

CVS, Rite Aid, Walgreens hand out medical records to cops without warrants
source link: https://arstechnica.com/science/2023/12/cvs-rite-aid-walgreens-hand-out-medical-records-to-cops-without-warrants/
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

prescription for privacy —
CVS, Rite Aid, Walgreens hand out medical records to cops without warrants
Lawmakers want HHS to revise health privacy law to require warrants.
Beth Mole - 12/12/2023, 8:31 PM

All of the big pharmacy chains in the US hand over sensitive medical records to law enforcement without a warrant—and some will do so without even running the requests by a legal professional, according to a congressional investigation.
The revelation raises grave medical privacy concerns, particularly in a post-Dobbs era in which many states are working to criminalize reproductive health care. Even if people in states with restrictive laws cross state lines for care, pharmacists in massive chains, such as CVS, can access records across borders.
Lawmakers noted the pharmacies' policies for releasing medical records in a letter dated Tuesday to the Department of Health and Human Services (HHS) Secretary Xavier Becerra. The letter—signed by Sen. Ron Wyden (D-Ore.), Rep. Pramila Jayapal (D-Wash.), and Rep. Sara Jacobs (D-Calif.)—said their investigation pulled information from briefings with eight big prescription drug suppliers.
They include the seven largest pharmacy chains in the country: CVS Health, Walgreens Boots Alliance, Cigna, Optum Rx, Walmart Stores, Inc., The Kroger Company, and Rite Aid Corporation. The lawmakers also spoke with Amazon Pharmacy.
All eight of the pharmacies said they do not require law enforcement to have a warrant prior to sharing private and sensitive medical records, which can include the prescription drugs a person used or uses and their medical conditions. Instead, all the pharmacies hand over such information with nothing more than a subpoena, which can be issued by government agencies and does not require review or approval by a judge.
Three pharmacies—CVS Health, The Kroger Company, and Rite Aid Corporation—told lawmakers they didn't even require their pharmacy staff to consult legal professionals before responding to law enforcement requests at pharmacy counters. According to the lawmakers, CVS, Kroger, and Rite Aid said that "their pharmacy staff face extreme pressure to immediately respond to law enforcement demands and, as such, the companies instruct their staff to process those requests in store."
AdvertisementThe rest of the pharmacies—Amazon, Cigna, Optum Rx, Walmart, and Walgreens Boots Alliance—at least require that law enforcement requests be reviewed by legal professionals before pharmacists respond. But, only Amazon said it had a policy of notifying customers of law enforcement demands for pharmacy records unless there were legal prohibitions to doing so, such as a gag order.
HIPAA and transparency
The lawmakers note that the pharmacies aren't violating regulations under the Health Insurance Portability and Accountability Act (HIPAA). The pharmacies pointed to language in HIPAA regulations that allow health care providers, including pharmacists, to provide medical records if required by law, with subpoenas being a sufficient legal process for such a request. However, the lawmakers note that the HHS has discretion in determining the legal standard here—that is, it has the power to strengthen the regulation to require a warrant, which the lawmakers say it should do.
"We urge HHS to consider further strengthening its HIPAA regulations to more closely align them with Americans’ reasonable expectations of privacy and Constitutional principles," the three lawmakers wrote.
They also pushed for pharmacies to do better, encouraging them to follow the lead of tech companies. "Pharmacies can and should insist on a warrant, and invite law enforcement agencies that insist on demanding patient medical records with solely a subpoena to go to court to enforce that demand. The requirement for a warrant is exactly the approach taken by tech companies to protect customer privacy." The trio noted that Google, Microsoft, and Yahoo have since 2010 required law enforcement to have a warrant to obtain customers' emails.
Also noting tech companies' lead, the lawmakers encouraged pharmacies to publish annual transparency reports. In the course of the investigation, only CVS Health said it planned to do so.
"Americans deserve to have their private medical information protected at the pharmacy counter and a full picture of pharmacies’ privacy practices, so they can make informed choices about where to get their prescriptions filled," the lawmakers wrote.
For now, HIPAA regulations grant patients the right to know who is accessing their health records. But, to do so, patients have to specifically request that information—and almost no one does that. "Last year, CVS Health, the largest pharmacy in the nation by total prescription revenue, only received a single-digit number of such consumer requests," the lawmakers noted.
"The average American is likely unaware that this is even a problem," the lawmakers said.
</div
Recommend
-
9
Victory at the High Court against the government’s use of 'general warrants’ In a major victory for the rule of law, the UK High Court has ruled that the security and intelligence services can no longer rely on ‘gen...
-
6
Comment: The state of Apple TV and end of HomePod warrants a Home strategy roundtableApple’s Friday night move to suddenly pull the plug on HomePod after three y...
-
7
The situation involving the Thodex exchange in Turkey grows more worrisome over time. Even though the company claims everything is fine, Turkish police have arrested several dozen individuals. This is not good news for the affected users, as...
-
8
October 7, 2021
-
8
TechJPMorgan sues Tesla for $162 million in warrants dispute around Elon Musk take-private tweetsPublished Mon, Nov 15 20218:54 PM ESTUpdated Mon, N...
-
6
Get WIRED for just $29.99 $10. Subscribe Now...
-
10
Home ...
-
9
TechRite Aid to be barred from using facial recognition under proposed FTC settlemen...
-
15
Rite Aid used facial recognition on shoppers, fueling harassment, FTC saysA landmark settlement over the pharmacy chain’s use of the surveillance technology could raise further doubts about facia...
-
7
At a GlanceThe US Federal Trade Commission (FTC) on Tuesday said Rite Aid misused an artificial intelligence facial recognition system that mistakenly tagged customers -- often African Americans, Latinos, and women -- as s...
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK