PogoWasRight.org

Menu
  • About
  • Privacy
Menu

HIV patients accuse city of violating privacy by giving out personal data without notice

Posted on December 12, 2017June 25, 2025 by Dissent

Some privacy breaches are not data security breaches. And some privacy breaches may not be privacy breaches, although to make that determination, we will need to wade into the exemptions under HIPAA and the privacy policies and consent forms patient sign.

But even if the incident described below turns out not to be a privacy breach, we have a situation where patients were dismayed that sensitive information about them was provided to a third party and they had had no explicit notification of that in advance. Randy Billings reports:

The city of Portland is apologizing to more than 200 patients previously enrolled in its HIV-positive health program for not telling them it planned to share their private health information with University of Southern Maine researchers.

Two patients and two former health care officials say the city violated patient privacy by providing a list of the patients’ names, addresses and phone numbers to USM’s Muskie School of Public Service so it could conduct a survey on the city’s behalf. The survey was to examine the closing of the city’s HIV program at the India Street Public Health Clinic and transferring the grant that funds it to the Portland Community Health Center, and to determine whether there were any gaps in service.

Read more on The Press Herald.

Related posts:

  • California fines hospitals for breaches of medical privacy
  • Critics Worry Government Surveillance of HIV May Hurt More Than It Helps
  • Information Commissioner: Persistent sensitive information breaches failing people living with HIV
  • BULLETIN: HIPAA Privacy and Novel Coronavirus — from HHS OCR
Category: Healthcare

Post navigation

← eBay Privacy Breach Exposes Customer Names on Google (Updated)
Will the Department of State start collecting medical details on visa applicants? →

Search

Contact Me

Email: info[at]pogowasright.org
Security Issue: security[at]pogowasright.org
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]pogowasright.org

Research Report of Note

A report by EPIC.org:

State Attorneys General & Privacy: Enforcement Trends, 2020-2024

Categories

Recent Posts

  • FTC Denies Petition from SpyFone App CEO to Vacate 2021 Order
  • Privacy concerns raised as Grok AI found to be a stalker’s best friend
  • PRIVACY—S.D. Cal.: Employee did not waive privacy right in personal email data on company provided laptop, (Dec 5, 2025)
  • EU justice chief draws red line on privacy reforms
  • Kaiser Permanente to Pay Up to $47.5M in Web Tracker Lawsuit
  • How Palantir shifted course to play key role in ICE deportations
  • U.S. Judge Blocks Trump From Cutting Medicaid Funding For Planned Parenthood In 22 States

RSS Recent Posts at DataBreaches.net

  • Defense Bill Would Require New Cyber Requirements for Some DoD Telecom Contracts
  • Tell the truth, or someone will tell it for you — Trumbull County, Ohio edition (1)
  • US Posts $10 Million Bounty for Iranian Hackers
  • South Korea police raid e-commerce giant Coupang over data leak; govt schedules hearing
  • FinCEN Report: Reported Ransomware Incidents and Payments Reached All-Time High in 2023
©2025 PogoWasRight.org. All rights reserved.