5 ms·
I work for a large US based corp that focuses on technology and data services for the healthcare field. We have massive amounts of PHI for the majority of peopl
by DIVx0 7y ago
I work for a large US based corp that focuses on technology and data services for the healthcare field. We have massive amounts of PHI for the majority of people who have visited a provider within the country.
We apply all sorts of stuff to this data, ML, AI or whatever other buzzy tech you can think of.
Most of this work happens within our own data centers but there is significant work done within public clouds.
We have BAAs (business associate agreement) with every cloud vendor we work with. We also have gone to extreme lengths to be confident that our cloud deployments are as secure (or more) than our on premises stuff.
However, none of that is unique. We're no industry trail blazers with adopting public clouds. Just about every other major player is doing this in a way fairly similar to ours
So, what I _really_ don't understand with this story is, did Ascension just simply give up their data to google without boundaries? Their BAA should be very clear that Ascension intends to use google's cloud services but not giving rights to their data to google.
It would not be unusual to engage a vendor or form some other partnership with another firm to work on problems or generate new products. I assumed that this is what Ascension and google were doing but this whistleblower and other stories make it seem like google just has free and clear access to this data outside of their relationship with Ascension.
Is that true? If so, that's crazy! Otherwise, business as usual?
- ocdtrekkie 7y agoI think the highlight point, that is new information (AFAIK) in this article is that 150 Google employees are working on this project. So this isn't "Ascension is hosting their data in the cloud", it's "Google is working with health data".
- summerlight 7y agoIIUC, this is also an industry standard practice as long as it's covered by their BAA. The question would be whether the actual content in the BAA makes sense or not, but I think the requirement for a BAA is pretty specific. https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html https://www.hhs.gov/hipaa/for-professionals/covered-entities...
- JohnFen 7y agoTo the best of my knowledge, the BAA has not been published, so we have no idea what it says. But what seems clear is that a ton of complete medical data, including names and other identifying data, has been handed to Google for its use in what sounds like training an ML system. That we don't know what restrictions are in place (if any) is a large part of why this is so alarming.
- deleted 7y ago[deleted]
- temac 7y agoIt is not just because "everybody" is doing crazy shit, that it is OK to do it.
- summerlight 7y agoThen you should blame the industry rather than a newcomer to the industry who tries to follow the industry standard?
- mfer 7y agoFrom the original WSJ article... > Staffers across Alphabet Inc., Google’s parent, have access to the patient information, documents show, including some employees of Google Brain, a research science division credited with some of the company’s biggest breakthroughs. I'm struck by the wide access of those within Alphabet to health information that's not anonymous. Is this how other healthcare companies are doing it?
- Kalium 7y agoOne reading of this is that it's a cross-departmental collaboration, rather than just a single division.
- mfer 7y agoMaybe and sort of. Alphabet is a conglomerate, right. Alphabet is the parent company that owns Google, LLC. I'm personally surprised to see talk of the data crossing the Google / Alphabet company boundary. That makes it cross company collaboration, right?
- bilbo0s 7y agoThat's the difference everyone here is talking about though. Normally in the healthcare industry, you engage a cloud provider, and it's "you store this data for us." Full Stop. You don't look at it. You don't analyze it. You don't share it. You don't touch it. It's our data, not yours. If what you're saying is true, Ascension, for some reason, has a deal with its cloud provider that allows Google to search through, analyze, etc etc etc. It sounds like all sorts of rights were given to Google. That's an irregular agreement. It's not normally how things are done.
- Spooky23 7y agoThat's a very naive view of what happens. It's exactly how things are done, except that it's a one-stop shop. The reality is that there is a fig leaf of privacy. HIPPA protects you from the office staff gossiping about your medical conditions. When you are admitted to the hospital, your prescriptions are sent to data aggregators in near real-time, your claims are sent to your insurer and subrogation in near real-time, etc. Each one of these downstream providers perform their own analysis on the data. The prescription data is sold to pharmaceutical companies and wholesalers to provide KPIs for the sales organization. The insurance and subrogation people sell de-personalized data to marketing companies. The marketing companies can trivially figure out who most people are. The end result is that you can easily get a list of every person in a zipcode who is pregnant (with estimated due date), has diabetes, had a stroke, etc.
- thatfrenchguy 7y ago> I work for a large US based corp that focuses on technology and data services for the healthcare field. We have massive amounts of PHI for the majority of people who have visited a provider within the country. The real question here is: why can't I opt-out ? I want a easy button when I do anything medical to say "no, don't use my health data for any of this stuff". And the current CA privacy law does not provide this, unlike GDPR, which sucks.
- igetspam 7y agoThis I exactly it. In Texas, there is always a check box about sharing. I opt out 100% of the time. This only covers a specific use case though and there are still tons of sharing agreements in place that I can't do anything about. I'd opt out of all of them if I could but at least knowing how many places my data exist would be a start.
- chopin 7y agoGDPR does not provide this unfortunately. Just last week a bill in Germany was enacted which allows the medical data of all insured people to be shared with medical companies. There is no opt-out.
- Hamuko 7y agoI believe GDPR does provide that, but consent is not required to process data if that processing is "necessary for compliance with a legal obligation to which the controller is subject". So if an EU member state makes a law that requires insurance companies to export your medical data wholesale to medical companies, GDPR does not give you an option to opt out. Really the only solution there is either to a) move elsewhere b) vote for people who don't want to enact such laws.
- CPLX 7y agoI've seen a ton of responses from people in the industry along the lines of "this is normal" or similar. People who work on this stuff are incredulous that there's even an issue, since everyone's health info is already being uploaded to AWS or something. This is business as usual, they say. The uproar is taken by people actually working in the business as a sign that the public are ignorant and misinformed. Things are actually HIPPA compliant, they say. This isn't a big deal, they say. But perhaps the education should be going in the other direction, and the people in the industry should realize they are the ignorant ones for realizing that this is totally not OK for a huge number of people. Realize that we are absolutely horrified that this data is being shared, that a reasonable response is to say that if HIPPA is OK with this then we need stronger laws, that we don't want faceless algorithms studying our most intimate personal and medical issues at companies we never had a relationship with. And, especially, we are absolutely fucking certain that we want literally none of it to be seen by employees of the sociopathic tech companies that are surveilling every aspect of our life in order to better manipulate politics, markets, and our society. The thing to take away here is that people are shocked and horrified at what's apparently business as usual.
- trebligdivad 7y agoBut if they're just using Google as cloud storage/compute it's not being shared. Only very few Google employees would have access, they'd have very careful limitations and access on who accessed what - that's not the same as giving to google for some big AI experiment.
- inetknght 7y ago> Only very few Google employees would have access That's "very few" Google employees more than zero. I expect zero Google employees to have access to my medical data. Any number above zero is absolutely not acceptable to me. > they'd have very careful limitations and access on who accessed what Yeah, just like Equifax, right?
- kazen44 7y ago> That's "very few" Google employees more than zero. I expect zero Google employees to have access to my medical data. Any number above zero is absolutely not acceptable to me. Heck, people owning my medical data who are not my doctor/GP and related medical professionals is a big no go in my opinion. Medical data is rather private.
- vl 7y agoThe irony, of course, (as anyone with failed ML launch at Google knows, haha) is that internally Google has extremely strong privacy practices and safeguards and probably is the best organization to actually handle this data correctly. As for de-anonymization, of course raw data should be pre-anonymized: anonymization is a major source of mistakes in the data, often rendering data useless, and needs to be done correctly by the people who know how to do it correctly.