
The "consent" agreement is clearly a CYA document:
Discovery takes all reasonable steps to protect personal information and maintain confidentiality. By signing below, I give Discovery Health (Pty) Ltd and my medical scheme, being a medical scheme administered by Discovery Health (Pty) Ltd (“Scheme”), permission to release my Electronic Health Record (EHR) to my healthcare provider. This includes details about chronic condition(s), benefit plan details, certain biographical data and pathology and radiology results. This may include information related to HIV/Aids.So in spite of assurances from the very top that the HealthId iPad app is "secure", the first thing you have to sign is a waiver that says that Discovery isI understand that once Discovery Health (Pty) Ltd and the Scheme have handed my records to the healthcare provider, they have no further control over this information and that they will not be accountable for the safeguarding of this information. I do understand that the healthcare provider has confirmed to Discovery Health (Pty) Ltd that he/she will treat my health records as confidential and in line with the relevant legislation.
I agree that by making this information available, Discovery Health (Pty) Ltd and the Scheme are not responsible for any loss (whether direct or indirect) that may arise from the use of this information.
I agree that I may not hold Discovery Health (Pty) Ltd or the Scheme responsible for any loss that may result from the incorrect use or disclosure of the information by my healthcare provider.

Update: ITWeb has an article that explains how your Vitality info, pathology results and other info will be made available to doctors, hospitals and emergency personnel.
Broomberg says Discovery was concerned with the growing problems of fragmentation between all the role players within the health system.Emergency personnel will scan a QR Code on a car sticker Or other location to access your data. How secure is that going to be? The mind boggles.
“Doctors, hospitals, pathology and radiology are all separate practices, and this results in lack of co-ordination, and limited or no sharing of critical health information that would enable doctors to make more informed decisions or reduce inefficiency in the system,” he explains.
According to IOL, they will pay doctors to use the app.
Once the patient reads the consent waiver and agrees to allow the doctor access to their medical records, they can no longer withhold that information from the doctor. It is an all or nothing deal, though Discovery Health may be developing limiting tools in the future.Doctors use the app at no extra cost to them or their patients. In fact, doctors can earn an additional R15 per consult if they use the app for 50 percent of their Discovery Health consultations daily.
Update: Wednesday 15 Aug: Dr Noach refuses to provide me with the contact details of the KPMG people who did the web site security audit. All I wanted to ask them was why they didn't check for insecure passwords, like "passw0rd".
Discovery has clarified that the "consent" is doctor-specific, not practice specific. That means if a doctor leaves a practice he can take all "his" patients' electronic records with him. I wonder what the other doctors will think of that? Will they know? If the doctor now gets a job at Discovery Life, will they use the information to adjust the policies of those patients?
Some relevant Security Maxims: So We’re In Agreement Maxim: If you’re happy with your security, so are the bad guys.
Thanks for Nothin’ Maxim: A vulnerability assessment that finds no vulnerabilities or only a few is worthless and wrong.
High-Tech Maxim: The amount of careful thinking that has gone into a given security device, system, or program is inversely proportional to the amount of high-technology it uses.
Big Heads Maxim: The farther up the chain of command a (non-security) manager can be found, the more likely he or she thinks that (1) they understand security and (2) security is easy.
Huh Maxim: When a (non-security) senior manager, bureaucrat, or government official talks publicly about security, he or she will usually say something stupid, unrealistic, inaccurate, and/or naïve.
Update: Discovery has lied to the public and bullied the industry, according to this GP.
1 comment:
Hi Donn,I am so pleased that you have raised this issue. I had gone in for an op and the next morning my doctor did his rounds,he was mumbling about something about Discovery,now I was still very much under the weather.He then gave me his Ipad and said I must sign which I did of course not knowing what I was actually signing for,which was wrong in the first place.When I got to work Dicovery had sent me the documents with my signature on that I had signed for. Basically he has now full control over my health records,I agree with you I dont agree with this whole thing where is the just of it all,my doctor was wrong in the first place by asking me to sign for something that I hadn't even had the chance of reading through I am now going to cancel the whole thing of which I have the right, no so? many thanks for putting your thoughts and advise people as to what they would be doing with the health info.
regards
Post a Comment