Live data from Hacker News

Google whistleblower: the medical data of millions of Americans is at risk

theguardian.com

61–70 of 83 posts

Re: Google whistleblower: the medical data of millions of Americans is at risk

#61

Earlier quoted context omitted.

But if they're just using Google as cloud storage/compute it's not being shared. Only very few Google employees would have access, they'd have very careful limitations and access on who accessed what - that's not the same as giving to google for some big AI experiment.

> Only very few Google employees would have access That's "very few" Google employees more than zero. I expect zero Google employees to have access to my medical data. Any number above zero is absolutely not acceptable to me. > they'd have very careful limitations and access on who accessed what Yeah, just like Equifax, right?

> That's "very few" Google employees more than zero. I expect zero Google employees to have access to my medical data. Any number above zero is absolutely not acceptable to me.

Heck, people owning my medical data who are not my doctor/GP and related medical professionals is a big no go in my opinion.

Medical data is rather private.

Re: Google whistleblower: the medical data of millions of Americans is at risk

#62
post #29

Earlier quoted context omitted.

Then you should blame the industry rather than a newcomer to the industry who tries to follow the industry standard?

No one should be excused for unethical behavior just because it’s standard industry practice.

Also, this shows the massive disconnect between those who make money from said data and those who provide that data.

Re: Google whistleblower: the medical data of millions of Americans is at risk

#63
post #40
post #6

I work for a large US based corp that focuses on technology and data services for the healthcare field. We have massive amounts of PHI for the majority of people who have visited a provider within the country. We apply all sorts of stuff to this data, ML, AI or whatever other buzzy tech you can think of. Most of this work happens within our own data centers but there is significant work done within public clouds. We…

I've seen a ton of responses from people in the industry along the lines of "this is normal" or similar. People who work on this stuff are incredulous that there's even an issue, since everyone's health info is already being uploaded to AWS or something. This is business as usual, they say. The uproar is taken by people actually working in the business as a sign that the public are ignorant and misinformed. Things ar…

> we don't want faceless algorithms studying our most intimate personal and medical issues

So you don't want an advanced algorithm to analyze your vitals and detect your cancer at an early stage?

Technology has more than doubled our life expectancy. More technology could do even more so. The fact that it's a faceless algorithm, and not a creepy biased human, should be a comfort. But you're reacting like this is all going to harm you, when it's way more likely to do the opposite.

> we are absolutely horrified that this data is being shared

People always fear the things they don't understand. That doesn't mean that fear is justified, by a long shot.

Re: Google whistleblower: the medical data of millions of Americans is at risk

#64
post #61

Earlier quoted context omitted.

> Only very few Google employees would have access That's "very few" Google employees more than zero. I expect zero Google employees to have access to my medical data. Any number above zero is absolutely not acceptable to me. > they'd have very careful limitations and access on who accessed what Yeah, just like Equifax, right?

> That's "very few" Google employees more than zero. I expect zero Google employees to have access to my medical data. Any number above zero is absolutely not acceptable to me. Heck, people owning my medical data who are not my doctor/GP and related medical professionals is a big no go in my opinion. Medical data is rather private.

> Heck, people owning my medical data who are not my doctor/GP and related medical professionals is a big no go in my opinion.

Not even "owning", but having.

Having even "anonymized" data is not acceptable to me.

Re: Google whistleblower: the medical data of millions of Americans is at risk

#65
post #32

What is the risk of exposing our health data? To me it is not so obvious, other than maybe embarrassment? Is it like how in our culture we don't like to talk about how much money we make? Why are all these things supposed to be secret in the first place?

Would you want future employers, romantic partners, loan officers, and/or family members to know your medical history? What if you were HIV+ or taking Viagra? What if you were just sick and didn’t want to be discriminated against? There are life and death implications in medical privacy in most countries. Stigma is real, as are insurance risk algorithms.

> There are life and death implications in medical privacy in most countries. Stigma is real, as are insurance risk algorithms.

Hell, in some countries people have been killed because of their medical history. Also, centralizing this data is very dangerous if this data falls into the wrong hands at a later date.

A prime example would be the registration of religion which happened in the Netherlands prior to world war 2. (for taxation reasons). Which resulted in a large number of victims during the holocaust in part because of this record keeping.

Re: Google whistleblower: the medical data of millions of Americans is at risk

#66
post #6

I work for a large US based corp that focuses on technology and data services for the healthcare field. We have massive amounts of PHI for the majority of people who have visited a provider within the country. We apply all sorts of stuff to this data, ML, AI or whatever other buzzy tech you can think of. Most of this work happens within our own data centers but there is significant work done within public clouds. We…

> I work for a large US based corp that focuses on technology and data services for the healthcare field. We have massive amounts of PHI for the majority of people who have visited a provider within the country. The real question here is: why can't I opt-out ? I want a easy button when I do anything medical to say "no, don't use my health data for any of this stuff". And the current CA privacy law does not provide th…

GDPR does not provide this unfortunately. Just last week a bill in Germany was enacted which allows the medical data of all insured people to be shared with medical companies. There is no opt-out.

Re: Google whistleblower: the medical data of millions of Americans is at risk

#67
post #33

Earlier quoted context omitted.

> This is like "blowing the whistle" because your dentist sent your dental impression to a company to create a crown for you. I see a huge difference here, though. the company making my crown doesn't get my complete medical records. They get what is necessary to make the crown. Google is getting everything, to use for purposes beyond the patient's immediate medical needs. > That's literally what HIPAA was created to…

> Google is getting everything, to use for purposes beyond the patient's immediate medical needs. That claim was never made anywhere in this whistleblower account. Furthermore, it's illegal, and anyone working with health care records knows that. You can't use the records for anything other than what was covered by the business associate contract. It's clear from the letter that the whistleblower literally has no ide…

> That claim was never made anywhere in this whistleblower account.

I may have misread the various reports and press releases, of course. If so, please do correct me. But I believe that everyone, including Google and the medical group, has mentioned this data is to be used to train a ML engine.

> You can't use the records for anything other than what was covered by the business associate contract.

My understanding is that the ML use is covered by the BAA. Of course, I haven't read it, so I don't know, but it seems likely.

I seriously doubt that anyone is actually overtly and intentionally breaking any laws here.

Re: Google whistleblower: the medical data of millions of Americans is at risk

#68
post #38

Earlier quoted context omitted.

That's the difference everyone here is talking about though. Normally in the healthcare industry, you engage a cloud provider, and it's "you store this data for us." Full Stop. You don't look at it. You don't analyze it. You don't share it. You don't touch it. It's our data, not yours. If what you're saying is true, Ascension, for some reason, has a deal with its cloud provider that allows Google to search through, a…

That's a very naive view of what happens. It's exactly how things are done, except that it's a one-stop shop. The reality is that there is a fig leaf of privacy. HIPPA protects you from the office staff gossiping about your medical conditions. When you are admitted to the hospital, your prescriptions are sent to data aggregators in near real-time, your claims are sent to your insurer and subrogation in near real-time…

We're talking about cloud providers here, not pharmaceutical or insurance providers. There are different levels of interaction required to accomplish different operational objectives. Giving a cloud provider this sort of access is, as I said initially, highly irregular. There is just not that same level of collaboration needed with your cloud provider.

Just as a for instance, there are very good operational reasons on your side that pharmaceutical partners need the data to be reasonably certain that the 1000 doses of highly controlled substance X that they previously sent to you, or distributed on your behalf, were administered to people who both required the medication, and who actually exist. That pharmaceutical partner needs to have the ability to be certain of this prior to sending you, or distributing for you, the 10000 additional doses you are all of a sudden requesting.

By contrast, there is no operational reason on your side that a cloud provider needs to know the names and addresses of the patients in your database.

Re: Google whistleblower: the medical data of millions of Americans is at risk

#69
post #40

Earlier quoted context omitted.

I've seen a ton of responses from people in the industry along the lines of "this is normal" or similar. People who work on this stuff are incredulous that there's even an issue, since everyone's health info is already being uploaded to AWS or something. This is business as usual, they say. The uproar is taken by people actually working in the business as a sign that the public are ignorant and misinformed. Things ar…

> we don't want faceless algorithms studying our most intimate personal and medical issues So you don't want an advanced algorithm to analyze your vitals and detect your cancer at an early stage? Technology has more than doubled our life expectancy. More technology could do even more so. The fact that it's a faceless algorithm, and not a creepy biased human, should be a comfort. But you're reacting like this is all g…

> So you don't want an advanced algorithm to analyze your vitals and detect your cancer at an early stage?

That’s correct, I don’t want that.

And if one day I change my mind and make the choice to opt-in to a system that works like that, I still won’t ever want Google to be involved in it.

Re: Google whistleblower: the medical data of millions of Americans is at risk

#70
post #68

Earlier quoted context omitted.

That's a very naive view of what happens. It's exactly how things are done, except that it's a one-stop shop. The reality is that there is a fig leaf of privacy. HIPPA protects you from the office staff gossiping about your medical conditions. When you are admitted to the hospital, your prescriptions are sent to data aggregators in near real-time, your claims are sent to your insurer and subrogation in near real-time…

We're talking about cloud providers here, not pharmaceutical or insurance providers. There are different levels of interaction required to accomplish different operational objectives. Giving a cloud provider this sort of access is, as I said initially, highly irregular. There is just not that same level of collaboration needed with your cloud provider. Just as a for instance, there are very good operational reasons o…

Cloud providers can provide all sorts of services. Who says they are just selling dumb storage services?

If you use Office 365, they process your data to do analytics. Some they expose to you (Delve, MyAnalytics), others they don’t.

In government, they do even more. Medicaid systems are usually run by third parties, who also sell services to providers to optimize billing.

Post reply on HN