lingo.lol is one of the many independent Mastodon servers you can use to participate in the fediverse.
A place for linguists, philologists, and other lovers of languages.

Server stats:

61
active users

#ghostery

0 posts0 participants0 posts today

We don't track you. Don't care where you come from or where you go (or if you would have been married a long time ago).

You don't need blockers on our website. Always good to have them enabled but you should always see a "0" on any extensions like #Ghostery.

This is how the web should be. It was how it was. You see that "0" on #mastodon too which is why it's the best social media.

Roastinghouse.co.uk

In case someone uses the Ghostery brower.

Sunsetting the Ghostery Private Browser
Key Points:

Ghostery Private Browser (formerly Dawn) will be discontinued.
Use Firefox + Ghostery Tracker & Ad Blocker on Android and Desktop.
Use Safari + Ghostery Tracker & Ad Blocker on iOS and iPadOS.
This change lets us focus on advancing anti-tracking and ad-blocking technologies.

ghostery.com/blog/ghostery-pri

GhosterySunsetting the Ghostery Private BrowserFollow our recommendations in the blog to continue enjoying the benefits of Ghostery.

The just-released #Firefox 120 for #Android opens up to add-ons. There are already 50 of them available and the number should grow quickly as more add-ons get verified.
I've installed #Ghostery to get rid of cookie pop-ups. What a relief.
If you are not using Firefox on Android, I highly recommend giving it a try. It's been my daily driver for years and it's gotten really good and no other relevant mobile #browser has such a wide variety of add-ons available AFAIK.

TITLE: When Your HIPAA BAA Subcontractor Most Likely Means Well

Therapists are going to have to make an effort to educate our own BAA subcontractors about privacy.

Amongst therapists, privacy has always been paramount.

On the Internet, tracking has gone through several understandings. First, early webmasters were excited to get free website use statistics from Google Analytics. Then followed several years of tactics to effectively market ads following client computers around the Internet. Now, there is an awareness of that data as valuable in-and-of-itself.

Recently there is a new awareness that data other than name, SSI, address, & diagnosis CAN be considered PHI (Protected Health Information) when it is specific enough to ID the patient. Also when a data aggregator (tracking the same client across the Net) can obtain & combine data from multiple websites to build a composite file on the client. Browser cookies, pixels, beacons, mobile application identifiers, Adobe Flash technology, and IP address geolocation data can all be used -- in conjunction with websites visited -- to figure out specific individuals. ( See "Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates" from HHS at hhs.gov/hipaa/for-professional )

Also growing is an awareness that this data can be used for something other than just targeted advertising -- like in the recent Washington Post story in which the Planned Parenthood website was inadvertently sending data to Facebook and others -- which in theory could be used by hostile state governments to prosecute women for their medical choices. (See "You scheduled an abortion. Planned Parenthood’s website could tell Facebook." wapo.st/3Nyf6sr ) (Brick & mortar stores can also contribute. See "What Walmart’s tech investments mean for workers and shoppers" wapo.st/3J86PeE )

Therapists are going to have to make an effort to educate our own BAA subcontractors about privacy -- especially in cases where its not clear if HIPAA laws are being broken. Especially in cases where the subcontractors -- coming from the Internet world -- might not know better.

There are the more egregious cases (like BetterHelp sharing clear PHI data) -- situations in which therapists should walk or run away from the company. (See "FTC fines BetterHelp $7.8M, alleges it shared consumers' health info with advertisers" modernhealthcare.com/digital-h )

Then there are less clear cases where we need to change the mindset of our BAA subcontractors if possible.

Many of them may not understand the evolving definition of PHI. Their marketing/webdev teams may not talk with legal. They may just put together a required data consent policy with everything in it including the kitchen sink whether or not they actually collect it to "cover themselves". This needs tuning for their HIPAA clients. They may communicate with sites for legit use known to track (like fonts.google.com which provides fonts and is used by about every webmaster on earth).

If you want to see some of the URLs that your BAA subcontractors communicate with, You can double-check them by installing Ghostery and Privacy Badger in the Firefox browser (and maybe others) and checking which connections they warn you about or block when you go to those sites. This won't tell you WHAT data is communicated, only that SOME data is communicated (and if these services think they are a security risk). Knowing what data is actually sent would require someone with expertise in a packet sniffing software such as Wire Shark.

-- Michael

--
Michael Reeder, LCPC
michael(at)hygeiacounseling.com

#psychology #counseling #socialwork #psychotherapy
@psychotherapist @psychology @socialpsych @socialwork #HIPAA #BAA #hack #datasecurity #legal #psychiatry @psychiatry #webdev #cookies #dataprivacy #security #beacons #Ghostery #PrivacyBadger #privacy #medical

HHS.gov · Use of Online Tracking Technologies by HIPAA Covered Entities and Business AssociatesThe Office for Civil Rights at the U.S. Department of Health and Human Services is issuing this Bulletin to highlight the obligations of Health Insurance Portab