HACKER Q&A
📣 anm89

Dr sending marketing emails after multple unsubscribes HIPAA Violation?


A doctor's office has been sending me marketing emails for years after multiple unsubscribes. Just based on the nature of their office specialty and based off of the content of this email it would be very easy to infer pieces of my past medical history that I would not want public. I'm assuming google now understands this part of my medical history based on their parsing of these messages.

I'm also just annoyed at the concept of having to unsubscribe over and over again.

My question is: could anything here be construed as a HIPAA violation?


  👤 jklein11 Accepted Answer ✓
Big disclaimer IANAL but I do work in Health IT.

If this really has you irked and you want to do something about it you can file a formal complaint.[1] I would have to think that a call from the OCR would get a practice thinking more about their patients’ privacy and that must be a good thing.

I think it is unlikely that they are breaking any laws. The practice likely posted their Notice of Privacy Policy, and you may have even signed something. Once you allowed them to share your health data, your right to revoke that consent is largely dependent on if the data is considered sensitive (ie substance abuse and mental health data) and your state and local laws.

It is shocking to me how far removed people are from the ownership of their health data. I’m really passionate about changing that. If anyone is interested in working on this problem feel free to reach out.

1. https://www.hhs.gov/hipaa/for-individuals/guidance-materials...


👤 taf2
HIPAA aside if you have unsubscribed and you continue to receive email... you might be able to go after for violators can spam act... check it out here https://www.ftc.gov/tips-advice/business-center/guidance/can...