
The period of rampant, unconsented, and unregulated on-line information assortment might lastly be winding down for consumer health data. However the advances in client privateness haven’t but totally reached the thousands and thousands of individuals with well being data associated to their drug use, substance use dysfunction therapy, or restoration.
In July, two key businesses for client well being privateness, the Division of Well being and Human Companies and the Federal Commerce Fee, despatched letters to 130 hospital techniques and telehealth suppliers cautioning towards the usage of on-line trackers that could be impermissibly sharing shoppers’ delicate well being information. Equally, final yr, the businesses labored collectively in releasing a tool to make clear which federal privateness legal guidelines would possibly apply to well being apps and the patron information they accumulate, generate, use, retailer, and share.
In our more and more digital world, it is encouraging to see HHS and the FTC taking a proactive, collaborative strategy to client well being privateness on-line, however there is a gaping gap on the heart of their work: the privateness rights of individuals searching for providers on-line for well being points associated to drug use.
At the moment, the tens of millions of People who use medicine and alcohol nationwide can search assist from hundreds of on-line providers. These apps and web sites supply to assist you set targets for alcohol consumption, monitor your each day drinks, find a supplier to deal with opioid use dysfunction, join you to a counselor who makes a speciality of stimulant use dysfunction, or present the platform on your telehealth visits with a therapy program.
For individuals who can’t entry such helps in particular person, these on-line providers could also be enormously useful. However they could additionally accumulate very delicate information about present and up to date criminalized drug use that can probably result in arrest and prosecution, in addition to household separation, eviction, deportation, discrimination, and denial of well being care providers, insurance coverage, or employment.
Given the potential weaponization of this information and the significance of increasing entry to well being providers for individuals who use medicine, it’s onerous to know why HHS and the FTC should not utilizing a strong instrument at their disposal: the HHS rules at 42 CFR Part 2 (extra generally generally known as Half 2), which give robust privacy protections for individuals with substance use dysfunction (SUD) therapy information. These privateness rules nearly actually apply to information collected by a lot of these web sites, apps, and telehealth platforms providing SUD therapy providers.
However HHS and the FTC stay silent: Neither federal company has issued any steerage, enforcement actions, nor public statements affirming Half 2’s function in defending SUD privateness on-line. The FTC’s current enforcement actions have addressed apps offering reproductive well being and mental health providers, however the fee has not but addressed any of the hundreds of apps offering providers associated to drug use, dependancy, and restoration.
Despite the fact that Half 2 probably applies to information collected on-line by some addiction-related apps and web sites, the dearth of any federal steerage or enforcement leaves corporations’ privateness practices working in a regulatory grey space that finally harms shoppers. For instance, after the FTC and HHS launched steerage in regards to the prohibited use of trackers on HIPAA-covered entities’ web sites, two alcohol restoration apps introduced in March that they used the steerage to find out that that they had impermissibly shared more than 100,000 patients’ private data and well being information with advertisers for years. However the notice to sufferers solely referred to “HIPAA and all different relevant regulation,” with out addressing Half 2 in any respect.
Furthermore, HHS-FTC’s silence on Half 2 is tough to know, contemplating the 2 businesses’ concerted effort elsewhere to deal with a number of federal privateness legal guidelines and rules. For instance, the privateness instrument for well being apps covers a half-dozen legal guidelines and rules, together with the HIPAA Privateness, Safety, and Breach Notification Guidelines, the Data Blocking Laws, and the Federal Meals, Drug, and Beauty Act.
Half 2’s privateness protections matter for individuals with delicate and usually criminalized well being data. Within the wake of the Supreme Court docket’s resolution in Dobbs, privateness for criminalized well being information has attracted extra consideration; for instance, greater than three dozen members of Congress just lately wrote a letter calling on the Biden administration to finish the “warrantless authorities surveillance” permitted by the HIPAA Privateness Rule.
Not like the HIPAA Privateness Rule, Half 2 already prohibits regulation enforcement from accessing or utilizing SUD therapy information with out strict judicial oversight: If regulation enforcement subpoenas an app that falls below the SUD privateness rules, Half 2 prohibits the app from turning over any affected person information except regulation enforcement first obtains a judicial courtroom order discovering that there was no different manner of acquiring the knowledge, the knowledge is required to research an “extraordinarily critical” crime, and the necessity for the disclosure outweighs the potential harm to the affected person, the physician-patient relationship, and the power of the supplier to supply providers to different sufferers, amongst different standards. Maybe greater than some other privateness framework, Half 2 acknowledges that the criminalization of well being data can finally deter individuals from searching for providers and getting therapy, and so its protections go additional than HIPAA to safeguard individuals towards warrantless authorities surveillance.
Plain and easy: The privateness protections below Half 2 are integral to the well-being of individuals who use medicine, and it’s previous time for the HHS-FTC collaboration to deal with their on-line privateness rights.
For one straightforward first step, HHS and the FTC ought to add Half 2 to the listing of “related” federal privateness legal guidelines and rules within the FTC’s cell well being instrument. On the Authorized Motion Heart, the place I work, we created this quick and easy “mHealth SUD Privacy tool” to assist fill the hole and clarify how Half 2 might apply to cell well being apps providing SUD therapy providers.
Secondly, HHS and the FTC ought to appropriate the document and guarantee that future motion on client well being privateness incorporates the vital privateness protections in Half 2. They will begin by taking a look at all the methods that people’ privateness rights are ignored, misunderstood, or violated within the SUD mHealth ecosystem. For instance, our report in collaboration with the Opioid Coverage Institute, “Web sites for Opioid Dependancy Therapy and Restoration Companies: Knowledge Sharing and Privateness Dangers,” particulars troubling privateness practices on a dozen standard therapy and restoration websites over a 16-month interval. As soon as the problems are recognized, they need to work collectively to ensure their regulatory actions are addressing Half 2 all through the web ecosystem of therapy and restoration help.
As we proceed to lose increasingly more individuals annually to deadly overdose, it’s crystal clear that we must be doing all we are able to to broaden entry to care and promote therapy over punishment. On-line providers supply to assist bridge that hole, however people mustn’t must pay with their privateness with a view to entry providers. For his or her half, the following coordinated motion by HHS and the FTC should embrace and uplift the privateness rights of individuals who use medicine and folks with substance use dysfunction therapy information. Lives rely on it.
Jacqueline Seitz is a lawyer and deputy director of well being privateness at Authorized Motion Heart, the place she advocates for the rights of people that use medicine and folks dwelling with HIV.