Skip to main content
In Sickness, Health, and Cyberspace: Protecting the Security of Electronic Private Health Information
Boston college Law Review (2007)
  • Sharona Hoffman
  • Andy Podgurski, Case Western Reserve University

The electronic processing of health information provides considerable benefits to patients and health care providers at the same time that it creates serious risks to the confidentiality, integrity, and availability of the data. The Internet provides a conduit for rapid and uncontrolled dispersion and trafficking of illicitly-obtained private health information, with far-reaching consequences to the unsuspecting victims. In order to address such threats to electronic private health information, the U.S. Department of Health and Human Services enacted the HIPAA Security Rule, which thus far has received little attention in the legal literature. This article presents a critique of the Security Rule from both legal and technical perspectives. We argue that the Rule suffers from several defects relating to its narrow definition of “covered entities,” to the limited scope of information it allows data subjects to obtain about their health information, to the vagueness and incompleteness of the Rule’s standards and implementation specifications, and to the lack of a private cause of action. The article explores the difficult problem of crafting static regulations to adequately address rapidly changing computer and communications technologies and associated security threats to private health information. In addition, it develops detailed recommendations for improving safeguards for electronically processed health records.

  • Privacy,
  • HIPAA Security Rule,
  • Private health information,
  • electronic health records
Publication Date
March, 2007
Citation Information
Sharona Hoffman and Andy Podgurski. "In Sickness, Health, and Cyberspace: Protecting the Security of Electronic Private Health Information" Boston college Law Review Vol. 48 Iss. 2 (2007)
Available at: