So what do we do to stop this? What recourse do people directly affected by this have?
Go to fitbit and delete your data. I just did; it's pretty painless. login, click on the wheel, and the delete link is at the bottom.
> Go to fitbit and delete your data.
That has no effect on the central theme of the story (which is health care firms partnering with Google as a Business Associate, and thereby sharing patient data).
Any google employees/friends of google employees here with insight as how staff is receiving this news? My guess is like all other egregious abuses of power, the employees will stage a "protest" to feel good about themselves then keep working there.
Unlike other companies Google employees atleast protest. In many cases they win. No company is a saint. It's a bit rich asking everyone to leave their jobs. 99% of HN will work for the most money. Google still tries its best unlike Facebook or Oracle. None of the good things it does ever get attention.
> Does anybody enforce this or do we just take Google at their word? Yes, the DHHS Office of Civil Rights enforces HIPAA Privacy and Security rules. That enforcement is reactive of there is no independent regular compliance certification or monitoring required, however, which is a weakness, but the fact that detection of violation can lead to personal as well as institutional penalties, and that those penalties are c…
Thank you. So this department has the authority and capability to ensure (to a reasonable degree) that Google does not abuse this data?
They have the job of doing so for the whole healthcare industry; and certainly have the authority. Capability is a question I'm less comfortable answering, but I would say that I see no evidence that they have a Google-specific problem in that regard. There is definitely a lot that could be done to improve enforcement capacity in the health data privacy and security space, and that's definitely something that should be pursued independently of whether some firms choose Google as BA.
If entering into a BAA under HIPAA for work involving PHI is “harvest”, and you're worried that this reaches “millions” for Google, you probably don't want to think about the deals public and private firms in the healthcare and health insurance/payments space have with Amazon and Microsoft. From the news article (I don't have time to review the source leak indepently) there doesn't seem to be anything really concerni…
Not defending the article (I’ve not read it), but I suppose I probably would be horrified with the status quo. I really wish we had a more consent based data culture. I suppose I don’t know how that would be designed. But lots of real things are horrifying and it’s not necessarily fine just that something is normal.
If entering into a BAA under HIPAA for work involving PHI is “harvest”, and you're worried that this reaches “millions” for Google, you probably don't want to think about the deals public and private firms in the healthcare and health insurance/payments space have with Amazon and Microsoft. From the news article (I don't have time to review the source leak indepently) there doesn't seem to be anything really concerni…
Why do you think Amazon purchased PillPack ;)
However, their little snafu with SureScripts and Remy Health just got them banned from accessing healthcare history - however there are pending FBI and FTC investigations regarding their mis-management of healthcare data. Worst case, the digital pharmacy Amazon just bought will be barred from sending or receiving digital prescriptions and their HIPAA accreditation will be voided for three years (with a fine).
Seems like a great way to waste a couple hundred million dollars.
> Google could go on to use its AI analytics to predict outcomes for individual patients, they posited. This is the most scary part[0]. I'm sure plenty here would disagree, but I simply don't (yet) share your optimism for A.I. [0] Not that the rest isn't scary.
Ubers ai won't even slow down when it sees a person in the road. A computer can prescribe a drug for me, but I can't prescribe a drug for me?
Instead of down voting me, you could reply saying that this article has new details (like the leaked presentation). I just assumed it was a repost of yesterday's discussion.
> and patient data cannot and will not be combined with any Google consumer data. Does anybody enforce this or do we just take Google at their word?
Does anyone enforce any law?
Your point is valid, but I think there was a mis-read or mis-statement. The parent comment probably should have addressed the difficulty of enforcing such provisions.
I wonder if this is not a coincidence given acquisition of fitbit.
I suspect the Fitbit acquisition is more to have a product that competes with Apple's and Samsung's smartwatch offerings. At this point it seems like having a watch that integrates with your phone offerings is table stakes, and I don't think Google had that.
This is not "fake news" at all. This is the same factual event covered with a different spin. Use of the term "fake news" to describe reporting that is merely slanted in a direction you don't like--rather than presenting demonstrably false information as fact--is completely unwarranted, and is doing terrible damage to our social institutions.
This is a TEXTBOOK case of fake news - a newspaper owned by Google competitor spinning purchase of space on encrypted Cloud Storage and Google Apps productivity suite as a big medical data mining attempt by Google to drive a political agenda. There are obvious concerns around data security here, but the article is very heavily distorting facts to drive outrage.
No, it really isn't. The Guardian article is factually reporting on what the "whistleblower" told them, both via the video and in a separate interview. They did not fabricate any details, or make any claims they knew to be false. They made a cursory attempt to present the other side of the story. Sensationalized, yes. Slanted, yes. But not fake.