What is actually happening here? A lot of rhetoric about the "Transfer of data" etc, but other times this just reads like a Google Cloud Infrastructure play, with some consulting on top. Also - The deal was only just signed, e.g. the transfer hasn't happened yet? There's a lot of hearsay in all of this reporting...
Seems like a lot of fake news over a cloud storage deal https://cloud.google.com/blog/topics/inside-google-cloud/our...
Google's harvest of medical data includes names and full details of millions
21–30 of 120 posts
Re: Google's harvest of medical data includes names and full details of millions
#22Any google employees/friends of google employees here with insight as how staff is receiving this news? My guess is like all other egregious abuses of power, the employees will stage a "protest" to feel good about themselves then keep working there.
After all, many companies trial new ideas and technology in house.
So would be insightful into what companies like Google do inhouse.
Re: Google's harvest of medical data includes names and full details of millions
#23This is the most scary part[0]. I'm sure plenty here would disagree, but I simply don't (yet) share your optimism for A.I.
[0] Not that the rest isn't scary.
Re: Google's harvest of medical data includes names and full details of millions
#24So what do we do to stop this? What recourse do people directly affected by this have?
login, click on the wheel, and the delete link is at the bottom.
Re: Google's harvest of medical data includes names and full details of millions
#25Earlier quoted context omitted.
The article says that it might be: "According to the whistleblower, the security fears raised at that meeting, including concerns that the transfer may be in breach of federal HIPAA rules on data privacy, have so far gone unanswered by Google." That said, most people do not understand how HIPAA works (I am in no way saying you are one of these people). Unless you are a healthcare provider (think doctor) or a business…
I am indeed someone who doesn’t understand how HIPAA works. I have seen instances of healthcare professionals getting jail time for disclosing celebrity health records however. How is google able to legally get access to these records? I suspect they’re not and if so, someone should be held criminally liable for this. If google is able to get these, what’s stopping anyone else?
It doesn't preclude other crimes whether from hackers but doesn't technically guarantee them in Google's part. Technically the provider could have just given sensitive information like complete idiots because they were asked.
Re: Google's harvest of medical data includes names and full details of millions
#26How is this not a criminal breach of HIPAA laws? https://www.hhs.gov/hipaa/for-individuals/guidance-materials...
Re: Google's harvest of medical data includes names and full details of millions
#27Earlier quoted context omitted.
The article says that it might be: "According to the whistleblower, the security fears raised at that meeting, including concerns that the transfer may be in breach of federal HIPAA rules on data privacy, have so far gone unanswered by Google." That said, most people do not understand how HIPAA works (I am in no way saying you are one of these people). Unless you are a healthcare provider (think doctor) or a business…
I am indeed someone who doesn’t understand how HIPAA works. I have seen instances of healthcare professionals getting jail time for disclosing celebrity health records however. How is google able to legally get access to these records? I suspect they’re not and if so, someone should be held criminally liable for this. If google is able to get these, what’s stopping anyone else?
Having said that, my job in the healthcare IT world is building interfaces, i.e. facilitating the transfer of health data from one system to another. Most likely what's going on here is Google and Ascension have a project together, and part of that project is either an interface or a data dump from Ascension to Google for the purposes stated in the article. I haven't read all the information, but generally the data will be "de-identified", which some interpret as sufficient to avoid HIPAA violations.
Neither company is small or ignorant; they both had their lawyers look at the contract and they signed off on it. So either the lawyers at both companies are mistaken or mislead, or somewhere after the initial scoping the scope changed (which, btw, happens all the time) and nobody updated legal or felt the need to update management or raise a concern
And that's concerning, regardless of which option it is. Either the legal teams at both companies are ill-informed or outright ignorant (perhaps intentionally), or there are no checks -- and no responsible project managers -- in place to prevent this from occurring. Somewhere along the line, someone should have suggested that this was perhaps not cool, and taken the issue up the chain of command. Most healthcare companies have a well established process in place for that, and I can't believe either of these would be different in that respect.
Re: Google's harvest of medical data includes names and full details of millions
#28Earlier quoted context omitted.
Seems like a lot of fake news over a cloud storage deal https://cloud.google.com/blog/topics/inside-google-cloud/our...
This is not "fake news" at all. This is the same factual event covered with a different spin. Use of the term "fake news" to describe reporting that is merely slanted in a direction you don't like--rather than presenting demonstrably false information as fact--is completely unwarranted, and is doing terrible damage to our social institutions.
Re: Google's harvest of medical data includes names and full details of millions
#29Any google employees/friends of google employees here with insight as how staff is receiving this news? My guess is like all other egregious abuses of power, the employees will stage a "protest" to feel good about themselves then keep working there.
[0]: https://www.zdnet.com/article/google-employees-protest-dont-...
[1]: https://www.theverge.com/2019/7/16/20695964/google-protest-l...
[2]: https://www.cnn.com/2019/05/01/tech/google-employees-protest...
[3]: https://www.vox.com/recode/2019/6/19/18691870/google-employe...
[4]: https://www.theverge.com/2019/5/1/18525473/google-employee-s...
Re: Google's harvest of medical data includes names and full details of millions
#30Earlier quoted context omitted.
The article says that it might be: "According to the whistleblower, the security fears raised at that meeting, including concerns that the transfer may be in breach of federal HIPAA rules on data privacy, have so far gone unanswered by Google." That said, most people do not understand how HIPAA works (I am in no way saying you are one of these people). Unless you are a healthcare provider (think doctor) or a business…
I am indeed someone who doesn’t understand how HIPAA works. I have seen instances of healthcare professionals getting jail time for disclosing celebrity health records however. How is google able to legally get access to these records? I suspect they’re not and if so, someone should be held criminally liable for this. If google is able to get these, what’s stopping anyone else?
Per their press release (https://cloud.google.com/blog/topics/inside-google-cloud/our...), Google is playing the role of a BA as a part of this deal. They have signed a business associate agreement (BAA), as HIPAA requires. This agreement will have defined the permitted uses for the PHI that Ascension is transmitting to Google.
Basically this all sounds utterly ordinary. It's 2019 and even healthcare companies want to be in The Cloud (and especially want to be associated with AI and ML). My last company stored lots PHI in AWS. AWS signed a BAA with us. Now, if someone at Google with access to this PHI misuses it (e.g., accesses it for an invalid reason or sells it on the black market), then they could be in violation of HIPAA and face penalties. But the mere fact that a covered entity is transferring data to a business associate in no way suggests a HIPAA violation its own.
(Disclosure: I work at Google, but know nothing about this project.)