help but take a cue from all the mimes and stories going around about the toilet conditions in Sochie at the Winter Olympics. Talk about a lack of privacy...

I don't know if the pictures and/or stories are real, but they sure are fun. And like most online authors, I plan to make the most of it, perpetuate the myth, and basically exploit the heck out of it. oo rah.

Let's compare the supposedly lack of privacy of Sochi Olympic toilets to the sanitary conditions of some countries. Sochi has toilets. Some countries do not. Are we as a leading world power spoiled? We have indoor plumbing, filtered water, sophisticated waste management, and private commodes almost everywhere. Is there some reason why Olympians cannot tolerate something less than the best? Is there some reason why our Olympians cannot see what it feels like to live on the other side?  We have antibiotics, right? Is privacy required to take a poop? As a nurse, we often had to deal with a patient's inability to urinate on command - hesitation. It's prevalent in pre-employment physicals and drug screens as well. Some people simply cannot perform with an audience.

So let's transfer some of these same considerations over to privacy. In the U.S., we are horrified of being asked to use the restroom in front of someone, but we don't consider personal information to be private. Bowel movements, yes. Date of birth, no. So that's our scale of privacy need. We don't flinch at sharing a lot of information or categories of information. We expect that companies who possess our information in certain contexts to be using that information to gain a business or competitive edge or to use it in some way that is advantageous to them. Thus, when there is a breach, fewer than 10%  of people contact the company or take them up on mitigation offers (anecdotally and my own experience dealing with breaches - seriously was closer to 3-5%).

Yet, in the E.U., people have other expectations. They expect privacy. They expect their information will only be used for the purpose it is collected and nothing else. Nothing else. And once the purpose is achieved, the information should be deleted. Deleted. So they are horrified at U.S. citizens' and businesses' cavalier attitudes towards privacy.

This would be a different world if we were as horrified at our information being gathered, shared, used, and kept as we are having to poop side-by-side with someone else. Take that and flush it. 

Tuesday, February 4, 2014

Happy Birthday, Facebook!

So today is Facebook's 10th anniversary or birthday...

What were you doing 10 years ago? It was 2004...I was graduating law school. I recall hearing about the new service for college kids and some scandal about posting pictures. My daughters were in junior high, so they were on the infamous MySpace (where is that now, anyway?).  That proves that first-to-market is not always market leader.

Facebook has faced (pardon the pun) many challenges in the U.S. and globally about their privacy practices, which seem to change daily without notice. Which is not true, by the way. Facebook does not change its policies daily. On the other hand, since they eliminated the public voting process last year or so, now we as users don't know when it is changed.

Much of the controversy over Facebook has been based in its for-profit side - we, as users, don't provide it any money directly so they have to get it from somewhere. They get it from ads. You may recall how users' likes were used as product endorsements at one time. Now, we get served targeted behavioral ads in our newsfeeds. You can report these as spam. 

But let's move away from the negatives and look at the positives. There are people I have not even thought about in over 25 years...and now, through Facebook, I see what they are doing in their lives - pictures of them and their children, families, colleagues, and friends. It is kinda cool. Many people who I love that I do not get to see for years, now I am a permitted peeping Tom in their lives. It's wonderful.

Facebook made our 25th high school reunion a huge success - cause we could find people!

Facebook let me know when some older family friends passed away - I could send flowers and/or make it to the funeral.

Facebook sometimes provides me more of a look into lives than I wish to have - don't need to know when someone has a bowel movement or is mad at the cashier at Wal-Mart. But in general, I like Facebook, which is why I use it. Under my real name. I also get to "like" the pages of actors and writers I like and they frequently have contests and cool information. It's fun.

So Happy Birthday, Facebook - may the next decade see you enjoy even more success and more maturity in your practices.

Sunday, February 2, 2014

When can Employers share your Information?

My daughter, Dazlin, asked this question on privacy..."Under what circumstances can or should my employer share my information?"

What a brilliant inquiry.

And I have no brilliant, quick responses, yet I am forcing her to wait for the answer on here even though I am currently comfortably ensconced in her apartment, sitting across from her. 

First, for me, the easy answer is about medical information. Any information in the medical context, whether as part of disability accommodation, employment prescreening, genetic information, employer medical coverage, or workers' compensation must be kept confidential. This means, generally, in HR, there are two files for each employee or a bifurcated file where the health information is kept separated from discipline, hiring and firing, pay, etc.

Can they ever share it? Of course they can. They can share it with people and entities who have a need to know, such as benefit managers, health care professionals who are treating you, risk management, and so forth. But in general, the information should not be shared anywhere without a legitimate reason. Most of the protection here is federal - EEOC (disability, genetic information), OSHA (injuries on the job) - but there is also state law that applies (workers' comp, HR law, data breach law).

I am not going into a terrible amount of detail here if for no other reason than it is a blog and not a legal treatise. Some factors also depend on whether your employer is a public or private entity and/or what job you hold. But if anyone is curious, write me and let me know that you have questions. I'll see what I can do.

Now, for the sharing...in almost all laws, there are exceptions and privacy law is no exception to that. In general, the exceptions are around subpoenas, law enforcement, public health, emergencies, and business operations that require disclosures. Business operations could include mergers, account houses, and other entities that are contracted to perform some duty on your employer's behalf, like mailing 1099s. To do so, the other entity has your information. Do you also remember all the stories about how many subpoenas and requests for information are being served on internet service providers? If information is part of an investigation, your employer will likely give it up.

Other than medical information, employers are required to keep certain information secure - like your date of birth and social security number. In countries other than the U.S., who have data protection laws, certain information is considered sensitive information. Sensitive information includes ethnicity, political views, member of professional organizations, etc. Now here in the U.S., race, age, gender is also considered confidential, but mainly because an employer can be sued for discrimination if negative decisions are based on race, gender, being over 40, disabled - things that make you a member of a protected class. Also, credit reports and background checks must be performed and retained securely. In fact, after the financial troubles of 2008, several states placed background check laws in place - mainly either the employer could not ask certain questions in an application or could not do a background check before meeting the person.

Many states have laws protecting certain information, although Massachusetts with 17 CMR 201 is the strongest. In Massachusetts, if you have information on their residents, to include name (either first name/initial with last name) plus some other elements (SSN, driver license number, or financial account number), then you are required to have a security program in place and provide certain data protections.

Mainly states have data breach notification laws, meaning that if your data is breached somehow, your employer must let you know (these are general law not employment laws, but apply to entities that collect certain information). Thus, if your employer wants to be excluded in most of these states from notification provisions, then they need to encrypt and take precautions with your information. Not all states recognize encryption as an exception, but most do - and of course, this only applies to electronic information.

Speaking of electronic information: analyzing whether employers can access your electronic communications such as email, texts, and social media is a full blog on its own. Morality consideration is another - think of teachers fired for posting naked party pictures on their own facebook or sports figures who get into scandals and lose endorsements. And last, lifestyle (which includes morality) is also a very deep discussion of law. 

So this is part of her answer. In reality, not all employers follow the laws - and certainly not all employees of your employer will follow the law. Training and awareness are huge for data protection and training is not generally a high budget item for many employers, especially towards protecting their employees' data.

So my advice point coming out of this is to be careful of your own information in the workplace. It is not necessarily a good idea to friend people on social media that you work with - you just may have information disclosed to your employer that you wish was not - and if a negative action is taken towards you based on this information, then you likely will have a very hard time proving it.

Saturday, February 1, 2014

What is a Privacy Counsel, anyway?

My name is K and I am a privacy counsel.

Most of the time when people ask what I do, they have no clue when I say "I am a privacy counsel." Confession time, I usually only say I'm an attorney, but sometimes they want to know what I practice. I don't practice. I am in-house. For those that don't know, in-house means that I am not with a law firm and do not take clients. I work for a company as an employee. The company is my client.

And given that I blog about privacy, I have to always disclaim that my views are not those of my employer.

But back to the question, what is a privacy counsel anyway? If I said I was an employment counsel or IP counsel, people would not be confused. I work in privacy. That is what is confusing, because people in the U.S. don't get privacy and I'm a dork.

Working in Silicon Valley does make for a little more acceptance. With the number of global companies here, they all pretty much have people doing what I do. It's kinda cool. There are lots of other privacy counsels.

Okay, Okay - back to the question. It means I make sure that the laws of the nations who have privacy laws are followed. Every other country who has privacy laws at all approach privacy vastly different than does the U.S.  We look at data on a sectoral level - health care, education, financial. There is no national privacy law in the U.S. and no national protections for general data on individuals. The states are a little different. 46 states have data breach laws - and they have many commonalities and some differences. The strongest data protection laws are in California, Texas, and Massachusetts. 

So in the U.S., I make sure we abide by sectoral laws and state laws. Globally, I deal with the laws of the European Union (28 or so different sets of law for the various countries, if you include the EEA 30 or so), APAC, Canada, Mexico, etc. etc. And I love it.

As stated above, I love privacy law. I caution people not to think of it as privacy, because most people tend to have tunnel vision. Think of it as personal data management - and in many cases, the most sensitive data I deal with (and thus, protect) is that of employees.

But like any area of compliance, it is always an uphill battle. Compliance is a cost center not a money maker. Ensuring certain protections are in place can slow down innovation and development. And especially given that most would prefer to build the house, then add the fence for privacy - we (privacy professionals) would prefer you to bring us the blueprints and make sure you are not building on someone else's property and/or get the right permits. Privacy by Design, or Privacy by Default. Build the product right to begin with. Then I am not a roadblock, I am a roadsign. I can point you in the right direction if you come to me early. If you come to me when you are ready to roll it out...well, I have to come up to speed on the product, check the contracts, vet the vendors, and know every data element you collect, how, when, what, where you get it, share it, and store it, how to send it, back it up, and delete it. 

So that is what a privacy counsel does.

It is one of the fastest growing fields in the world.

And when it is me - you get all this personality with the package. fun time, my friends, fun times.

Thursday, January 30, 2014

Practical HIPAA basics for Patients and their Families

My daughter was rushed to the ER one evening and I joined her. She was 18, maybe 19. They took her to do an ultrasound and I started walking with the bed. The employees stopped me and said I could not accompany her, she was an adult. She looked at them and said "I want her with me." And they replied that HIPAA would not permit me to accompany her. I explained that I could take the time to educate them as to why that statement was not true and would be happy to educate their supervisors if they also held the same mistaken beliefs, but given my daughter's emergency - if she was okay with going alone, I would not object at this time. My daughter agreed and off they went. I complained the next day.

I have another daughter who was having x-rays done as an outpatient and was also told I could not accompany her due to HIPAA. She was actually a minor. I was prepared in a non-emergent situation with a minor to object, but this daughter was actually quite happy for me not to accompany her - she was 15. Very independent. 

In one case, my mother was in the hospital following surgery and the nurses were giving her a hard time about her lack of following their instructions....and my mom is a nurse. She wasn't following the instructions, because the nurses were only taking into account the immediate situation and not the full history - which was clearly in the record. I called to inform them. Upon the nurse haughtily telling me she could not speak to me about my mother due to HIPAA, my response was that first, HIPAA would not stop her and second, I am not asking her for information, merely providing information to her. She need only listen - not speak. (Yeah, I can be a bit of a prat, but while firm, I was also very polite in all situations described above). 

I have heard HIPAA used as an excuse for so many things - doctors cannot talk to a family, nurses cannot listen to information from families, companies cannot respond to patients directly, etc. ad nauseum. 

So in this post, let me share a few things about HIPAA with you. (HIPAA is the Health Insurance Portability and Accountability Act of 1996, including all its subsequent amendments under the Affordable Care Act and implementing regulations that were effective in 2013 with the HIPAA Omnibus Rule). HIPAA has never been intended to interfere with medical care and in fact, to share patient information for treatment between health care providers, a patient authorization is not required. 

But to help address the situations above, 1) when a person verbally states that they want someone with them, that is patient authorization. And patient authorization is all that is required in HIPAA in order for a health care provider to share information - it does not need to be in writing, especially when the patient, the person, and the provider are standing there together. So when my daughter said she wanted me with her - that was sufficient. And yes, the hospital privacy officer agreed with me and sent us written apologies stating he would ensure that all staff were appropriate educated on that factor. It did not matter that we were related or that she was an adult and I her mother - what mattered was she gave permission. 

This leads into the situation with my other daughter. As a minor, she is not legally capable of providing legal consent, therefore, the parent was the appropriate person to grant consent. Perhaps at 15, her assent is desired or even required under certain state laws for medical treatment, but if an authorization to share medical information was required in writing, the parent or guardian would have to sign for it to be legal (foregoing any discussion here of emancipation and exceptions). Thus, as her parent, it was my right to give myself access to her information and accompany her to testing. 

Let's take that one step further. Perhaps the medical technician in either situation intended to protect the privacy of other patients. So? HIPAA provides for incidental disclosures, which covers situations in which patients are in close proximity and it is near impossible to maintain strict confidentiality. One should take reasonable precautions, but there is nothing illegal about an emergency room that has curtains instead of walls or stage all patients waiting on surgery in the same waiting area. That's not a valid enough reason to override a scared person's need to have their support person with them.

Last, my mother. Believe it or not, providers can share patient information with people the provider feels/knows is involved in the patient's care and wellbeing. Thus, knowing I was the daughter, the choice could have been made legally to provide me with information about my mother. True, this scenario can get complicated and ugly quickly - how could they verify who I am, or whether my mother and I were close, or any number of other variables. And so, it is logical that an entity would not permit employees to make this decision - but there are other ways to handle it. One could check with the patient, ask the doctor, or have an escalation process to find a potential solution rather than shutting out what may have been the only person in the patient's life (not the case here, but the nurse might not have known that). 

I hope this helps you with some basic misunderstandings about HIPAA. Please do not assume that your providers, health care employees, or even all privacy officers understand this - and by no means do I claim to know everything about HIPAA. Few take the time to fully understand all of HIPAA and sometimes a simple straightforward policy by the entity is much easier to train and enforce than are policies that enable HIPAA to be followed in full. And sometimes state law is more strict (I do not know of any, but they could exist). 

One final point, pl ease note that HIPAA is spelled with two As and NOT two Ps, e.g. HIPPA. If you are a consultant or vendor trying to get my business, you at least need to spell it right.

Wednesday, January 29, 2014

Why are we not Outraged?

Edward Snowden (of the now infamous and controversial U.S. National Security Agency rampant surveillance) has spoken out in his first television interview . He speaks frankly about the threats to his life due to his revelations, but more importantly why he did what he did. A friend of mine posted the link on facebook and I asked this same question there - why are we not more outraged? Why do TV or music celebrities get more comments from both fans and haters than does someone who opened the U.S. pandora's privacy box? It is scandalous!

It is scandalous what the NSA has done. 

It is scandalous that we as a nation do not seem to care. 

In fact, it appears and I allege that the only reason we are starting to hear from our political leaders about fixing the problem is because nations which actually provide privacy rights to their citizens are outraged. They are outraged. We are not.

The White House has spoken now. President Obama finally laid out a plan: consider reforming the PATRIOT Act; improve the public's confidence in governmental oversight; have the Intelligence Community make public information about their surveillance programs - including hiring a privacy officer (more on this later as one has now been appointed); and last, having a high-level group of experts review intelligence and communication technologies. Yours truly was not invited. durn.

What will it take for the people of this nation to actually pay attention to their own privacy and to the entities violating that privacy?? I am honestly perplexed, outraged on your behalf, and frankly, wishing there was a privacy cattle prod that someone with integrity could wield as rampantly as the government wields surveillance. 

Tuesday, January 28, 2014

Global Data Privacy Day and a 21 year old

I would be remiss if I did not post something about today being Global Data Privacy Day - so woot woot - everyone may now celebrate their privacy!!

right.

Perhaps Snowden is celebrating, but the rest of us in the U.S. at least are dealing with data breaches and privacy violations with little to no government intervention and lots of outrage towards the government from large megadata corporations. I try to be positive and not abscribe deflection motivations towards these large technology companies, but it does require some effort. Yet, I remain optimistic that those companies who collect, share, analyze, combine, and use our data in every way imaginable and some ways never imagined by the common person actually are becoming privacy conscious. If not, fake it till you make it.

But more importantly in my own family - today is my youngest child's 21st birthday. WOW. Happy birthday to her and I am sure everyone reading this (anyone reading this) wishes her the best. 

So what does a 21 year old think about privacy? She grew up in the information age, where every thought, emotion, intention, and action is immediately shared, judged, and forgotten. Except nothing on the internet is ever forgotten. (California just passed a law that minors can request their information on social media to be erased. No one really knows what this means yet, but it's a start.).

It has been proposed that millenials, GenY'ers, have no comprehension of privacy and have missed learning basic etiquette of society - there is no period of reflection when something happens - it is immediate reaction, instantly shared, no sense of privacy. I disagree to some extent. I think the new group of young professionals completely understand what being on the job/on call for the job 24/7 due to smartphones means. I think they treasure quality of life more knowing they have to fit in life around work and school. That leaving work at 6 pm does not mean being off work - and they compensate by enjoying life more.

So I asked my newest adult daughter what privacy means to her. Her first response was "What? What about?" - but perhaps I was a bit blunt and unexpected in my question. So I explained more and am anxiously awaiting her answer as I type this. 8 minutes later, I am still waiting. Perhaps it is not only the newest generation who expect immediate gratification...

We are seeing changes every day in privacy - some for the good, some not so much. Young and old, U.S. or not, corporate or individual - we are all impacted and some will care more than others. Some will do more than others. It's a brand new world every time the sun rises. Take the opportunity to make a change in the way you share/use data whether your own or someone else's - take the opportunity to think about what privacy means to you.

Happy Global Data Privacy Day and Happy Birthday, my child.