Epic Tells Customers It Will Stop Google Cloud Integrations
healthcareitnews.com
healthcareitnews.com
In most implementations, neither Cerner not Epic encourage structured data recording except for billing codes. This means that if a patient comes through the medical system frequently, doctors have to read pages and pages of unstructured text to get a sense of what's going on for the patient. The software is designed to be sold to administrators and, as currently designed is unquestionably leading to worse outcomes for patients.
Google has made a lot of mistakes. If they build something doctors truly want to use and that helps properly organize information, however, and if Google doesn't misuse the data/people aren't unreasonably paranoid about data misuse, it will be a godsend for the industry and it will save lives.
We haven't even begun to talk about the potential for machine learning and statistics to understand what treatments are most effective if data are structured properly. This is unquestionably an interesting and unique case where collecting massive amounts of data and handing in to a trusted, competent, creative, research-oriented authority could have incredible benefit for mankind. I don't trust Cerner or Epic with this mission for a second.
Many people simply don't believe anything Google says, and even those who do believe them to some degree know that others won't.
Google has become a reputational hazard in fields that deal with sensitive data such as healthcare.
Some decisions made by current management don't help at all. Instead of separating the advertising business from other activities like cloud and AI, they are moving in the exact opposite direction.
Why? I find this entirely baffling.
What if something questionable happens, even if it's legal, and you're found to have handed over patient data to Google, the largest ad targeting firm on the planet?
Pointing at legalities will not save your reputation or your job in the face of glaring misalignment of interests.
It's like letting your dog guard your employer's sausages after giving it state of the art training in self control.
Also, ads are currently indispensible for privacy as weird as that may sound. There is currently no widespread, privacy preserving form of electronic payment, and I very much doubt that there will ever be one.
What we should do is regulate/restrict ad targeting and make sure that advertising is as transparent as possible.
But none of that has anything to do with Google's reputation issues and conflict of interest. Google should split off its ad business from all other activities. Otherwise they will always remain an advertising company and distrust in everything else they do will only grow.
You have to ask yourself what advertisers would do if you ban those in-your-face super annoying ads. Stop spending money on trying to influence our decisions? I don't think so.
https://www.bloomberg.com/news/articles/2014-03-03/advertisi...
I think transparency is more important than fighting annoyances.
> people aren't unreasonably paranoid about data misuse
Is this a joke? Google is an ad company. And if I look at the US, I think there are periphery problems here.
What really improves the situation in the medical field are large databases of indications.
A remote city or village has a few general practitioners. They cannot know about any form of illness that has been indentified. To help them, they need an information infrastructure to support them for diagnostics. That would help people and might save lives.
> We haven't even begun to talk about the potential for machine learning
Then you just have to ask patients if they want to share their data. That is not asking to much. Until then medical data should be protected.
Now they all do their best to feed your data straight into Google, while other similar products do their best to protect it. How long until GCP says 'let's pool all of our data for machine learning' or 'centralize your network traffic for security analysis' and 'We've updated our privacy policy, please leave immediately if you don't agree to the updates'
It is also very likely that any data collected is used to reinforce and consolidate their main business.
A company can do more than one thing. It probably would be a decent idea to make GCP a subsidiary, just so it‘s absolutely clear to everyone. Their capabilities in data analysis and ML make this an ideal project.
Like why is no one saying Amazon might be misusing data from AWS to benefit themselves. This just seems like the usual HN bias.
Apple listens to Siri conversations, whatever. Experian leaks private data, no biggie. Experian gets hacked, oops. Grindr sells your sexual orientation data, business as usual.
In a cloud data misuse case the civil liabilities are actually terrible, because you’re going up against other cash-rich corporations. Insert saying: stealing from the poor vs stealing from the wealthy.
The difference is, Amazon hasn't demonstrated a massive desire to collect and use health data, and fundamentally, isn't an ad company.
The other thing you're forgetting is that Google regularly changes the terms of the agreements it makes. When it bought DoubleClick, it swore that DoubleClick would never be able to access people's Google account data and that there would be a clear firewall of ad personalization information. Up until they changed their terms of service so that they could: https://www.propublica.org/article/google-has-quietly-droppe...
Google literally embodies the classic "I am altering the deal. Pray I do not alter it any further." Just because they claim they won't abuse the health data they are zealously collecting today doesn't mean they won't change their mind tomorrow.
An ad company should not be allowed to hold your health data.
I‘m pretty sure they are only accessing their data as allowed by the contracts for maintenance for example. Likewise for GCP and Azure.
Regarding your second argument. Doubleclick is on the consumer side. That‘s why GCP has it‘s own CEO, it‘s own buildings and org in general. They are seperate from the consumer side.
Put yourself in Google‘s shoes. They can make tons of money by revolutionizing the health care sector, improving patient care at the same time. Why would they fuck it up by feeding data to the ad side illegally. The risk is too high. No one would ever trust them again and they‘d probably be sued out of existence.
Is it not feasible that they are simply trying everything they can to become less reliant on ads. They have stated several times that the cloud side will be the dominant revenue source in the future. Is that possible? No idea. But strategically it makes sense to push cloud with all possible force.
Executive of one 'mini company' is free to take their own decision which is good for their division and their OKR.
That aside, I do not want to rely on the inefficiency of internal processes for data protection.
I do not, however, believe that Google has any incentive to keep it that way, once there's buy-in. What Google's doing here is great, but on the other hand it's Google that's doing it.
What incentive do doctors and patients have to keep vending the data to Google at that point? And what incentive would other Cloud customers have to trust their data wouldn't get aggregated?
The GCP business model is different from Google's other business models and they know it.
Inertia, if nothing else. Moving platforms, especially in a highly-regulated industry, is no small thing.
Regardless of your personal good intentions and honesty, or anyone else's working there right now, a lot of people are never going to trust an organisation with the track record and potential conflicts of interest that Google has to process sensitive personal data responsibly. Its leaders and the investors backing them made their bed by helping to create the culture of pervasive involuntary surveillance that we all now suffer, and they will forever have to lie in that bed as a result.
It's unfortunate, because clearly there is considerable potential for improving patient outcomes through better use of big data and automation in medicine, and no doubt many of the people working on these kinds of projects have nothing but good intentions. However, until the culture of the technologists operates on the same kind of ethical and legal level as the culture of the clinicians, I don't see how the trust is ever going to be there now. The individuals doing the work need to be personally responsible for behaving ethically, even if they are directed to do otherwise by their superiors, like doctors and real engineers. Organisations that fail to meet the required standards need to face penalties that are an existential threat, so their investors stand to lose everything and their leaders can end their own careers if anyone breaks the rules deliberately or through gross negligence. Without those kinds of obvious, strong incentives, with the way so many players in the tech industry have exploited people's data in recent years, I think the barrier may simply be too high to clear.
> The software is designed to be sold to administrators and, as currently designed is unquestionably leading to worse outcomes for patients.
disclaimer: I’m a former Epic employee who worked on their inpatient app.
Do you have data or literature to support these statements for a typical Epic implementation or is this just anecdotal and biased?
Although there were ALWAYS some sort of issues and pushback from clinicians during implementation and go live, Epic software and data flow literally revolves around patient care and not billing. I don’t recall exactly which apps came first when Epic was born in the 1970s, but I believe their billing and admin apps came much later than many of the clinical apps. It’s actually why they still use a backend on top of mumps and cache, because the way data is stored and flows in these systems can do so literally around the core patient data structure, which should theoretically make a clinicians job easier to review a complete patient record (not make it easier for billing).
Source: staff meetings (former Epic IS) and this old article: https://isthmus.com/news/cover-story/epic-systems-an-epic-ti...
These are absolutely, extremely different. Assuming that Google will somehow break into your VMs or GKE clusters to get data out and monetize it is crazy, of course, but EPIC tries to suggest that.
All these things taken together means it is not crazy to imagine that this is the case. If it is not the case currently, we have to assume it will be the case soon and that when it does become the case, historic data is still available. They are therefore always a bad choice.
Sure, and what company would drive around the entire planet and collect peoples private info and WiFi networks? That’s crazy obviously lmao
It’s pretty hard to trust google from where I’m standing right now. So many incentives to do the wrong thing.
Edit - I can’t help but to say they are still better than most... at least for now. They should get some credit for their track record. It’d just be nice to know how their incentives are still aligned to the end consumers, and how to know how that would change.
not really. Maybe that's how they started, but that's not what they have evolved into.
-> the software is always purchased by administrators, typically with little input from doctors.
again, maybe that's how it used to happen but anywhere that I've worked or consulted on has a myriad of doctors, nurses, etc that have input. The last hospital I worked for wouldn't even let us change a single field in the EMR without it being approved by a committee of nurses.
-> In most implementations, neither Cerner not Epic encourage structured data recording except for billing codes.
This is not true at all. In fact, it is the clinicians' preference to write or dictate notes that is the reason for this. Both Epic and Cerner provide digital forms that allow for selections from lists or checkboxes which are then stored as discrete data elements in their respective databases. I'm not going to say either are perfect and - surprise! - clinicians hate change so they always hate their EMR, but it's not for the reasons you state.
I'm curious which division of Google you work for and how much experience you have working for an EMR vendor or healthcare system.
Google is absolutely NOT doing the right thing here. They’re are stealing people’s private medical data without their consent.
|and if Google doesn't misuse the data -Don’t worry, they will, like every piece of data they’ve ever fathered.
|people aren't unreasonably paranoid about data misuse, -They are, because google has shown they can’t be trusted ever. They view fines as the cost of doing business so why should they care?
So instead doctors need to spend hours typing up their notes using the just correct code or term so it's structured? As I understand it, doctors find having to type things into EMRs to be a giant time sink as it is that takes away from their ability to care for patients.
The perspective of “how can we extract and exploit more personal data”, FTFY.
We are long past the point of giving Google any benefit of the doubt. They keep attempting to exfiltrate data from the NHS as well.
Healthcare can't be fixed with software or cloud providers. Healthcare is a problem of four groups with misaligned incentives. Any "solution" usually only considers one or two of these groups. The only way to solve healthcare in the US is to push regulations via CMS (Medicare). Medicare is such a huge piece of the pie that they drive the ship. Anything they mandate will move to commercial payors since they need to implement it everywhere anyway.
Healthcare is like homelessness. It is a political problem not a technical problem without solutions. We know what will fix it, we just don't have the will to do so.
The solution is to make it fewer competing concerns. We need to make employer provided healthcare illegal (go back to pre WWII) and force competition on the open market. We can still have you buy your own with HSA pre-tax dollars. We need to move to reference based pricing. Payors can't charge more than 1.3 * Medicare. This also solves the "out of network" bullshit, it is all the same so just pay. We also need to separate wellness/preventative from "health insurance". The one you know you will and should perform annually and the other is against catastrophe. Unfortunately, today we treat them as the same thing. I don't think a Medicare for all works but I do think it might work if it was for primary care only. Specialty care and Urgent/Emergency care could be handle by private payors.
Institutional Review Boards are responsible for ethical scrutiny of research involving human subjects. Informed consent, safety, etc.
As long as HIPAA is intact, I'm not sure any panic about misuse of patient data is justified, by any cloud provider.
That being said, systems like Cerner and EPIC definitely serve the interests of fee-for-service medical providers. Read this article by Atul Gawande. https://www.newyorker.com/magazine/2018/11/12/why-doctors-ha...
WSJ has had some good converge about parallel medical record stories that are going on right now too, as has CNBC:
https://www.cnbc.com/2020/01/17/epic-systems-warns-customers...
https://www.wsj.com/articles/paging-dr-google-how-the-tech-g...
WSJ podcast about it: https://www.wsj.com/podcasts/the-journal/why-google-is-pushi...
To quote the end of the WSJ article:
> Existing players in the health-care data market also fear that the tech giant will gain too much power in their industry. Some hospital and technology executives say they declined deals with Google lest it become a future competitor.
> “We could never pin down Google on what their true business model was,” says a Cerner executive involved in the discussions.
Oracle over the years, acquired some of our competitors.
Then every time customers would need to renew database licenses with Oracle, Oracle's sales reps would try to sell them the competing enterprise systems that they had acquired.
I think they really do understand what the Google true business model is, and this is exactly why they say that and avoid giving Google the access to the data.
Here’s an old article I found that references this juicy revenue opportunity (the rest have been cleared by Epic, so the story goes): https://www.healthcareitnews.com/news/setback-sutter-after-1...
The situation is sort of like moving from SOAP+XML Schemas to REST/JSON. Easier to develop, but the underlying data structures are still extremely complicated and tricky to get right.
This is especially true when dealing with ancient systems written in niche languages/database hybrids (MUMPS comes to mind): https://en.m.wikipedia.org/wiki/MUMPS
Healthcare IT is full of deeply committed professionals who deeply dislike Epic.
Then once you do, you're told who to hire, what to buy, what to train on, what to overall do, and if you don't do that they hold your support costs hostage under the guise of a "quality installation score". Not to mention the no-competes they slap on hospital staff so they can't bail as soon as Epic goes live.
Also, I wonder if AWS is pushing their heads into the sand. Particularly now that Cerner committed to AWS but DoD gave Jedi to Azure (Defense Health and VA are migrating their medical records to Cerner). AWS may be pressuring a customer (Epic) to squeeze their customers. Which absolutely sounds like something I'd expect from Amazon.
I'm a fan of Google, but what's with people thinking Silicon Valley companies can easily "get into" everything? What business is Google in that leads you to believe they could run hospitals? They couldn't even design a decent social network, which is their wheelhouse. At least Amazon was selling groceries before they bought Whole Foods.
Google could develop the best electronic medical record the world has ever seen, and still not take business from the companies that have been honing their dirty tricks since 1979.
https://cloud.google.com/solutions/healthcare-life-sciences/
Because it (atleast the demo) looks like readonly-data aggregation application (that has somesort note functionality that is not directly linked to actual ehr data)
“We’ve historically seen hospital systems make these decisions independently of their medical record provider,” said Aneesh Chopra, the president of health-technology company CareJourney and the former chief technology officer of the United States. “It will be interesting to see if Epic’s thumb on the scale moves cloud market share.”
So apparently if I'm a hospital I can run the Epic systems anywhere, or at least store my records anywhere, well, at least at AWS or Azure, and apparently not Google now.
> That report notes that "insufficient interest" from Epic customers in Google is behind the decision to focus efforts instead with those cloud competitors.
It seems like if you run Epic Systems at Google, you were in a minority that is apparently not worth supporting. This seems less like Epic putting their thumb on the scale, and more like their customers putting their thumb on the scale.
They don't do it because it may or may not be right for their needs. They pick Azure because somewhere along the line the mid- and upper-level managers, including director-level IT people, have been made to believe that anything other than Windows is insecure and not suitable for HIPAA.
If I even mention the word "Linux" or "AWS" to them they immediately curl up in a little ball mentally and treat me like I'm some kind of evil script kiddie, or magical wizard. It's truly baffling the responses I get from people who are supposed to be in charge of these things.
I don't know these people outside of boardroom presentations, so I don't know how they got this way. My best guess is that it's either Microsoft salesmen, industry conferences, or simply what they're comfortable with and anything else is not worth risking their jobs.
Lastly, all three of AWS, Azure and GCS do try and make a big deal of their HIPAA compatible instances, but whatever the compliance officer at a company is used to is what will get by the easiest - honestly anyone who has a compliance officer that is happy to accept a non-on-premises solution should count themselves as lucky.
All that said - I'd be amazed if MSFT hasn't invested heavily into advertising to cement this decision, but I'd also be surprised if AWS hasn't been trying to dump even more money in there - google just seems a bit clueless when it comes to the convention game and these sort of closed circles where everyone plays golf on tuesdays.
I'd argue it's less because of a belief that a non-Windows environment is inherently insecure and more that Microsoft very aggressively promotes their products as being compliant with regulations like HIPAA.
This isn't limited to PaaS. For example, I think that Teams will likely gain a foothold in healthcare environments over Slack because MS markets Teams as explicitly HIPAA compliant. (Slack explicitly is not).
Things like that buy them a lot of mindshare when it comes time to choose a PaaS provider.
Oh, and Slack is available with HIPAA compliance — https://slack.com/help/articles/360020685594-slack-and-hipaa
Also, as someone who actively shops for SaaS offerings for healthcare users, I can say that AWS and Azure are some of the very, very few organizations who offer anything with HIPAA compliance that isn’t locked away at the most expensive “contact us for pricing” tier. It’s so annoying. Never a chance to try a service with a low cost/stakes pilot/prototype because they hit you with the full sales pitch and highest price points. Being able to dip our proverbial toe into AWS with a low time/dollar commitment was a huge win.
What Microsoft sells is a "good enough" solution that speaks the right language for the decision makers. In turn, this makes their decision less risky while still satisficing the requirements.
If you have an existing business relationship with a company and already trust them to help you navigate regulatory hoops, there's going to be strong inclination to continue to trust them as you expand your infrastructure to the cloud.
Like you said, it's the kind of very smart, long-term marketing I tend to associate with "New"/Nadella Microsoft.
I still don't trust them, but credit where credit is due.
Namely, if you were to state to a higher level manager that you "don't trust Microsoft", you will come across as a crank. Or a developer who doesn't see the bigger picture.
To improve perception, folks should try to reframe their personal preferences ("I don't trust MS") as risks to the business - "I worry that MS will lock us in to their platform and jack up prices". The former is reputation-harming; the latter is being a savvy 2nd order thinker, who looks beyond just what the MS salesman says.
The next one would be the PRISM connection (Skype architecture, etc), and FISA orders they're surely under.
It's not totally they're fault I don't trust them. Buuuuut, it is partly.
Definitely appreciate the feedback - lucky for me, I have removed myself from corporate tech bureaucracy, become self-employed, and can preach from my poor man's pulpit ;D
As a result what we end up having is this shadow-structure/architecture at the company that is highly resistant to change, such that when new projects are discussed and designed, oftentimes decisions are made that are technically worse but save time due to not messing with the SOX structure.
I feel the Azure choice might be due to a similar phenomenon. Maybe the Azure people promise all sorts of out-of-the box HIPAA compliance and insurance and security etc. and the upper management is happy not having to deal with it. Price difference almost doesn't matter very much, if saving a few bucks means that you'll now have to hire and retain a team to design and maintain compliance in your AWS stack. I've no idea if this is actually what happens but it smells like it.
SOX is the standard for change management for financial companies to prevent shadow changes that could enable another Enron, Worldcom, or Adelphia style cooking-of-books financial scandal. The idea is that all changes should be fully analyzed for their impact. If a change is found to have been made without going through the controls process then a review and an emergency after-the-fact change record must be created. This leads me to believe you did not just login to a server, unless you weren't supposed to have access in the first place (separation of duties requirement), but actually made a modification to that server without an approved change.
All this means that the system is very resilient and will not suffer random outages but most importantly, in the SOX world, there is no avenue for malicious changes to be introduced to critical financial systems and their data.
Even good and thoughtful regulations get interpreted into nonsensical bureaucratic nightmares by some companies’ compliance departments. The implementations that add disproportionate friction usually don’t achieve the intended benefit either. It’s not people choosing a convenience vs. safety tradeoff. It’s just people who don’t understand the subject matter at all.
I work with hundreds of vendors and digital health organizations that deliver life critical software applications to health systems - and we host everything on AWS. Independent 3rd party HIPAA assessments + a HITRUST (not self assessed) certification goes a long way with hospitals now.
Also, Microsoft support for enterprise customers is just amazing. They have been deploying their own engineers to support enterprise customers in the past for their hosted clouds.
Cant mention much about security but Microsoft does open fewer lower level Apis compared to Linux. For example, it's impossible to do certain socket-level ops with Windows apis. So, in a sense I guess it makes Windows safer at least historically?
If lacking a ribbon interface makes you feel like someone chopped off your hands...take your hands off the mouse and put them on the keyboard, haha
People are professionals, and these decisions are important and expensive enough that they are very rarely made by lower level management. Sure your CTO will advice the executives to go with Azure, but it’s not because he or she fears Linux, Azure runs a lot of Linux after all. It’s because of several business related reasons.
When you’re and enterprise sized organisation your IT staff probably knows Microsoft products. They are certified in them, and have worked on them for maybe decades. You probably also already run an Office365 platform, which means you probably already run things like Azure AD, which again means, that training and re-training costs will be millions lower if you stick with Microsoft rather than going with AWS, and Google is typically not even on the table because their support isn’t competitive with Microsoft or Amazon. Not only are there the training cost, but you will probably lose your best IT staff members if you don’t pick the technologies they like, and that’s really expensive in a world where some of the hardest IT people to hire are people who know how to manage an enterprise sized cloud setup.
Then there is the business relationship. We’ve worked with Microsoft for what? Three decades? And while the average Joe was making M$ jokes, they were the only company, aside from IBM, to take enterprise organisations with a lot of different business related needs serious. It’s hard to compete with that sort of history. Amazon actually does a great job with AWS now that they’ve realised just how much money is available in public sector cloud, but they’re still up against a business relationship where we know that we can call directly to Seattle when something breaks and that they will be on the phone with us all the way until it’s fixed. Not having the same relationship with Amazon is a huge risk factor in your strategic analysis, and that is something most enterprise organisations but especially the public sector is very careful with.
I don’t think I’ve ever heard a single argument to run Windows because it was safer than Linux, or any of the million other Internet armchair options on why the public sector wastes its money on Microsoft. The truth is a lot simpler, there is no alternative, and Microsoft is actually very good at selling software solutions as well as support to enterprise organisations. There is no actual alternative to office365, and 90% of the 300-500 applications/IT-systems you operate only run on Windows and have no alternatives available. Like we run a medical journal that keeps track of first graders vaccination history, it’s client only works on Windows and it’s backend is on a mainframe. We’d like to replace it, because only a few companies know how to operate mainframes, which means they can squeeze us on price, but no one has made a competing system, and that’s just one of a million such stories.
If the price difference isn’t significant, you’re going to have a very hard time competing with Microsoft if the enterprise organisation you’re selling to in anyway has to operate part of its backend in a lot of organisations.
All that said, cross-cloud data links are relatively easy to establish - just like linking in data from someone else when everyone had on-premises servers.
EPIC is a perfect example of the walled garden ecosystem that extracts every last drop from its clients and keeps anyone trying to innovate out. Healthcare tech could use the competition to drive down costs related to medical record management and exchange.
Google doesn't do this?
Total garbage software that essentially functions as a billing tool.
Samething in Norway, central Norweigian health district chose epic.
Oh and almost forgot capital area in Denmark. Huge epic installation.
It's garbage on the backend because the update process is ridiculously manual. Every minor change sends out a ticket with incredibly detailed instructions, e.g. to update a single element somewhere. The role of the analyst is essentially to execute a script, by hand. Not only is this more costly and slower, it's more error prone. But it creates an ecosystem of these Epic-trained and -approved technicians which helps lock in customers and ensures another steady stream of income to epic.
You're basically saying that software can be used in a shitty way. That's not exactly unique to this space.
A lot of it does depend on the organization you're working with, as some are more dysfunctional than others when it comes to setting up best practices and build for their physicians. Others actually listen to their clinical users and tailor the system for them.
I also don't disagree with the fact that some of the issues arise from the implementation requirements. But at some point, it's still the system's fault if it allows its users to be burdened like that. It shouldn't take clicking across three different pages and who knows how many modals to triage one patient in an emergency room. It's silly that I've had to learn which order to provide my transfer of care report so the nurse doesn't have to keep clicking back and forth between different pages...
At any rate, this all started with a glib "garbage software" comment, so I suppose I should happy that you acknowledge that the implementation requirements set by the organization have at least something to do with overall user satisfaction.
I’m going to agree with the garbage software sentiment.
I will say that Epic implementations tend to be liked better than alternatives... but when it replaced some piece of shit Meditech implementation nursed from 1980 that’s not really high praise dude.
If very large amounts of 'implementation' have to be done on top of the software, then that's also a sign of bad design. It should be handling more of the implementation and making it more streamlined.
My main point I wanted to make was 1) that I also hated Epic the first time I used it in residency (we switched from Cerner to Epic for outpatient only). 2) I have so far never met someone who prefers another EMR over Epic, which really says something since Epic is also bad.
You should check out who leads wins KLAS awards.
As for the MUMPS code, there was a node size limitation for the code. Which included variable names and comments. So each code segment (identified by inscrutable five-letter (or less) names like "^ZHMRG") was jam-packed as tightly as possible with one-letter variable names and zero comments. Basically unmaintainable, but I bet they're still using it.
Garbage software. I left in 2007.
They like to hire straight out of universities. It was the second job for me, so I didn't really know to jump ship earlier.
Saying that, I wonder if Epic has a plan to go after smaller players who might be using Google Apps and fears google’s dominance.
GCP != Google Health, at least for the purposes of patient privacy. If you hold the encryption keys, google can't do anything, or am I wrong in that assumption?
It is fine, and expected, to rule out GCP for storing your own records for competitive reasons (e.g. choosing them would make future Google Health integrations easier). It is also expected, if not quite fine, to try to actively prevent your customers from using GCP.
Cerner seemed happy to play a few rounds of golf with Eric Schmidt regarding using GCP, presumably to try to glean insight into Google Health, while EPIC flat out refused a meeting. Cerner then helpfully provided a misleading quote to the WSJ to help spread FUD.
There’s nothing novel about what Epic or any other B2B enterprise software company does (for the most part), other than total addressable market (and profits) being far smaller than the B2C FAANG giants - the market caps reflect this as well.
(I'm new to the field and genuinely curious... I haven't heard anybody saying anything nice about any of them...)
What concerns me most about the larger players in the field is their dedication to minimizing interoperability to lock people into their software.
- Home-grown systems which were fit for purpose but not operable or available outside the organisation for which they were designed. The Birmingham (UK) University Hospitals system [1] is a great example of these.
- "Enterprise" (pejorative) systems which generally came from the US and focused almost entirely on billing capture, and had almost no thought put into clinicians workflow. This encompassed Epic, Cerner Millenium and so forth.
- "New" systems which were UX first, but were often little more than front-end mockups. A good example was "Alert", a Portuguese system written in Flash which had almost nothing in the way of basic medicine management safeguards, and the team demonstrated zero aptitude for the ability to build them.
In the end the hospital in question used paper-based prescribing.
[1]: https://www.digitalhealth.net/2017/05/birmingham-childrens-g... is a reasonable story about this.
Hard agree. There's also an incentive for hospital systems to "hold onto" patient data, which is not great.
* The Cerner hospital will duplicate medications for a single visit. It also classifies a bunch of vital signs as lab test results, so things like blood pressure don’t get merged in with other sources of data.
* The Epic system seems to use more recent/complex FHIR structures, so occasionally there’ll be more info in the raw data (this is more a knock on Apple Health though).
The Epic system has a big advantage with MyChart though. It’s their app and website for accessing your records at various hospitals. Through the app you can get push notifications of test results and schedule procedures. The latter was nice as I’d get roughly 15-30 minutes of advance notice before having a procedure done. The discharge instructions being made available in the app is also very helpful. Finally, being able to browse the raw clinical notes through the website, and request a dump of all of my data is appreciated.
In an independent practice, there are more options, and some are quite good (I work for one that I happen to think is pretty great in that regard, and most of our users seem to agree)
EMR is a difficult field to "disrupt" IMO because a hospital comprises so many departments with wildly different requirements for a software system, that it's basically only the big players who can do it all. And if you're a CIO for a hospital looking for an EMR system to purchase, one system that handles everything sounds much more appealing than trying to cobble together something yourself.
It's also why there's only a few major ERP players.
Epic was by far the jankiest. i.e. if you tried to cancel a recurring appointment the wrong way it crashed the entire system. Athena and Nextech were among the least disliked
That’s an optimistic assessment of what Epic does.
Google does business in potentially adjacent areas on the ad side. At one point, the government was buying targeted ads to debunk extremist search topics when people at risk of extremist behavior pursued them.
There’s a lot of obvious health use cases that could use the same framework. Google knows more about you that anyone. Epic has medical claims data before the insurers do, and knows more about your healthcare spending that most anyone. They probably have or will have a business where they monetize that data for similar outcomes.
AWS - because they really don't have a choice.
"De-identified data" is "somebody's records".
Also, for all the PR put behind the patient, Epic (and likely Cerner too) focus all their bizdev efforts on what the hospital and HMO administrators want, because they're the ones that sign the checks. Back when I worked there, they threw huge stacks of employees at customizing every installation, and significant developer effort at making broad customization possible. If patient care were the primary issue, every Epic implementation would be identical at the keyboard shortcut level. Hospital admins would have had to backdoor their customizations in by forcing their physicians and nurses to demand them as features. But instead, I saw page after page of customizations, inserting arbitrary administrator-created workflows on the staff via the software.
After 3 emails spread over several months I eventually got a note saying I should expect to talk with my Google Cloud salesguy, but it can only happen over a Hangout. And not any hangout - they sent a cheap ass Android "netbook" that I had to physically go to the post office to get, that the Hangout call was supposed to happen through.
I did get it from the post office, noted that it took minutes to start up, then gave it away and never heard from GC again.
No, I'm sure they could have accepted any Hangouts call or being coerced into accepting a phonecall as well.
But truthfully what they wrote in the sendout was like I described - they outlined the procedure to go get the netbook and use it and at no point did they suggest a physical phone number to call or similar. I went along with it as far as I did just because I was kind of baffled by the suggested procedure :)
I assume it was part of some marketing scheme to try to market Hangouts and/or Chromebooks (or whatever it was) at the same time as GCP, but it just confused the sale and added unnecessary pain-points. The AWS guys just send an email and let me call them by a normal phone.
‘ Please don't comment on whether someone read an article. "Did you even read the article? It mentions that" can be shortened to "The article mentions that." ‘
https://www.managedcaremag.com/dailynews/20191113/hhs-invest...
https://healthitsecurity.com/news/google-uchicago-medicine-s...
I've heard there are a couple Google Ventures - backed healthcare startups that have questionable HIPAA-compliance as well, directly from clients that have worked with them. They're not necessarily holes in GCP itself but rather in integrations with certain services.
The dementi was overspecific. "We did not discuss this in 2018". Which could mean they discussed it in 2019 or 2017.
Doesn’t seem like it offers anything different from the “non-government” packages.
Imagine being that insecure in what you do. What were they looking for? A non-compete from Google? Innovate or die.
It's not insecurity to paranoia to worry about today's partner being tomorrow's competitor when it's so common. In fact, this is exactly one of the things China has used to jump start many industries. In their fervor to enter the Chinese market, many companies have given over intellectual property in exchange for access (an excahnge only really on the table because the Chinese government could and did constrain that access otherwise), and found that after some time they had local competitors with similar advantages (and possibly government consrtaints again to boot).
That a company might recognize that a deal may have long-term consequences that vastly outweigh the short term gains is not something to deride, it's exactly what they should be on the lookout for if they intend to survive and grow.
Heck, dealing with large scale Enterprise tech, a 10-year roadmap (in terms of updates & support) is the standard. I don't expect Google to have such roadmaps for things they're piloting, but then I also wouldn't build anything critical, anything that might be strategic and core to my business, on someone else's "pilot" project.
Managing a massive business is complex, successfully doing so cannot be reduced to something as simple as "innovate or die".
Good faith. Google has for years selected for raw bureaucratic ambition and a cloistered view of technical talent. That set of cultural defects is coming home to roost.
You can say the same to Google Cloud.
Close cousin to "financially support your competitors and die."
Google's very business model is selling their users to their customers.
3. Know that customer data is not used for advertising.
You own your data. Google Cloud does not process your data for advertising purposes.
https://cloud.google.com/security/privacy/I believe usage for ads is highlighted on the non-legalese privacy page because it's a common question/concern, but the terms specify that data can only be processed as requested by the customer (IANAL, but that's my read and understanding as a Googler who works on Cloud infrastructure).
That said, it's completely understandable that companies don't want to help fund competitors. --Walmart knows that they could use AWS without having any real fear of Amazon employees looking at their data to get a competitive advantage, but they chose Azure because Microsoft is not a direct competitor.
Likewise, companies providing healthcare software look at what Google is doing in that space and they don't want to fund the competition by using GCP.
These are rational decisions that we would expect companies to make. It's actually more surprising that, for example, Netflix still uses AWS given the fact that Amazon is a direct competitor in the streaming business. --GCP or Azure would make more sense here unless Amazon is giving them a really good deal to keep their business.
That being said, and with 15 years of adtech of experience, I guarantee that there's absolutely no usage of business customers' first party data by Google's adtech system. While companies can use it to match and target their users, they have to do explicitly with lots of restrictions and protocols and it's only become more limited with new privacy regulations.
Epic "archived" their TODO item on Trello: https://trello.com/c/lzLwtb5P/124-vulkan-for-pc-and-linux