Re: Employment form
Karen-
Well- we're going to have to simply disagree on this one.
Yes- HIPAA does extend to vendors in as much as how they handle, and disemenate "patient" personal and health information. What she is gathering is no where near "patient" information and at this point has nothing to do what so ever with any prison "patient".
I still maintain that HIPAA pertains to "patient" personal and health related information. It does not reach as far as a pre-employment process.
As to the list of other resources that you gave- I looked each one up. Not one regulates or stipulates "encryption" of gathered personal information over the internet. They speak to the regulation of purchacing and sale of personal info (like mailing lists) or in the case of the Wireless 411 Privacy Act where it prohibits cell phone companies from giving out or publishing your cell phone number with out consent first. Or in the case of the Online Privacy Protection Act in California. This simply states that a website must post its privacy policy on its website.
One day I hope that there is a standard for data gathering and transfer.
For now it is left up to self policing and companies often put inplace policies and procedures to help limit their liability in the event sensitive info is intercepted or stolen. These companies often require encryption and proof of secure storage and often lists of personal who have access to such info. But that is on the company side and not by law as yet.
Bottom line of which we both agree on- gathering personal information via a form should be done in a secure manner to protect it from being intercepted or stolen.
Andy
Karen-
Well- we're going to have to simply disagree on this one.
Yes- HIPAA does extend to vendors in as much as how they handle, and disemenate "patient" personal and health information. What she is gathering is no where near "patient" information and at this point has nothing to do what so ever with any prison "patient".
I still maintain that HIPAA pertains to "patient" personal and health related information. It does not reach as far as a pre-employment process.
As to the list of other resources that you gave- I looked each one up. Not one regulates or stipulates "encryption" of gathered personal information over the internet. They speak to the regulation of purchacing and sale of personal info (like mailing lists) or in the case of the Wireless 411 Privacy Act where it prohibits cell phone companies from giving out or publishing your cell phone number with out consent first. Or in the case of the Online Privacy Protection Act in California. This simply states that a website must post its privacy policy on its website.
One day I hope that there is a standard for data gathering and transfer.
For now it is left up to self policing and companies often put inplace policies and procedures to help limit their liability in the event sensitive info is intercepted or stolen. These companies often require encryption and proof of secure storage and often lists of personal who have access to such info. But that is on the company side and not by law as yet.
Bottom line of which we both agree on- gathering personal information via a form should be done in a secure manner to protect it from being intercepted or stolen.
Andy
Comment