Attorney Insights on Elite Data Protection | Flourish Re-Release with Helen Oscislawski

This Week Health
This Week HealthMay 15, 2026

Why It Matters

As data flows accelerate, misaligned regulations and misunderstood privacy practices threaten patient trust and expose health systems to legal and reputational risk, making proactive governance essential.

Key Takeaways

  • Instant data liquidity clashes with need for robust privacy safeguards.
  • Outdated laws, like 1972 SUD privacy act, lag modern interoperability.
  • Information‑blocking rule flips HIPAA, forcing mandatory data sharing.
  • Misunderstanding de‑identification leads to legal exposure for providers.
  • Consumer health apps sit outside HIPAA, raising new privacy risks.

Summary

The episode revisits the core tension in today’s healthcare transformation—trust. Host Sarah Richardson interviews nationally‑recognized attorney Helen Oshilovski to unpack the "privacy paradox": clinicians and innovators demand instant, frictionless data exchange while patients and regulators insist on iron‑clad safeguards.

Oshilovski highlights three systemic gaps. First, legacy statutes such as the 1972 Substance Use Disorder privacy law have not kept pace with interoperable workflows, prompting calls for privacy‑by‑design and updated legal frameworks. Second, the 2020 information‑blocking rule overturns decades of HIPAA thinking, mandating data sharing unless a specific legal exemption applies, which has spurred confusion and litigation. Third, many organizations misinterpret de‑identification, assuming removal of names equals anonymity, exposing them to compliance risk.

A vivid illustration comes from Oshilovski’s personal experience as a legal proxy for her hospitalized mother, where internal processes failed to honor valid proxy documentation, forcing escalation to legal counsel. She also warns that most consumer health apps—wellness trackers, fertility tools, genetic kits—operate outside HIPAA’s jurisdiction, leaving data subject to varied state privacy laws and commercial exploitation unless users scrutinize terms of service. The pending Cassidy bill aims to extend HIPAA‑level protections to these apps.

The conversation underscores that leaders must embed privacy into technology architecture, refine governance, and stay alert to emerging legislation. CIOs and CISOs should treat data sharing as a trust engine, not a compliance afterthought, and rigorously vet third‑party applications to protect patient rights and avoid costly breaches.

Original Description

Healthcare privacy laws just got flipped on their head, and most leaders don't realize it. Privacy Law Attorney Helen Oscislawski, Founder and Managing Partner at Attorneys at Oscislawski, reveals how information blocking rules fundamentally changed the game. But here's the twist: this shift is creating massive unintentional risks. Helen shares why even she had to escalate to legal when trying to access her own mother's medical records as a proxy, exposing the gap between policy and practice. From consumer apps that aren't actually HIPAA-compliant to de-identification mistakes that could trigger lawsuits, this conversation uncovers the privacy paradox every healthcare leader needs to understand right now.
Key Points:
01:26 The Privacy Paradox in Healthcare
06:34 Challenges in Data Governance
12:03 Consumer Apps and Data Privacy
19:07 AI in Healthcare: Risks and Opportunities
Donate: Alex’s Lemonade Stand: Foundation for Childhood Cancer - https://www.alexslemonade.org/mypage/3173454

Comments

Want to join the conversation?

Loading comments...