OCR reminder: HIPAA rules apply to online tracking technologies

HIPAA-regulated entities are not permitted to use online tracking technologies in a manner that would result in impermissible disclosures of protected health information to tracking technology vendors or any other violation of the HIPAA rules, the Department of Health and Human Services鈥 Office for Civil Rights reminded covered entities and business associates in a yesterday.
鈥淧roviders, health plans, and HIPAA-regulated entities, including technology platforms, must follow the law,鈥 OCR Director Melanie Fontes Rainer. 鈥淭his means considering the risks to patients鈥 health information when using tracking technologies. Our Bulletin answers questions for those using tracking technologies, importantly how to protect the privacy and security of the health information they hold.鈥