Monday, December 14, 2009
Facebook setting the standards for Health Care?
This is EXACTLY what will happen to the health care system when Americans find out they have NO CONTROL over over who sees, uses, and snoops in their electronic health information.
Patient Privacy Rights' job is to make sure they learn as fast as possible.
Sign up at www.patientprivacyrights.org for our e-alerts so you can help!
Thursday, October 29, 2009
Employers after DNA: GINA does not protect like you think.
The idea that GINA protects genetic tests from being held or used by employers and insurers is wrong. Genetic tests ordered by your doctor at any other time--when you are NOT seeking a job or insurance--can be collected and used by your employer and insurer to make decisions about you.
Lobbyists for the insurance industry and employers got this massive loophole into the bill, eliminating the intended consumer protections. Instead GINA should have forbidden employers and insurers to ever collect or access genetic tests.
This is one of the key reasons we need Congress to restore OUR rights to control our personal health information, so WE can make sure employers and insurers do not get our genetic records. Genetic information is so sensitive it should ONLY be seen by health professionals directly involved in our treatment, or if we choose to participate in research and share it.
Saturday, October 17, 2009
Re-Identification. From Netflix to Health Records.
See the NY Times Article: When 2+2 Equals a Privacy Question
Friday, September 25, 2009
De-identified? Yeah, right.
Netflix Contest Seen As Posing Privacy Risk
Netflix is about to commit a privacy Valdez with its customers' viewing data
AOL, Netflix and the end of open access to research data
Once again Netflix plans to violate the privacy of those who rate the movies they rent. Two University of Texas computer scientists demonstrated that the Netflix database of 500,000 with movie ratings could be re-identified, revealing sensitive political and sexual preferences of the actual people who rated movies. Netflix did not get the consent of renters to expose their ratings to the public or ot researchers.
Yet Netflix is moving ahead to release even MORE personal data for its next million-dollar contest. The major media (NYT's STeve Lohr for example) has NOT reported at all on how Netflix is violating movie renters' privacy, but instead trumpets the prizes paid to those who develop more accurate ways to predict which movies you will want to watch next.
The problem of re-identification is VERY serious for the healthcare system because health data is impossible to de-identify. It is so rich in detail that de-identification is almost impossible.
Today, the treasure trove of all Americans' sensitive health data is being endlessly used and disclosed without informed consent to millions of "covered entities" and "business associates" (and their millions of employees)--subjecting EVERY American to the theft, sale, and misuse of the most sensitive personal information that exists.
Who will hire you knowing all about your prescriptions, illnesses and genes?
Saturday, August 15, 2009
Healthcare moving to Cloud Computing
Today there is not yet a trusted organization to certify the privacy of electronic health records systems, whether on servers or in clouds.
Until the privacy of health data can be assured first with trusted security certification and then with a separate stringent privacy certification (proving that patients control the use and disclosure of their sensitive records) Americans will not trust that their data is safe.
Proof that consumers control personal data in clouds will be essential for trust in health IT.
So far all we have are promises of security and privacy. We won't trust without verification .
Wednesday, August 12, 2009
Who is tracking YOU?
It is impossible to search for health information privately via Google, etc.
Health websites take massive advantage of Americans' powerful expectations that ALL healthcare providers put their interests and their privacy first---expectations which come from the traditional doctor-patient relationship and the ethics that have governed Medicine for 2,400 years (derived from the Hippocratic Oath).
Americans are not yet ready to believe that every aspect of healthcare in the US is profit-driven, rather than driven by the ethical codes all health professionals swear to at graduation: the promises to "do no harm" and to "guard their secrets".
Americans are not yet ready to believe that Wall Street has taken over Medicine---and that instead of guaranteeing the strong health privacy rights Americans have under the law, Wall Street erases our rights to ensure shareholder profits.
View this story in the NY Times: Ads Follow Web Users, and Get More Personal
Tuesday, August 4, 2009
Security and Hacking, Real Fears
Securing health records in small doctor's offices and clinics is not easy: small offices can't afford Fort-Knox style data protection measures, like hiring security experts to make sure hackers aren’t getting into their systems. Even if electronic health records software includes encryption and other security features doesn't mean those features will be turned on and used.
• Now, many privacy advocates are concerned the administration's effort could end up making health information less secure. "If there isn't a concerted effort to acknowledge that the security risks are very real and very serious then we could end up doing it wrong," says Avi Rubin, technical director of the Information Security Institute at Johns Hopkins University.
• "As more information is shared, it is subjected to the weak-link effect."
• Mr. Osteen's efforts to safeguard information won't be useful if smaller providers he shares it with haven't made the same kind of security investments."
Wednesday, July 22, 2009
Genetic Privacy Debate hits Major League Baseball
• “DNA contains a host of information about risks for future diseases that prospective employers might be interested in discovering and considering,” said Kathy Hudson, the director of the Genetics and Public Policy Center and an associate professor at Johns Hopkins University. “The point of GINA was to remove the temptation and prohibit employers from asking or receiving genetic information.”
The big problem is that the Genetic Information Non-Discrimination Act (GINA) does not stop employers or insurers from receiving or using genetic information. It isn’t enforceable.
Baseball players are not the only ones whose DNA and genetic tests can be used against them--the same thing can happen to all of us.
According to GINA, employers and insurers can't use genetic tests to discriminate against employees or enrollees in health plans, but there is no way to tell whether they do or not. Employers and insurers do not have to inform us if they have copies of our genetic or DNA records.
• Do you think an employer is going to tell you were passed over for a promotion based on your DNA?
GINA is toothless--it forbids bad behavior but there is no way to enforce it.
And Americans' genetic privacy is not protected by HIPAA. HIPAA makes it impossible for any of us to prevent OUR sensitive health information from being used by millions of 'covered entities' and 'business associates' for purposes we would never agree with--including using genetic tests to discriminate againts us.
Face Book users control who sees the personal information they post on their walls, but Americans can't control who sees their electronic health information. What's wrong with this picture?
The rules for spending $19 Billion on health IT are being written now. Now is the time we must press to restore control over OUR personal health data.
Stay tuned--sign up for our alerts and we'll tell you what you can do to save privacy.
Monday, June 22, 2009
But privacy is ALREADY gone!
The authors fear that Americans' health privacy rights will be eliminated by health reform if a proposed "public plan" evolves into "single payer".
They are too late, there is no privacy (the right to control personal information) in the US electronic health system ---EXCEPT for the strong new rights Congress added to the stimulus bill: the ban on sales of PHI, the right to segment sensitive records, and the right to limit disclosure of PHI to health plans for payment or HCO if treatment is paid for out-of-pocket.
Our strong existing ethical and legal privacy rights (a powerful national consensus arrived at over 200+ years) are being totally ignored by federal and state government and industry.
The authors clearly don't know that we have no health privacy today or that privacy advocates in the bipartisan Coalition for Patient Privacy (representing 10 million Americans) work to restore those rights.
In 2002, amendments to the HIPAA regulations granted new rights to corporations and government to use ALL health data without informed consent for purposes no one would ever agree to AND eliminated Americans' rights to give consent before our data is used. See: http://www.patientprivacyrights.org/site/PageServer?pagename=HIPAA_Intent_Vs_Reality . In 1999, the HIPAA statute granted law enforcement unfettered access to all electronic health records without informed consent or any judicial process.
Both Democratic and Republican Administrations and Congress have contributed to eliminating patients' rights to control personal health information. The ONC-Coordinated Federal Health IT Strategic Plan: 2008-2012, requires all EHRs to be "wired" for data mining and requires every citizen to have an EHR by 2014.
See: http://www.patientprivacyrights.org/site/DocServer/HITStrategicPlan08.pdf?docID=5161
The Federal Strategic Plan grants "back door" access to the nation's electronic records to government agencies; to the for-profit research industry for P4P, QI, population health, genetic research (personalized medicine), etc; and to the insurance industry to detect fraud (this is one of the most offensive and discriminatory measures planned--the last people patients want to have MORE access to sensitive health records are insurers and employers).
Key Quotes:
• The Supreme Court created the right to privacy in the 1960s
• the justices posited a constitutionally mandated zone of personal privacy that must remain free of government regulation, except in the most exceptional circumstances.
• Taking key decisions away from patient and physician, or otherwise limiting their available choices, will render any new system constitutionally vulnerable.
• if over time, as many critics fear, a "public option" health insurance plan turns into what amounts to a single-payer system, the constitutional issues regarding treatment and reimbursement decisions will be manifold. The same will be true of a quasi-private system where the government claims a large role in defining acceptable health-insurance coverage and treatments. There will be all sorts of "undue burdens" on the rights of patients to receive the care they may want. Then the litigation will begin.
• In crafting the law, however, its White House and congressional sponsors must keep privacy -- that near absolute right to personal autonomy they have so often praised and promoted -- squarely before them. The only thing that is certain today is that the courts, and not Congress, will have the last word.
The authors tilt at the wrong windmill --not realizing they are too late: the privacy for health data in electronic systems is already GONE. We hope they will join us and work to RESTORE Americans' longstanding ethical and legal rights to health privacy--regardless of a "public plan" or whether it turns into "single payer".
Wednesday, May 6, 2009
A Start to Securing PHI?
Check out this zinger quote: "Most organizations don't even know where their PHI is." Why doesn’t the mainstream press tell the public that the health care organizations (like hospitals) have no idea where all their sensitive personal health data resides?
How about this: "The software (Identity Finder) automatically finds PHI such as social security numbers, medical record numbers, dates of birth, driver licenses, personal addresses, and other private data within files, e-mails, databases, websites, and system areas. Once found, the software makes it simple for users or administrators to permanently shred, scrub, or secure the information." Emails? Who sends drivers license numbers, SS#s, and Dates of Birth in emails? Clearly lots of healthcare organizations do.
We can only hope products like this sell.
See full article at http://news.prnewswire.com/DisplayReleaseContent.aspx?ACCT=104&STORY=/www/story/05-05-2009/0005019328&EDATE
Thursday, April 2, 2009
Is not just celebs who need strong security and privacy for PHI
Is not just celebs who need strong security and privacy for PHI--what about women whose abusers work for hospitals? What about all the minor local celebs? Do you want your nosy neighbor who is a clerk to be able to read your records?
Stepping up employee snooping via retroactive audits is EXTREMELY expensive (major hospitals have to have large technical staffs to be able to audits millions of accesses looking for those that should not have occurred). 'Smart' consent technologies exist. Retroactive audits for improper access are like looking for needles in a haystack UNLESS you are Nadya Suleman or some other celebrity whose EHR is being actively watched. Why not keep the horses from getting out of the barn in the first place?
Refer to COMPUTERWORLD story: "Kaiser fires 15 workers for snooping in octuplet mom's medical records".
Wednesday, March 25, 2009
RealAge sets new low...
Is the RealAge quiz an unfair and deceptive trade practice? Where is informed consent?
Do the 27 million who took the test to find out if they are younger or older than their "biological age" really know that they are giving detailed information so RealAge can market drugs to them?
RealAge illustrates a critical problem with almost all health-related websites: people are actually going there for help - they appear to offer services, so people expect that health websites follow medical ethics and protect their privacy. But they don't. Health websites are not altruistic and don't adhere to medical ethics or privacy rights. Health-related websites offering rating scales, searchers, or information about diseases and treatments are typically just as deceptive: they also are designed primarily to collect personal information for personally-targeted marketing or worse.
View the New York Times article Online Age Quiz Is a Window for Drug Makers.
Tuesday, February 24, 2009
From Sharing Music to Sharing Medical Records
Dr. Eric Johnson's latest study is out. Our job is to inform the public and Congress, who are continually being falsely reassured that health IT systems are secure and private by spinmeisters for the insurance, hospital, drug, Health IT, and health data mining industries.
Industry's blatant false promises of security and privacy are something we have been urging FTC to investigate (as false and deceptive trade practices) and the new Administration should understand to ensure that the stimulus funds are not spent on primitive health technologies with abysmal security and no consumer control over PHI. We need 'smart' health IT, 'smart' human processes, and we need the health care industry to step up and use them, so we have trusted electronic systems and don’t waste the stimulus billions.
See Dr. Johnson's paper here.
The research examined samples of health-care data disclosures and search activity in peer-to-peer file sharing networks of the top 10 publicly traded health care firms (using Fortune Magazine's list) over a two-week period. More than 500 hospitals were represented in the 10 organizations. 3,328 files were collected for the study.
•"data losses in the healthcare sector continue at a dizzying pace"
•"Far worse than losing a laptop or storage device with patient data (Robenstein 2008), inadvertent disclosures on P2P networks allow many criminals access to the information, each with different levels of sophistication and ability to exploit the information."
•"Many of the documents were leaked by patients themselves. For example we found several patient-generated spreadsheets containing details of medical treatments and costs--likely for tax purposes."
•"we found a hospital-generated spreadsheet of personally identifiable information on recently-hired employees including social security numbers, contact information, job category, etc"
•"For a hospital system, we found two spreadsheet data bases that contained detailed information on over 20,000 patients including socials security numbers, contact information, and insurance information."
•"For a mental health center, we found patient psychiatric evaluations."
Where is the mainstream and trade journal reporting on this???
Tuesday, February 3, 2009
Identity Theft Through Your Health Records
This story details identity theft by a Denver hospital employee. It is a single instance, but it shows how easy it is for any hospital employee, anywhere to steal patients' identities.
Hospitals will become a major source for identity theft because today's primitive, poorly designed health IT systems allow thousands of employees access to all patient information--including what's needed to steal identities. Not only can thousands of hospital employees see every patient's medical records (think George Clooney and Farah Fawcett--whose records were sold to the Enquirer), they can see and steal the demographic and financial information too.
For whatever reasons, the media has primarily reported on how wonderful electronic health systems are without explaining the severe risks they pose to privacy and the new problems they can create (errors, downtime, work flow obstacles, data sales, lack of interoperability, etc).
The health IT stimulus bill with $20B for HIT needs very strong consumer protections to ensure that the current 'norm' for hospital electronic health systems, ie badly designed, open access systems, is replaced by systems that only allow access to the few staff members the patient has given permission to see and use his/her electronic records. The current HIT bill does not require the use of consent management technologies to restore patient control over PHI.
Tuesday, January 27, 2009
Pro-Privacy Will Continue to Grow
The real reason privacy will win is simple and practical: electronic systems will never be trusted or work unless consumers control personal health information.
In the words of Justice Brandeis: "The right to be let alone is the most comprehensive of rights and the right most valued by civilized men. To protect that right, every unjustifiable intrusion by the government upon the privacy of the individual, whatever the means employed, must be deemed a violation of the [Constitution].” Justice Brandeis 1928.
Olmstead v. United States, 277 U.S. 438, 478, 48 S.Ct. 564, 572 (1928) (Brandeis J., dissenting).
Brandeis dissented from the conventional wisdom of his time. Today we are the dissenters from the CW of our time, but like Brandeis' dissent, ours will prevail.
Wednesday, December 24, 2008
DoD does WHAT?
Maybe when you join the military you lose all privacy and Constitutional rights. I don’t know, I'm not a lawyer. If so, that is a steep price to pay to serve your country: losing all health privacy for yourself and your relatives forever. Do those who join the armed forces know they are signing up to become medical guinea pigs? Do they really understand the consequences for their futures and their families futures?
Many questions abound:
• Are the electronic records adequately secured? What a rich target: 12 million health records! What if enemies hack the privately held data base to learn about key military leaders?
• Will Phase Forward continue to use and sell the records for other purposes as HIPAA authorizes? Other data management corporations (such as Thomson Medstat) the government pays to perform fraud and waste audits obtain millions of health records that they later aggregate and sell to employers without anyone's consent.
• Furthermore--this is clearly medical research without informed consent. That is simply unethical and illegal. The US signed the Declaration of Helsinki after WW II because Nazis did human research without consent. Back then America recognized the need for informed consent before research takes place. Today, the codes of research and medical ethics still require patients to give informed consent before personal records can be used or disclosed. Why is this project not being done with informed consent when new 'smart' electronic consent tools could make it easy, cheap, and fast to obtain informed consent and explain all the risks and consequences?
Review this article from the Washington Post's Government Inc. Blog for more information:
Data Mining for DoD Health
Tuesday, December 9, 2008
Genomes: Behold or Beware
According to Navigenics, the personal data shared is "aggregated" and "de-linked" from "your account information", but Navigenics offers no proof that it cannot be re-identified.
As we learned from the NIH experience, it is very difficult to "de-identify" or "anonymize" genetic data. The NIH closed a public research data base of "de-identified" genetic data after researchers proved the data could be re-identified See:
Questions abound:
• How can anyone be sure that Navigenics protects the privacy of genomic tests without trusted external audits of their privacy practices and policies?
• Does Navigenics pay MDVIP's doctors a "kickback" for "collaborating" each time a patient gets genomic tests? Does MDVIP inform patients that it has a contract with Navigenics and what each doctor is paid?
• Who is being paid for "collaboration"? What exactly are the financial and contractual terms of "collaboration" between MDVIP and Navigenics?
• Do MDVIP's patients really understand the risks of using Navigenics to do the testing or the risks of letting Navigenics share their genomic data with unknown researchers and research organizations----that can put their data into public data respositories and publish it in studies? Or the security risks that a particular public respository can be hacked?
• Are MDVIP's patients coreced into taking Navigenics tests by their doctors? Most patients want to do what their doctors recommend. What is the consent process?
• Did MDVIP contractually sell or give their patients' genomic data or to Navigenics to own or sell? Should the public trust Navigenics, a for-profit corporation, when personal genomic data is a very valuable commodity?
• Should any for-profit collaboration "define the standards in which preventive genomic medicine will be integrated into patient care for decades to come"? No consumer health privacy expertise, assessment, or input was sought.
• There is not yet an operational, trusted, consumer-led privacy certification organization to audit genomic testing corporations to certify they don't sell genomic data and that consumers control sensitive personal genomic data in their data bases. In the absence of a trusted privacy certification organization, the privacy principles developed in 2007 by the bipartisan Coalition for Patient Privacy
• Would MDVIP's patients still feel "the experience (was) positive", "empowered rather than anxious", and "desire to change their lifestyles and more productively work with their physicians" if they knew their doctors were paid by Navigenics and their data was sold and/or put in public data repositories with unknown security and privacy protections?
This blog is in response to the article: Physician network to use genomic-based preventive healthcare
Wednesday, October 22, 2008
Response to: Will Technology Cure Health Care — Or Kill It?
1) Americans NO longer have the right to health privacy! Today, your rights to health privacy in electronic health systems are nil. You have no control over personal electronic health information. Federal bureaucrats eliminated our rights to control the use and disclosures of personal health information in electronic systems in 2002. The media has not reported on this drastic elimination of every Americans’ privacy rights. See HIPAA's Intent v. Reality.
2) Once you reveal your genome, you will never be able to delete it from the private corporation’s data bases or make it private again. Why on earth would you pay someone to take and use the most personal health data that exists about you and your family for whatever purposes they choose? Think about Paris Hilton’s sex video, once it was out in cyberspace, it can never be private again. It will live for millenia on the Internet.
3) Why pay a private corporation like 23andMe or any other for-profit genetic testing lab to take your extremely valuable and sensitive personal health data and give it to them as a CORPORATE asset—to sell, to disclose to researchers for studies you might not want to be part of, to sell as an asset to employers or insurers or financial institutions, or even to sell to the US Government as part of the data profiles they are building on every American in Fusion Centers.
4) The legal duties of coporations are to stockholders, not to patients or people who buy genetic tests. Genetic testing labs like 23andMe can be bought by Google or the Bank of America or to a business that sells employers genetic snapshots of future employees’ potential illnesses. Even if you trust a genetic lab—-you have no control over whether that corporation is sold to another corporation that you would never want to own your DNA.
5) Today’s health IT systems are notoriously insecure and hackable. An industry study of 850 electronic health records systems found ALL of them could easily be hacked. See Article.
What assurances do you have that the lab’s database is secure enough to prevent your genome or genetic tests from being stolen?
6) It is crtical to understand that giving ownerhsip of a personal asset like your DNA or genome to a corporation is a very bad idea. Not only do you put your future opportunities at risk, you endanger your entire family’s futures at the same time.
As a practicing physician who has spent over 30 years listening to patients whose sensitve medical records were used against them by employers or used to humiliate them or harm them in public, I am very well aware of how personal health information is used to harm people and ruin lives. I founded Patient Privacy Rights because health information should never be used except to help you get well or for research WITH your informed consent. No one should be denied a job or a promotion because of fears about their future health.
Because of the lack of privacy, 600,000 people refuse to seek treatment or early diagnosis for cancer and 2,000,000 refuse treatment for mental illness. 150,000 Iraqi vets refuse treatment for PTSD because they fear their treatment will not be private. The result is the highest rate of suicide among active duty military in 30 years. The lack of health privacy kills.
Current law is just not enough to protect health privacy. GINA is not enough. We need Congress to restore our longstanding Constitutional, legal, and ethical rights to control personal health information. Without that right firmly re-established in Federal law, giving ANYONE your sensitive genomic or health information is a very bad idea.
Check out our website. You can sign up for e-alerts about health privacy in the Digital Age. If we are able to restore control over our personal digital health information, then we have a powerful model for building personal control over ALL our personal electronic data (financial, email, phone records, purchases, etc). If you do not fight for your privacy rights, who will?
If EVERYTHING about you is for sale and can be seen by everyone, will you continue to have your precious liberties and freedoms?
See Original Article
Wednesday, August 6, 2008
Missing Laptop Keeps Firm From Registering New Fliers -- by Joseph Galante
Here's what Verified Identity Pass says about security and privacy. They had an audit by Ernst and Young, but apparently it didn’t mean much:
Clear's Commitment to Privacy
"Since our founding in 2003, we have been committed to the privacy and security rights of our members. We have created an exhaustive privacy and data security program and we will always clearly communicate any changes to that program with members.
We are committed to the transparency of our privacy practices and that's why we have instituted open, independent checks on our privacy promises, including an independent and public security and privacy audit, the appointment of an independent privacy ombudsman, and an unprecedented Clear Identity Theft Warranty.
In June, 2007, Ernst & Young LLP concluded a comprehensive, independent audit of our privacy policies and practices. This was the first ever independent privacy audit conducted for a national registered traveler program."
View Full Article
Saturday, March 29, 2008
Electronic Health Records wired for abuse
“Oops! They did it to Britney again.” No, it’s not a song parody, but a reflection of the poor state of American health privacy - something Bay Staters should think about as their Legislature considers a bill to mandate Electronic Health Records (EHRs).
Staff members at UCLA’s Medical Center are under investigation over allegations staffers accessed Britney Spears’ medical records earlier this year. Sadly, this is not the first time individuals other than the paparazzi violated Spears’ privacy; staffers also took inappropriate peeks when her first child was born.
...Most Americans think the Health Insurance Portability and Accountability Act (HIPAA) protects their privacy and that the HIPAA notice they sign at the doctor’s office lists all of their rights to privacy. In fact, that HIPAA notice lists the vast number of ways their private health information can be used, without asking and over objections.
HIPAA was originally intended to protect privacy. Regulators earlier in this decade rewrote the rule to sanction disclosure of medical information for treatment, payment or health care operations.
“Particularly troubling about HIPAA’s Privacy Rule is the governmental authorization for covered entities to use patients’ confidential information without their consent for health care operations that are unrelated to “payment or treatment,” writes Dr. Richard Sobel, senior research associate in the Program in Psychiatry and the Law at Harvard Medical School. Sobel explains that “health-care operations” can include using information for marketing purposes, which normally would require written consent.
Data-mining firms were given a gift by the rewriting of the HIPAA Privacy Rule. Data-mining firms can obtain information about your prescriptions, treatment for mental health and genetic predisposition to illnesses. That information can be passed on to credit firms, marketing firms and even prospective employers.
...Patients need progress and privacy in this digital era. The only way to ensure we get both, and avoid the negative “celebrity treatment” Spears received, is to ensure the health IT bill signed by the governor fully recognizes the right of patient consent.
View the Full Story