Google to use patient data to develop healthcare algorithms for hospital chain
theverge.com
theverge.com
Most electronic medical records (EMR) systems are really about billing. Yes, there are clinically relevant data fields available but a large amount of what we were after as researchers was only available in free-text. Data abstraction is still mostly a human-expert driven activity. It would be fun if that could be better automated but there is significant ambiguity in clinical notes and pathology reports.
And don't get me started on data-ownership "turf wars." We often got significant pushback and simple refusal to have regular data feeds of IRB-approved data fields for collection with patients who were consented to studies.
Nothing was more annoying to me to get shot-down when trying to get data from our hospital EMR (again, data that was specifically approved for research use by IRB for patients already consented to studies) only to hear later about private enterprise "partnerships" that had full and unlimited access to all EMR data . . .
Is there no way to parse this? Surely the EMR systems could have a simple key-value syntax. Patient history is too complex to be expressed that way but there is a lot of other valuable data that could. Blood pressure, for example. Ideally, things like lab results would already be stored as structured data.
Most of those lab values are more or less worthless outside of context - which is why so much time is spent on training docs on physio, pathophys, and history taking. I know that it's frustrating to hear, but it's why every "helpful" tech solution to date has resulted in increasing doc griping and burnout.
Which is another way of saying "even where it looks like the numbers matter unto themselves without context, nope, you still can't meaningfully interpret them without context."
FHIR is an actually-JSON (+XML) health data protocol that is gaining adoption (most recently because of CMS Interoperability and Patient Access Final Rule), so it's not all bad.
:/
That being said, it is JSON but much worse
I am involved with phone call centers. I have a lot of numbers. I use phone numbers like others use throwaway catch-all email addresses.
I signed up for the covid vaccine through my family doctor who partners with a hospital. They required registration (no walk ups) and the online form was branded (domain, privacy policy, everything) to the hospital. I used a unique email address and a unique phone number. I'm a curious person.
To confirm the appointment they send you a text. Guess what number the text went to? Not the one I typed in. It was to a unique number that I only used with my Google billing account. (I was using a corporate computer in no way tied to Google.)
I looked into it and the hospital partners with a fourth-party health care scheduling servicer, who then has some sort of partnership with Google cause all I saw was that Google bought a low-percentage stake in the company.
Something tells me the integration between these types of companies and Google is much stronger than the article lets on.
tl;dr :
EHR are mostly about charts.
EMR are mostly about billing.
The risks of unfettered access to EMR is that conditions can be inferred and future profitabilit of patients predicted so that they can be steered to different types and qualities of care (for good or for evil).
For-profit healthcare will overall optimize for profits before patient outcomes. It's as certain as gravity. FPH should be illegal.
The Medicare agency cut off funding for heart transplants at [a nonprofit hospital] last year after the Chronicle-ProPublica investigation documented an outsized number of patient deaths and unusual surgical complications following the procedure in recent years.
https://www.houstonchronicle.com/news/investigations/article...
I would much rather google handle this data rather than unknown third parties with their own agendas, at least with google, the data comes with privacy risks that are relatively well known and might actually be useful for clinicians due to google's expertise on AI/pattern classification work which is primarily what medical diagnoses is about now (IANAD so perhaps this is incorrect).
1. The company that collects the data (the covered entity) has to have a Business Associate Agreement in place with the company they're sharing it with. This basically affirms that the other company is aware of their HIPAA requirements and intends to follow them.
2. The Business Associate needs to access the data to do the job they were hired for, which in turn should be related to patient care.
There are definitely a lot of companies out there doing this already, but I will say that the people with the data are not exactly giving it up easily. HIPAA makes it so that in the event of a breach the Covered Entity is responsible for beach notification to the patients. That means there's a huge incentive for hospitals, radiology groups, and anyone else who collects this data to make sure that the people they share it with have the proper safeguards in place. There are a ton of hoops to jump through, normally including independent third party audits. I've seen a few medical AI companies fail simply because they didn't have the security and no one trusted them with data.
That said, were I an attacker trying to re-identify a specific person's data it would be hard to do with just basic demographic information but if you combine some specific health knowledge (a couple health problems you know your coworker has) or appointment info (date, type of doctor, stuff that may also come up in common conversations) it gets a lot easier.
- Other large companies with other big agendas have violated rules on data sharing to improve performance in other areas. Amazon comes to mind with how they used markeplace data on vendors to produce their own competitive products. Rules are regularly broken.
- Will Google let auditors really have enough insight to make sure data is kept in a controlled manner? Google is so secretive.
If a data broker started a secure file sharing service I wouldn't trust them. That's how I feel about this.
I can tell you with 100% certainty that there is no way in hell that any of the health data for a project like this could possibly ever be used for advertising to patients. Someone on an eng team with access to this data (which is VERY tightly controlled) who have to write a data export pipeline and deliberately export that data to Ads, and someone on the Ads side would then have to deidentify that data and join it with advertising data.
Getting someone to write an export pipeline that will be consumed by other folks in Health, and actually get it used in practice is hard enough, when dealing with all the data restrictions. What you're suggesting is just not going to happen.
You shouldn't think of Google as one giant org with a big pot of shared data. It's really dozens of orgs, each with their own sub-orgs, which all have their own databases, file storage, etc. Getting access to data owned by a team the next aisle over is hard. Getting access to data from another org is basically impossible without a ton of oversight.
My experience has been that Google's internal culture has always been extremely serious about restricting access to privacy-relevant data. On top of that, there's recently been a big push to defend against malicious internal actors, things like engineers intentionally creating backdoors or the like. You'd have to work to specifically and intentionally override defaults to mislabel the data and every piece of code that works with it, actively defeat multiple layers of access-control tech, get the code to accomplish that past privacy-and-security review by engineers from the privacy and security team, lie continuously and fake a bunch of supporting evidence when requesting about four different kinds of quota, hide your column names and API definitions from infrastructure engineers doing migrations and routine load-management stuff, lie to a bunch of lawyers and general Search+Ads PMs during launch reviews, and more. It's just not going to happen.
It's also not going to happen because "someone at the top told everyone to do it and nobody complained", either. Googlers pitch shitfits like no employee body I have ever seen, and using health data to drive ads would instantly cause internal messaging to explode into a tornado of hatred. I've seen it happen for less.
Like QuercusMax said, using totally-aboveboard anonymized-and-aggregated-and-scrubbed query logs is already hard enough, enough so that my team has a policy of just plain not doing it. I have a coworker whose account is irrevocably tainted because he used to work on a project that used data from the "This result is wrong" button on search results with biographical information about public figures. Misusing health data like this would be so obnoxious and difficult as to be unbelievable.
To be clear, just because something represents a common-sense workflow improvement or might be useful to the physician doesn't mean you can just go and do it. While it might be a good idea to pull similar cases (or counterfactual examples) from your vast set of patient records, it doesn't mean it's LEGAL. Medical records are not like case briefs, you can't just crack open someone's record without proper consent.
> Google exposed the private data of hundreds of thousands of users of the Google+ social network and then opted not to disclose the issue this past spring, in part because of fears that doing so would draw regulatory scrutiny and cause reputational damage, according to people briefed on the incident and documents reviewed by The Wall Street Journal.
https://www.wsj.com/articles/google-exposed-user-data-feared...
The Google reputation is so bad that my previous company was actually asked by customers if we used Google Cloud, with the implication that they wouldn't work with us if we did.
https://nvlpubs.nist.gov/nistpubs/ir/2015/NIST.IR.8053.pdf
Additional helpful works:
Anonymizing Health Data by Khaled El Emam, Luk Arbuckle
Building an Anonymization Pipeline by Luk Arbuckle, Khaled El Emam
Practical Synthetic Data Generation by Khaled El Emam, Lucy Mosquera, Richard Hoptroff
Accelerating AI with Synthetic Data by Khaled El Emam
Khaled El Emam's website: http://www.ehealthinformation.ca/
It's a for-profit institution, which is alarming in and of itself when the bar for hospitals to be nonprofit is so low (and when most of the "non-profit" hospitals are essentially for profit institutions anyway.)
This sounds worse than a for-profit institution declaring itself as a for-profit institution.
What is it about the chain that is “super, super shady”?
https://www.justice.gov/archive/opa/pr/2003/June/03_civ_386....
Verily has its own things it wants to focus on, and I don't think large EHR analytics projects are one of them. Their ambitions are probably budget limited now (IE, they have to be selective about which projects to take on) while Google Research and Cloud have a lot of funding to build products like this.
I applied for a job at Verily a while back out of a desire to pivot out of my current industry. Once I got up close to it though I had a little trouble sussing out how they would operate separate from Google, which I think is going to have to be the case eventually. Stuff like this just makes it even harder to see. (edit: I wonder if it has anything to do with patents/ip)
Everyone I actually talked to was great though and I wish then the best.
For-profit healthcare is evil.
Some healthcare is vital (emergency intervention for heart attacks), some healthcare is grey-area quality of life (do I need glasses vs. LASIK?), and some healthcare is pure luxury (cosmetic). These are not all created equal.
Additionally, removing the profit motive has its own consequences. Ever notice how the front-desk staff that serves as your docs' connection to the rest of the healthcare sector generally suck? Try to get a preauth, or a drug renewal, or an etc. There's a reason they suck: if your doc is working with a price ceiling (as most are, due to health insurance if not due to socialized medicine), they have a hard cap on their annual income for the year. The difference between a 2/10 and a 10/10 service staff doesn't make a single extra cent of income for the doc, but they have to pay the difference in salary straight out of their annual take-home. How many docs are going to get an 80K/yr front desk vs. a 40k/yr front desk just out of charity?
Compare this to for-profit clinics like One Medical, where your appointment typically starts exactly on time and front desk staff are courteous, helpful, and responsive to calls and emails. This holds true to every location of theirs I've used across major US metros (NYC, SF, PHX, CHI) [1].
Anecdotally, one time I forgot my eyedrops on a trip to SF. I tried to get a hold of my ophthalmologist's office back in NYC so they could send a prescription to a pharmacy in SF. On hold for 25 minutes, disconnected, tried one more time then gave up. Opened One Medical app, requested a virtual visit, had a Dr on a video call in 3 minutes who confirmed my eye drops and submitted the prescription to the pharmacy I was sitting in.
I'm not sure how much of it is down to profit motive and I'm sure there are tons of other confounding factors, but it's hard to not notice the huge difference in experience.
[1] I work in the healthcare industry and I'm a happy One Medical customer; I initially got it as a perk thru work but upon leaving I coughed up the money to continue using them.
Payors identify specific procedures or treatments which represent things they want more information about before they commit to paying for it. It is difficult work on the healthcare provider side to understand what requires pre-auth and provide the payor's decisional information. There is a HL7 group that is working on the problem, the DaVinci Project:
Interoperability challenges have limited many stakeholders in the healthcare community from achieving better care at lower cost. The dual challenges of data standardization and easy information access are compromising the ability of both payers and providers to create efficient care delivery solutions and effective care management models. The goal of the Da Vinci project is to help payers and providers to positively impact clinical, quality, cost and care management outcomes.
Responding to what you have written, however:
1. I provided a direct explanatory mechanism for how physician reimbursement caps lead to low-quality auxiliary services - by pointing out that investing in an activity or service that provides no marginal revenue is a strictly money-losing proposition. You assert, without mechanism or evidence, that this is strictly due to "for profit insurance." You need to clarify how the insurer, and their profit motive, creates this result - as the mechanism I put forward simply requires that the physician is has a fixed fee schedule and is at capacity volume. I won't go so far as to assert you should take my word on it, but you could do worse than listening to a doctor say "this is exactly what's going on in my and my friends' practices."
2. The majority of healthcare dollars in the United States flow through Medicare and Medicaid. Given that these services reimburse quite a bit lower in dollars/service than for-profit insurers, they actually make up a larger volume of total services rendered. I can't argue with a statement as vague as "usually a for-profit entity," but I can state more precisely that it "will be a non-profit entity for more than 50% of services and more than 50% of reimbursed dollars."
3. Minimizing loss ratio has nothing to do with what I said at all. If you can put forward a mechanism that translates my front desk expenses into reduced MLR for the payor, I'm listening with open ears. Look at this thought experiment: let's say my insurer's MLR stays flat, and I can accept a 100$/yr subscription fee from all of my patients to improve front-desk service, with the caveat that I'm taking a profit off the top. Would the insurer care? No? Is there anything the insurer's payment processes would do to affect this? No? Then the issue is my profit motive, not the insurer.
4. The convoluted payment processes are there to aid the insurer in sorting through their giant piles of paperwork (you didn't think that administering a health insurance network was low in bureaucracy, did you?) and, more cynically, to create pitholes for us to step into so patient care is denied reimbursement. You're going to have actually, again, provide a mechanism by which that translates into "Doctor doesn't improve services offered." Because I can tell you that if the bureaucratic hurdle that is insurance billing doesn't step me from billing in the current environment, then it's not going to stop me from billing for higher amounts if I could get them.
Exchange plans are just about the most price sensitive insurance product I can think of; in ACA markets typically the lowest premium plan will capture the overwhelming majority of the signups. Insurance co's are highly incentivized to optimize their MLR to provide the maximum amount of care up to the rebate threshold, while driving costs down as much as possible to ensure you can offer the lowest premium plan on the exchange and be the take-all winner.
Also, so much of prior auth, step therapy, etc are dictated by federal or state regulations and not necessarily what the insurer would like or prefer to do.
There are plenty of pain points in our insurance industry but to carte blanche blame "for profit" companies seems really lazy.