Live data from Hacker News

Google whistleblower: the medical data of millions of Americans is at risk

theguardian.com

51–60 of 83 posts

Re: Google whistleblower: the medical data of millions of Americans is at risk

#51

What is the risk of exposing our health data? To me it is not so obvious, other than maybe embarrassment? Is it like how in our culture we don't like to talk about how much money we make? Why are all these things supposed to be secret in the first place?

Because your medical information can be used against you. Want a new job? Nope! We don't want someone with your condition on our team. Want to buy a house? Nope! An AI bot says may not live long enough to pay the loan. Want to get some ice cream? Can't haz. When you swipe your electronic payment method the database says you're at a risk for diabetes. There are thousands of other scenarios.

> Want to buy a house? Nope! An AI bot says may not live long enough to pay the loan.

Nobody cares whether you pay or not, as long as the property value isn't under water. They want you to die. If you die without an heir who can take over the payments (perhaps with the help of insurance money), they get everything you paid so far, and the property.

Re: Google whistleblower: the medical data of millions of Americans is at risk

#52

What is the risk of exposing our health data? To me it is not so obvious, other than maybe embarrassment? Is it like how in our culture we don't like to talk about how much money we make? Why are all these things supposed to be secret in the first place?

I see you skipped a lot of work because of health issues lately. That aside and completely unrelated, I think you are just not a good fit in our team.

I may not be a good person. Or I can rationalize it enough because some people pay me to minimize any risk.

Re: Google whistleblower: the medical data of millions of Americans is at risk

#53
post #40
post #6

I work for a large US based corp that focuses on technology and data services for the healthcare field. We have massive amounts of PHI for the majority of people who have visited a provider within the country. We apply all sorts of stuff to this data, ML, AI or whatever other buzzy tech you can think of. Most of this work happens within our own data centers but there is significant work done within public clouds. We…

I've seen a ton of responses from people in the industry along the lines of "this is normal" or similar. People who work on this stuff are incredulous that there's even an issue, since everyone's health info is already being uploaded to AWS or something. This is business as usual, they say. The uproar is taken by people actually working in the business as a sign that the public are ignorant and misinformed. Things ar…

One of the challenges is how do you distinguish the kinds of outrage? It seems to me like the majority of outrage is based on falsehood (Ascension is selling data to Google to use for ads). Then there are some people where the very idea of medical data being managed by cloud providers is unacceptable. The presence of the first shadows the latter and makes the whole thing come across as misinformed.

Re: Google whistleblower: the medical data of millions of Americans is at risk

#54

Earlier quoted context omitted.

Because your medical information can be used against you. Want a new job? Nope! We don't want someone with your condition on our team. Want to buy a house? Nope! An AI bot says may not live long enough to pay the loan. Want to get some ice cream? Can't haz. When you swipe your electronic payment method the database says you're at a risk for diabetes. There are thousands of other scenarios.

The can't get ice cream one is a bit far fetched eh? I'm sure that no matter if they knew my health history they would still sell me some ice cream :)

Not if the Point of Sale system won't let them.

Re: Google whistleblower: the medical data of millions of Americans is at risk

#55
post #38
post #25

Earlier quoted context omitted.

One reading of this is that it's a cross-departmental collaboration, rather than just a single division.

That's the difference everyone here is talking about though. Normally in the healthcare industry, you engage a cloud provider, and it's "you store this data for us." Full Stop. You don't look at it. You don't analyze it. You don't share it. You don't touch it. It's our data, not yours. If what you're saying is true, Ascension, for some reason, has a deal with its cloud provider that allows Google to search through, a…

[deleted]

Re: Google whistleblower: the medical data of millions of Americans is at risk

#56

What is the risk of exposing our health data? To me it is not so obvious, other than maybe embarrassment? Is it like how in our culture we don't like to talk about how much money we make? Why are all these things supposed to be secret in the first place?

Because your medical information can be used against you. Want a new job? Nope! We don't want someone with your condition on our team. Want to buy a house? Nope! An AI bot says may not live long enough to pay the loan. Want to get some ice cream? Can't haz. When you swipe your electronic payment method the database says you're at a risk for diabetes. There are thousands of other scenarios.

These are independent of any sharing. A medical provider could directly provide these features as a service without sharing any of the underlying data.

Re: Google whistleblower: the medical data of millions of Americans is at risk

#57
post #40
post #6

I work for a large US based corp that focuses on technology and data services for the healthcare field. We have massive amounts of PHI for the majority of people who have visited a provider within the country. We apply all sorts of stuff to this data, ML, AI or whatever other buzzy tech you can think of. Most of this work happens within our own data centers but there is significant work done within public clouds. We…

I've seen a ton of responses from people in the industry along the lines of "this is normal" or similar. People who work on this stuff are incredulous that there's even an issue, since everyone's health info is already being uploaded to AWS or something. This is business as usual, they say. The uproar is taken by people actually working in the business as a sign that the public are ignorant and misinformed. Things ar…

> Realize that we are absolutely horrified that this data is being shared, that a reasonable response is to say that if HIPPA is OK with this then we need stronger laws, that we don't want faceless algorithms studying our most intimate personal and medical issues at companies we never had a relationship with.

I absolutely 150% agree with you and I know others off of HN who do as well.

Re: Google whistleblower: the medical data of millions of Americans is at risk

#58
post #40

Earlier quoted context omitted.

I've seen a ton of responses from people in the industry along the lines of "this is normal" or similar. People who work on this stuff are incredulous that there's even an issue, since everyone's health info is already being uploaded to AWS or something. This is business as usual, they say. The uproar is taken by people actually working in the business as a sign that the public are ignorant and misinformed. Things ar…

But if they're just using Google as cloud storage/compute it's not being shared. Only very few Google employees would have access, they'd have very careful limitations and access on who accessed what - that's not the same as giving to google for some big AI experiment.

> Only very few Google employees would have access

That's "very few" Google employees more than zero. I expect zero Google employees to have access to my medical data. Any number above zero is absolutely not acceptable to me.

> they'd have very careful limitations and access on who accessed what

Yeah, just like Equifax, right?

Re: Google whistleblower: the medical data of millions of Americans is at risk

#59
post #33

> Two simple questions kept hounding me: did patients know about the transfer of their data to the tech giant? Should they be informed and given a chance to opt in or out? That's literally what HIPAA was created to address. The user doesn't have to opt-in to every single solitary business that touches their data, because there is a chain of business contracts that explicitly dictate what they can do, that originates…

> This is like "blowing the whistle" because your dentist sent your dental impression to a company to create a crown for you. I see a huge difference here, though. the company making my crown doesn't get my complete medical records. They get what is necessary to make the crown. Google is getting everything, to use for purposes beyond the patient's immediate medical needs. > That's literally what HIPAA was created to…

> Google is getting everything, to use for purposes beyond the patient's immediate medical needs.

That claim was never made anywhere in this whistleblower account. Furthermore, it's illegal, and anyone working with health care records knows that. You can't use the records for anything other than what was covered by the business associate contract.

It's clear from the letter that the whistleblower literally has no idea at all what's going on, so they got frightened and yelled fire, in hopes that somebody who knows more than them will come and look for a fire.

If they did about 30 minutes of research, they'd know that any person whose records are covered by this agreement has the legal right to request from Google all information about how their medical records are being used. All they'd need to do is ask 8 random people to request records from Google, and one of them might be covered. They could then find out the answer, or at least have some kind of evidence of a lack of process or oversight. They have provided none.

Multiple times in the letter they mention that the public must consent to this. There is no law requiring this, so really the whistleblower is trying to assert their own opinions about public policy, and using the veiled threat of malfeasance to get press time.

I'd expect this anonymous source to out themselves soon so they can lead some kind of public demand for more visibility (hence more regulation). Which might be good, except the HHS (which actually regulates HIPAA claims) already doesn't enforce it much at all. So it's probably just going to be used as a political tool to gain votes without actually improving people's lives.

Re: Google whistleblower: the medical data of millions of Americans is at risk

#60
I created this anon account because I don't want to lose my job.

I work at a major hospital/university as a research engineer and, 100%, the whole system is completely broken. Using our hospital and the 10 or so other major hospitals we work with as my source, I cannot come to any other conclusion.

HIPAA is constantly touted as the reason to push more and more CYA hurdles on to the staff's day to day interactions. One of the hospital I work with has an email system where you receive a notification (via email) that you have a message from xyz@majorhospital.com, in the body is a link you have to click through to reach a "secure" portal, then you 2FA, just to read an email someone sent _you_ (with no PII).

While the system that actually handle all the PII are basically rubber stamped with no real security reviews. Prototypes I've built that should never pass a security review, regularly do and get let out into the wild. I've been screaming from the top of a mountain for years and all I ever hear back is that it would cost too much, or prolong the dev cycle, or . If I counter with "I can't believe this will pass HIPAA muster," the answer is always the same: "It passed the review and that is what matters."

When that something eventually happens, we can say we went through the proper vetting with the review team and that's it, next to no liability for building crap infrastructure. Of course the security review team will say, they used an analysis software that cleared everything so it's not their fault. Finally the company that made that software will say it's not perfect, but it got certified by XYZ, and just like that the whole thing blows over.

The hospital itself is what facilitates this shifting of responsibility, they pays millions upon millions of dollars for any software claiming to securely retain and protect PII, when all to often that software isn't even in beta, let all vetted and hardened. But hey, they got some certification that the hospital can point to and say "It wasn't us." Every year there is some new thing we are supposed to do that feign interest in security, but the weakest links just keep getting weaker. No one cares about your personal information, hospitals only care that they aren't liable when your personal information getting leaked.

I literally lie to my doctor, not because I don't trust her, but because I know that it's just a matter of time before my information is out there.

Post reply on HN