首页> 外文期刊>Health policy and technology. >The implications of the California Consumer Privacy Act (CCPA) on healthcare organizations: Lessons learned from early compliance experiences
【24h】

The implications of the California Consumer Privacy Act (CCPA) on healthcare organizations: Lessons learned from early compliance experiences

机译:《加州消费者隐私法案》(CCPA) 对医疗机构的影响:从早期合规经验中吸取的经验教训

获取原文
获取原文并翻译 | 示例
           

摘要

Objective: In 2018, California legislators passed the California Consumer Privacy Act (CCPA), a digital privacy regulation conferring consumers more control over their online personal information. CCPA is a significant regulation overseeing technology companies' data collection and usage practices in the United States. This article analyzes CCPA and its implications on healthcare organizations. We elaborate on the compliance challenges that have emerged due to the interplay of the CCPA with the Health Insurance Portability and Accountability Act (HIPAA) from legal and technical/operational perspectives. Methods: Qualitative methods comprising semi-structured expert interviews, qualitative data coding, and analysis were used to explore the perceptions of the practitioners on various dimensions of the policy and to obtain in-sights from the field. Results: Our findings indicated that California's healthcare organizations faced several legal and technological challenges in complying with CCPA. A lack of regulatory clarity and a low likelihood of enforcement emerged as two major themes of legal concern. Poor data discovery and inventory processes, lack of sophisticated digital infrastructure, the interaction between technology and privacy professionals, and the high cost of compliance emerged as significant technological hurdles to CCPA compliance. Conclusions: Despite considerable ambiguity around the scope and jurisdiction of CCPA in the healthcare sector, healthcare organizations may be subject to CCPA, primarily when they collect personally identifiable informa-tion that is not protected health information. Such organizations may need to comply with both regulations. Furthermore, it is in their best interest to develop compliance plans proactively rather than being caught in the quandary of last-minute implementation or expensive litigation.
机译:目标:2018 年,加州立法者通过了《加州消费者隐私法案》(CCPA),这是一项数字隐私法规,赋予消费者对其在线个人信息的更多控制权。CCPA 是一项重要的法规,负责监督美国科技公司的数据收集和使用实践。本文分析了 CCPA 及其对医疗机构的影响。我们从法律和技术/运营角度详细阐述了由于 CCPA 与《健康保险流通与责任法案》(HIPAA) 的相互作用而出现的合规挑战。方法:采用定性方法,包括半结构化专家访谈、定性数据编码和分析,探索从业人员对政策各个方面的看法,并从实地获得实地见解。结果:我们的研究结果表明,加州的医疗机构在遵守 CCPA 方面面临多项法律和技术挑战。监管不明确和执法可能性低成为法律关注的两大主题。糟糕的数据发现和库存流程、缺乏复杂的数字基础设施、技术和隐私专业人员之间的互动以及高昂的合规成本成为 CCPA 合规的重大技术障碍。结论:尽管 CCPA 在医疗保健领域的范围和管辖权存在相当大的模糊性,但医疗保健组织可能受到 CCPA 的约束,主要是当他们收集不受保护的健康信息的个人身份信息时。这些组织可能需要遵守这两项规定。此外,主动制定合规计划符合他们的最佳利益,而不是陷入最后一刻实施或昂贵诉讼的困境。

著录项

相似文献

  • 外文文献
  • 中文文献
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号