{"id":668728,"date":"2026-05-27T20:28:19","date_gmt":"2026-05-27T20:28:19","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/668728\/"},"modified":"2026-05-27T20:28:19","modified_gmt":"2026-05-27T20:28:19","slug":"the-form-asked-to-share-my-health-data-then-it-wouldnt-let-me-say-no","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/668728\/","title":{"rendered":"The form asked to share my health data. Then it wouldn\u2019t let me say no."},"content":{"rendered":"<p>By <a href=\"&quot;https:\/\/calmatters.org\/author\/alex-rosenblat\/&quot;\" title=\"&quot;Posts\" by=\"\" alex=\"\" rosenblat=\"\" class=\"&quot;author\" url=\"\" fn=\"\" rel=\"&quot;author&quot;\">Alex Rosenblat<\/a>, CalMatters<\/p>\n<p>\t\t\t\t<img decoding=\"async\" width=\"&quot;1200&quot;\" height=\"&quot;800&quot;\" src=\"&quot;https:\/\/i0.wp.com\/calmatters.org\/wp-content\/uploads\/2026\/05\/052226-OPT-OUT-MAZES-GH-CM.jpg?fit=1200%2C800&amp;ssl=1&quot;\" class=\"&quot;attachment-post-thumbnail\" size-post-thumbnail=\"\" wp-post-image=\"\" alt=\"&quot;Illustration\" of=\"\" alice=\"\" from=\"\" in=\"\" wonderland=\"\" dressed=\"\" a=\"\" patient=\"\" gown=\"\" falling=\"\" down=\"\" rabbit=\"\" hole=\"\" surrounded=\"\" by=\"\" buttons=\"\" that=\"\" say=\"\" accept=\"\" and=\"\" privacy=\"\" policies=\"\" decoding=\"&quot;async&quot;\" loading=\"&quot;lazy&quot;\"  https:=\"\" \/><br \/>\n\t\t\t\tIllustration by Gabriel Hongsdusit, CalMatters<\/p>\n<p>This story was originally published by <a href=\"&quot;https:\/\/calmatters.org\/&quot;\">CalMatters<\/a>. <a href=\"&quot;https:\/\/calmatters.org\/subscribe-to-calmatters\/&quot;\">Sign up<\/a> for their newsletters.<\/p>\n<p>When Paula Stannard, one of the federal government\u2019s top healthcare privacy officials, visited her eye doctor this year, she was asked to sign a form, acknowledging she\u2019d received a privacy notice about how the office would use her health data.\u00a0<\/p>\n<p>\u201cHad I received the notice of privacy practices? No,\u201d she told an audience at one of the nation\u2019s <a href=\"&quot;https:\/\/app.himssconference.com\/event\/himss-2026\/planning\/UGxhbm5pbmdfNDM2NDE5Nw==&quot;\">largest health industry conferences<\/a> in March.<\/p>\n<p>\u201cI did not want to tell them who I was and why they should not be doing that,\u201d said Stannard, who is director of the Office for Civil Rights at the U.S. Department of Health and Human Services. \u201cBut I did write a note that says, \u2018I have not received this. I am not acknowledging receipt.\u2019&#8221;\u00a0<\/p>\n<p>Had a similar experience? Tell us<\/p>\n<p>This story was originally published on The Markup, now a part of CalMatters.\u00a0<\/p>\n<p>If you\u2019ve gone to an appointment in California and have struggled with opting out of sharing your data, or if you\u2019re a doctor or patient in California who has had challenges with AI transcription, we\u2019d love to hear from you.<\/p>\n<p>Email Alex Rosenblat, our Director of Sociotechnical Research, at <a href=\"&quot;mailto:arosenblat@themarkup.org&quot;\">arosenblat@themarkup.org<\/a>.<\/p>\n<p>If you\u2019re worried about being tracked or discovered, you can send messages and files securely by using the Signal app (download it <a href=\"&quot;https:\/\/signal.org\/&quot;\">here<\/a>). Reach Alex on Signal: 530-364-1838<\/p>\n<p>Stannard\u2019s story is all too common.<\/p>\n<p>Over the last year, I\u2019ve interviewed more than 20 patients, healthcare providers, experts and advocates about the privacy forms they must sign to get care at their providers\u2019 offices.<\/p>\n<p>Time and again I was told the same thing: Across the country, from large hospital systems to small, private clinics, patients are being asked to sign waivers blindly without knowing exactly what they\u2019re signing.<\/p>\n<p>When patients ask to see more, staff usually don\u2019t have an easy way to show them. When patients do get the forms, it tells them all the ways their medical data will be shared and reused, and some of the ways patients can refuse. But electronic systems make it impossible to opt out on the spot, requiring follow up emails.<\/p>\n<p>Records sharing between unaffiliated providers through these networks can benefit patients by making their scattered records more visible to the provider who is treating them.\u00a0<\/p>\n<p>But it can also harm patients.<\/p>\n<p>Patients seeking an abortion may not want records to travel with them from a state where that treatment is <a href=\"&quot;https:\/\/pmc.ncbi.nlm.nih.gov\/articles\/PMC9748529\/pdf\/ocac194.pdf&quot;\">legal to one where it is criminalized<\/a>.<\/p>\n<p>In other cases, companies, such as GuardDog, have admitted to accessing patient records \u201c<a href=\"&quot;https:\/\/www.hipaajournal.com\/epic-sues-health-information-exchange-network-improper-record-access\/&quot;\">under the guise of treatment<\/a>\u201d and funneling them to personal injury law firms.<\/p>\n<p>Researchers have also found <a href=\"&quot;https:\/\/jamanetwork.com\/journals\/jamanetworkopen\/fullarticle\/2791007&quot;\">healthcare workers snooping<\/a> through electronic health records. Other dangers include <a href=\"&quot;https:\/\/pmc.ncbi.nlm.nih.gov\/articles\/PMC6439649\/&quot;\">data breaches<\/a> and serious potential for misuse, such as domestic abusers stalking their partners though the <a href=\"&quot;https:\/\/pmc.ncbi.nlm.nih.gov\/articles\/PMC8882201\/&quot;\">pediatric records of their children<\/a>.<\/p>\n<p>There\u2019s not much patients can do to limit the risks of their data being available across networks, except by aggressively pursuing opt-outs when providers offer them. Turns out, that can be pretty hard to do.\u00a0<\/p>\n<p>Gale Oleson is a retired dermatologist in Missouri who recalled visiting the emergency room after a hand injury.<\/p>\n<p>\u201cThey hand me the signature pad,\u201d he said. \u201cThey said, you have to sign this so we can do the procedure. And I said, well, I don&#8217;t know what the heck I&#8217;m signing. Is it like you get my house today? You know, you could be taking my car, you know, signing over my life insurance. And they just laugh, you know?<\/p>\n<p>\u201c&#8230; In those situations, I&#8217;ve had them either turn the screen to me or I request that they print out a copy for me to review and they&#8217;ve always done it, but it&#8217;s always a \u2018I forgot how a printer works\u2019 kind of thing.\u201d<\/p>\n<p>Experts have a name for this practice: \u201c<a href=\"&quot;https:\/\/themarkup.org\/2021\/06\/03\/dark-patterns-that-mislead-consumers-are-all-over-the-internet&quot;\">Dark patterns<\/a>,\u201d which are manipulative design choices that steer people into doing things or making decisions they otherwise would not make. It\u2019s easier to check the box to say that you\u2019ve received the privacy notice, even if you haven\u2019t. It\u2019s easier to sign the digital signature box, even if you can\u2019t see what you\u2019re signing.<\/p>\n<p>The alternative \u2014 saying you didn\u2019t get the privacy notice, or asking repeatedly to see what you\u2019re signing \u2014\u00a0sounds like a simple request, but can be scary for patients. Many of the patients I\u2019ve interviewed, including a lawyer who works as a privacy advocate, told me they\u2019re afraid that speaking up or pushing back against terms they don\u2019t agree to will make health providers categorize them as inconvenient patients and make it harder to get the care they need.<\/p>\n<p>As a privacy researcher, I\u2019ve experienced this hesitation myself. Last year, I wrote about the epic lengths I went through to get a copy of the consent forms I signed when my toddler needed surgery. When my child was strapped to a movable bed, the surgeon standing there at the ready, I was asked to verify my signature on a consent form. When I asked if I could have a copy of it, a nurse said she wasn\u2019t allowed to give it to me \u2014 and sent me to a ghost office at another hospital to search for it. In the moment, I let it go, so I wouldn\u2019t hold up the surgery. Later, after asking multiple people for help, I was <a href=\"&quot;https:\/\/themarkup.org\/hello-world\/2025\/07\/19\/patient-data-use&quot;\">finally able to get a copy<\/a>.\u00a0<\/p>\n<p>To experience more of what patients have to deal with and test whether they\u2019re able to successfully get the information they need, say no, or opt-out of having their data shared, I checked out over a dozen health care systems myself by registering and going to appointments in Iowa, New Jersey, New York, Ohio, Oregon, South Carolina and Virginia.<\/p>\n<p>One telehealth appointment with a provider showed me how easily dark patterns force patients to share their data with big healthcare networks, even when the privacy form they\u2019re signing explicitly says they can opt-out.\u00a0<\/p>\n<p>In October 2025, I booked a telehealth appointment with a women\u2019s health clinic in Virginia, after a source was frustrated with the clinic\u2019s check-in process. During registration, I was asked to sign their notice of privacy practices. It\u2019s the same type of form that Stannard never got, but was asked to say she did.<\/p>\n<p>The <a href=\"&quot;https:\/\/www.documentcloud.org\/documents\/28163616-phreesia-and-privia-patient-registration-process\/&quot;\">notice told me<\/a> that I was giving them permission to let my physician share my health data with a health information exchange, a network that allows providers to search my medical records, like lab results or medical history, from other health organizations when they treat me. These networks can be regional, state-wide or national in reach. The privacy notice says that by signing the form, \u201c<a href=\"&quot;https:\/\/www.documentcloud.org\/documents\/28163616-phreesia-and-privia-patient-registration-process\/&quot;\">you agree to have your medical information shared<\/a>.\u201d\u00a0<\/p>\n<p>It also says I have two other choices:<\/p>\n<p>Say no by following instructions on the opt-out form, but there\u2019s no link to the form.\u00a0<\/p>\n<p>Say yes now and kick off the opt-out process later by sending an email. An email address is provided.<\/p>\n<p>But when I got to the end of the privacy notice, I wasn\u2019t allowed to say no. I had only one choice: \u201cI accept.\u201d After that, there\u2019s a spot to type my name \u201cto accept the policy,\u201d check a box that I understand that I\u2019m electronically signing, and a big button to \u201cContinue.\u201d<\/p>\n<p>I ignored the accept button and tried clicking \u201cContinue.\u201d An error message told me I couldn\u2019t move forward unless I hit \u201cI accept.\u201d<\/p>\n<p>I was at a crossroads. The privacy notice <a href=\"&quot;https:\/\/www.documentcloud.org\/documents\/28163616-phreesia-and-privia-patient-registration-process\/&quot;\">literally describes<\/a> \u201cSay No Thanks\u201d as a choice, but doesn\u2019t let me pick it.<\/p>\n<p>At this point, most of the patients I\u2019ve interviewed would probably click \u201cI accept\u201d and move on, even if they wanted to keep their information private. But I was researching what patients have to do for healthcare systems to honor their wishes around consent and privacy, so I stopped filling out the form.<\/p>\n<p>Instead, I emailed the address on the privacy notice. I was surprised that an employee got back to me that day, shared <a href=\"&quot;https:\/\/www.documentcloud.org\/documents\/28164164-hie-opt-out\/&quot;\">the opt-out request form<\/a>, and confirmed that \u201cregistration is required to opt-in.\u201d She also told me her company, which manages this consent process for the information exchange, will process my opt-out after I sign it and they\u2019re able to process it. The risk is that they might not do it before my appointment. I emailed her back and asked what we should do about this, since the original privacy notice says, \u201cPlease note, your opt-out does not affect health information that was disclosed through HIE [health information exchanges] prior to the time that you opted out.\u201d How could we make sure none of my information is shared?\u00a0<\/p>\n<p>The next day, she replied that her company would proactively opt me out of the information exchange, that I should still complete the opt-out form she sent me, and that \u201cYou should now be able to complete your check-in, and the setting will remain unchanged.\u201d<\/p>\n<p>When I went back to check in for my appointment, I clicked \u201cI accept,\u201d because the health services company assured me nothing will change. Just to be safe, I wrote \u201cI opt out of HIE\u201d and my initials, \u201cAR\u201d into the box where I\u2019m supposed to write my name.<\/p>\n<p>When I wrote to a manager of the women\u2019s clinic about this, they stood by Privia\u2019s process and said that Privia makes themselves available for patients who want to opt-out.<\/p>\n<p>\u201cThis is a dark pattern,\u201d said Lior Strahilevitz, a <a href=\"&quot;https:\/\/www.law.uchicago.edu\/faculty\/strahilevitz&quot;\">legal scholar at the University of Chicago<\/a> who has published papers on <a href=\"&quot;https:\/\/academic.oup.com\/jla\/article\/13\/1\/43\/6180579?login=false&quot;\">privacy and dark patterns<\/a> and teaches health law. In fact, Strahilevitz sees multiple dark patterns in the patient registration process I went through.<\/p>\n<p>One is called an \u201cobstruction dark pattern,\u201d which means the design makes it harder for patients to make any choice except the one healthcare providers want.\u00a0<\/p>\n<p>Another dark pattern was \u201cvisual interference\u201d where the interface makes it hard on the patient. \u201cThe patient\u2019s going to have to face inordinate burdens in order to make an autonomous choice,\u201d he said, because they will need to go \u201coutside the user interface, outside the screens, in order to exercise your opt-out rights.\u201d<\/p>\n<p>Lucia Savage, former chief privacy officer at the federal health IT office, called the Office of the National Coordinator for Health IT, said that problems like this can happen when people carelessly put physical forms online. \u201cThis isn\u2019t really a design at all,\u201d she said. \u201cThis is just a bunch of paper pasted onto a web page. Could you even really call it design?\u201d<\/p>\n<p>So, is all of this legal?<\/p>\n<p>Legal experts point out that only one element of the check-in process violates the spirit of health privacy law, and it\u2019s not the part I expected.<\/p>\n<p>In Virginia, where I had my appointment, it\u2019s legal for providers to opt patients in at registration and give them a way to opt-out later.<\/p>\n<p>Some states, like <a href=\"&quot;https:\/\/www.leg.state.fl.us\/statutes\/index.cfm?App_mode=Display_Statute&amp;URL=0400-0499\/0408\/Sections\/0408.051.html&quot;\">Florida<\/a> and <a href=\"&quot;https:\/\/www.law.cornell.edu\/regulations\/new-york\/10-NYCRR-300.5&quot;\">New York<\/a>, require providers to get a patient\u2019s explicit consent before they can share or access a patient\u2019s data from information exchanges. Other states, like <a href=\"&quot;https:\/\/www.azleg.gov\/legtext\/54leg\/1R\/laws\/0311.pdf&quot;\">Arizona<\/a> and <a href=\"&quot;https:\/\/regs.maryland.gov\/us\/md\/exec\/comar\/10.25.18.03#A(1)&quot;\">Maryland<\/a> have laws that allow data-sharing through health information exchanges by default, as long as providers tell patients and give them a way to opt-out. Some states have not passed any additional regulations, which means they follow the federal baseline. Federally, under the Health Insurance Portability and Accountability Act (HIPAA), sharing a patients\u2019 data in a health exchange is legal.<\/p>\n<p>According to Sarah Jaromin, a health policy specialist at the National Conference of State Legislatures, in Virginia, there is no current state policy with explicit opt-in or opt-out requirements.<\/p>\n<p>Craig Konnoth, a law professor at the University of Virginia who specializes in <a href=\"&quot;https:\/\/www.law.virginia.edu\/faculty\/profile\/dcs9pr\/2994724&quot;\">health and civil rights<\/a> looked at the privacy notice I was asked to accept. \u201cYou have the choice as to whether your data is going to be used. In this particular situation, \u2018we are going to use your data until you file in the opt-out paperwork\u2019 \u2014 then that&#8217;s actually kosher,\u201d he said.\u00a0<\/p>\n<p>What experts say violates the spirit of the law, however, is requiring that patients sign the privacy notice itself.\u00a0<\/p>\n<p>When I was checking in, the privacy notice forced me to add my signature and click \u201cI accept\u201d before I could click \u201cContinue.\u201d<\/p>\n<p>\u201cWhat becomes problematic for me is that you can&#8217;t actually proceed. The design forces you to do something that the HIPAA privacy rule does not require you to do,\u201d said Stacey Tovino, a professor who teaches HIPAA privacy law at the University of Oklahoma College of Law. (Full disclosure: As a part of my role as Director of Sociotechnical Research at The Markup and CalMatters, I am combining a broader journalistic investigation with a small ethnographic research studying on digital patient intake procedures, The Markup paid Tovino to consult on the HIPAA implications of my findings, but she did not participate in data-collection or editorial decision-making.)<\/p>\n<p>\u201c<a href=\"&quot;https:\/\/www.hhs.gov\/hipaa\/for-professionals\/privacy\/laws-regulations\/index.html&quot;\">Nothing in HIPAA<\/a> requires them to make you sign the notice,\u201d said Tovino. \u201cIf they don\u2019t obtain the signature they simply have to document why they didn\u2019t get it.\u201d<\/p>\n<p>There\u2019s an important nuance here. At a doctor\u2019s office, patients usually have to sign and give consent to treatment and financial responsibility policies before they can actually get medical care. But when it comes to privacy notices, HIPAA only requires healthcare providers to ask that patients acknowledge receiving it. Patients should be able to ignore it.\u00a0<\/p>\n<p>Many of the privacy-focused patients I interviewed, including those who also work as doctors and nurses, deliberately decline to sign a notice of privacy practices if it contains terms they disagree with. But when modern check-in technology refuses to let a patient move forward without agreeing to the notice of privacy practices, is that legal?<\/p>\n<p>Emily Hilliard, press secretary at the U.S. Department of Health and Human Services (HHS), confirmed that the HIPAA privacy rule does not require providers to get a patient\u2019s consent to their privacy notice, but it also does not \u201cprohibit covered entities from requiring individuals to acknowledge, or agree to the terms of, an NPP.\u201d<\/p>\n<p>In other words, requiring patients to agree to a privacy notice before getting treatment is legal.<\/p>\n<p>\u201cLikely because HHS never envisioned this happening, HIPAA does not explicitly prohibit a covered entity from requiring an acknowledgement of receipt of the notice of privacy practices as a condition of treatment,\u201d said Adam Greene, a partner at the law firm Davis Wright Tremaine who focuses on health information, privacy and security.<\/p>\n<p>\u201cHHS has heard about widespread problems with the acknowledgment of receipt of the notice of privacy practices becoming an obstacle to patient care and a cause of confusion,\u201d he said. \u201cIn 2021, they issued a proposed rule that, amongst other things, proposed deleting the requirement for an acknowledgment of receipt of the notice of privacy practices.\u201d The <a href=\"&quot;https:\/\/www.hipaajournal.com\/hipaa-privacy-rule-update-progress\/&quot;\">rule was never finalized<\/a>, but it is back on the agenda this year.\u00a0<\/p>\n<p>Stannard confirmed that at HHS, \u201cwe are in the process of finalizing the rule which includes some additional requirements for the notice of privacy practices.\u201d<\/p>\n<p>The <a href=\"&quot;https:\/\/www.federalregister.gov\/d\/2020-27157\/p-114&quot;\">current proposed rule<\/a> includes, \u201cEliminating the requirement to obtain an individual&#8217;s written acknowledgment of receipt of a direct treatment provider&#8217;s Notice of Privacy Practices.\u201d<\/p>\n<p>Experts say patients should be able to opt out immediately \u2014\u00a0not eventually<\/p>\n<p>Legal experts say that regulators can fix this problem with one fell swoop: make it a rule that companies must let patients opt-out right away, at the same moment they\u2019re notified that they can.<\/p>\n<p>\u201cAmend these [federal] regulations to say covered entities shall not impose an undue burden on people trying to opt out. Covered entities shall not make it functionally problematic. Covered entities shall not, in registration documents, force people to proceed, thus waiving their right to opt out at the earliest possible time,\u201d Tovino said.<\/p>\n<p>She suggested that when a company notifies someone of their right to opt out, the next sentence should include a link to do so.<\/p>\n<p>Savage agreed that this change would \u201cabsolutely\u201d be a substantial intervention. \u201cI believe that&#8217;s something OCR [Office of Civil Rights at HHS] could do in regulations.\u201d<\/p>\n<p>At the same event where Stannard shared that her eye doctor asked her to acknowledge a privacy notice she never got, I asked her, \u201cWould updating the privacy rule to require a live link when patients make a choice to opt out or into sharing their information be empowering to Americans as individual patients?\u201d She\u2019d just spoken about U.S. Health Secretary Robert F. Kennedy Jr.\u2019 s agenda \u201cto empower individuals with their own health information.\u201d<\/p>\n<p>&#8220;That&#8217;s an interesting idea,\u201d Stannard responded. \u201cI don&#8217;t remember if we&#8217;ve considered it before. It&#8217;s certainly something that we could consider going forward.&#8221;\u00a0<\/p>\n<p>One registration form, but a cocktail of technology companies<\/p>\n<p>Navigating the dark patterns in the check-in process was difficult. What I\u2019ve learned however, is that it\u2019s hard to know who picked that interface to use with patients. Did it come from the clinic or the sprawl of vendors that health facilities have come to rely on?\u00a0<\/p>\n<p>Private clinics often partner with multiple outside companies (vendors covered by HIPAA) to get technology and administrative support. My appointment involved three different companies:\u00a0<\/p>\n<p>The mobile link I received to check-in for my appointment comes from a company named Phreesia, which handles patient-facing software, like consents, medical screening surveys and payment. When a patient clicks through those consent forms in the U.S., it goes through Phreesia every <a href=\"&quot;https:\/\/www.businesswire.com\/news\/home\/20260330072462\/en\/Phreesia-Announces-Fourth-Quarter-Fiscal-2026-Results&quot;\">1 in 6 patient visits<\/a>.<\/p>\n<p>The clinic had joined Privia Health, which handles management services for nearly 5,000 providers across 15 states, which affect 5.2 millions patients, according to a 2025 <a href=\"&quot;https:\/\/ir.priviahealth.com\/news-releases\/news-release-details\/privia-health-reports-first-quarter-2025-financial-results&quot;\">press release<\/a>. The privacy notice I struggled with sent me to Privia\u2019s medical records office to opt out. Phreesia\u2019s logo was also on the copy of my forms that the clinic emailed me.\u00a0<\/p>\n<p>Finally, for my second telehealth appointment six months later, the clinic sent me a link with the name of <a href=\"&quot;https:\/\/www.athenahealth.com\/resources\/case-studies\/privia-health&quot;\">another vendor, \u201cathenahealth<\/a>,\u201d in it. The clinic had replaced Phreesia with athenahealth entirely.<\/p>\n<p>\u201cUnless you&#8217;re a really giant system,\u201d said Savage, &#8220;you don&#8217;t have internal expertise on how to do this. So you buy it. You buy what&#8217;s plug-and-play and what&#8217;s affordable.\u201d\u00a0<\/p>\n<p>The Markup and CalMatters asked all three companies who was responsible for the design of the patient registration interface, and no company gave us a clear answer.<\/p>\n<p>Privia: \u201cPrivia is committed to the privacy and security rights of our patients\u2019 information and to ensuring we comply with all regulatory requirements regarding our use of that information,\u201d said Robert Borchert, senior vice president of investor and corporate communications at Privia Health.<\/p>\n<p>athenahealth: \u201cathenahealth provides technology that healthcare providers use to manage patient registration and clinical workflows \u2026 configured according to each provider&#8217;s requirements and applicable law,\u201d read a statement from athenahealth, provided by Nikki D\u2019Addario, senior public relations manager.<\/p>\n<p>Phreesia: \u201cIt is the provider\u2019s form and they determine the content and interface options,\u201d said Dori Zweig Young, Phreesia spokesperson.<\/p>\n<p>None of the companies responded to detailed written questions about how much control clinics have over the interface.<\/p>\n<p>A blindspot for regulators and how it can be fixed<\/p>\n<p>Outside of healthcare, regulators, like the <a href=\"&quot;https:\/\/www.ftc.gov\/news-events\/news\/press-releases\/2022\/09\/ftc-report-shows-rise-sophisticated-dark-patterns-designed-trick-trap-consumers&quot;\">Federal Trade Commission<\/a> (FTC), the Consumer Financial Protection Bureau (CFPB) and <a href=\"&quot;https:\/\/www.naag.org\/wp-content\/uploads\/2025\/08\/2022.11.14-Multistate-Assurance-of-Voluntary-Compliance.pdf&quot;\">multiple<\/a> state attorneys general and agencies, have called dark patterns <a href=\"&quot;https:\/\/agportal-s3bucket.s3.amazonaws.com\/uploadedfiles\/Another\/News\/Press_Releases\/2022_01_24FinalRedactedComplaint.pdf&quot;\">manipulative<\/a> or <a href=\"&quot;https:\/\/www.consumerfinance.gov\/about-us\/newsroom\/cfpb-issues-guidance-to-address-abusive-conduct-in-consumer-financial-markets\/&quot;\">abusive<\/a> tactics that confuse <a href=\"&quot;https:\/\/cppa.ca.gov\/announcements\/2024\/20240904.html&quot;\">consumers about their privacy choices<\/a> or lock consumers into paying for services (like the famous <a href=\"&quot;https:\/\/www.ftc.gov\/news-events\/news\/press-releases\/2023\/06\/ftc-takes-action-against-amazon-enrolling-consumers-amazon-prime-without-consent-sabotaging-their&quot;\">Amazon Prime<\/a> case). Researchers consistently find that <a href=\"&quot;https:\/\/journals.sagepub.com\/doi\/10.1177\/1461444814543995&quot;\">people want more control over the context<\/a> of how their data is shared, and that patients are <a href=\"&quot;https:\/\/pmc.ncbi.nlm.nih.gov\/articles\/PMC9960046\/&quot;\">least comfortable<\/a> handing over blanket access with broad, open consents, even if they are largely willing to share it for specific uses.<\/p>\n<p>Strahilevitz explained, however, that agencies like the FTC and CFPB, which have been the most active on regulating dark patterns, regulate privacy within their zones, and only occasionally take on boundary cases.<\/p>\n<p>\u201cHealth privacy, for the most part, is going to be primarily addressed by HIPAA and Health and Human Services rather than the FTC Act and the Federal Trade Commission,\u201d she said.<br \/>\u201cThere are limits on [the commissions] ability to protect patient privacy because that&#8217;s basically another entity&#8217;s job.\u201d<\/p>\n<p>Greene and Savage both agreed that the Federal Trade Commission has jurisdiction to enforce against dark patterns as unfair or deceptive practices in for-profit healthcare entities. The clinic I went to, like hundreds of thousands across the country, is for-profit.\u00a0<\/p>\n<p>But HHS has a broader mandate to regulate healthcare organizations, including non-profit hospitals.\u00a0<\/p>\n<p>For example, Strahilevitz said, in consumer finance, regulators at the Consumer Financial Protection Bureau treat a practice as unfair or deceptive when a consumer <a href=\"&quot;https:\/\/ncua.gov\/regulation-supervision\/manuals-guides\/federal-consumer-financial-protection-guide\/compliance-management\/unfair-deceptive-or-abusive-acts-or-practices-udaap#:~:text=Members%20cannot%20reasonably%20avoid%20injury%20if%20the%20act%20or%20practice%20interferes%20with%20their%20ability%20to%20effectively%20make%20decisions%20or%20to%20take%20action%20to%20avoid%20injury&quot;\">cannot reasonably avoid the resulting injury<\/a>. Just as hard-to-cancel online subscriptions force people to pay more, maze-like opt-out structures force patients to pay with their data by default.<\/p>\n<p>Strahilevitz said this provides a framework for thinking about privacy injuries in healthcare. An information exchange could serve as a clearing house for information about a patient\u2019s abortion, which has a clear potential for injury if that information becomes known in a state where abortion treatments are criminalized.<\/p>\n<p>\u201cIn other privacy contexts, the courts have said where it&#8217;s literally possible to opt out of something but, practically quite difficult, unduly onerous, then we&#8217;re not going to treat that as creating an opt-out right,\u201d he said.\u00a0<\/p>\n<p>Savage sees more opportunities in carrots than sticks to get to best practices. She argued that the government could invest in good interface design that\u2019s open source and available for anyone to use, and the federal health IT office, where she used to work, could create competitions focused on improving the technical tools that providers buy and use.<\/p>\n<p>If the big technology vendors that independent clinics are already using make these changes, it could affect millions of patients.<\/p>\n<p>State regulation is another possible solution. Strahilevitz said that scrutiny of dark patterns is spreading as states, like California, and regulatory agencies, like the FTC, seek to reign in unfair or deceptive practices through the simple intervention that it should be as easy to cancel as it is to subscribe, with one click.<\/p>\n<p>\u201cI hope that at some point, we&#8217;ll get to a point where symmetry of choice is the law of the land, not only with respect to consumer privacy in some states, but to these kinds of medical privacy or financial privacy or other contexts,\u201d he said.<\/p>\n<p>How we reported this story<\/p>\n<p>Over the last year, we interviewed more than 20 patients, healthcare providers, experts and advocates about the privacy forms they must sign to get care at their providers\u2019 offices. Our reporter then replicated individual patient experiences by signing up for appointments at multiple clinics and documenting her own experience, which includes reading every word of all registration paperwork given to her as a patient.\u00a0<\/p>\n<p>This article also draws from a small <a href=\"&quot;https:\/\/forms.gle\/DDXbxcFYLQctyWHg7&quot;\">ethnographic study<\/a>, which was reviewed by an institutional review board. An IRB is a committee that has reviewed this research study to help ensure that the rights and welfare of all research participants are protected and that the research study is carried out in an ethical manner.<\/p>\n<p>This article was <a href=\"&quot;https:\/\/calmatters.org\/economy\/technology\/2026\/05\/opt-out-dark-patterns\/&quot;\">originally published on CalMatters<\/a> and was republished under the <a href=\"&quot;https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/&quot;\">Creative Commons Attribution-NonCommercial-NoDerivatives<\/a> license.<\/p>\n","protected":false},"excerpt":{"rendered":"By Alex Rosenblat, CalMatters Illustration by Gabriel Hongsdusit, CalMatters This story was originally published by CalMatters. Sign up&hellip;\n","protected":false},"author":2,"featured_media":668729,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[59],"tags":[97,252,253,514],"class_list":["post-668728","post","type-post","status-publish","format-standard","has-post-thumbnail","category-health-care","tag-health","tag-health-care","tag-healthcare","tag-privacy"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/668728","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=668728"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/668728\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/668729"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=668728"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=668728"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=668728"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}