14 ms·
Google's harvest of medical data includes names and full details of millions
- SEJeff 7y agoHow is this not a criminal breach of HIPAA laws? https://www.hhs.gov/hipaa/for-individuals/guidance-materials-for-consumers/index.html https://www.hhs.gov/hipaa/for-individuals/guidance-materials...
- mercwear 7y agoThe article says that it might be: "According to the whistleblower, the security fears raised at that meeting, including concerns that the transfer may be in breach of federal HIPAA rules on data privacy, have so far gone unanswered by Google." That said, most people do not understand how HIPAA works (I am in no way saying you are one of these people). Unless you are a healthcare provider (think doctor) or a business that is supporting those providers (think 3rd party tools built specifically for managing healthcare records) it's pretty difficult to have a legitimate HIPAA complaint made against you.
- SEJeff 7y agoI am indeed someone who doesn’t understand how HIPAA works. I have seen instances of healthcare professionals getting jail time for disclosing celebrity health records however. How is google able to legally get access to these records? I suspect they’re not and if so, someone should be held criminally liable for this. If google is able to get these, what’s stopping anyone else?
- Nasrudith 7y agoEssentially HIPAA is /the/ responsibility of the healthcare provider - not Google. I am not sure about the transferrance and the laws there but not giving out is the less famous provider's job. They operate on an unavoidable consequences to a designated entity for enforcement - no excuses or buck passing they signed off on it sort of thing. It doesn't preclude other crimes whether from hackers but doesn't technically guarantee them in Google's part. Technically the provider could have just given sensitive information like complete idiots because they were asked.
- taborj 7y agoI, too, am familiar with (and bound by) HIPAA. I agree this is likely a violation. Having said that, my job in the healthcare IT world is building interfaces, i.e. facilitating the transfer of health data from one system to another. Most likely what's going on here is Google and Ascension have a project together, and part of that project is either an interface or a data dump from Ascension to Google for the purposes stated in the article. I haven't read all the information, but generally the data will be "de-identified", which some interpret as sufficient to avoid HIPAA violations. Neither company is small or ignorant; they both had their lawyers look at the contract and they signed off on it. So either the lawyers at both companies are mistaken or mislead, or somewhere after the initial scoping the scope changed (which, btw, happens all the time) and nobody updated legal or felt the need to update management or raise a concern And that's concerning, regardless of which option it is. Either the legal teams at both companies are ill-informed or outright ignorant (perhaps intentionally), or there are no checks -- and no responsible project managers -- in place to prevent this from occurring. Somewhere along the line, someone should have suggested that this was perhaps not cool, and taken the issue up the chain of command. Most healthcare companies have a well established process in place for that, and I can't believe either of these would be different in that respect.
- JohnFen 7y ago> I haven't read all the information, but generally the data will be "de-identified" You should read what both Google and Ascension has said about this -- the data is intentionally not being de-identified, although it's not clear as to what the rationale for that decision is. Even if it were, though, de-identification isn't actually very effective, particularly if you have easy access to a mountain of other personal data (such as Google has). > Neither company is small or ignorant; they both had their lawyers look at the contract and they signed off on it. I'm quite certain that, at worst, both companies think that they can get away with this legally. Even if it's entirely legal, though, that in no way means it's right or acceptable.
- vechagup 7y agoIf you're a covered entity (CE) under HIPAA, you are allowed to have business associates (BAs). BAs are other parties that the CE exchanges PHI with in order to provide services (billing companies, cloud storage providers, etc.). According to the HITECH Act, BAs are bound by the provisions of HIPAA. Per their press release (https://cloud.google.com/blog/topics/inside-google-cloud/our-partnership-with-ascension?mod=article_inline https://cloud.google.com/blog/topics/inside-google-cloud/our...), Google is playing the role of a BA as a part of this deal. They have signed a business associate agreement (BAA), as HIPAA requires. This agreement will have defined the permitted uses for the PHI that Ascension is transmitting to Google. Basically this all sounds utterly ordinary. It's 2019 and even healthcare companies want to be in The Cloud (and especially want to be associated with AI and ML). My last company stored lots PHI in AWS. AWS signed a BAA with us. Now, if someone at Google with access to this PHI misuses it (e.g., accesses it for an invalid reason or sells it on the black market), then they could be in violation of HIPAA and face penalties. But the mere fact that a covered entity is transferring data to a business associate in no way suggests a HIPAA violation its own. (Disclosure: I work at Google, but know nothing about this project.)
- papln 7y ago> I suspect they’re not Why not?
- dragonwriter 7y ago> How is google able to legally get access to these records As a Business Associate of a health care provider organization, with an agreement in place binding them to the same rules for that data the principal they serve would have, which is enforceable not only by the principal, and by patients, but also directly against Google by the government. > If google is able to get these, what’s stopping anyone else? Nothing is stopping anyone else from offering the kinds of services to health care providers and insurers that involve patient data under a BAA; most health care providers and insurers have numerous Business Associates performing various functions involving patient data, including, in many cases, large tech firms like Microsoft, Amazon, and, sure, Google. If anything, Google is behind in this space in terms of volume because of Amazon, Microsoft, and some more specialized forms in the healthcare space have stronger enterprise sales positions in general, and, especially for Microsoft and some of the more specialized forms, more established relations with firms in the space that make it a lower “activation energy” to engage those firms as BAs.
- ceejayoz 7y agoIt's not inherently a HIPAA breach to use cloud hosting for your data. As long as you tick the security and compliance boxes, it's perfectly legit.
- hammock 7y agoHIPAA only applies to Covered Entities: insurers, healthcare providers and clearinghouses (claims processors). This info is in your link.
- amsully 7y agoFrom the link below the bullet points: "In addition, business associates of covered entities must follow parts of the HIPAA regulations." All vendors must comply with HIPAA laws (ie EMR systems)
- izacus 7y agoGoogle's press release actually adresses HIPAA: https://cloud.google.com/blog/topics/inside-google-cloud/our-partnership-with-ascension?mod=article_inline https://cloud.google.com/blog/topics/inside-google-cloud/our...
- bduerst 7y agoImportant part: >What about patient data? All of Google’s work with Ascension adheres to industry-wide regulations (including HIPAA) regarding patient data, and come with strict guidance on data privacy, security and usage. ... To be clear: under this arrangement, Ascension’s data cannot be used for any other purpose than for providing these services we’re offering under the agreement, and patient data cannot and will not be combined with any Google consumer data.
- OnlineGladiator 7y ago> and patient data cannot and will not be combined with any Google consumer data. Does anybody enforce this or do we just take Google at their word?
- papln 7y agoDoes anyone enforce any law?
- OnlineGladiator 7y agoWhen there's an obvious breach, hopefully. How would we even know if Google were abusing this data though? Does anyone have access to it besides Google? Are we literally asking Google to regulate itself with this data? EDIT: I guess I don't understand. Once we give Google the sensitive information, how do we have any way of knowing what they do with it? I'm guessing an audit on all of Google's data is out of the question.
- mattmanser 7y ago
- s3r3nity 7y agoI hope this gets more attention. Not because I think what Google did breaks HIPAA laws - there are many sub-threads below that can explain that better than I that this doesn't violate HIPAA - but rather the question helps highlight where we should truly be upset. What Google did was legal; because of that, we should be upset that the government / regulatory bodies created an environment such that this was legal. Rallying against a publicly traded company of 100's of 1000's of employees for doing something "immoral" is not a productive use of your energy. (The irony here is I usually am _against_ more regulation!) It's a similar argument I made with the whole martin shkreli debacle: senators & congressmen/women got their picture day grilling him with the whole "how could you price gouge these poor, sick people?" But his consistent response was, essentially, the inverse: "How could you create an environment where this is totally 100% legal?"
- tensor 7y agoI'm having trouble understanding how you feel this is immoral. You have a private healthcare system, and as such your data is already in the hands of numerous private companies. From the hospital itself, to various data processing partners that implement patient record systems, billing systems, image processing for various tests, lab companies and so on. But suddenly this company, Google, makes it immoral? It seems to me that if you care this much about private companies having your data, you should switch to a publicly owned healthcare system.
- kyrra 7y agodupe. https://news.ycombinator.com/item?id=21507370 https://news.ycombinator.com/item?id=21507370
- kyrra 7y agoInstead of down voting me, you could reply saying that this article has new details (like the leaked presentation). I just assumed it was a repost of yesterday's discussion.
- dredmorbius 7y agoMy practice is to usually limit "dupe" to the identical link or story submitted multiple times. Major mainstream breaking news possibly excepted. For different takes on the same story, "Previously" with a link to earlier discussion, may be better. For evergreen topics (e.g., Bertrand Russell's "In Defence of Idleness", submitted many times through the years, and again a day or so back), "earlier submissions" noting the years, of 2-3 top instances, can point to earlier interesting discussion.
- yRetsyM 7y agoWhat is actually happening here? A lot of rhetoric about the "Transfer of data" etc, but other times this just reads like a Google Cloud Infrastructure play, with some consulting on top. Also - The deal was only just signed, e.g. the transfer hasn't happened yet? There's a lot of hearsay in all of this reporting...
- umeshunni 7y agoSeems like a lot of fake news over a cloud storage deal https://cloud.google.com/blog/topics/inside-google-cloud/our-partnership-with-ascension?mod=article_inline https://cloud.google.com/blog/topics/inside-google-cloud/our...
- dimator 7y agoWell, that seems a lot less sensational than the article. Covers HIPAA as well.
- amsully 7y agoWithout reading the Business Association Agreement it is hard to determine if Google has 'Acceptable Use' of healthcare data. Storing in the cloud is one thing, allowing a Business Associate to siphon that data for other use is another.
- excalibur 7y agoThis is not "fake news" at all. This is the same factual event covered with a different spin. Use of the term "fake news" to describe reporting that is merely slanted in a direction you don't like--rather than presenting demonstrably false information as fact--is completely unwarranted, and is doing terrible damage to our social institutions.
- chooseaname 7y agoThank you for stating this so aptly and concisely. People are throwing "fake news" around for anything and everything they don't agree with. It really is making it difficult to have a reasoned discussion with people when they just dismiss something so generally.
- me_me_me 7y agoI wonder if this is not a coincidence given acquisition of fitbit.
- ocdtrekkie 7y agoGoogle's been investing in medical data analysis long before buying Fitbit. They got in trouble for DeepMind's involvement with NHS data over in the UK, which started years ago. And then Google absorbed that whole project from DeepMind into Google Cloud proper, after assuring the British government Google would never have access to the data from the project. tl;dr: Unrelated avenue in a field they've been interested in for a long time.
- Cd00d 7y agoI suspect the Fitbit acquisition is more to have a product that competes with Apple's and Samsung's smartwatch offerings. At this point it seems like having a watch that integrates with your phone offerings is table stakes, and I don't think Google had that.
- shadowgovt 7y agoI'd expect it's coincidence but in the other direction; Google's Fitbit motion has led to journalists being curious what other moves Google is making in the medical space.
- rayuela 7y agoSo what do we do to stop this? What recourse do people directly affected by this have?
- twobat 7y agoGDPR should kick in long before medical data is on the table.
- buboard 7y agolaws protecting medical data are stricter and preceded gdpr by many years
- dragonwriter 7y agoGDPR will only occasionally and coincidentally (if at all) be relevant to health data held by US health care providers and their business associates, whereas HIPAA will always be relevant.
- x0x0 7y agoGo to fitbit and delete your data. I just did; it's pretty painless. login, click on the wheel, and the delete link is at the bottom.
- dragonwriter 7y ago> Go to fitbit and delete your data. That has no effect on the central theme of the story (which is health care firms partnering with Google as a Business Associate, and thereby sharing patient data).
- papln 7y agohttps://www.hhs.gov/hipaa/filing-a-complaint/complaint-process/index.html https://www.hhs.gov/hipaa/filing-a-complaint/complaint-proce... Complaint Requirements Anyone can file a health information privacy or security complaint. Your complaint must: Be filed in writing by mail, fax, e-mail, or via the OCR Complaint Portal Name the covered entity or business associate involved, and describe the acts or omissions, you believed violated the requirements of the Privacy, Security, or Breach Notification Rules Be filed within 180 days of when you knew that the act or omission complained of occurred. OCR may extend the 180-day period if you can show "good cause"
- Aaronstotle 7y agoAny google employees/friends of google employees here with insight as how staff is receiving this news? My guess is like all other egregious abuses of power, the employees will stage a "protest" to feel good about themselves then keep working there.
- urgeblumbling 7y agoAs opposed to yelling into the void on an anonymous online forum?
- mc32 7y agoI don’t see them staging a protest. The issue is too mainstream to earn them any Internet points. However, this is the kind of issue that matters to many people and could affect adversely. Still I think it’s up to the Congress and people to push back on abuses like this.
- Zenst 7y agoI wonder what type of biometric and other monitoring of employees by employers that could happen under employment contracts or in the name of security or `Health and Safety`. After all, many companies trial new ideas and technology in house. So would be insightful into what companies like Google do inhouse.
- big_chungus 7y agoGoogle's employees appear from their past behavior to protest when the issue at hand is one about which the far left cares. [0][1][2][3][4] This issue is rather bi-partisan, so I don't expect any significant protest. [0]: https://www.zdnet.com/article/google-employees-protest-dont-bid-for-border-control-cloud-contract/ https://www.zdnet.com/article/google-employees-protest-dont-... [1]: https://www.theverge.com/2019/7/16/20695964/google-protest-leader-meredith-whittaker-leaves-company https://www.theverge.com/2019/7/16/20695964/google-protest-l... [2]: https://www.cnn.com/2019/05/01/tech/google-employees-protest-may-day/index.html https://www.cnn.com/2019/05/01/tech/google-employees-protest... [3]: https://www.vox.com/recode/2019/6/19/18691870/google-employees-activists-protest-alphabet-shareholder-meeting https://www.vox.com/recode/2019/6/19/18691870/google-employe... [4]: https://www.theverge.com/2019/5/1/18525473/google-employee-sit-in-retaliation-protest https://www.theverge.com/2019/5/1/18525473/google-employee-s...
- chooseaname 7y ago> Google could go on to use its AI analytics to predict outcomes for individual patients, they posited. This is the most scary part[0]. I'm sure plenty here would disagree, but I simply don't (yet) share your optimism for A.I. [0] Not that the rest isn't scary.
- vineyardmike 7y agoI know several smart people at google, and I dont want to be critical of individuals. BUT it seems sometimes like google-the-company is of the mentality that they're smart, and with enough data and some ML chops they can solve anything, and frankly I'm not as confident - but I don't find it scary. The casual data-grabbing that they're doing is most-scary to me, since I would hope that my data would never be accessible to them/others as readily as I now suspect it is.
- throwaway35784 7y agoUbers ai won't even slow down when it sees a person in the road. A computer can prescribe a drug for me, but I can't prescribe a drug for me? Can I please have my life back please?
- shadowgovt 7y agoDrug self-prescription is forbidden for several good reasons that have stood the historical test of time, unfortunately. It'd be convenient if we could assume perfect personal responsibility, but human behavior doesn't align with that assumption.
- throwaway35784 7y agoPrescriptions aren't required in many countries of the world. Protecting people from themselves is not a good reason. If it were lots of dangerous activities would be illegal. You can risk your life to make it more fun, but not more healthy? Prescriptions in the USA have only really been a thing for the century since the Harrison act, which brought drug smuggling with it.
- swedtrue 7y agoTime to use private cloud
- dragonwriter 7y agoIf entering into a BAA under HIPAA for work involving PHI is “harvest”, and you're worried that this reaches “millions” for Google, you probably don't want to think about the deals public and private firms in the healthcare and health insurance/payments space have with Amazon and Microsoft. From the news article (I don't have time to review the source leak indepently) there doesn't seem to be anything really concerning here. The closest to an indication of anything wrong seems to be that someone raised an issue about the risk of improper employee use of data and a need for training around that in an internal meeting on the project and has not received a formal specific response on that issue from corporate leadership. Having spent a long time in HIPAA-related work, that neither that issue being raised in regard to a new project or the fact that it was raised being merely one of many inputs into a policy generating process that makes general adjustments considering a wide range of concerns, legal parameters, and other issues but not receiving a specific direct response seems...pretty typical. And HIPAA does not require notification or opt-in (or even opt-out opportunity) for data sharing between a covered entityand Business Associate, as BA’s are (while under HITECH independently subject to HIPAA privacy and security rules) basically considered institutional agents of the covered entity to which the covered entity’s authority to have and use data is delegated under the Business Associate agreement. I don't know if there is really nothing of concern in the dump or the journalists covering it don't have enough understanding of the domain to even distinguish things that would indicate a problem, but what it looks like from the news article is a “whistleblower” making accusations and dumping docs, but nothing substantial and concrete in the docs supporting the thrust of the “whistleblower’s” accusations of wrongdoing.
- TaylorAlexander 7y agoNot defending the article (I’ve not read it), but I suppose I probably would be horrified with the status quo. I really wish we had a more consent based data culture. I suppose I don’t know how that would be designed. But lots of real things are horrifying and it’s not necessarily fine just that something is normal.
- dredmorbius 7y agoMy view is that consent is oversold. If I "consent" to a boilerplate agreement handed me moments before an action is taken, have I really? Boundaries and distributions should be clearly, specifically specified, with any non-essential distributions requiring specific assent, defaulting to none. If there are consequences to sharing, those can be made known. We've been drawn into a circumstance which has long been untenable.
- deleted 7y ago[deleted]
- Braggadocious 7y agoI fear all of this will be used as part of a prediction program to find the best employees based on performance metrics. Imagine if before you even gave an applicant a callback you could see if they've ever had a bout of depression, insomnia, anything that may affect their job performance or the performance of their team. That would be standard part of any background check if that information was available.
- perl4ever 7y agoThe nice thing about the modern world is that nobody has to make the decision to do that or be aware. That sort of discrimination can filter through ML-derived correlations at two, three or more levels removed, and every human being can be as innocent as can be.
- drcode 7y agoI know I'm very much in the minority here, but just like we should have more open borders and more open software, we should encourage more openness around medical data. Google and other large companies have made some significant AI advances in the last decade & I think it's in all of our interests to see if these advances can lead to improvements in health care. Yes, it's scary how much data these companies have collected about us, but there are other things in the world which are even more scary, like heart attacks and cancer. I think we need to stop having an automatic knee-jerk reaction every time a company gets access to our data, especially if proper legal protocols with privacy protections are being followed, as it appears to be in this case. Of course, I would love to live in a world with 100% perfect personal privacy AND perfect treatments for all diseases, but we don't live in that world: In our world, as we move forward, there are going to be difficult tradeoffs between health innovation and patient data access: We should try to navigate these tradeoffs in a level-headed way, without just insisting on greater walls around all data in every instance.
- legulere 7y agoI know how hard it is to get enough medical data to do research. But why do you need names? Correlate diseases with first names?
- bilbo0s 7y agoTotally agree. Last thing we should do is have radically open medical data. Some busybody parent could go out and search all the kids in in her kids' school who might have HIV or something. Or imagine all the crazies out there searching for a list of women in their town who have had abortions. The only thing you do with open medical data is ratchet up the "crazy" in society. In an ideal world where everyone is rational, it's fine. But that world doesn't exist.
- drcode 7y agoThey probably get all the data in fragments from different EHR systems, pharmacy records, diagnostic monitors, etc etc and need ways of knowing which records belong to the same patient. Sure, we may want to have properly-designed legislation to come up with standards across databases that make the use of such sensitive data for combining records less necessary, but we better make sure it's well designed or we could end up slowing down medical innovations.
- altgoogler 7y agoGoogler here, my opinions are my own, standard disclaimer. I'm not going to comment on this specific case but I do have almost a decade of previous non-Google experience working in clinical documentation technology. As others have said, entering into a BAA with a covered entity, as HIPAA defines it, shouldn't be seen as a controversial action. There are numerous problems in healthcare that are too complex for individual health systems to tackle. For example: * Population Health: are there emergent changes in the regional population? What do you do about it? * Continuity of Care: The number of individual providers involved in a particular person's care continues to grow. How can you effectively inform the entire team--across health systems--what's most important for an individual now? How do you make sure nobody drops the ball? To give you an idea of the scale, I have two examples. The first is MD Anderson Cancer Center in Houston. They used to have 200+ engineers working on their sophisticated home-grown EMR. It was a huge undertaking. But even with MDACC revenue, that development was unsustainable, and they moved to a 3rd party EMR vendor. Second is the Mayo Health System. Another huge provider with facilities not just in flagship Rochester MN, but in several other sites. Again, there were realities that even at this scale internal development isn't sustainable across the board and they wound up with a $100M+ adoption of a 3rd party vendor. And this is mostly straight-forward CRUD-level workflows. The technology is straightforward but the workflow expertise is not. Now, try and solve some bigger problems. You're going to need help to do this at scale, and trying to solve it necessarily means giving access--not control of!--to medical records to drive R&D. It's happening right now, and Google is not the only player doing this at scale. They're not even the largest one. Lastly HIPAA controls have real teeth, in comparison to the general consumer space (at least in the US).
- jhayward 7y ago> To give you an idea of the scale, I have two examples. The first is MD Anderson Cancer Center in Houston. They used to have 200+ engineers working on their sophisticated home-grown EMR. It was a huge undertaking. But even with MDACC revenue, that development was unsustainable, and they moved to a 3rd party EMR vendor. I'm not certain what aspect you are trying to highlight with this example, but readers should know that the MD Anderson implementation of the EPIC EMR system led to a 77% drop in income and layoffs approaching 1,000 people (2016-2017 time frame)[1][2]. I'm not up to date enough to know whether they have ever recovered. [1] https://www.modernhealthcare.com/article/20170106/NEWS/170109948/md-anderson-cancer-center-to-cut-900-jobs-due-to-losses-from-ehr-rollout https://www.modernhealthcare.com/article/20170106/NEWS/17010... [2] https://www.beckershospitalreview.com/finance/md-anderson-points-to-epic-implementation-for-77-drop-in-adjusted-income.html https://www.beckershospitalreview.com/finance/md-anderson-po...
- Lagogarda 7y agoStopped reading after 2 popups and one add blocked the article.
- valiant55 7y ago>The disclosed documents include highly confidential outlines of Project Nightingale, laying out the four stages or “pillars” of the secret project. > Among the documents are the notes of a private meeting held by Ascension operatives involved in Project Nightingale. The whole article is written like they are trying to tell a spy story which brings into question the credibility that there's any wrong doing.
- JohnFen 7y agoEvery time that I think that Google couldn't be any worse, they prove me wrong.
- vfclists 7y agoWhere is the Guardian's report on this - https://www.dailymail.co.uk/health/article-7588337/Google-gets-green-light-access-FIVE-YEARS-worth-sensitive-patient-data-NHS-trust.html https://www.dailymail.co.uk/health/article-7588337/Google-ge... As a UK based paper Guardian could at least focus on British issues
- 1_over_n 7y agoPersonally i think the frustrating thing here is that it sours the pool for others who are interested in medical innovation that requires data.