cross-posted from: https://links.hackliberty.org/post/1028406

The state of medical privacy has become quite appalling lately. I started using a young doctor in a new office and they are gung ho on modern tech. That’s fine to some extent but they want to send me invoices and all correspondence via e-mail. No PGP of course. I did an MX lookup on their vanity email address & it resolves to an MS Outlook server.

I asked them for my test results. They offered to email them.

My response: I do not want sensitive medical info coming by e-mail via Microsoft’s servers. I did not give you a copy of my email address for that reason. It needs to be snail-mailed to me.

Perhaps of greater concern is that the receptionist acted like I am making a unusual request, and that they do not mail things. Apparently I am the only patient who has a problem with sensitive medical info going to Microsoft. So the receptionist is investigating whether she can get approval to mail me my results by post.

I wonder if someone in that clinic will have to run out and buy stamps because I have a problem with Microsoft.

  • @Rustle
    link
    410 months ago

    I work in healthcare. If you think that is appalling, you should see the other things people don’t care about.

    But I do agree a lot of people don’t recognize the security vulnerabilities I go on.

    Do what you Gotta do to keep your information private

    • @[email protected]OP
      link
      fedilink
      -1
      edit-2
      10 months ago

      Do what you Gotta do to keep your information private

      Indeed but to be clear, there are two motivations for my insistance that the doc buy a stamp and use the post:

      1. keeping my data out of MS hands to mitigate them exploiting me directly, by e.g. selling the medical data to insurance companies.

      2. Forcing the doc’s office to go through some burden and expense for poorly choosing their email service provider (a controversial one).