HIPAA and web development

FlipperBizkut

[H]ard|Gawd
Joined
Sep 25, 2002
Messages
1,268
Does anyone know the specifics of when HIPAA compliance is required when developing a medical website? I have been asked to build a site for a small clinic, and they are contemplating having it to where users can fill out the "new patient" paperwork online, and also having the patients have access to test results online and the such.

The last thing I want to do is get sued, so I was wondering if anyone knew any HIPAA specifics, or any place that I could go to find out.
 
Patients own their records. It's their information, and HIPAA is geared more towards people accessing information of other people.

All you have to do is ensure information security. In other words, the patient and only the patient can access their information.
 
So long as the patients (or legal guardians with power of attorney) are the only ones who can access their records, that should satisfy compliance.

If i were you, I'd make sure to get a VERY thorough security review of the website before I'd even think of launching it.
 
Yeah, to be honest, it scares the daylights out of me. One little mistake, and I'm being sued for everything I own. How do you go about getting a security review of the site? Are there companies out there that do that for a fee?

The clinic also mentioned just having their patients be able to submit the new patient paperwork or schedule appointments and not have any medical records or test results available. I don't think that I would have too much to worry about with that would I?

One last thing. Verisign wants in the neighborhood of $1k for a SSL cert. My webhosting company will sell me one for $30. What's the difference besides paying for the name?

Thanks for the replies!
 
Patient information should never be anywhere near the outside world. Ever.
 
Patient information should never be anywhere near the outside world. Ever.

It's moving that way though. A hospital I used to work with had a massive electronic system for everything. Doctors walked into the hospital and wireless networks synced up their PDAs with updated patient lists, test results, etc.

They next phase they were working on doing was to allow patients to log in from home and view their entire medical record including test results.

It was really impressive what they were doing and I don't see anything wrong with being able to check out my record online. I would definitely want to know that such a system was as locked down as possible though.
 
Your website should also keep an audit of who has accessed what information. HIPAA is big on keeping data safe, controlling who can access the data and controlling who has accessed the data. There are PLENTY of companies out there who offer products even targeted at this market. The penalties for HIPAA violations are large and your legal liability here will be also. Personally, I'd advocate you to pass on this and let the pros handle it. Getting opinions from people on this site is NOT sufficient to either inform you or cover your yourself in terms of legal liability. Picture yourself in court trying to explain how you posted a question on some site called Hardocp and got your HIPAA information there.

I wouldn't suggest you take this assignment unless you hire a HIPAA consultant, chat with a lawyer and have the business insurance to cover yourself in case you get sued. Don't be a headline.

"Yeah, to be honest, it scares the daylights out of me. One little mistake, and I'm being sued for everything I own. How do you go about getting a security review of the site? Are there companies out there that do that for a fee?"

You're probably not incorporated and are the lowest cost option for your customer. I'm sure there are customers who do that for a fee. This is all part of the cost of the corporate offerings for this. You might be best off researching what is out there and pushing your client that way. I know its probably a sweet project, but unless you're looking to create a product out of this you might want to pass.
 
The penalties for HIPAA violations are large and your legal liability here will be also. Personally, I'd advocate you to pass on this and let the pros handle it. Getting opinions from people on this site is NOT sufficient to either inform you or cover your yourself in terms of legal liability.
I agree with that. While the intent of HIPAA may be to keep data safe and have an audit log, just doing that will not ensure compliance. I would stay `far' away from anything that can make you be held liable.
 
Hey, thanks for all the replies. I believe that I will tell them that if they want an informational site that I would be glad to build it for them. Anything else, and I will just have to pass on the deal.

I am not incorporated, and I really don't feel like losing my house because of a website. Thanks for the reality check.
 
You could probably talk to an attorney about coming up with some sort of waiver that basically states that you are not liable for so-and-so acts and events that you and the clinic could sign. If it's a legally binding document, you may be able to get rid of that nasty liability unless there are some bizarre exceptions.
 
Back
Top