Live data from Hacker News

Google whistleblower: the medical data of millions of Americans is at risk

theguardian.com

31–40 of 83 posts

Re: Google whistleblower: the medical data of millions of Americans is at risk

#32

What is the risk of exposing our health data? To me it is not so obvious, other than maybe embarrassment? Is it like how in our culture we don't like to talk about how much money we make? Why are all these things supposed to be secret in the first place?

Would you want future employers, romantic partners, loan officers, and/or family members to know your medical history?

What if you were HIV+ or taking Viagra? What if you were just sick and didn’t want to be discriminated against?

There are life and death implications in medical privacy in most countries. Stigma is real, as are insurance risk algorithms.

Re: Google whistleblower: the medical data of millions of Americans is at risk

#33

> Two simple questions kept hounding me: did patients know about the transfer of their data to the tech giant? Should they be informed and given a chance to opt in or out? That's literally what HIPAA was created to address. The user doesn't have to opt-in to every single solitary business that touches their data, because there is a chain of business contracts that explicitly dictate what they can do, that originates…

> This is like "blowing the whistle" because your dentist sent your dental impression to a company to create a crown for you.

I see a huge difference here, though. the company making my crown doesn't get my complete medical records. They get what is necessary to make the crown.

Google is getting everything, to use for purposes beyond the patient's immediate medical needs.

> That's literally what HIPAA was created to address.

That HIPAA allows this sort of thing to happen is a great reason to pressure lawmakers to improve HIPAA.

Re: Google whistleblower: the medical data of millions of Americans is at risk

#34

What is the risk of exposing our health data? To me it is not so obvious, other than maybe embarrassment? Is it like how in our culture we don't like to talk about how much money we make? Why are all these things supposed to be secret in the first place?

Because your medical information can be used against you. Want a new job? Nope! We don't want someone with your condition on our team. Want to buy a house? Nope! An AI bot says may not live long enough to pay the loan. Want to get some ice cream? Can't haz. When you swipe your electronic payment method the database says you're at a risk for diabetes. There are thousands of other scenarios.

Also, consider the poor security track record of implantable medical devices [1]. From the source [2]:

> The vulnerabilities could allow an unauthorized individual (i.e. someone other than a health care professional) to access and potentially change the settings of an implantable device, home monitor or clinic programmer.

Ok cool, so there's millions of implantable cardioverter defibrillators whose voltages can be changed by someone who sits nearby at a restaurant. If they up the ampage high enough, the patient has a heart attack.

Now, what if I found out that a sitting president or other elected politician had a small electronic defibrillator implanted in their chest? We could see targeted assassinations look like medical device malfunctions when in reality someone learned about this device, built an exploit for it, and hired someone to sit within bluetooth range to deliver the payload.

It's not impossible to do. Unlikely, sure, but this is a result of the high-tech world we are living in.

[1]: https://nakedsecurity.sophos.com/2019/03/25/medtronic-cardia...

[2]: https://global.medtronic.com/xg-en/product-security/security...

Re: Google whistleblower: the medical data of millions of Americans is at risk

#36
post #25
post #23

Earlier quoted context omitted.

From the original WSJ article... > Staffers across Alphabet Inc., Google’s parent, have access to the patient information, documents show, including some employees of Google Brain, a research science division credited with some of the company’s biggest breakthroughs. I'm struck by the wide access of those within Alphabet to health information that's not anonymous. Is this how other healthcare companies are doing it?

One reading of this is that it's a cross-departmental collaboration, rather than just a single division.

Maybe and sort of.

Alphabet is a conglomerate, right. Alphabet is the parent company that owns Google, LLC. I'm personally surprised to see talk of the data crossing the Google / Alphabet company boundary. That makes it cross company collaboration, right?

Re: Google whistleblower: the medical data of millions of Americans is at risk

#37

What is the risk of exposing our health data? To me it is not so obvious, other than maybe embarrassment? Is it like how in our culture we don't like to talk about how much money we make? Why are all these things supposed to be secret in the first place?

Imagine even more sophisticated advertising from Big Pharma to the old and vulnerable. That is reason enough.

As a society we are getting better at talking about income. We hide _that_ because of a lack of class consciousness. We should absolutely be transparent with income (except when negotiating for a new salary).

Re: Google whistleblower: the medical data of millions of Americans is at risk

#38
post #25
post #23

Earlier quoted context omitted.

From the original WSJ article... > Staffers across Alphabet Inc., Google’s parent, have access to the patient information, documents show, including some employees of Google Brain, a research science division credited with some of the company’s biggest breakthroughs. I'm struck by the wide access of those within Alphabet to health information that's not anonymous. Is this how other healthcare companies are doing it?

One reading of this is that it's a cross-departmental collaboration, rather than just a single division.

That's the difference everyone here is talking about though. Normally in the healthcare industry, you engage a cloud provider, and it's "you store this data for us." Full Stop. You don't look at it. You don't analyze it. You don't share it. You don't touch it. It's our data, not yours.

If what you're saying is true, Ascension, for some reason, has a deal with its cloud provider that allows Google to search through, analyze, etc etc etc. It sounds like all sorts of rights were given to Google. That's an irregular agreement. It's not normally how things are done.

Re: Google whistleblower: the medical data of millions of Americans is at risk

#39
post #6

I work for a large US based corp that focuses on technology and data services for the healthcare field. We have massive amounts of PHI for the majority of people who have visited a provider within the country. We apply all sorts of stuff to this data, ML, AI or whatever other buzzy tech you can think of. Most of this work happens within our own data centers but there is significant work done within public clouds. We…

> I work for a large US based corp that focuses on technology and data services for the healthcare field. We have massive amounts of PHI for the majority of people who have visited a provider within the country.

The real question here is: why can't I opt-out ? I want a easy button when I do anything medical to say "no, don't use my health data for any of this stuff". And the current CA privacy law does not provide this, unlike GDPR, which sucks.

Re: Google whistleblower: the medical data of millions of Americans is at risk

#40
post #6

I work for a large US based corp that focuses on technology and data services for the healthcare field. We have massive amounts of PHI for the majority of people who have visited a provider within the country. We apply all sorts of stuff to this data, ML, AI or whatever other buzzy tech you can think of. Most of this work happens within our own data centers but there is significant work done within public clouds. We…

I've seen a ton of responses from people in the industry along the lines of "this is normal" or similar. People who work on this stuff are incredulous that there's even an issue, since everyone's health info is already being uploaded to AWS or something. This is business as usual, they say.

The uproar is taken by people actually working in the business as a sign that the public are ignorant and misinformed. Things are actually HIPPA compliant, they say. This isn't a big deal, they say.

But perhaps the education should be going in the other direction, and the people in the industry should realize they are the ignorant ones for realizing that this is totally not OK for a huge number of people.

Realize that we are absolutely horrified that this data is being shared, that a reasonable response is to say that if HIPPA is OK with this then we need stronger laws, that we don't want faceless algorithms studying our most intimate personal and medical issues at companies we never had a relationship with.

And, especially, we are absolutely fucking certain that we want literally none of it to be seen by employees of the sociopathic tech companies that are surveilling every aspect of our life in order to better manipulate politics, markets, and our society.

The thing to take away here is that people are shocked and horrified at what's apparently business as usual.

Post reply on HN