Live data from Hacker News

Google's harvest of medical data includes names and full details of millions

theguardian.com

91–100 of 120 posts

Re: Google's harvest of medical data includes names and full details of millions

#91
post #87
post #67

I know I'm very much in the minority here, but just like we should have more open borders and more open software, we should encourage more openness around medical data. Google and other large companies have made some significant AI advances in the last decade & I think it's in all of our interests to see if these advances can lead to improvements in health care. Yes, it's scary how much data these companies have coll…

> we should encourage more openness around medical data. Encouraging is fine, but in the end, consent from individuals should be obtained and if it isn't, that data should be omitted.

Well, I think most people in this comments section would say "blanket consent when signing hospital forms is unacceptable and patients should get notified and paid every time someone uses an element of their data".

If that's the standard society wants to adopt, so be it- But it might come at a dramatic cost in slowing down medical innovations. Personally, that seems like a bad tradeoff to me, but who can say for sure?

Re: Google's harvest of medical data includes names and full details of millions

#92
post #91
post #87

Earlier quoted context omitted.

> we should encourage more openness around medical data. Encouraging is fine, but in the end, consent from individuals should be obtained and if it isn't, that data should be omitted.

Well, I think most people in this comments section would say "blanket consent when signing hospital forms is unacceptable and patients should get notified and paid every time someone uses an element of their data". If that's the standard society wants to adopt, so be it- But it might come at a dramatic cost in slowing down medical innovations. Personally, that seems like a bad tradeoff to me, but who can say for sure…

> patients should get notified and paid every time someone uses an element of their data

I don't know about most people here, but I wouldn't say that. Notification or being paid is beside the point. The point is that informed consent should be obtained.

You're right that blanket consent forms don't count as "informed consent" for this sort of thing because they don't actually inform you.

> Personally, that seems like a bad tradeoff to me

Which is fair -- you'd have no problem giving such consent. I, however, would not be willing to give such consent.

I put a lot of effort into reducing the amount of data that Google (and Facebook, Amazon, etc.) can get about me. If/when my medical provider just hands my data over to them, that's a very serious betrayal of trust and undermines my ability to protect myself from those companies.

I find that completely unacceptable, particularly because medical care is not exactly an optional thing.

Re: Google's harvest of medical data includes names and full details of millions

#93

Earlier quoted context omitted.

Ubers ai won't even slow down when it sees a person in the road. A computer can prescribe a drug for me, but I can't prescribe a drug for me? Can I please have my life back please?

Drug self-prescription is forbidden for several good reasons that have stood the historical test of time, unfortunately. It'd be convenient if we could assume perfect personal responsibility, but human behavior doesn't align with that assumption.

Prescriptions aren't required in many countries of the world. Protecting people from themselves is not a good reason. If it were lots of dangerous activities would be illegal.

You can risk your life to make it more fun, but not more healthy?

Prescriptions in the USA have only really been a thing for the century since the Harrison act, which brought drug smuggling with it.

Re: Google's harvest of medical data includes names and full details of millions

#94
post #27
post #14

Earlier quoted context omitted.

I am indeed someone who doesn’t understand how HIPAA works. I have seen instances of healthcare professionals getting jail time for disclosing celebrity health records however. How is google able to legally get access to these records? I suspect they’re not and if so, someone should be held criminally liable for this. If google is able to get these, what’s stopping anyone else?

I, too, am familiar with (and bound by) HIPAA. I agree this is likely a violation. Having said that, my job in the healthcare IT world is building interfaces, i.e. facilitating the transfer of health data from one system to another. Most likely what's going on here is Google and Ascension have a project together, and part of that project is either an interface or a data dump from Ascension to Google for the purposes…

> I haven't read all the information, but generally the data will be "de-identified"

You should read what both Google and Ascension has said about this -- the data is intentionally not being de-identified, although it's not clear as to what the rationale for that decision is.

Even if it were, though, de-identification isn't actually very effective, particularly if you have easy access to a mountain of other personal data (such as Google has).

> Neither company is small or ignorant; they both had their lawyers look at the contract and they signed off on it.

I'm quite certain that, at worst, both companies think that they can get away with this legally. Even if it's entirely legal, though, that in no way means it's right or acceptable.

Re: Google's harvest of medical data includes names and full details of millions

#95
post #83

Googler here, my opinions are my own, standard disclaimer. I'm not going to comment on this specific case but I do have almost a decade of previous non-Google experience working in clinical documentation technology. As others have said, entering into a BAA with a covered entity, as HIPAA defines it, shouldn't be seen as a controversial action. There are numerous problems in healthcare that are too complex for individ…

> As others have said, entering into a BAA with a covered entity, as HIPAA defines it, shouldn't be seen as a controversial action. You place more faith in HIPAA than I do. HIPAA does not protect privacy to the degree that most people assume. > There are numerous problems in healthcare that are too complex for individual health systems to tackle. True, but that doesn't mean that Google is the right entity to do this.…

> You place more faith in HIPAA than I do. HIPAA does not protect privacy to the degree that most people assume.

Can anyone elaborate?

Re: Google's harvest of medical data includes names and full details of millions

#97
post #66

Earlier quoted context omitted.

Yes, if you have HIPPA you get routine audits to make sure you are obeying the law.

No you don’t, there are fines if you are found in violation but no one is checking on an ongoing basis. Specific entities may privately pay for audits or do so as part of certifications (HiTrust, etc) but that’s not required.

The dept of HHS requires any organization with HIPAA business associate status to regularly undergo audits.

Can you fly under the radar and potentially get away with not doing it? Of course, anything is possible. Could a multibillion dollar internet organization beholden to shareholders and under public scrutiny get away with it? Not likely.

Re: Google's harvest of medical data includes names and full details of millions

#98

Googler here, my opinions are my own, standard disclaimer. I'm not going to comment on this specific case but I do have almost a decade of previous non-Google experience working in clinical documentation technology. As others have said, entering into a BAA with a covered entity, as HIPAA defines it, shouldn't be seen as a controversial action. There are numerous problems in healthcare that are too complex for individ…

> To give you an idea of the scale, I have two examples. The first is MD Anderson Cancer Center in Houston. They used to have 200+ engineers working on their sophisticated home-grown EMR. It was a huge undertaking. But even with MDACC revenue, that development was unsustainable, and they moved to a 3rd party EMR vendor. I'm not certain what aspect you are trying to highlight with this example, but readers should know…

The point is that even MDACC figured out is was too expensive to continue their own EMR.

You're correct in that literal books could be written about EMR adoption gone wrong. That doesn't change the fact that even super huge mega-health systems can't afford to do it all themselves.

Re: Google's harvest of medical data includes names and full details of millions

#99
post #86

Earlier quoted context omitted.

I don't think they see this as an egregious abuse of power. Googlers trust Google to do a pretty decent job of securing private information almost all of the time; this isn't an area of moral concern for them. (i.e. the question in their minds is "Is the data safer in the source repositories?" And it's probably not).

The problem is that Googlers (like far too many tech companies) view data as being secure if outsiders can't get access to it. They don't count access by themselves as a security issue, even though it objectively is.

Googler here. I don't speak for Google and obviously shouldn't and won't divulge internals, but this just makes me cringe so hard: unauthorized or illegitimate access by staff is OBVIOUSLY treated as a security issue. I'm kind of shocked that folks would think otherwise.

Re: Google's harvest of medical data includes names and full details of millions

#100
post #83

Googler here, my opinions are my own, standard disclaimer. I'm not going to comment on this specific case but I do have almost a decade of previous non-Google experience working in clinical documentation technology. As others have said, entering into a BAA with a covered entity, as HIPAA defines it, shouldn't be seen as a controversial action. There are numerous problems in healthcare that are too complex for individ…

> As others have said, entering into a BAA with a covered entity, as HIPAA defines it, shouldn't be seen as a controversial action. You place more faith in HIPAA than I do. HIPAA does not protect privacy to the degree that most people assume. > There are numerous problems in healthcare that are too complex for individual health systems to tackle. True, but that doesn't mean that Google is the right entity to do this.…

> You place more faith in HIPAA than I do. HIPAA does not protect privacy to the degree that most people assume.

That's correct. People would be surprised at the number of HIPAA violations that happen everyday. It is, however, among the strongest and most well-enforced data privacy laws (in the US).

> True, but that doesn't mean that Google is the right entity to do this. In my opinion, they're the wrong entity, because Google is not exactly trustworthy.

You're certainly right to be concerned. I don't share your opinion about Google per se, but this is important data for our society. I'd argue that OpSec at a large provider--let's say Microsoft--is more sophisticated than a start-up. So how does an organization decide who is the "right" entity to deal with?

> But they're Google. What this sort of thing means for me is that I need to start asking medical providers if they're participating in this sort of thing with Google (or other companies that I consider bad actors), so I know which ones to avoid using.

If this is important to you, I would strongly encourage it. Our health industry is better when consumers are better informed, and can make informed decisions. Personally, it's more important to me to be able to actually know how much a procedure is going to cost rather than who owns the AI stack behind their clinical decision support system.

Post reply on HN