Live data from Hacker News

Google's harvest of medical data includes names and full details of millions

theguardian.com

41–50 of 120 posts

Re: Google's harvest of medical data includes names and full details of millions

#41
post #37

Earlier quoted context omitted.

> and patient data cannot and will not be combined with any Google consumer data. Does anybody enforce this or do we just take Google at their word?

Does anyone enforce any law?

When there's an obvious breach, hopefully. How would we even know if Google were abusing this data though? Does anyone have access to it besides Google? Are we literally asking Google to regulate itself with this data?

EDIT: I guess I don't understand. Once we give Google the sensitive information, how do we have any way of knowing what they do with it? I'm guessing an audit on all of Google's data is out of the question.

Re: Google's harvest of medical data includes names and full details of millions

#42
If entering into a BAA under HIPAA for work involving PHI is “harvest”, and you're worried that this reaches “millions” for Google, you probably don't want to think about the deals public and private firms in the healthcare and health insurance/payments space have with Amazon and Microsoft.

From the news article (I don't have time to review the source leak indepently) there doesn't seem to be anything really concerning here. The closest to an indication of anything wrong seems to be that someone raised an issue about the risk of improper employee use of data and a need for training around that in an internal meeting on the project and has not received a formal specific response on that issue from corporate leadership. Having spent a long time in HIPAA-related work, that neither that issue being raised in regard to a new project or the fact that it was raised being merely one of many inputs into a policy generating process that makes general adjustments considering a wide range of concerns, legal parameters, and other issues but not receiving a specific direct response seems...pretty typical. And HIPAA does not require notification or opt-in (or even opt-out opportunity) for data sharing between a covered entityand Business Associate, as BA’s are (while under HITECH independently subject to HIPAA privacy and security rules) basically considered institutional agents of the covered entity to which the covered entity’s authority to have and use data is delegated under the Business Associate agreement.

I don't know if there is really nothing of concern in the dump or the journalists covering it don't have enough understanding of the domain to even distinguish things that would indicate a problem, but what it looks like from the news article is a “whistleblower” making accusations and dumping docs, but nothing substantial and concrete in the docs supporting the thrust of the “whistleblower’s” accusations of wrongdoing.

Re: Google's harvest of medical data includes names and full details of millions

#43
post #33

Earlier quoted context omitted.

Seems like a lot of fake news over a cloud storage deal https://cloud.google.com/blog/topics/inside-google-cloud/our...

Did you even read the article you linked to? > What is the work we’re doing with Ascension? Back in July, on our Q2 earnings call, we announced “Google Cloud’s AI and ML solutions are helping healthcare organizations like Ascension improve the healthcare experience and outcomes. "AI and ML solutions" sounds like a lot more than just data storage. They have complete access to the entire database of names, addresses, m…

> If I had a nickel for every time a tech giant outright lied about how they handle data, I'd be able to afford SV rent.

Maybe we can get them to pay when they lie?

Re: Google's harvest of medical data includes names and full details of millions

#44
post #31

Earlier quoted context omitted.

Important part: >What about patient data? All of Google’s work with Ascension adheres to industry-wide regulations (including HIPAA) regarding patient data, and come with strict guidance on data privacy, security and usage. ... To be clear: under this arrangement, Ascension’s data cannot be used for any other purpose than for providing these services we’re offering under the agreement, and patient data cannot and wil…

> and patient data cannot and will not be combined with any Google consumer data. Does anybody enforce this or do we just take Google at their word?

> Does anybody enforce this or do we just take Google at their word?

Yes, the DHHS Office of Civil Rights enforces HIPAA Privacy and Security rules. That enforcement is reactive of there is no independent regular compliance certification or monitoring required, however, which is a weakness, but the fact that detection of violation can lead to personal as well as institutional penalties, and that those penalties are criminal as well as civil, means it's not a risk that decision-makers tend to be willing to take on just because it would (so long as undetected) provide a business opportunity.

Re: Google's harvest of medical data includes names and full details of millions

#45

Earlier quoted context omitted.

> and patient data cannot and will not be combined with any Google consumer data. Does anybody enforce this or do we just take Google at their word?

> Does anybody enforce this or do we just take Google at their word? Yes, the DHHS Office of Civil Rights enforces HIPAA Privacy and Security rules. That enforcement is reactive of there is no independent regular compliance certification or monitoring required, however, which is a weakness, but the fact that detection of violation can lead to personal as well as institutional penalties, and that those penalties are c…

Thank you. So this department has the authority and capability to ensure (to a reasonable degree) that Google does not abuse this data?

Re: Google's harvest of medical data includes names and full details of millions

#46
post #14
post #9

Earlier quoted context omitted.

The article says that it might be: "According to the whistleblower, the security fears raised at that meeting, including concerns that the transfer may be in breach of federal HIPAA rules on data privacy, have so far gone unanswered by Google." That said, most people do not understand how HIPAA works (I am in no way saying you are one of these people). Unless you are a healthcare provider (think doctor) or a business…

I am indeed someone who doesn’t understand how HIPAA works. I have seen instances of healthcare professionals getting jail time for disclosing celebrity health records however. How is google able to legally get access to these records? I suspect they’re not and if so, someone should be held criminally liable for this. If google is able to get these, what’s stopping anyone else?

> How is google able to legally get access to these records

As a Business Associate of a health care provider organization, with an agreement in place binding them to the same rules for that data the principal they serve would have, which is enforceable not only by the principal, and by patients, but also directly against Google by the government.

> If google is able to get these, what’s stopping anyone else?

Nothing is stopping anyone else from offering the kinds of services to health care providers and insurers that involve patient data under a BAA; most health care providers and insurers have numerous Business Associates performing various functions involving patient data, including, in many cases, large tech firms like Microsoft, Amazon, and, sure, Google. If anything, Google is behind in this space in terms of volume because of Amazon, Microsoft, and some more specialized forms in the healthcare space have stronger enterprise sales positions in general, and, especially for Microsoft and some of the more specialized forms, more established relations with firms in the space that make it a lower “activation energy” to engage those firms as BAs.

Re: Google's harvest of medical data includes names and full details of millions

#48
I fear all of this will be used as part of a prediction program to find the best employees based on performance metrics. Imagine if before you even gave an applicant a callback you could see if they've ever had a bout of depression, insomnia, anything that may affect their job performance or the performance of their team. That would be standard part of any background check if that information was available.

Re: Google's harvest of medical data includes names and full details of millions

#49
post #33

Earlier quoted context omitted.

Seems like a lot of fake news over a cloud storage deal https://cloud.google.com/blog/topics/inside-google-cloud/our...

Did you even read the article you linked to? > What is the work we’re doing with Ascension? Back in July, on our Q2 earnings call, we announced “Google Cloud’s AI and ML solutions are helping healthcare organizations like Ascension improve the healthcare experience and outcomes. "AI and ML solutions" sounds like a lot more than just data storage. They have complete access to the entire database of names, addresses, m…

> AI and ML solutions" sounds like a lot more than just data storage.

Everyone in the space, from providers (well, the ones big enough to) to insurers (essentially all of which are big enough to), is looking at AI and ML solutions for clinical, fraud detection, or other purposes, whether in house, or via Business Associates, or (probably most commonly for large orgs) a combination, and much of that involves BAs with cloud firms that also provide AI/ML solutions like Amazon, Google, and Microsoft. From everything I've seen, Amazon and Microsoft are getting a lot more of that business than Google, because of their established relationships and stronger enterprise sales.

Re: Google's harvest of medical data includes names and full details of millions

#50
post #13
post #8

So what do we do to stop this? What recourse do people directly affected by this have?

GDPR should kick in long before medical data is on the table.

GDPR will only occasionally and coincidentally (if at all) be relevant to health data held by US health care providers and their business associates, whereas HIPAA will always be relevant.
Post reply on HN