Live data from Hacker News

Facebook was in talks with hospitals about a proposal to share data

cnbc.com

41–50 of 120 posts

Re: Facebook was in talks with hospitals about a proposal to share data

#41
post #20

Earlier quoted context omitted.

I think this story could appear harmless - or perhaps not. The potential gold mine of information that insurers and the health industry could get from this kind of data could be staggering, particularly when we think about claims or the price of the insurance policy. This is what many of us have been suspecting for some time so this confirms our suspicions. I don't think it's a non-story. I feel that if such research…

Quite telling that it has been 'put on hold'. That in itself is a story. It's been put on hold because Facebook PR knows that people don't read the details of stories. By and large, they read headlines - and many of those are misleading at best. The issue with CA, for example, wasn't a data breach - the data they had was collected in compliance with Facebook's rules at the time. Yet many headlines and soundbites have…

Maybe, maybe not, but either way I don't want to give them the benefit of doubt for my reasons mentioned above. Cheers!

Re: Facebook was in talks with hospitals about a proposal to share data

#42
post #25

Although the medical data itself may be "anonymized", surely FB is in a position to associate that data with actual people, given that they know so much about a person's schedule, location, searches and private messages.

Deanonymization of medical data is actually pretty easy if you know a little about your target (age group, height, a set of pre-existing medical conditions limit the set of potential people considerably).

Just an aside...of the many things I have entered into Facebook over the years, I am 100% certain that I have never given them my height or pre-existing medical conditions.

Re: Facebook was in talks with hospitals about a proposal to share data

#44
post #13
post #6

The pile on continues... (1) This is probably a project by a small "research" group at Facebook. The goal of that group is probably to publish papers in a Psych journal or something like that about how they were able to correlate anonymized medical data with Facebook feed updates. Tech companies have these research groups for prestige, they are not central to the company mission. (2) According to the article, the pro…

Facebook has been screwing with people's privacy for years, so it's only fair that they are now criticised for years on end. This has got to be a new Facebook apology meme: the pile-on. Until Facebook and privacy is regulated in the US, like GDPR does it for the EU, the pile-on should continue. Must continue, no matter how uncomfortable it is for the pro-Facebook, pro-ads or pro-spyware people.

For me, the result of having HN filled with these Facebook non-stories is that I'm going to stop taking an interest in them. As far as I can tell the situation with Facebook is substantially the same as it's been since it started. Users willfully broadcast information using Facebook, and sometimes Facebook uses that information in ways its users didn't intend or expect. Among the recent slew of dramatic stories I haven't seen anything I found particularly surprising or shocking, so I've started to pattern match anti-Facebook stories as fluff. One day something actually shocking will happen, like Facebook leaking people's private messages or browsing histories. Hopefully when that happens we won't all have reached the point of ennui, boiling frog-style.

Re: Facebook was in talks with hospitals about a proposal to share data

#45
It could be an epidemiological study on aggregate populations for some communicable disease. In all cases the hospital side would be bound by HIPAA to anonymized any data they provided. Google does similar prediction studies based on search, and it is very valuable to the CDC for allocating flu vaccine.

Re: Facebook was in talks with hospitals about a proposal to share data

#46
post #4

Surely this passes into the realms of illegality?

I was wondering something similar. If Party B acquires Party A's anonymized-but-subject-to-HIPAA data and successfully deanonymizes it, who is liable? If the data is deanonymized, doesn't this mean the data wasn't sufficiently anonymized to begin with and Party A has some liability? Is Party B also liable since their goal from the start was to deanonymize the data?

Hopefully ICA susceptible De-anonymization techniques are no longer HIPAA best practice. Or perhaps this is a study to prove that newer additive and multiplicative techniques, are also susceptible to De-anonymization attacks.

Re: Facebook was in talks with hospitals about a proposal to share data

#48
post #25

Earlier quoted context omitted.

Deanonymization of medical data is actually pretty easy if you know a little about your target (age group, height, a set of pre-existing medical conditions limit the set of potential people considerably).

Just an aside...of the many things I have entered into Facebook over the years, I am 100% certain that I have never given them my height or pre-existing medical conditions.

There may be some other ways to link it up, at least with a degree of confidence. It really depends on what information is shared from the medical community and by the patient on Facebook.

A couple points of speculation:

* Facebook may possess a machine learning algorithm which can estimate weight from pictures. Getting within 5 pounds would eliminate most other people.

* Facebook could make photos of you and estimated weights into a time series, and pair up appointment dates with photos shared.

* Given enough photos with you and other people, they could probably estimate your height reasonably well. We know height distributions by age and race. If you're a Caucasian 21 year old female and consistently on average 10% shorter than the Caucasian males you're standing next to, that gives some info.

* Many people have willingly given the familial relationships to Facebook (tagging people as mom, dad, cousin, etc.) which will only help in being confident of race and the various risk factors which are higher in each race.

* Facebook knows your gender, which cuts out about half of the people. Such a basic fact would almost certainly be shared by the medical community.

* Facebook either has your birthday or could estimate it based on how you look. Again, being 98% confident of your age +/- 3 years cuts out most people.

All these fuzzy signals added up could lead to a reasonably confident matching up.

Anonymous data release is difficult. About 87% of people are uniquely identifiable by their date of birth, zip code, and gender.

https://news.ycombinator.com/item?id=2942967

Re: Facebook was in talks with hospitals about a proposal to share data

#49
post #20

Earlier quoted context omitted.

I think this story could appear harmless - or perhaps not. The potential gold mine of information that insurers and the health industry could get from this kind of data could be staggering, particularly when we think about claims or the price of the insurance policy. This is what many of us have been suspecting for some time so this confirms our suspicions. I don't think it's a non-story. I feel that if such research…

Quite telling that it has been 'put on hold'. That in itself is a story. It's been put on hold because Facebook PR knows that people don't read the details of stories. By and large, they read headlines - and many of those are misleading at best. The issue with CA, for example, wasn't a data breach - the data they had was collected in compliance with Facebook's rules at the time. Yet many headlines and soundbites have…

This again...

"Data breach" means an unauthorised access or use of data. Cambridge Analytica was not authorised to access or use the users' data. Therefore, it's a data breach.

It makes no difference if the breach uses a zero-day exploit to access FB's database, or if it uses social engineering to get someone at Facebook to send them a hard drive, or if it's some researcher being given access under false pretences.

"Data breach" is a catch-all like "homicide": that term encompasses murder but also involuntary manslaughter, euthanasia, and capital punishment.

Re: Facebook was in talks with hospitals about a proposal to share data

#50

In light of this news, the fact that Zuckerberg General Hospital exists is in some ways completely irrelevant/cosmetic, but is simultaneously kind of hideous.

I just stumbled upon the name when it was reported that the victims of the Youtube shooting were taken there.
Post reply on HN