• ShortFuse@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    edit-2
    4 months ago

    HIPAA doesn’t even require encryption. It’s considered “addressable”. They just require access be “closed”. You can be HIPAA compliant with just Windows login, event viewer, and notepad.

    (Also HIPAA applies to healthcare providers. Adobe doesn’t need to follow HIPAA data protection, though they probably do because it’s so lax, just because you uploaded a PDF of a medical bill to their cloud.)

    • Katana314@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      4 months ago

      HIPAA applies to whichever entity consciously chooses to move/store data.

      Generally, after a patient downloads a healthcare-related item, they are that entity - and as the patient, they have full control/decisions about where it goes, so they can’t violate their own HIPAA agreement even if they print it and scatter it to the wind.

      BUT, if your operating system “decides” to upload that document without the user’s involvement, then Microsoft is that entity - and having not received conscious permission from the patient, would be in violation. It’s an entirely different circumstance if the user is always going through clear prompts, but their more recent OneDrive Backup goal has been extremely forceful and easy to accidentally turn on - even to the point of being hard to disable. As you said, encryption has nothing to do with it.