Live data from Hacker News

Google whistleblower: the medical data of millions of Americans is at risk

theguardian.com

71–80 of 83 posts

Re: Google whistleblower: the medical data of millions of Americans is at risk

#71

I created this anon account because I don't want to lose my job. I work at a major hospital/university as a research engineer and, 100%, the whole system is completely broken. Using our hospital and the 10 or so other major hospitals we work with as my source, I cannot come to any other conclusion. HIPAA is constantly touted as the reason to push more and more CYA hurdles on to the staff's day to day interactions. On…

hey — i'm a journalist at the New York Times. I'd like to chat more about this with you if you're interested. you can reach me at charlie.warzel@nytimes.com or via protonmail cwarzel@protonmail.com

Re: Google whistleblower: the medical data of millions of Americans is at risk

#72
post #69

Earlier quoted context omitted.

> we don't want faceless algorithms studying our most intimate personal and medical issues So you don't want an advanced algorithm to analyze your vitals and detect your cancer at an early stage? Technology has more than doubled our life expectancy. More technology could do even more so. The fact that it's a faceless algorithm, and not a creepy biased human, should be a comfort. But you're reacting like this is all g…

> So you don't want an advanced algorithm to analyze your vitals and detect your cancer at an early stage? That’s correct, I don’t want that. And if one day I change my mind and make the choice to opt-in to a system that works like that, I still won’t ever want Google to be involved in it.

Given that early detection increases chances of survival[1] considerably, you may not have a chance to opt-in later. Which raises interesting questions about whether society might force you to participate in having your data analyzed, similar to say, vaccinating.

1: https://www.canaryfoundation.org/wp-content/uploads/EarlyDet...

Re: Google whistleblower: the medical data of millions of Americans is at risk

#73
post #29

Earlier quoted context omitted.

Then you should blame the industry rather than a newcomer to the industry who tries to follow the industry standard?

No one should be excused for unethical behavior just because it’s standard industry practice.

Who is being accused of being unethical?

Re: Google whistleblower: the medical data of millions of Americans is at risk

#74
Disclaimer: Googler here, my opinions are my own.

I have no non-public knowledge of this topic besides these two Guardian reports, and the Google public blog post on the same subject[1].

I do, however, have nearly a decade in non-Google work experience working in clinical documentation technologies for a company who had BAAs with literally dozens of health companies.

I simply do not understand the objection this whistle-blower is raising. As far as I understand it, the controversy is simply because Google is involved.

> Above all: why was the information being handed over in a form that had not been “de-identified"

DeID is typically used at the edges of an IT system, and is tailored to the rights of certain users accessing the system. If you have a system that says, "A ha! There's a patient with a 5mm AAA with no evidence of follow-up! They need a procedure STAT!", you obviously need to have the original documentation to know who to contact.

There are ways to keep PHI (identifying info) separated from documentation, but if Google is both the cloud storage provider and doing R&D, both sides of that system would fall on the Google side of the fence.

The bulk transfer of documents was almost certainly done via HL7v2 messages which, IIRC, don't have any built-in mechanism for redacting PHI, and if it did usually health systems lack the expertise do this consistently between all BAAs they contract with.

> I was worried too about the security aspect of placing vast amounts of medical data in the digital cloud.

I mean, yeah, this is an important set of data. In previous years the issues were people walking out of the health system with their laptop and it getting stolen with 1ks of records on it. Cloudification has certainly reduced the vectors to steal large quantities of data.

> data potentially being handed on to third parties;

Their BAA specifically prevents this.

> adverts one day being targeted at patients according to their medical histories.

Again, the law specifically prevents this use. These are all hypothetical scenarios.

> Full HIPAA compliance must be enforced, and boundaries must be put in place to prevent third parties gaining access to the data without public consent.

There simply is no evidence that full HIPAA compliance isn't being followed.

> Employees at big tech companies having access to personal information

Thousands of employees at Ascension have this level of access. I personally had access to millions of health care records. BUT! There were auditing systems in place. If you attempted to use that access outside of the scope of your job, you're fired, no second chance.

> To quote one of my role models, Luke Skywalker: “May the force be with you”.

Are you kidding me? Is this satire?

> In short, patients and the public have a right to know what’s happening to their personal health information at every step along the way.

In short, the concerns here are all hypothetical. There's no basis of any wrong doing. There is no proposal to actually address these concerns in a practical way.

[1] https://cloud.google.com/blog/topics/inside-google-cloud/our...

Re: Google whistleblower: the medical data of millions of Americans is at risk

#76
post #32

What is the risk of exposing our health data? To me it is not so obvious, other than maybe embarrassment? Is it like how in our culture we don't like to talk about how much money we make? Why are all these things supposed to be secret in the first place?

Would you want future employers, romantic partners, loan officers, and/or family members to know your medical history? What if you were HIV+ or taking Viagra? What if you were just sick and didn’t want to be discriminated against? There are life and death implications in medical privacy in most countries. Stigma is real, as are insurance risk algorithms.

So... You are advocating that your hiv status should be hidden from your romantic partner? ;) More seriously, unified health record sharing is inevitable, especially if we are to move to universal healthcare. Would you be against a different entity hosting this data, or just Google?

Re: Google whistleblower: the medical data of millions of Americans is at risk

#77
post #66

Earlier quoted context omitted.

> I work for a large US based corp that focuses on technology and data services for the healthcare field. We have massive amounts of PHI for the majority of people who have visited a provider within the country. The real question here is: why can't I opt-out ? I want a easy button when I do anything medical to say "no, don't use my health data for any of this stuff". And the current CA privacy law does not provide th…

GDPR does not provide this unfortunately. Just last week a bill in Germany was enacted which allows the medical data of all insured people to be shared with medical companies. There is no opt-out.

I believe GDPR does provide that, but consent is not required to process data if that processing is "necessary for compliance with a legal obligation to which the controller is subject". So if an EU member state makes a law that requires insurance companies to export your medical data wholesale to medical companies, GDPR does not give you an option to opt out. Really the only solution there is either to a) move elsewhere b) vote for people who don't want to enact such laws.

Re: Google whistleblower: the medical data of millions of Americans is at risk

#78
This strikes me as a whistleblower fail.

The story isn't, "I know that something bad happened", as whistleblowing is supposed to mean. Instead they complain that essentially, "I am not personally privy to the consent requirements and privacy protections required, nor do I know what has been implemented." Which... congratulations on not being important, I guess?

But in particular, this person gives an emotional plea that people must be given the explicit opportunity to "opt-out", not from the medical research in general, but from any subset of research conducted in collaboration with Google, specifically because it's Google, rather than another research contractor.

I donno. Should Internet users be given the opportunity to opt-out from having their IP packets transit fiber owned by AT&T? I mean, sure I agreed to a bunch of stuff when I signed up with my ISP, but my provider is Comcast. They never mentioned AT&T. And some of those packets might not me encrypted....

Re: Google whistleblower: the medical data of millions of Americans is at risk

#79

I created this anon account because I don't want to lose my job. I work at a major hospital/university as a research engineer and, 100%, the whole system is completely broken. Using our hospital and the 10 or so other major hospitals we work with as my source, I cannot come to any other conclusion. HIPAA is constantly touted as the reason to push more and more CYA hurdles on to the staff's day to day interactions. On…

Stuff like this is everywhere. I used to work for a company that had millions of credit profiles. We had the chief of IT spending enormous amounts of time to make things "secure," but in the meantime junior PMs (and pretty much everyone else too) had access to a web portal where they could decrypt and inspect anyones credit information, address, name, etc. Inspecting the personal financial details of people in our system was something employees would do on a lark. We had a horrible password manager that nobody used, so the passwords that were employed to validate logins to this portal were literally the names of the employees with one or two extra characters. No 2FA, no IP address restriction, nothing.

We would deploy enormous resources to protect something if IT believed that had a legal requirement to do so (and make a lot of noise about how "secure" we were), but we would leave treasure chests of information sitting around in the open if there wasn't a box they needed to check saying "don't leave unattended treasure chests of private data in the open."

If anything this convinced me that the regulations surrounding this sort of thing are a joke. We don't need rules about security or how to build X - IT will just see a list of boxes, check them, and then ignore everything not specifically enumerated. We need a white hat law for certifying hacking teams that can legally try to crack corporations with sensitive data. If they succeed, the company has to pay enormous fines _to the team that hacked them_ and solve the problem or get their certifications/contracts revoked.

Re: Google whistleblower: the medical data of millions of Americans is at risk

#80
post #32

Earlier quoted context omitted.

Would you want future employers, romantic partners, loan officers, and/or family members to know your medical history? What if you were HIV+ or taking Viagra? What if you were just sick and didn’t want to be discriminated against? There are life and death implications in medical privacy in most countries. Stigma is real, as are insurance risk algorithms.

So... You are advocating that your hiv status should be hidden from your romantic partner? ;) More seriously, unified health record sharing is inevitable, especially if we are to move to universal healthcare. Would you be against a different entity hosting this data, or just Google?

> You are advocating that your hiv status should be hidden from your romantic partner?

No, I'm advocating that a corporation or data leak does not get to decide when/how someone's HIV status is revealed.

> Would you be against a different entity hosting this data, or just Google?

I would be against most entities hosting this data, but Google has proved to be untrustworthy.

My ideal situation would be for my medical records to be encrypted and only usable with my explicit permission.

Post reply on HN