HIPAA Madness and Covid - True Story -
Genuine Realist - 12-09-2020
My younger daughter lives on her own in a one bedroom studio on El Camino, limited to disability housing. I'm very,very proud of her for this accomplishment. She no more likes living at home than any other thirty-something. The complex is managed and staffed by a charitable organization, that sees to the administration. In better times, there is a fair amount of community activity, but of course all that ceased for the time being in March.
The complex consists of two buildings, four stories each, about six apartments per floor - maybe 48 in all.
About a week ago, Anne reported that someone in the complex had tested positive for covid. But she didn't know who, or where, or when. She learned of this from her ILS (Independent Living Services) worker, almost as an aside. It was not clear whether this was fact or rumor, or when the positive test had occurred - if it had occurred at all. (
Also, social interaction among the residents is all but nonexistent in the absence of planned activities. They all live like monks in individual cells.)There was nothing to act on, so her mother and had her isolate to the extent practical, e.g, taking leave from work, doing her grocery shopping for her, etc. That did put a modest risk on me, but there was no concrete reason to go the extra mile. Anne remained asymptomatic.
Last night, at a parent's meeting, we learn that the positive test was not rumor, but quite real, and that the individual did live in my daughter's building. This was enough to press the administrators for more information.
A couple of hours ago, I receive an email to the effect that TWO residents tested positive at the end of November, and have been living in quarantine since then. It would be nice to know who they are, as we could assess whether there was any incidental contact. Even though that is extremely improbable, it would have been valuable. However, no one said anything. The good news is the asymptomatic condition. Since ten days - at least - have gone by, and Anne spending even 10 seconds in the company of any other resident almost never happens, we are very much on the safe side and are not contemplating doing anything more.
However, I would have liked to have received this information in a more timely fashion. And I would definitely have liked to know who the positives are. She would have had to be extremely unlucky to have had even a few seconds' contact, but it would have been useful to evaluate even that chance.
The excuse given for the failure to communicate is HIPPA regulations. This seems absolute madness to me with respect to covid. I have indicated that Anne will sign a release relative to HIPPA privilege, and that other residents might wish to do the same. It's to everyone's benefit.
RE: HIPAA Madness and Covid - True Story -
akiddoc - 12-10-2020
The housing management is mistaken. Public health emergencies allow the release of privileged information to protect the public.
RE: HIPAA Madness and Covid - True Story -
BostonCard - 12-10-2020
Also, it is not clear based on the description, whether the charitable organization's administration would be considered a covered entity under HIPAA. Now, to be fair, HIPAA is often shorthand for "we want to respect people's medical privacy" which is normally a good thing. But as akiddoc has mentioned, it may not be appropriate in a public health emergency. The better part of valor would be, as you note, to get the patients' consent to disclose the info, and then do so.
BC
RE: HIPAA Madness and Covid - True Story -
oldalum - 12-10-2020
HIPAA has to be one of the most commonly misunderstood laws, if not the most.
RE: HIPAA Madness and Covid - True Story -
Farm93 - 12-10-2020
(12-10-2020, 04:48 PM)oldalum Wrote: HIPAA has to be one of the most commonly misunderstood laws, if not the most.
But most USA organizations understand avoiding lawsuits is sound business practice.
Unless something specifically requires them to disclose private information it is generally best to not disclose that information. Then trust the individual or the government will provide contact tracing information, as needed.
There are a number of reasons why the USA is #1 in COVID cases and deaths, privacy rights and concerns are definitely in the mix.
For example, has everyone consented to the CA Notify app yet?
RE: HIPAA Madness and Covid - True Story -
BostonCard - 12-10-2020
(12-10-2020, 06:11 PM)Farm93 Wrote: For example, has everyone consented to the CA Notify app yet?
Yes, I was pleasantly surprised that it actually asked, instead of making me go find it.
BC
lex24 -
lex24 - 12-10-2020
(12-10-2020, 06:11 PM)Farm93 Wrote: (12-10-2020, 04:48 PM)oldalum Wrote: HIPAA has to be one of the most commonly misunderstood laws, if not the most.
But most USA organizations understand avoiding lawsuits is sound business practice.
Unless something specifically requires them to disclose private information it is generally best to not disclose that information. Then trust the individual or the government will provide contact tracing information, as needed.
There are a number of reasons why the USA is #1 in COVID cases and deaths, privacy rights and concerns are definitely in the mix.
For example, has everyone consented to the CA Notify app yet?
I’m thinking about it. But I’m going to admit I’m concerned. Not that the government will use the information. But that Internet companies will. It’s all about data collection for them. That’s where the trillions of dollars are. So I’m probably an idiot on this – which I firmly admit. And in the end I suspect I’ll get it. But I’m not gonna lie, I have some concerns. Privacy, to the extent it exists is important to me. Having said that I guarantee you that if I get Covid I will engage in contact tracing and I would have no difficulty with them using my name. My problem is having a telephone that constantly monitors where I am. And companies out there that are willing to tap into that. Not to mention hackers.
So please tell me where I’m wrong on this. I mean that. I am not particularly tech savvy. Actually that’s an understatement.
RE: lex24 -
Farm93 - 12-10-2020
(12-10-2020, 07:32 PM)lex24 Wrote: (12-10-2020, 06:11 PM)Farm93 Wrote: (12-10-2020, 04:48 PM)oldalum Wrote: HIPAA has to be one of the most commonly misunderstood laws, if not the most.
But most USA organizations understand avoiding lawsuits is sound business practice.
Unless something specifically requires them to disclose private information it is generally best to not disclose that information. Then trust the individual or the government will provide contact tracing information, as needed.
There are a number of reasons why the USA is #1 in COVID cases and deaths, privacy rights and concerns are definitely in the mix.
For example, has everyone consented to the CA Notify app yet?
I’m thinking about it. But I’m going to admit I’m concerned. Not that the government will use the information. But that Internet companies will. It’s all about data collection for them. That’s where the trillions of dollars are. So I’m probably an idiot on this – which I firmly admit. And in the end I suspect I’ll get it. But I’m not gonna lie, I have some concerns. Privacy, to the extent it exists is important to me. Having said that I guarantee you that if I get Covid I will engage in contact tracing and I would have no difficulty with them using my name. My problem is having a telephone that constantly monitors where I am. And companies out there that are willing to tap into that. Not to mention hackers.
So please tell me where I’m wrong on this. I mean that. I am not particularly tech savvy. Actually that’s an understatement.
GR - Those concerns are legit enough. The app claims it is all bluetooth based, but not hard to imagine a world where someone, some company, some government gets the information and uses it for something.
However many aps actually track your physical location and info from your phone, so other apps would be better sources of info.
For example, I have a Wal-Mart app that allows me to "Check-In" for my curbside pickups that tracks my progress and projects my arrival time. That's great, today my purchases were literally in the parking lot waiting for me as I arrived. However, it also means Wal-Mart and others have a good chunk of information on my driving habits, purchases, vehicle type, etc.
I also have a few gaming apps on my phone that I often used in airports pre-COVID, and they push commercials all the time. My oldest child is applying to colleges, so I have a good bit of college browsing history on my phone. Sure enough, most of my game ads in the last 20 days have been for the University of Arizona. It really is a good ad, likely does wonders if I was a teenager thinking of going to UofA.
So, apps can reveal a lot about users. However, in this case if everyone was on CA Notify (I realize that won't happen) then you wouldn't have this worry about care facility disclosure of COVID interactions. CA Notify...would notify you.
So there is a touch of irony about you wanting information from others about COVID, but not willing to provide information about yourself for potential future COVID issues.
I am sure you see that too, right?
RE: HIPAA Madness and Covid - True Story -
magnus - 12-10-2020
lex24,
While I use plenty of tech, I'm not super knowledgeable about all the privacy things. For this app, I figure the benefits outweigh any negatives. I probably use enough apps (for sure I play some location based games and have my location tracker turned on so there's plenty of data that Google is is getting) that I'm already exposed, anyway.
lex24 -
lex24 - 12-10-2020
(12-10-2020, 07:48 PM)Farm93 Wrote: (12-10-2020, 07:32 PM)lex24 Wrote: (12-10-2020, 06:11 PM)Farm93 Wrote: (12-10-2020, 04:48 PM)oldalum Wrote: HIPAA has to be one of the most commonly misunderstood laws, if not the most.
But most USA organizations understand avoiding lawsuits is sound business practice.
Unless something specifically requires them to disclose private information it is generally best to not disclose that information. Then trust the individual or the government will provide contact tracing information, as needed.
There are a number of reasons why the USA is #1 in COVID cases and deaths, privacy rights and concerns are definitely in the mix.
For example, has everyone consented to the CA Notify app yet?
I’m thinking about it. But I’m going to admit I’m concerned. Not that the government will use the information. But that Internet companies will. It’s all about data collection for them. That’s where the trillions of dollars are. So I’m probably an idiot on this – which I firmly admit. And in the end I suspect I’ll get it. But I’m not gonna lie, I have some concerns. Privacy, to the extent it exists is important to me. Having said that I guarantee you that if I get Covid I will engage in contact tracing and I would have no difficulty with them using my name. My problem is having a telephone that constantly monitors where I am. And companies out there that are willing to tap into that. Not to mention hackers.
So please tell me where I’m wrong on this. I mean that. I am not particularly tech savvy. Actually that’s an understatement.
GR - Those concerns are legit enough. The app claims it is all bluetooth based, but not hard to imagine a world where someone, some company, some government gets the information and uses it for something.
However many aps actually track your physical location and info from your phone, so other apps would be better sources of info.
For example, I have a Wal-Mart app that allows me to "Check-In" for my curbside pickups that tracks my progress and projects my arrival time. That's great, today my purchases were literally in the parking lot waiting for me as I arrived. However, it also means Wal-Mart and others have a good chunk of information on my driving habits, purchases, vehicle type, etc.
I also have a few gaming apps on my phone that I often used in airports pre-COVID, and they push commercials all the time. My oldest child is applying to colleges, so I have a good bit of college browsing history on my phone. Sure enough, most of my game ads in the last 20 days have been for the University of Arizona. It really is a good ad, likely does wonders if I was a teenager thinking of going to UofA.
So, apps can reveal a lot about users. However, in this case if everyone was on CA Notify (I realize that won't happen) then you wouldn't have this worry about care facility disclosure of COVID interactions. CA Notify...would notify you.
So there is a touch of irony about you wanting information from others about COVID, but not willing to provide information about yourself for potential future COVID issues.
I am sure you see that too, right?
Not quite sure what you mean. If I get Covid, I’ll provide info. No question. My concern on the App is the use of info from it.
RE: lex24 -
magnus - 12-11-2020
(12-10-2020, 11:06 PM)lex24 Wrote: (12-10-2020, 07:48 PM)Farm93 Wrote: GR - Those concerns are legit enough. So there is a touch of irony about you wanting information from others about COVID, but not willing to provide information about yourself for potential future COVID issues.
I am sure you see that too, right?
Not quite sure what you mean. If I get Covid, I’ll provide info. No question. My concern on the App is the use of info from it.
Likely a case of mistaken identity, lex24.
RE: HIPAA Madness and Covid - True Story -
M T - 12-11-2020
I am someone who is tech-savvy and concerned about how much data is gathered about me that I don't think others should collect (and sell!). In March, before I saw the details of the Apple/Google system, I heard of the concept of a phone keeping track of who was in its vicinity, so one could do contact-tracing. I worked through how one could do something with the app that maintains privacy but does the association of a infected person with you.
As it turned out, my design was pretty similar to the Apple-Google methodology. That similarity isn't surprising as it is fairly obvious how one would approach this to maintain privacy. Actually, compared to mine, the Apple-Google design was better in one important way.
I'm sure others have shown their own explanations of how it works, but you can see the basic concept of the method in question 4 of the
Apple-Google FAQ about their Exposure-Notification system. If you want more technical information, more can be found at
this page. In particular, what I consider the interesting information can be found in the
Bluetooth Specification for the system.
Note that you can use this system to alert you to an exposure but then decline to share the fact that you get COVID.
===========
The "rolling proximity indicator" (RPI, the temporary id for your device) is a 128-bit number. It is broadcast by your device about 4 times a second. It is changed every 10-20 minutes (actual interval is random). Also broadcast in the same message4 is Associated Encrypted Metadata AEM, which encodes the version of the algorithm used and the transmit strength. Each is the result of encrypting a time-based string via the 128-bit pseudorandom number (temporary exposure key, TEK) generated daily.
Your device remembers your 14 TEK's for the last 14 days. It also keeps track of all the RPIs (with their associated, AEM) and measured signal strength and time of detection, for the last 14 days.
If you get COVID, you can choose to reveal your 14 TEKs. This can be done in a way that can be authenticated by your health department. (I'm not sure how that authentication is done. If some bad guy wanted to upload a million such keys, maybe it could be done. But the likelihood that a million or even a trillion such false keys would match even one real key is vanishingly small.)
These revealed 14 TEKs are now called Diagnosis Keys. They would be supplied to the app of anyone in the public health area (for instance, California). If you were in multiple areas during that 14 days, they would need to be distributed there too.
Every user's app will download all Diagnosis Keys they haven't yet processed. From those keys, your app will generate all the RPIs that would have been broadcast using each key and see if there are any matches. If there are matches, your app will decode the associated encrypted metadata received with the RPI and compare the transmit strength with the received strength of the signal. It will also see how many times it saw that signal. The app will then apply an algorithm to determine whether your are a close contact or not. If so, you will be notified that you may have been exposed. In theory, it could tell you the 10-minute windows when you had the contact, but I believe that is not done.
=======
Privacy risks that I have thought of:
1. If you are ever close enough to someone, you could record his RPI. It wouldn't be hard to detect a particular person's RPI at some point. If they ever broadcast their TEK for that day, then you know that person probably has COVID and chose to release his TEKs.
2. If you monitored a location, you could record the RPIs at the location. If you identified a person's RPI from that day, and he later revealed his TEKs, you could prove that person was in the location at the time you recorded it.
3. If you wanted to disrupt a target(s), you could intentionally "expose" him/them with a device that was close enough to him for long enough. Subsequently you could associate that device with someone who tested positive. That would cause a notification to the target(s) that he/they was/were exposed. This could be used to attempt to identify people in a group meeting. (Suppose you sent an FBI agent into a KKK meeting where everyone was masked. The agent's TEK for that day was released, causing the people in that meeting to get a notification all about the same time that they had been exposed. You can't prove they were in the meeting from that, but see (4).)
3a. This anonymity of the exposure notification is both a strength and a weakness. It protects the privacy of the person reporting COVID, but it simultaneously hides the identity of a person who intentionally causes a notification to a person with the intent to cause problems for that person.
4. If phones were seized and the authorities were able to get to the TEKs of the devices, they would then be able to show they were together at some period in time. If (2) were also done, they may be able to prove that they were at the location. (For instance, a phone accessible to authorities was in a bank vault when a bunch of bank robbers broke into it.) (Knowing Apple, I bet the TEKs are in an encrypted storage that requires your phone to be on & unlocked to be accessible. I'd expect that of Google too.)
5. You could use an app or device that records the RPIs, but also the location and time. If you get access to the Diagnosis Keys, you could identify just when & where you were exposed, making it likely that you could identify the individual. For instance, a business might put a device near an entrance (with video recording) that records the RPI. If it can get the Diagnosis Keys, it then could find if any of those that entered their property submitted a Diagnosis Key within 14 days. Whether you can get those Diagnosis Keys outside the app, I'm not sure, but I'd expect so.
If either (1) or (2) concerns you, you should not reveal your TEKs. For most of us, I doubt they are of concern.
If you're concerned about (3) or (4), you probably do not want to enable this app.
RE: HIPAA Madness and Covid - True Story -
Genuine Realist - 12-11-2020
(12-10-2020, 04:48 PM)oldalum Wrote: HIPAA has to be one of the most commonly misunderstood laws, if not the most.
I'm too old and lazy to research HIPPA, but my instincts were that the failure to disclose on HIPPA grounds is wildly overstated. The excess of caution is typical of the way in which the modern privilege works out in practice.
Legislatures have responded to too many social developments in the last few decades by either (a) criminalizing them, (b) privileging them, or © both. Very few of these statutes are simple - usually they have exceptions, and exceptions to the exceptions, and so on. The drafters, more often than not legislative staff, move on, the statutes or regs are too complex to test in litigation, and the practical result is that everyone lives in a miasma of uncertainty.
The staff members at my daughter's residence aren't dumb. But their training is in caring for and treating disabled adults. They're not employed to parse legal privileges. The simplest response is always to refuse to disclose anything. You never get into trouble that way, and you save legal fees. That with covid this does not lead to a good social result is literally not their problem.
In a different line, with vaccine distribution, I suggested birthday lottery on a KISS basis. Zip codes and employment categories are doubtless more directly equitable - but what you gain in equity, you lose - and more - in administrative complexity, particularly the necessity to react to potential fraud.
There's a lot to be said for KISS. If you ever discuss building codes with home builders, they'll complain about how arbitrary they are. You have to use so many 2x4's in they typical bubble frame, with so many nails of such a weight, etc. It all could easily be different. But the practical result is that a building inspector can come onto the site, know what he (sic) is looking for, and do the inspection easily and inefficiently.
Simplicity would be useful even with privileges as sensitive as HIPPA.
lex24 -
lex24 - 12-11-2020
(12-11-2020, 03:24 AM)M T Wrote: I am someone who is tech-savvy and concerned about how much data is gathered about me that I don't think others should collect (and sell!). In March, before I saw the details of the Apple/Google system, I heard of the concept of a phone keeping track of who was in its vicinity, so one could do contact-tracing. I worked through how one could do something with the app that maintains privacy but does the association of a infected person with you.
As it turned out, my design was pretty similar to the Apple-Google methodology. That similarity isn't surprising as it is fairly obvious how one would approach this to maintain privacy. Actually, compared to mine, the Apple-Google design was better in one important way.
I'm sure others have shown their own explanations of how it works, but you can see the basic concept of the method in question 4 of the Apple-Google FAQ about their Exposure-Notification system. If you want more technical information, more can be found at this page. In particular, what I consider the interesting information can be found in the Bluetooth Specification for the system.
Note that you can use this system to alert you to an exposure but then decline to share the fact that you get COVID.
===========
The "rolling proximity indicator" (RPI, the temporary id for your device) is a 128-bit number. It is broadcast by your device about 4 times a second. It is changed every 10-20 minutes (actual interval is random). Also broadcast in the same message4 is Associated Encrypted Metadata AEM, which encodes the version of the algorithm used and the transmit strength. Each is the result of encrypting a time-based string via the 128-bit pseudorandom number (temporary exposure key, TEK) generated daily.
Your device remembers your 14 TEK's for the last 14 days. It also keeps track of all the RPIs (with their associated, AEM) and measured signal strength and time of detection, for the last 14 days.
If you get COVID, you can choose to reveal your 14 TEKs. This can be done in a way that can be authenticated by your health department. (I'm not sure how that authentication is done. If some bad guy wanted to upload a million such keys, maybe it could be done. But the likelihood that a million or even a trillion such false keys would match even one real key is vanishingly small.)
These revealed 14 TEKs are now called Diagnosis Keys. They would be supplied to the app of anyone in the public health area (for instance, California). If you were in multiple areas during that 14 days, they would need to be distributed there too.
Every user's app will download all Diagnosis Keys they haven't yet processed. From those keys, your app will generate all the RPIs that would have been broadcast using each key and see if there are any matches. If there are matches, your app will decode the associated encrypted metadata received with the RPI and compare the transmit strength with the received strength of the signal. It will also see how many times it saw that signal. The app will then apply an algorithm to determine whether your are a close contact or not. If so, you will be notified that you may have been exposed. In theory, it could tell you the 10-minute windows when you had the contact, but I believe that is not done.
=======
Privacy risks that I have thought of:
1. If you are ever close enough to someone, you could record his RPI. It wouldn't be hard to detect a particular person's RPI at some point. If they ever broadcast their TEK for that day, then you know that person probably has COVID and chose to release his TEKs.
2. If you monitored a location, you could record the RPIs at the location. If you identified a person's RPI from that day, and he later revealed his TEKs, you could prove that person was in the location at the time you recorded it.
3. If you wanted to disrupt a target(s), you could intentionally "expose" him/them with a device that was close enough to him for long enough. Subsequently you could associate that device with someone who tested positive. That would cause a notification to the target(s) that he/they was/were exposed. This could be used to attempt to identify people in a group meeting. (Suppose you sent an FBI agent into a KKK meeting where everyone was masked. The agent's TEK for that day was released, causing the people in that meeting to get a notification all about the same time that they had been exposed. You can't prove they were in the meeting from that, but see (4).)
3a. This anonymity of the exposure notification is both a strength and a weakness. It protects the privacy of the person reporting COVID, but it simultaneously hides the identity of a person who intentionally causes a notification to a person with the intent to cause problems for that person.
4. If phones were seized and the authorities were able to get to the TEKs of the devices, they would then be able to show they were together at some period in time. If (2) were also done, they may be able to prove that they were at the location. (For instance, a phone accessible to authorities was in a bank vault when a bunch of bank robbers broke into it.) (Knowing Apple, I bet the TEKs are in an encrypted storage that requires your phone to be on & unlocked to be accessible. I'd expect that of Google too.)
5. You could use an app or device that records the RPIs, but also the location and time. If you get access to the Diagnosis Keys, you could identify just when & where you were exposed, making it likely that you could identify the individual. For instance, a business might put a device near an entrance (with video recording) that records the RPI. If it can get the Diagnosis Keys, it then could find if any of those that entered their property submitted a Diagnosis Key within 14 days. Whether you can get those Diagnosis Keys outside the app, I'm not sure, but I'd expect so.
If either (1) or (2) concerns you, you should not reveal your TEKs. For most of us, I doubt they are of concern.
If you're concerned about (3) or (4), you probably do not want to enable this app.
My problem is that I don’t trust either Google or Apple.
RE: HIPAA Madness and Covid - True Story -
oldalum - 12-11-2020
I share your sentiments GR (with the whole field of wills and estates law as a prime example of unnecessary complexity), but I'm sure you know that a primary cause of legal complexity is that one of the main functions of lawyers is to generate work for other lawyers, and vice versa.
When I was about to take the MPRE (multiple choice legal ethics exam required to join the bar), I was told I should just apply the following test to each question: choose the answer that produces the most income for the legal profession as a whole. Turns out it worked every time it was possible to apply it, and it applied to nearly every question on the 50-question test (for the 1 or 2 remaining questions it did not produce any answer so I was on my own). I concluded from this experience that to be an ethical lawyer, all one had to do was generate the most income possible for the legal profession. (fortunately for the public, I never did practice law)
RE: HIPAA Madness and Covid - True Story -
Genuine Realist - 12-11-2020
(12-11-2020, 11:47 AM)oldalum Wrote: I share your sentiments GR (with the whole field of wills and estates law as a prime example of unnecessary complexity), but I'm sure you know that a primary cause of legal complexity is that one of the main functions of lawyers is to generate work for other lawyers, and vice versa.
When I was about to take the MPRE (multiple choice legal ethics exam required to join the bar), I was told I should just apply the following test to each question: choose the answer that produces the most income for the legal profession as a whole. Turns out it worked every time it was possible to apply it, and it applied to nearly every question on the 50-question test (for the 1 or 2 remaining questions it did not produce any answer so I was on my own). I concluded from this experience that to be an ethical lawyer, all one had to do was generate the most income possible for the legal profession. (fortunately for the public, I never did practice law)
Oh, no question. I don't like most other lawyers, and prosecuted a few of them. The profession has become a catch-all for liberal arts majors with nothing better to do. Many of them graduate from law school with some vague notion that all arguments are colorable, none as a practical matter is conclusive, and that's the state of reality.
In 2009, there was a once-in-a-generation chance for real financial reform, which Obama completely f---ked up. My own thought was simple. Rather than let investment banks do business as corporations (which was never done before 1984), require they adopt the form of limited partnership, with all members of the firm above a certain managerial level (the exact level would have to be determined by regulation) required to participate as general partners. In other words, you use GIGO type analysis of financial risk, which was the type of deluded analysis that got us into the 2008 mess, at your own risk - your own money is on the table. Simple, elegant, relatively foolproof - it was the form of organization that they all had before 1984, so hardly all that radical.
Chance of enactment? Zero. Instead, Barack Obama, aka Pretty Boy, stalled for two years, squandered the mandate, and gave us another 1,000 page legal briar patch in the form of Dodd-Frank [ironically named after two of the principal architects of the disaster]. Typical.
RE: HIPAA Madness and Covid - True Story -
oregontim - 12-12-2020
(12-09-2020, 02:40 PM)Genuine Realist Wrote: My younger daughter lives on her own in a one bedroom studio on El Camino, limited to disability housing. I'm very,very proud of her for this accomplishment. She no more likes living at home than any other thirty-something. The complex is managed and staffed by a charitable organization, that sees to the administration. In better times, there is a fair amount of community activity, but of course all that ceased for the time being in March. The complex consists of two buildings, four stories each, about six apartments per floor - maybe 48 in all.
About a week ago, Anne reported that someone in the complex had tested positive for covid. But she didn't know who, or where, or when. She learned of this from her ILS (Independent Living Services) worker, almost as an aside. It was not clear whether this was fact or rumor, or when the positive test had occurred - if it had occurred at all. (Also, social interaction among the residents is all but nonexistent in the absence of planned activities. They all live like monks in individual cells.)There was nothing to act on, so her mother and had her isolate to the extent practical, e.g, taking leave from work, doing her grocery shopping for her, etc. That did put a modest risk on me, but there was no concrete reason to go the extra mile. Anne remained asymptomatic.
Last night, at a parent's meeting, we learn that the positive test was not rumor, but quite real, and that the individual did live in my daughter's building. This was enough to press the administrators for more information.
A couple of hours ago, I receive an email to the effect that TWO residents tested positive at the end of November, and have been living in quarantine since then. It would be nice to know who they are, as we could assess whether there was any incidental contact. Even though that is extremely improbable, it would have been valuable. However, no one said anything. The good news is the asymptomatic condition. Since ten days - at least - have gone by, and Anne spending even 10 seconds in the company of any other resident almost never happens, we are very much on the safe side and are not contemplating doing anything more.
However, I would have liked to have received this information in a more timely fashion. And I would definitely have liked to know who the positives are. She would have had to be extremely unlucky to have had even a few seconds' contact, but it would have been useful to evaluate even that chance.
The excuse given for the failure to communicate is HIPPA regulations. This seems absolute madness to me with respect to covid. I have indicated that Anne will sign a release relative to HIPPA privilege, and that other residents might wish to do the same. It's to everyone's benefit.
Sorry to read this. I share your frustration.
RE: HIPAA Madness and Covid - True Story -
Mick - 12-13-2020
(12-11-2020, 11:47 AM)oldalum Wrote: I share your sentiments GR (with the whole field of wills and estates law as a prime example of unnecessary complexity), but I'm sure you know that a primary cause of legal complexity is that one of the main functions of lawyers is to generate work for other lawyers, and vice versa.
When I was about to take the MPRE (multiple choice legal ethics exam required to join the bar), I was told I should just apply the following test to each question: choose the answer that produces the most income for the legal profession as a whole. Turns out it worked every time it was possible to apply it, and it applied to nearly every question on the 50-question test (for the 1 or 2 remaining questions it did not produce any answer so I was on my own). I concluded from this experience that to be an ethical lawyer, all one had to do was generate the most income possible for the legal profession. (fortunately for the public, I never did practice law)
I know the test. I had a conversation with a lawyer who said something similar; in order to pass the test, just come up with the most inefficient means to handle a legal issue, which amounts to generating more fees, so basically the same thing.
I'm waiting for someone to do a Ted talk on how and why the legal profession is set up mainly to wring revenue from clients.
When my wife got cancer, I left a full-time position with a law firm to help care for her (it took four years, but she fully recovered. Now, during COVID, she's on Round Two. Different kind of cancer, but treatable and beatable). At the time, I needed the flexibility, so I started working as a legal procurement consultant to clients. What became immediately apparent was that inhouse legal counsel were terrific lawyers, who typically came from traditional law firms, and they were operationally, uh...challenged, and tended to consider fees of secondary performance to result and relationship. And, while I had been through several thousand new engagement processes by that time, most inhouse counsel had only been through a few.
Which leads us to the three most interesting developments in the legal profession since 2009:
1.
The Rise of ALSPs (Alternative Legal Service Providers). Alternatives to costly traditional law firms have been around forever, but as barriers to entry start to fall, some of the ALSPs are really accelerating. What's happening in the legal profession now happened in the accounting profession (albeit slightly differently) in the 1970s and 1980s. 42 of the top 50 accounting firms in 1972 were gone by 1988, including half of the Big Eight. Those firms became hyper-efficient and hyper-client focused. As the Big Four take on more and more legal services, they're edging out traditional law firms. The next two decades are going to be
very interesting for traditional law firms. Because of COVID-19, tradlaw firms are seeking to eliminate as many costs as possible to maintain profits, since demand is slightly down.
2.
The Rise of Procurement/Purchasing. The first RFP I received in 2009 from one of the largest technology companies in the world didn't originate with the general counsel, or the head of legal ops. It came from an individual with the title "Commodities Manager" (no kidding). At the same time, the head of our corporate practice told me that a large publicly traded client approached him for a discount. Our CorpHead floated a 5% discount. The client said 50% was the minimum acceptable discount. Why? Because when the financial world started melting down, the CFO, CEO and COO became inordinately concerned about costs -- everywhere. Legal was a rich target, and it will be richer still in the next two decades. My prediction is that we are not too far from reverse auctions for discrete legal services becoming the norm.
3.
Focus on Legal Operations. Most legal departments are run by lawyers rather than professional managers. But since 2009, there has been a laser focus on generating efficiency within the department, so they have been ramping up their game. End result for traditional law firms is that inefficiencies are being beaten back. A side result is that companies with large legal departments (10+) are placing a closer focus on their management skills.