Epic uses cookies to improve your experience on our website.
By continuing to access Epic.com, you will receive all cookies from the Epic website.
You may adjust your browser settings if you do not wish to receive cookies.
Read our privacy policy here.

HHS Comments on Patient Privacy

A 2016 report from the U.S. Department of Health and Human Services describes the benefits of new technology patients use to engage with their care and the challenges with protecting patient privacy.

We appreciate HHS' willingness to listen to industry and health system voices working to balance access to data with consumer protections, as we all share the same goal of improving healthcare.

Examining Oversight of the Privacy & Security of Health Data Collected by Entities Not Regulated by HIPAA

U.S. Department of Health and Human Services, June 17, 2016

  • Organizations that are not regulated by HIPAA, the FTC, or state law may collect, share, or use health information about individuals that may put such data at risk...
  • Health information collected in more places without consistent security standards may pose a cybersecurity threat.
  • [I]ndividuals may inadvertently consent to unanticipated types of information sharing and use by [non-covered entities] collecting their health information
Read the full report
Read Epic's open letter: Epic Supports Patients' Access to Their Data, Proposes ONC Rule Solutions to Protect Privacy

Highlights from the Past