Google is exploring a health record tool for patients
statnews.com
statnews.com
This feels like yet another case of Google thinking it can throw machines and algorithms at a problem and a solution will magically appear. It won't. Search is hard. Healthcare is harder. Way harder.
Healthcare data is a never-ending log flume of exceptions, regulations, exceptions to regulations, and laws that change from week to week, or sometimes even day to day. And the data can sometimes be exceptionally dirty, in a way that only human intervention can clean it up.
The only way it all gets managed is with people. And Google hates wetware. Its entire reason for being is to abstract away the humans and replace them with math. That may work good enough for e-mail, or games, but it doesn't work for people. And it certainly doesn't work for healthcare, where "good enough" means people die.
https://health.google/our-team/
https://www.blog.google/technology/health/david-feinberg-goo...
But not after the feedback program has finished?
"The information will be encrypted"
So that only Google can read it?
"and stored in the cloud"
Yes, of course. What can possibly go wrong.
Hope this fails in the grandest of fashions long before they go to market.
They just need to ensure that's the client side that deciphers the data, and that the private key never leaves the browser side neither. I think that can be audited through JS debug tools.
Anyway, this is Google. There’s no way they’re planning to client-side encrypt. Even if they did, they’d eventually realize it wasn’t generating enough indirect ad revenue to be too big to kill. At that point they’d ungracefully shut it down.
Until advances in mathematics or computation obsolete the crypto. We might decide that it doesn't matter within each respective patient's lifetime (a debate) but that is getting longer and longer.
>> Google cloud provides protection from the actual privacy threats
Even if everyone in the clinic uses the same credentials?
This was true back in the 1990's. But hardly ever happens anymore. Healthcare operations are very strictly regulated, and everyone, even small offices, goes through security training. If they don't, they lose access to the things they need to operate.
The company I work for puts everyone in the company through HIPAA training once a year, and IT security training every six months. It doesn't matter if you're a receptionist, or a doctor, or the Director of IT. Everyone gets the training.
Security training is one of those things that are required by policy but which have no beneficial effect in practice. HIPAA is a thing that organizations use as a tool to keep you from getting your own data, but which again have no real benefit.
Health records feeling like a "small" addition to something is an indication that you've never had anything seriously wrong with you.
I would trust a health records service from Google far more than I would from any insurance agency or health care provider I can think of.
You trust Google knowing about your health more than you trust a doctor? That seems... odd to me.
You have to trust your data to the insurance company because it pays your bills. If you don't trust the insurance company, then you pay for your healthcare yourself.
I don't think I'm unusual that there are things about health (my own and in general) that I've searched on Google that I've never told or asked anyone.
It looks like the idea is to bring the real data sharing protocols to the patient level, which is going to be an interesting challenge for them.
The comments regarding traction etc. are all valid, there are many angles in the healthcare technology business. Google might be one of the few companies which can get the money and momentum in it. Whether that's desirable or not is for you to ponder.
If Google thinks it can do something useful with FIHR, then good for Google. But it will only solve a very small part of the healthcare data problem.
Most of the time, the more detailed reports you show to your physician the more they are overwhelmed, so I hope it would manage to become a new standard where the doctor can easily find what they look for.
People didn't like the idea then, and I'm not sure they will adopt it this time around...
[0] https://googleblog.blogspot.com/2011/06/update-on-google-hea...
I wonder if the product managers know that Google tried this.
I’m not sure I’d ever trust Google again with a health record. Also since they can de-identify and advertise based on health condition across all of Google that’s a privacy nightmare for me. And I think since a health record where you enter your data isn’t HIPAA protected, then who knows what they’ll do with the data.
It's honestly the sort of thing where you should have a standard created by an independent group designing a standard, which is then implemented by the government (handling storage and release of records to local providers).
this is actually the perfect breeding ground for a highly serviceable solution. thousands of at-bats to solve a thorny complicated problem. the challenge is bringing that whole breadth of knowledge to bear on said standards-making process. inter-/intra-group politics often gets in the way, but that is also solvable with good leadership and trust-making processes.
> https://en.wikipedia.org/wiki/Microsoft_HealthVault
Apple have been trying similar with the Health app too I'd argue, even if it's not nearly as integrated with medical records yet. Why does no one ever succeed?
I hate to say it (because it makes me groan) but I really think a trustless blockchain based solution would work best where medical professionals/researchers require active consent before pulling your records, a trustless form of anonymization/pseudonymization is built into the platform and an immutable record of every query made and why is held forever.
Hospitals and service providers in America have no incentive to do anything that would reduce switching costs and increase the quality of care that you get if you do switch. Moreover, since this is a low-information landscape with respect to both pricing and outcomes, consumers have little way of differentiating and thus service providers also have less incentive to adopt practices that improve outcomes.
Then you have to consider multiple decades of paper records, and records from other systems. Then there's many hospital systems composed of multiple health entities (hospitals, clinics, stand-alone emergency rooms). Some hospital systems span across multiple states and each state have their own set of rules (don't forget about the federal rules as well - HIPAA).
Then when you are building out your EHR system. You have to take into consideration the aspect from the doctor. There are many specialties within medicine. An EHR record from the point of view of an emergency medicine doctor vs a radiologist is very different.
It would make more sense if they were taking wearables / pixel phones more seriously but I guess this is primarily a data grab.
The right thing would have been to commit to exclusively specific use. Instead we have an incomplete enumeration of what it would not be used for.
Having seen that abuse first-hand, Google is still one of the better ones when it comes to having good internal safeguards and policies -- but they get so much attention for their scale and breadth of data.
Which will be hacked in 2 weeks of its existence..
If you have ever googled a symptom, they know, and unlike HIPAA there is no regulation on what they do with that data.
(This is a recycled comment from 2017¹.)