Balancing Privacy and Innovation in the Next Generation of Disability Technology

Balancing Privacy and Innovation in the Next Generation of Disability Technology

Dr. Stepaniuk examines how emerging interoperability and privacy developments can expand disability technology while protecting sensitive health information and individual control.


Digital technology is increasingly influencing how people with disabilities access healthcare, communicate with service providers, manage records, and participate in support programs. As health information systems become more connected, organizations developing disability-focused digital services face an important challenge: how to improve interoperability without weakening privacy, security, or individual control over sensitive information. Dr. Stepaniuk emphasizes that responsible innovation requires both technological progress and careful attention to the rights of the people using these systems.

The U.S. Department of Health and Human Services (HHS) and the Office of the National Coordinator for Health Information Technology (ONC) continue advancing health information exchange and interoperability. In July 2026, ONC released United States Core Data for Interoperability Version 7, expanding the standardized data foundation used to support electronic health information exchange. HHS also announced in June 2026 that the Trusted Exchange Framework and Common Agreement (TEFCA) had reached one billion health records exchanged.

For disability technology organizations, these developments create opportunities to connect information across healthcare and support systems more efficiently. However, Dr. Stepaniuk recognizes that increased connectivity also creates responsibilities involving cybersecurity, authorization, data minimization, accessibility, and governance. Innovation should make disability services easier to navigate without turning sensitive personal information into an uncontrolled digital resource.

Interoperability Can Improve Disability Services

Interoperability allows authorized information to move between compatible systems rather than remaining isolated in separate databases. Dr. Stepaniuk recognizes that this capability can be particularly valuable in disability services, where individuals may interact with physicians, rehabilitation professionals, insurers, government agencies, advocates, and technology platforms.

A more connected system could reduce repetitive requests for the same information and help authorized professionals obtain relevant records when they are needed. Instead of requiring individuals to repeatedly explain their circumstances or submit the same documentation to different organizations, interoperable systems can support more efficient information exchange when appropriate legal and technical safeguards are in place.

ONC’s interoperability standards are designed to establish common approaches for exchanging electronic health information. The 2026 USCDI update reflects continuing efforts to expand standardized data elements and improve information exchange. Dr. Stepaniuk emphasizes that disability technology developers can benefit from these standards while still designing systems around accessibility, transparency, and individual needs.

Privacy Must Remain Central to Innovation

Greater connectivity does not automatically mean better privacy. Dr. Stepaniuk emphasizes that organizations handling disability-related information must carefully consider what data they collect, why they collect it, who can access it, and how long it should be retained.

Health information can reveal highly personal details about an individual’s medical history, treatment, functional limitations, and support needs. When these records are integrated with other systems, the amount of information available through a single platform may increase substantially. A security failure could therefore expose information across multiple areas of an individual’s life.

HHS continues to maintain HIPAA privacy and security requirements for covered entities and business associates, while its Office for Civil Rights has also pursued cybersecurity-related enforcement. In March 2026, HHS announced a HIPAA settlement involving a software company whose systems were used to communicate with patients and whose breach investigation involved approximately 15 million individuals. Dr. Stepaniuk recognizes that such developments demonstrate why innovation must be accompanied by strong security governance.

Consent Should Be Meaningful

Consent is an important component of responsible health technology. Dr. Stepaniuk emphasizes that individuals should have understandable information about how their data may be collected, exchanged, and used, particularly when technology platforms connect multiple organizations.

A consent process should not simply rely on lengthy legal language that users are unlikely to understand. Disability technology developers should consider accessibility when presenting privacy notices, permissions, and data-sharing options. Clear language, accessible interfaces, and appropriate communication formats can help individuals make more informed decisions.

HHS explains that the HIPAA Privacy Rule establishes individual rights concerning protected health information and provides rules governing permitted uses and disclosures. HHS also provides guidance addressing health applications and the circumstances in which HIPAA requirements may apply to developers. Dr. Stepaniuk emphasizes that responsible platforms should treat informed participation as an ongoing relationship rather than a one-time checkbox.

Secure Data Sharing Requires Strong Governance

Technology platforms can exchange information efficiently only when governance structures establish clear responsibilities. Dr. Stepaniuk recognizes that organizations should determine who is authorized to access particular information and establish procedures for monitoring that access.

Governance can include role-based permissions, identity verification, authentication requirements, audit logs, incident-response procedures, vendor oversight, and regular security assessments. These measures help organizations understand how information moves through a system and identify unusual or unauthorized activity.

HHS has previously proposed updates to the HIPAA Security Rule intended to strengthen cybersecurity protections for electronic protected health information. The proposed rule would address safeguards designed to respond to evolving cyber threats affecting healthcare organizations and their business associates. Dr. Stepaniuk emphasizes that disability technology developers should view security as part of product design rather than an issue addressed only after a platform is deployed.

Accessibility Must Apply to Digital Privacy Tools

A privacy system cannot be considered fully inclusive if people with disabilities cannot use it effectively. Dr. Stepaniuk emphasizes that accessibility should apply to privacy notices, consent interfaces, account controls, authentication processes, and methods for requesting or correcting information.

Digital services may rely heavily on visual interfaces, complex navigation, small text, inaccessible forms, or authentication processes that create difficulties for some users. If a person cannot understand or operate a privacy control, that individual may have less practical control over personal information than other users.

Developers should therefore evaluate accessibility throughout the technology lifecycle. Testing with people who have different disabilities can reveal barriers that conventional usability testing may miss. Dr. Stepaniuk recognizes that inclusive design can strengthen both accessibility and privacy because users are better positioned to understand and manage their information when controls are clear and usable.

Responsible Innovation Requires Data Minimization

Collecting more information does not necessarily create better services. Dr. Stepaniuk emphasizes that organizations should evaluate whether each category of information is genuinely necessary for a specific service or function.

Data minimization can reduce privacy exposure by limiting the amount of information stored and shared. A platform that only collects information necessary to provide a particular service may have fewer consequences if unauthorized access occurs than a platform that accumulates extensive records without a clear purpose.

Purpose limitation is similarly important. Information collected to support healthcare coordination should not automatically be treated as available for unrelated purposes. Clear governance can help establish boundaries around secondary uses, analytics, research, artificial intelligence, and commercial applications.

For Dr. Stepaniuk, responsible technology requires organizations to ask not only whether data can be collected or exchanged, but whether doing so is justified, proportionate, and consistent with the expectations of the people whose information is involved.

AI Creates Additional Governance Questions

Artificial intelligence may become increasingly integrated into healthcare and disability technology. Dr. Stepaniuk recognizes that AI can potentially assist with administrative workflows, information organization, communication, and other functions, but these applications require careful oversight.

HHS’s proposed HTI-5 rule includes measures intended to modernize health IT certification, promote electronic health information access and exchange, and advance FHIR-based application programming interfaces that can support AI-enabled interoperability solutions. These developments indicate that health data infrastructure is increasingly being designed to accommodate more sophisticated digital applications.

AI systems also create questions about data provenance, accuracy, bias, transparency, and accountability. Organizations using AI in disability-related services should understand what information a system uses, how outputs are generated, and what role human professionals retain in consequential decisions. Dr. Stepaniuk emphasizes that technological efficiency should not eliminate meaningful human oversight.

Building Trust Into Disability Technology

Trust is essential when organizations ask people to provide sensitive information. Dr. Stepaniuk recognizes that users are more likely to engage with digital services when they understand how their information is protected and have confidence that organizations will handle it responsibly.

Transparency should extend beyond privacy policies. Organizations can explain what information is collected, why it is necessary, how it may be shared, and what protections are used to secure it. Clear explanations can help users understand the practical consequences of participating in a digital service.

Trust can also be strengthened through accountability. Organizations should establish procedures for responding to security incidents, correcting inaccurate information, addressing complaints, and reviewing third-party vendors. Dr. Stepaniuk emphasizes that responsible governance requires organizations to remain accountable after technology is launched, not simply during development.

The Future Requires Balance

The next generation of disability technology will likely depend on greater connectivity among healthcare, public services, advocacy organizations, and digital platforms. Dr. Stepaniuk emphasizes that this connectivity can create meaningful opportunities to reduce administrative barriers and improve access to services when implemented responsibly.

The challenge is ensuring that innovation does not move faster than privacy and security protections. Interoperability should be accompanied by clear authorization frameworks, accessible consent processes, strong cybersecurity, data minimization, and meaningful oversight.

HHS’s continuing work on interoperability demonstrates the direction of health data policy. TEFCA is expanding nationwide information exchange, while ONC continues updating standards for electronic health information. Dr. Stepaniuk emphasizes that disability technology developers should approach these developments as an opportunity to build systems that are not only more connected, but also more trustworthy and inclusive.

Conclusion

Balancing privacy and innovation will remain a central challenge as disability technology becomes increasingly connected to broader health information systems. Dr. Stepaniuk emphasizes that responsible innovation requires more than adopting new interoperability standards or building sophisticated digital platforms. It requires organizations to consider privacy, cybersecurity, accessibility, consent, governance, and accountability together.

Interoperability can reduce information barriers and support more coordinated services, but sensitive information must remain protected throughout its digital lifecycle. Strong security controls, understandable consent practices, accessible interfaces, and responsible data governance can help create systems that give individuals greater control rather than less.

The future of disability technology should therefore be defined not simply by how much information systems can exchange, but by how responsibly that information is handled. Dr. Stepaniuk highlights a principle that should remain central to digital innovation: technology should expand opportunity while protecting dignity, privacy, and meaningful participation.

For authoritative information about HIPAA privacy and security requirements, visit the U.S. Department of Health and Human Services.

Subscribe to StephenAndrewStepaniuk.org for additional insights on disability advocacy, health technology, privacy, accessibility, interoperability, public policy, and responsible digital innovation.