PogoWasRight.org

Menu
  • About
  • Privacy
Menu

HIV patients accuse city of violating privacy by giving out personal data without notice

Posted on December 12, 2017 by pogowasright.org

Some privacy breaches are not data security breaches. And some privacy breaches may not be privacy breaches, although to make that determination, we will need to wade into the exemptions under HIPAA and the privacy policies and consent forms patient sign.

But even if the incident described below turns out not to be a privacy breach, we have a situation where patients were dismayed that sensitive information about them was provided to a third party and they had had no explicit notification of that in advance. Randy Billings reports:

The city of Portland is apologizing to more than 200 patients previously enrolled in its HIV-positive health program for not telling them it planned to share their private health information with University of Southern Maine researchers.

Two patients and two former health care officials say the city violated patient privacy by providing a list of the patients’ names, addresses and phone numbers to USM’s Muskie School of Public Service so it could conduct a survey on the city’s behalf. The survey was to examine the closing of the city’s HIV program at the India Street Public Health Clinic and transferring the grant that funds it to the Portland Community Health Center, and to determine whether there were any gaps in service.

Read more on The Press Herald.

Category: Healthcare

Post navigation

← eBay Privacy Breach Exposes Customer Names on Google (Updated)
Will the Department of State start collecting medical details on visa applicants? →

Now more than ever

Search

Contact Me

Email: [email protected]

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • Vermont signs Kids Code into law, faces legal challenges
  • Data Categories and Surveillance Pricing: Ferguson’s Nuanced Approach to Privacy Innovation
  • Anne Wojcicki Wins Bidding for 23andMe
  • Would you — or wouldn’t you?
  • New York passes a bill to prevent AI-fueled disasters
  • Synthetic Data and the Illusion of Privacy: Legal Risks of Using De-Identified AI Training Sets
  • States sue to block the sale of genetic data collected by DNA testing company 23andMe

RSS Recent Posts on DataBreaches.net

  • Credit Control Corporation data allegedly from 9.1 million consumers listed for sale on forum
  • Copilot AI Bug Could Leak Sensitive Data via Email Prompts
  • FTC Provides Guidance on Updated Safeguards Rule
  • Sentara Health terminates remote employees after realizing they couldn’t be sure who was doing the work.
  • Hackers Break Into Car Sharing App, 8.4 Million Users Affected
©2025 PogoWasRight.org. All rights reserved.