If entering into a BAA under HIPAA for work involving PHI is “harvest”, and you're worried that this reaches “millions” for Google, you probably don't want to think about the deals public and private firms in the healthcare and health insurance/payments space have with Amazon and Microsoft. From the news article (I don't have time to review the source leak indepently) there doesn't seem to be anything really concerni…
Google's harvest of medical data includes names and full details of millions
111–120 of 120 posts
Re: Google's harvest of medical data includes names and full details of millions
#112What is actually happening here? A lot of rhetoric about the "Transfer of data" etc, but other times this just reads like a Google Cloud Infrastructure play, with some consulting on top. Also - The deal was only just signed, e.g. the transfer hasn't happened yet? There's a lot of hearsay in all of this reporting...
Honesty it’s one of the areas where (in the right hands) I think the benefits of collecting large amounts of data for targeting services to people is justified.
Is Google ‘the right hands’? That’s probably worth debating.
Re: Google's harvest of medical data includes names and full details of millions
#113Earlier quoted context omitted.
My view is that consent is oversold. If I "consent" to a boilerplate agreement handed me moments before an action is taken, have I really? Boundaries and distributions should be clearly, specifically specified, with any non-essential distributions requiring specific assent, defaulting to none. If there are consequences to sharing, those can be made known. We've been drawn into a circumstance which has long been unten…
> If I "consent" to a boilerplate agreement handed me moments before an action is taken, have I really? Obviously you have not . I wouldn't say this is consent being "oversold", but rather yet another way that the concept of consent is being actively undermined into a legal fiction. This is also why the GDPR has the provision for revoking permission to your data at any time - to counter its rights being otherwise nul…
Re: Google's harvest of medical data includes names and full details of millions
#114Earlier quoted context omitted.
> patients should get notified and paid every time someone uses an element of their data I don't know about most people here, but I wouldn't say that. Notification or being paid is beside the point. The point is that informed consent should be obtained. You're right that blanket consent forms don't count as "informed consent" for this sort of thing because they don't actually inform you. > Personally, that seems like…
> you'd have no problem giving such consent. I, however, would not be willing to give such consent. That logic only works if you don't still benefit from the research findings that are obtained from my data. e.g. "tragedy of the commons"
What you're proposing is that everyone should be subjected to spying because it may lead to some theoretical larger good. That argument also conveniently ignores the theoretical social and personal costs of that spying.
What I'm saying is that everyone has rights that include the right to not be spied on, and a theoretical larger good is not nearly a solid enough reason to strip me of rights.
Getting consent is a way to avoid this deadlock and make everyone happy as well as ensure that nobody get trampled.
Now, while I would never give Google consent for data collection from me, that's because I have zero trust in Google. However, if we're just talking about consent in the general sense, then it's certainly possible to make an argument that would get me to agree to share data. In fact, I do so with a few entities already.
Re: Google's harvest of medical data includes names and full details of millions
#115Earlier quoted context omitted.
The problem is that Googlers (like far too many tech companies) view data as being secure if outsiders can't get access to it. They don't count access by themselves as a security issue, even though it objectively is.
Googler here. I don't speak for Google and obviously shouldn't and won't divulge internals, but this just makes me cringe so hard: unauthorized or illegitimate access by staff is OBVIOUSLY treated as a security issue. I'm kind of shocked that folks would think otherwise.
Re: Google's harvest of medical data includes names and full details of millions
#116Earlier quoted context omitted.
> As others have said, entering into a BAA with a covered entity, as HIPAA defines it, shouldn't be seen as a controversial action. You place more faith in HIPAA than I do. HIPAA does not protect privacy to the degree that most people assume. > There are numerous problems in healthcare that are too complex for individual health systems to tackle. True, but that doesn't mean that Google is the right entity to do this.…
> You place more faith in HIPAA than I do. HIPAA does not protect privacy to the degree that most people assume. That's correct. People would be surprised at the number of HIPAA violations that happen everyday. It is, however, among the strongest and most well-enforced data privacy laws (in the US). > True, but that doesn't mean that Google is the right entity to do this. In my opinion, they're the wrong entity, beca…
Practically speaking, that's up to the company -- but the company needs to make sure that their clients are informed and are able to withdraw their data if they're concerned.
The larger part of what's wrong with this particular deal is that it was done in secret. Patients and doctors were not informed of this until after data has begun to be transferred. They should have been, and patients should have been given the option to remove their data from the dataset and find another health care provider if they wish.
> Personally, it's more important to me to be able to actually know how much a procedure is going to cost rather than who owns the AI stack behind their clinical decision support system.
I agree that knowing costs is very important, but we're miles away from that being a thing that is possible. In the meantime, I think it's important not to backslide in other areas such as this one.
I'd also say that my concern isn't really about who owns the stack, or the cloud. That sort of battle was lost years ago. My concern is the ability of Google to access that information.
Re: Google's harvest of medical data includes names and full details of millions
#117Earlier quoted context omitted.
> As others have said, entering into a BAA with a covered entity, as HIPAA defines it, shouldn't be seen as a controversial action. You place more faith in HIPAA than I do. HIPAA does not protect privacy to the degree that most people assume. > There are numerous problems in healthcare that are too complex for individual health systems to tackle. True, but that doesn't mean that Google is the right entity to do this.…
> You place more faith in HIPAA than I do. HIPAA does not protect privacy to the degree that most people assume. Can anyone elaborate?
Re: Google's harvest of medical data includes names and full details of millions
#118Earlier quoted context omitted.
> To give you an idea of the scale, I have two examples. The first is MD Anderson Cancer Center in Houston. They used to have 200+ engineers working on their sophisticated home-grown EMR. It was a huge undertaking. But even with MDACC revenue, that development was unsustainable, and they moved to a 3rd party EMR vendor. I'm not certain what aspect you are trying to highlight with this example, but readers should know…
The point is that even MDACC figured out is was too expensive to continue their own EMR. You're correct in that literal books could be written about EMR adoption gone wrong. That doesn't change the fact that even super huge mega-health systems can't afford to do it all themselves.
I think then that the example does not prove your point. It would have been vastly better, financially and medically, for MDACC to have continued with their in-house EMR.
Re: Google's harvest of medical data includes names and full details of millions
#119Re: Google's harvest of medical data includes names and full details of millions
#120Earlier quoted context omitted.
The point is that even MDACC figured out is was too expensive to continue their own EMR. You're correct in that literal books could be written about EMR adoption gone wrong. That doesn't change the fact that even super huge mega-health systems can't afford to do it all themselves.
> The point is that even MDACC figured out is was too expensive to continue their own EMR. I think then that the example does not prove your point. It would have been vastly better, financially and medically, for MDACC to have continued with their in-house EMR.
...until they (too) fall victim to "a rogue engineer" (or a "patient") coming in and plugging something into an open USB port on the workstation.