HIPAA

Note that HIPAA currently does not cover consumer-purchased wearables. If the wearable is purchased and provisioned to the patient by the health-care provider, then the data originating from that wearable is covered under HIPAA. However, in the case where the patient uses his/her own wearable to collect and provide data, that data is not covered. The concept of data aggregation is also important to understand related to IoT privacy. There are data elements that by themselves are not considered PHI (Protected Health Information) under HIPAA. However, when data elements are combined with identifying information, the combined data is then covered. HIPAA Security Rule identifies 18 criteria that define PHI. The FTC Report (Privacy and Security ...

Get Practical Internet of Things Security - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.