Blockchain Healthcare 2016 Report – Promise and Pitfalls
tierion.com
tierion.com
Blockchains are public record, which you do not want your health data stored in. Even this article acknowledges that and recommends using private blockchains, which offers no competitive benefit over other decentralized databases.
This just seems like another hammer looking for a nail.
You want a hash of your data stored in the Bitcoin blockchain, that can referenced at a later point in time to validate the accuracy of the data.
The Bitcoin blockchain is a global immutable data ledger that makes for a great place to anchor hashes to.
- You can't guarantee which block the transaction is on [1], which means all your customer encryption is asynchronous (slow).
- Your customers are assuming that you're keeping your private keys safe, which is not any different than trusting a non-bitcoin verification provider.
- The first quantum computer is going to destroy ECDSA, meaning your private keys will be reversed and every health product depending on your service will be trustless. Merkle trees can theoretically be used in a post-quantum world [2], but the method by which you're generating the root for the tree is not safe because you're relying on a network you don't control (Bitcoin).
How is this competitively good for healthcare?
[1] http://www.ibtimes.com/bitcoins-big-problem-transaction-dela...
[2] https://en.wikipedia.org/wiki/Post-quantum_cryptography#Hash...
[0] https://en.bitcoin.it/wiki/Quantum_computing_and_Bitcoin
The other points are still problems of using bitcoin right now.
[1] http://www.npr.org/sections/money/2016/10/05/496751771/episo...
Practically, advanced directive knowledge requires verbal confirmation with the patient or healthcare proxy; or something like a MOLST (paper).
Can you share some example?
I'm not sure how blockchain as a technology necessarily moves us forward to get there. The vendors have a stranglehold on medical record software and have no incentive to work together, share data, or agree to any standards -- I mean, it wasn't until last year that the two hospitals I work at (owned by the same umbrella hospital, using software from the same vendor, and 3 miles apart from each other) could electronically access records from each other. We had to fill out paper forms, make phone calls, and send faxes to get access.
It's not for want of a technological breakthrough that we've been struggling so much...
There is a standard for medical data already called HL7, but not everyone adheres to it.
What would work better is if the medical record is a service provided by the government or some public service which takes care of security for you. Every medical record would then be added to the patient's blockchain record and vendors can read/write to it.
Of course a vendor would have to vetted for security purposes.
My proposed solution is government regulation in order to level the playing field by way of EMR certification and/or tax-centivization. The goal should not be to pick a standard but rather set the rules:
- if you create data you offer public docs and/or SDKs to grok that data
- if you store data you offer public docs and/or SDKs to access that data
[0] http://siculars.posthaven.com/health-data-integration-regula...
Tamper evident transaction logs (rolling hash) were sufficient.
I don't quite see what blockchains (proof of work, consensus protocol) would add.
Is there a use case for tracking prescriptions? Not a provider, so I'm just guessing.
Or rather, the only way I can see this happening is that everyone, everywhere on the buying side is either actively doing harm or so incompetent those are indistinguishable.
The arguments that "butbutbut, all vendors require us to do X and never let us do anything" got to be bullshit. If you have sexy multimillion medical project that needs vendors, and some of them won't take it if they can't force you into submission, I have no doubt that the million other companies in the world would take the project more than gladly.
As such, the project will have a rather long list of problems. The functional specification of the system to be built will have a large number of gaps because the people writing the functional specification aren't the people using all of the parts of the system (no one person will be using all the functionalities). There will be a number of unforeseen problems causing delays, if the vendor does not have proper risk management in place the delays will compound and the entire project will become delayed. Due to frustrations, the customer will relax the priority of some of the nice-to-haves from the functional specifications and focus on the critical requirements.
Even if the new feature makes it into the end product, since it wasn't a key requirement of the system in the first place (otherwise the first vendor would have provided it from the beginning) it will most likely not be used often and may not even be piloted. Future upgrades to the system will degrade the functionality in unpredictable ways and no one will notice. When someone does notice, it is easier to revert to the old manual way of solving the problem than getting the functionality fixed or learning how to use it.
This is why some people are scared of replacing multi-million dollar software. That is why banks still have a lot of systems written in COBOL, risk averse people aren't willing to hope that everything might go right.
“…the term ‘blockchain’ has been so misappropriated that no one knows what it means anymore.” – Elaine Ou, Bloomberg
People are using blockchain to describe Bitcoin, private ledgers, the public Ethereum network, private Ethereum forks, and other tech that shares design characteristics with Bitcoin.
https://godistributed.com/health/
Our report was targeted at a non-technical audience. Printed copies were distributed to about 500 attendees. We wanted to make them aware that while there may some opportunities for using blockchain technology also comes with substantial risks. We want to help them cut through the hype and maintain a healthy dose of skepticism.
Gartner recently placed blockchain technology at the beginning of their hype cycle.
[0] https://lists.hyperledger.org/pipermail/healthcare-wg/2016-O...
[1] https://www.finextra.com/pressarticle/66385/medical-data-app...
Many databases can be modified by the ones who centrally operate it. The Bitcoin blockchain is the worlds first distributed global database that takes the burden of trust off your internal systems and records.
Yes, they are robustly distributed on each of 5,000 worldwide nodes.
But, think about that! How's that going to work for 10 million patients' MRI records? Each MRI being a series of high res images?
That's not possible with Bitcoin - its not designed to store near that quantity of data - its not even desirable.
I don't know what the advantage of Blockchain is with healthcare, but its certainly not storing your medical records on the Bitcoin blockchain. [Standard disclaimers about predicting the future apply.]
Maybe a hash of them, so you know they aren't tampered with, or that sort of thing - but that seems like a second order problem.
He's talking about using a technology like Tierion or Chainpoint to anchor a hash of the data in the blockchain. This can be used to verify the integrity and approximate timestamp of the data.
The post I responded to seemed to be.
It implied the data would be "distributed upon 5,000+ worldwide nodes in an immutable data ledger", and said it would:
"be there forever" "keep the data accurate and accessible"
I think its legit to call this out. Blockchain is a great technology, but its being hyped as if its the world's only distributed database.
> This can be used to verify the integrity and approximate timestamp of the data.
That may indeed be beneficial, but isn't the panacea that is being touted.
We agree. That's the primary conclusion of the report.
The DNS would like a word.
There are instances where blockchain type technology is useful such as transactions between multiple parties with lack of trust. This isn't true in healthcare and surely not for EMR/EHR data.