Do no harm petition: Don't give big tech access to our medical records
act.wemove.eu
act.wemove.eu
Ultimately however the worst part of these laws is that they are so harmful to research in the long run. With easy and ready access to medical data we could be decades ahead of where we are today. There are legitimate concerns about health privacy (especially for women in the US) but the upside is just so much larger than the harms. It could be 10x less costly and time consuming to do both epidemiology and longitudinal intervention studies if we only had access to data. We could be directly tackling disease causal factors in ways that researchers today only dream of. It really is tens of thousands of lives lost each year that could have been saved if we could only have moved faster toward interventions.
I believe medical records should be open and laws should address how people use the data, not trying to make something so valuable to all humanity secret from the beginning. For example you can download my genetic code here: https://www.openhumans.org/member/iandanforth/
Thier corporate records are none of your business
if we are gonna have no privacy, it should go both ways - companies lose privacy too
It is not our responsibility to make this public. Your logic is similar to the gov trying to get access to all exchanges over the web to scrape them for terrorism and violent behavior. Maybe take a step back and think about the harms that would come out of this?
I wouldn't want any future employers to see my medical data for example, as they may use this to discriminate (theoretically anyway; my medical history thus far is essentially non-existent).
Also: in the late 90s my mother worked for the city to digitize a lot of social security records and such. She had a good friend who had trouble walking (crutches, wheelchair); the story she told was that she was hit by a car, but my mother read her records during her job and found out she had simply fallen and was never hit by a car. Much drama ensued. I have no idea why anyone would lie about that and I'm fuzzy on the details as I was about 12-13 at the time, but fundamentally I think people should have the right to lie about things like this, if they so choose, for whatever reason.
My first job involved a one hour lecture about how people had repeatedly accidentally deanonymized and accidentally leaked data at other institutions, leading to divorces and worse.
We had somewhere between 10 to 100 bytes of entropy on each patient, and it would have been enough for any of their acquaintances to map back to real names and also severely violate privacy.
If you're ""Patient b15-2gty", then the data isn't aggregate. Aggregated data means that there are no individual data points at all, only aggregated ones, so there is no need for any sort of individual identifiers.
If there's any sort of individual identifier, then the data cannot be effective anonymized. If the data is aggregated, and the original records that were included in the aggregate figures is deleted, then I think that's adequately anonymized and I would have no problem with it.
Short of that, though, "anonymization" is a thing that doesn't actually exist.
I don't agree about anonymization; "true" anonymity is probably impossible in most areas of life, even for simple things like a walk in the forest as there's always something a significantly advanced sleuth can use.[1] There are no "true" one-way hashes either – you can always brute-force). It's about it being too infeasible to actually do that.
[1]: https://arstechnica.com/science/2023/05/human-genomic-bycatc...
Instead of taking the information by force (which health care conditioned on opt in certainly is), we should figure out how to build a trustworthy medical research and care industry.
For instance: They could only make this information available to universities, and ensure the results of the research were public domain.
Or, they could create separation of concerns for companies involved. If google wants to store medical data, then they have to spin off their ad business.
I don't think I'd find that sufficient.
What you're calling "collective hangups" are, in fact, real and serious risks. I am distressed at how many people have forgotten (or perhaps were never aware) of the real abuse and harm that was happening with the sharing of medical data before legal protections were enacted. Heck, those harms still happen now, but to a reduced degree.
Or more importantly, the harms are to me, and the upsides are to you, so who cares?
Doesn't make them any less fucking wrong.
That was a punishing read
The primary issue with this was the lack of ethical research, not the privacy of medical records. In fact the opposite argument could be made, with a more open and connected system, we could likely glean such information without the trial in the first place.
In fact a surefire guarantee essentially doesn't exist. But what exactly are you afraid of? How does someone weaponize your information? Everyone in my life already knows about my health conditions, i speak openly about them in my personal life, my business life and online there have been zero consequences to this.
But at least there is a law against it. Loosening the rules would certainly lead to misuse - use against the patient.
Not everyone is comfortable speaking openly about their health issues and not everyone is in a situation where they will be free from consequences if they do.
Well that's really the point, ain't it. You can't even meet the bare frakking minimum for this to be workable.
> Everyone in my life already knows about my health conditions, i speak openly about them in my personal life, my business life and online there have been zero consequences to this.
Would you mind listing them out? Also, some vital info like date, place of birth, name, family medical history? Who was your mom and dad? Grandparents? Got any siblings/cousins? Also, go ahead and measure your bp, heartrate, blood sugar levels, and post those here as well, might be useful to know those too. Oh, reminds me, gonna need to see your hepatic and renal panels as well, you never know when that sort of information about you might come in handy.
I mean, now that we've interacted, I'm in your life too, and I'd like to know all these medical facts about you.
Edit:
> How does someone weaponize your information?
A lot of other people have posted some of the terrible consequences that can result, but let me give you a more inane one that might actually be a little easier to connect with.
Blood types are not evenly distributed, especially when it comes to blood banks. Some blood types, and especially if your have an uncommon Rh factor might be harder to get. So just imagine if your health insurance was more less expensive just based on your blood type -- something that you will probably need to know (and will thus be available to your insurer) at some point in your life, and probably relatively sooner than later. How'd you like to pay hundreds or thousands more for health insurance based on your blood type alone (because there won't be any discounts for the common ones, just penalties for the rare ones.) Or worse, being denied coverage for a surgery because the blood you'd need transfused during it would be 'too expensive'.
Like throws you in prison because you were pregnant and now you are not, and the state concludes you must have had an abortion which just recently become illegal where you live?
Show baby diapers ads because Google knows I'm pregnant. Increase the price of baby furnitures because Amazon knows I'm pregnant. Decline a job interview because LinkedIn knows I'm alcoholic. Tell me what parties I might be interested in because Facebook knows I have cancer. Refuse a ride because Uber knows I'm not vaccinated.
None of this situations is far fetched, and none of those situations is something positive.
Companies only care about profits, not the betterment of society as you seem to believe. I am very happy there is no way for them to know more than they need about my private life.
> my business life and online there have been zero consequences to this.
because those laws were in place. Do you believe companies have been behaving nicely because they care about you ?
> None of this situations is far fetched, and none of those situations is something positive.
Not only is that type of a situation not far fetched, it was the reality throughout Canada as recently as 2021 and 2022.
"Also effective October 30, travellers departing from Canadian airports, and travellers on VIA Rail and Rocky Mountaineer trains, will be required to be fully vaccinated in order to travel."
https://www.canada.ca/en/transport-canada/news/2021/10/manda...
Given Canada's large geographic area, access to domestic air and rail travel is extremely important.
That type of unjustifiable discrimination also applied to other services/venues/events, too, such as restaurants.
What's even more nonsensical is how those policies remained in place even when it was blatantly obvious that the so-called "vaccines" involved didn't seem to prevent infection and didn't seem to prevent transmission, even among the so-called "fully vaccinated".
The very negative social and economic consequences of those awful policies far outweighed the non-existent "benefits".
If some good did come out of this, it's that at least a larger segment of the Canadian population realizes the importance of privacy, especially of medical records.
Fire you if you've had an abortion?
Fire you if you've had gender affirmation surgery?
Refuse to hire you if you've been treated for addiction?
What if you're a public figure?
Press announces you've had cosmetic surgery.
Press announces you had an anal fissure treated.
Press tells everyone you have an STI, or your children have an STI
There are a lot of ways to weaponize medical information.
“It doesn’t matter to me therefore it shouldn’t matter to anyone else. My experience is universal and correct.”
This is so easy to recognize that I have to wonder if you've ever met a less-privileged person than yourself.
1. A fully functioning, treatment-compliant schizophrenic is now at risk of being passed up for jobs or promotions because their medical history is up to be bought by employers.
2. A local concerned citizen will be much more afraid of protesting or publicly being against a politician if the politician can buy their history of getting PreP, an HIV preventative drug that is popular in the homosexual community.
3. A religious private school starts to buy the medical history of their young girls, and reveal which girls are taking birth control, had had an abortion, etc. by expulsing them from the school.
Or simply put: You first. Put up your hemorrhoid surgery photos up on your LinkedIn.
I guess you're not an alcoholic? That's information that potential employers would be glad to pay for. In the days of paper records, doctors would write "C2H4OH" on your record, as a semi-coded message to other doctors.
Estimates vary, but I understand that close to 25% of the UK population is alcohol-dependent to some degree. Deterring people from seeking treatment seems "unhelpful" from the POV of general social benefit.
America needs to be a radically different place for me to be okay with what you want.
We would still need controlled trials, which would continue to work similarly to today. But those would be perhaps less expensive as a result, reducing research costs and turn around times.
Obviously funding is needed: funding which already comes from government in many cases. It's just that now that research funding gets handed to execs who then use the data to make more money, and only have to use the data to help people if it happens to coincide with their business strategy. Having the data public just means that the people working on it are motivated more by helping people and less by acquiring data to leverage for profit, which is a feature not a bug.
That is the point. It is supposed to be burdensome. It is supposed to be difficult and cumbersome to do anything with anybody's medical data.
I don't want to dismiss your comment entirely, because I understand the frustration around the good that the data could do but in the wrong hands it could be truly disasterous. I do not want Meta or Google anywhere near my medical data (and they're already pretty close in a lot of ways). I do not want my medical information used to enrich shareholders and that is the first thing that will happen; not improved research.
It should be easier for people to opt-in to sharing their medical data with a wide range of organisations if they choose but right now they never get a choice. It's either "we're making a law so we can give this data away" or not.
> the upside is just so much larger than the harms
I also don't agree with this as a blanket statement. For many people, including women in the US as you pointed out (amongst many other groups), the harms are criminalisation and imprisonment. The harm here, for the individual, far outweighs any potential benefit.
I'm in the UK and if it transpired that Google (the company) had routine access to NHS medical data, I'd be very upset and complaining to the information commissioners office.
Does google/a private company have to do it? No, but at a minimum the UK govt needs to make significantly better use of this data for research purposes. a 100x increase in medical research spending and a new more agile public medical research body would probably be enough
The UK govt has proven that when it tries, it can do digital services _pretty well_.
The concern here isn't the government using the data for the betterment of society, it's the government handing over health data wholesale to companies whose sole purpose is to generate profit by exploiting data.
Ask for consent. If I say you can't use my medical data, then you can't use it.
If I say you can, then you can.
It's really very simple.
This is one of the many things that lead me to consider Google to be a harmful and reprehensible company.
This seems like a good compromise moving forward. Add a section on whatever HIPAA forms you already need to sign that gives you the chance to opt in to use of anonymized data for medical research purposes.
I think for this to work, the law would need to clearly define how records must be anonymized, and provide penalties both for poor anonymization and for not clearly communicating to patients that this sharing is optional.
"Can we provide your medical details in full to the following organisations?" "Can we provide an anonymised version of your record to them?"
Yes. No.
Abide by those wishes. It's pretty simple.
Unfortunately big tech companies see the fines for handling data poorly as a cost of doing business, and not the punishment it was designed as. Until that changes, the status quo can't change.
No, even for longitudinal studies, even with “anonymized” data, the risk is too great for any individual, and to society in general. Ideopathic and non-causal diseases should have some buy-in from patients; a standard waiver might be useful for research use of data. (I’ve signed one.) But in general, no, the restrictions are worth it.
some are illegal - think threating drug overdose
https://www.wingerdenlaw.com/blog/2020/02/can-you-be-charged...
Mental health is a big deal. For better or for worse, if your employer/licensing org is aware of any mental health issues, then they could adjust how they treat you.
Crappy bosses could use your history as a way to discredit or manipulate you. That's exactly what the CIA does, whenever someone blows a whistle on them.
Some medical conditions can be interpreted by different people, in intensely negative ways. For example, at one time, being left-handed, meant that you were possessed by the devil.
Often sexual orientation/behavior is a part of your medical history.
But I'm suuuuure that no one would ever use this information in a questionable way.
Look at the "mug shot protection racket" sites. These sites leverage personal information that has been made public, as a way to force you to pay them to remove it (and then immediately republish it in another venue).
I guarantee that a number of folks on this very site, run those sites, and sincerely believe there's nothing wrong with it.
No. Just because "I have nothing to hide," does not mean that I get to force others to divulge intensely personal stuff.
Very many things doctors need to be aware of, because the patients life depends on it, are left out when patients move between specialists and physicians, which happens all of the time.
Outbreaks of viral and bacterial illnesses result in thousands of people independently chasing diagnoses and treatment, because the system doesn't share information that could be used to piece together and get ahead of it. Every time my kid gets sick at school, I get to play a game of "What is it? Do we see a Doctor? How much money should we spend?". Lets pretend we know nothing about this and go see a Doctor who hasn't seen anyone else in school, who may provide antibiotics they may or may not need or worse.
Effective prevention methods and early detection of bad treatment are discarded because its so difficult to investigate and connect the dots between interventions and outcomes.
Patient privacy is important, but the system we have today is nothing less than a tragedy. Real damage in emotional, physical, and economic is happening on a grand scale every day in this country. We shouldn't pretend HIPPA is a good thing, or the current system is doing a good job. Its not. We need to radically transform how we operate, and much more open and connected medical records is certainly a part of that transformation.
Honestly, my problem with HIPAA is that it's not really adequate. There are too many loopholes in it. I'd like to see it strengthened quite a lot.
> much more open and connected medical records is certainly a part of that transformation.
As long as the patients those records are about are in full control over their disclosure and use.
I would start freaking the fuck out if my primary care physician gets to sell my diagnosis for money to Facebook, and I don't give a rat's ass if some 3 year old could've been cured of epilepsy if my doctor was able to do so. HIPPAA prevents my doctor from doing so and I'm glad for it.
> I would start freaking the fuck out if my primary care physician gets to sell my diagnosis for money to Facebook,
To play Devil's advocate, do you think Facebook doesn't know who is gay and who has diabetes? If Target can figure out when you're pregnant, Google can certainly figure out on which day you plan to go the abortion clinic. This information is already out there and used in ways we don't like. So maybe we should consider re-working HIPPA so the information can be used by the good guys instead.
You cannot say the protections it provides are overstated if you are not the people who were victimized by a lack of such protections in the first place. I do not want the "good guys" collecting panels on jews. I certainly don't want the "good guys" collecting panels of info on trans kids without involvement from parents. The idea there is a "good guys" in this scenario is ridiculous. The idea that it might save lives is a cold comfort to the status of my minor child's birth control prescription status being accessible to the government.
Who are these "good guys" you speak so highly of? CA gov? FL gov? Federal gov? FBI? Planned Parenthood? Some church?
I'm curious about these mythical "good guys" that you, the NRA, and other people with an agenda repeatedly handwave about.
Anyone who wants to use the records to improve healthcare. There are plenty of these folks in the medical field, based on my time in medical school and brief stint in a medical research group.
I would also include anyone involved in your direct care, i.e. the front-desk personal at the various doctors offices we visit, who have no way of easily obtaining your medical history if you aren't already in their system.
This is so nebulous. Anyone can claim they want to improve healthcare. The removal of abortion access has also been repeatedly been justified as improving healthcare. The Tuskeegee experiments (where they just let black men live with a curable, debilitating disease and continually lied to them about their suffering, some of them to their graves) was justified as improving healthcare. "Wanting to improve healthcare" does not preclude people from horrifically unethical behavior. Get better standards if you want to be accessing the private information of people without their consent.
https://www.hhs.gov/hipaa/for-professionals/faq/authorizatio...
When providers fail to obtain medical histories for new patients that's not due to any legal restrictions. In most cases they simply haven't bothered to implement the open interoperability industry standards which make it easy to exchange such data, or haven't joined networks that facilitate such exchange. For example, the majority of physicians still don't have a publicly listed DirectTrust Direct Secure Messaging address even though they could have one at a very low cost.
https://www.cdc.gov/nndss/about/index.html
And it's not "HIPPA". For some reason, people who are deeply ignorant about what the law actually does also seem to get the acronym wrong.
I see. So if three patients visit three separate physicians (with three separate healthcare systems) with the same illness (outbreak), these records may be aggregated to detect the outbreak? I was under the impression this kind of thing was not possible, or very difficult / limited, and would require some kind of patient authorization, and that HIPAA played a role in this.
(I expect this exists for known serious things like Ebola, but was thinking more directly about things like strep or typical viruses in a school. It seems like the outbreak information is put together after the fact, or after it gets grossly bad)
> For some reason, people who are deeply ignorant about what the law actually does also seem to get the acronym wrong.
Probably that HIPPA reads more like a word than HIPAA.
Listen, I'm not saying that this is ethically or morally right. I'm just saying that's the way things actually are (in the US).
I've no doubt that there is some assortment of corrupt laws bought by the medical industry that have enabled these blatantly abusive billing practices. But until shakedown victims actually force the issue and publicize it, then those corrupt laws continue to avoid scrutiny.
Also, I expect insurance companies to honor their contracts.
I could not agree more. This problem absolutely ruins lives. I've seen people who've suffered terrible injuries beg not to be taken to the hospital because it would result in devastating financial consequences.
> I expect insurance companies to honor their contracts.
I agree with this as well. But that's a separate issue than who is legally responsible for the debt.
I believe it is a liability for doctors to know a true medical history, and anything not already being treated can be ignored and re-diagnosed later, which of course is an ideal situation for the insurance and the new provider, because you can charge all over again for those diagnostics.
Case in point, I had two EKGs performed on me, one in urgent care and one in the hospital. It was not too long before I was going in for surgery, and a prerequisite was a "12-lead EKG" readout, so naturally the hospital tried to force me to undergo a new one at enormous cost and inconvenience, and I balked, because I already had two perfectly good readouts in hand. They eventually relented, but it was incredibly difficult for them to admit that the test results were valid and acceptable, and this is all part of the scam, to charge as many times as possible for anything that wasn't performed here and now by us.
Likewise with psychiatry and therapists; I've been through multiple clinics and dozens of counselors, and of course each one produces a mountain of case notes. So I always offer and suggest that I sign a release and have all the prior case notes transferred over so that they get to know me better. The answer is always "no". They want to know nothing beyond what is in the intake forms, that they will spend 5 minutes reading. Then we will start my therapy over from Square One with a stranger and I get to recount all my feelings and life experiences over and over and over again, on my dime.
Nevertheless, it is still of the utmost importance that you continually sign authorizations for release and that you requisition all available records from all your providers. Authorize all providers to release information to your friends and family. They will hang up the phone if there is no release on file. Renew those authorizations on time, every time; your provider will not remind you. Release all records to yourself on a regular basis, especially after a hospitalization or major incident. You will want good records, just for your own examination, and also if there is ever a dispute or litigation about something, your attorney will appreciate those records too.
An actual written request for consent from a research institution, telling me exactly what data they intend to access, how they will access it, how many people will have access, for how long, and what they will do with the data / results after they are done. One that I can at my option sign and send back, or trash.
I'd in all likelihood say yes! But as a patient, I deserve the right to say yes or no. "Lives might be lost" is simply not justification for obtaining it.
This doesn't seem that unreasonable to me. It balances the need for research with the patient's need for privacy.
And more importantly, _who_ the people are. Yeah, I want full legal names. I want someone to name in a lawsuit if things go wrong or my data is leaked. I want personal legal culpability from everyone interacting with that data.
I'm not. Getting pretty tired of having the meeting point of getting buttfucked and not buttfucked being buttfucked, but with lube.
You step forward.
He steps back.
"Meet me in the middle," says the unjust man.
Thanks to the likes of Facebook, Google and their ilk starting to stick their filthy paws into the most private medical data some years ago my answer now is always a resounding HELL, NO!
I always feel bad about it, because it really shouldn't be that way, but thanks to the slimy shenanigans of the tech brothership I just don't see a viable alternative to that answer.
What bugs me is my urge to explain to the poor admin to who I'm handing the form the why this is out of the question.
I made the exact same change in my behavior as well. I already felt that I was making a sacrifice by exposing my data to the likes of drug companies and such. Exposing my data to the likes of a FAANG-style company is simply a nonstarter.
I believe exactly that about not medical records but medical procedures. If the doctors force me to share my medical records with the world of spammers and scammers I would rather choose to be a doctor for myself. But I see a little bit of problem when medical books are hard to download and medical drugs are very expensive because of so-called intellectual property. Medical industry relies too much on just obeying to all the doctor tells to do, blindly and brainlessly.
Do you really believe that my medical records bond to my personal data are more important knowledge to society than how to do drugs which can save anybody?
You are saying that you'd like to take my personal data and make money from it without compensating me. My records are mine and they are private and it should stay this way.
And the people could be in big trouble because this data was stolen or is used against them.
On top of that it isn't even guaranteed that we were decades ahead.
Many of the big data promises didn't work out. Remember IBM's Watson?
>but the upside is just so much larger than the harms.
How do you know?
That's just bullshit.
Also, given the state of medical research methodology, you could just as well argue that it would yield even more unreliable studies, each adding confusion to our knowledge.
Please trust the opinions of people who have tried to do this work. There are many people trying to advance medical research in good faith who can attest to the insane inefficiencies of working with medical data.
Skip the essay but at least give me three or four sentences why I should feel differently?
Let's say that each research study spends 10% of its time on recruitment and another 5-10% of its time on compliance. (Real numbers can be much higher).
Open medical data would reduce both these efforts, so every study, regardless of quality now goes more quickly and/or is less expensive. This is the primary benefit.
Now you're pointing out that extremely open data can lead to rapid and perhaps erroneous analysis. This is true, but it would also lead to rapid and accurate analysis. My point is that everything speeds up and compliance regulations around data handling are far less impactful on study quality than are protocols around experiment design.
I believe open medical data would have absolutely zero effect on the amount of time spent on recruitment.
Source: Me. I work with clinical trials data management in a medical research institution pulling hospital-side clinical data and patient schedules into systems on the research-side specifically for the purpose of recruitment.
Without the privacy, the world would be a different place and the people in power in that world would have no interest in advancing anything that doesn't directly give themselves more power. There would be no well funded scientist outside of the military.
It's clear which takes priority over the other.
Europe gets to use their free and open medical data freely for research. The US gatekeeps that information. It's a huge competitive advantage for Europe.
Sometimes people blame HIPAA for all sorts of random stuff which has no connection to the actual law.
Big Tech is not a thing, just like big-sensors was not a thing. Electric sensing became a thing in the 1900s, and the medical community benefitted from the machines built because of them. Tech is similarly a tool that has become available to all fields over the last 30 years. By treating big-tech as a bogeyman, we end up anthropomorphizing an inanimate marker of of progress in our time. It's Scientific cartelized Amish-ness.
My controversial & intentionally provocative opinion for a while has been : "Doctors are evil". The more I read about it, the more I feel like there is an ounce of truth there.
Other people's medical records, you mean?
I then went through the process of applying for disability insurance and dealt with the quagmire of them wanting access to all of my mental health records. Not a summary of my mental health diagnoses, but ALL of the individual progress notes. I refused them having those records and ended up having to waive any disability coverage due to mental health issues I was facing. That type of data I just didn't trust this insurance company to keep the data safe, especially as the paperwork stated they would share the data with all of their affiliates and partners with no recourse on my part to restrict what was shared. At that point, I realized that there are VERY good reasons why we don't just allow all of our medical data to be open.
You misspelled "villain" there. If that were to happen, I'd 100% be calling for them to spend as much time in prison as possible.
https://www.hhs.gov/hipaa/for-professionals/privacy/special-...
"Under the patchwork of laws existing prior to adoption of HIPAA and the Privacy Rule, personal health information could be distributed—without either notice or authorization—for reasons that had nothing to do with a patient's medical treatment or health care reimbursement. For example, unless otherwise forbidden by State or local law, without the Privacy Rule patient information held by a health plan could, without the patient’s permission, be passed on to a lender who could then deny the patient's application for a home mortgage or a credit card, or to an employer who could use it in personnel decisions."[1]
That's what's on the HHS website, and that's a mild example of what was happening prior to HIPAA. Health information was being used to out gays and HIV patients, discover people's race, bypass due process, stalk women, etc. With data being weaponized against individuals more and more, we have good reason to believe that this would be worse in 2023 if these laws didn't exist, not better.
Yes, I'm aware of the burden that this puts on medical research. Behaving ethically is hard sometimes--get over it. You don't get a free pass to use people's private data without their consent. You might claim that you're only going to use that data for good, but the fact that you think bypassing people's basic human rights is acceptable shows that you don't have a working moral compass. You can't be trusted to only use people's data for good.
The fact that you wrote three paragraphs on this topic and didn't even mention the rights of the patient shows me I don't want you to have access to my medical data, let alone having authority to make decisions about who else can see my medical data. You're not a person who will make that decision ethically and responsibly.
[1] https://www.hhs.gov/hipaa/for-professionals/faq/188/why-is-t...
> With easy and ready access to medical data we could be decades ahead
So make it ! On premises. Pay for helping in that. Do not pay for storage and cpu in clouds ! And don't be naive about what good and progress "they" can bring to medicine. They will promise then stall as much as possible and you will be paying for not deleting your precious data. Or accessing your own data :> And watching like your data are published and sold on black markets...
They don't even say how to opt-out.
I think it doesn't really matter in what form the government appears. It's still the government and so its rules apply.
If it's a "limited company", that means it's liability is limited to shareholder capital. It's going to have to have an awful lot of capital if it's going to be able to compensate the entire population for mishandling their data.
Also, if it's a limited company, then the shareholders can sell their shares; the company can change hands, often to owners in a different jurisdiction.
A limited company is not an arm of the government, and I can't hold a limited company accountable in the same way I can the government; especially if my personal data has left the jurisdiction.
Translation using Deepl:
Leasts on the Judgment of the First Senate of February 22, 2011 - 1 BvR 699/06 - Mixed-economy enterprises controlled by the public sector in private-law form are subject to a direct fundamental-rights obligation in the same way as wholly state-owned public enterprises organized in private-law forms.
This is apparently the German equivalent to an LLC.
Pretty sure you misunderstood what "limited liability" means. Pretty much all organizations today have the same legal status: https://en.m.wikipedia.org/wiki/Limited_liability
Thats exactly the issue
GP is arguing that the entity in charge of all your medical information should not be an LLC. LLCs in general are great.
This company probably shouldn't be LLC.
Are people confused that limited liability limits the liability of the company? Because limited liability means that the liability of the owners is limited to their investment. The company can go bankrupt from losing lawsuit.
Otherwise you end up with people who can create as many harmful businesses as they want and just walk away when it explodes, ignoring everyone caught in the shrapnel. I'm 1000x more concerned about the effects of harmful companies than whatever friction it creates for starting new companies. Everything already moves too fast, it would be far preferable to have fewer corporations if it meant they were of higher ethical behavior.
No, that's what insurance is for.
Companies operated before the concept of Limited liability was even invented.
We have records of successfull companies from year 578, like Kongō Gumi, in Japan.
Also, LLC in US is kind of company. It is mostly used for small sole proprietorships and partnerships. Technically, public companies are “limited by shares” where shareholders are liable up to value of their shares. But there is no difference in terms of protecting owners from liability so they are called limited liability.
Limited Liability is a double-edged sword. It does reduce the risk of starting a company. But it reduces some mechanisms to protect society from misbehaving companies.
More-so than anything else, the focus should be on preventing pre-existing conditions from being able to affect individuals negatively than adding hoops for the individual to access their own gated personal records (Moving between hospital systems today can be an absolute nightmare in the states).
NHS England has been trying repeatedly to make huge amounts of NHS data available to various kinds of commercial "partners". It started with supplying the Society Of Actuaries with the records of a million patients. For £3,000! Actuaries, of course, are primarily employed by insurance companies - not the kind of people I want having access to my medical data.
We were given the chance to opt out; you had to get and complete the official form from your GP, and go to the clinic and hand it in. But it turned out that only covered your GP's records; hospital records were subject to a different opt-out. You had to ask for a form from your local Health Trust, complete that, and mail it in. None of this was electronic or online.
Then there was a new plan, all your old opt-outs were obsoleted, and you had to go through the whole rigmarole again.
The UK has the finest collection of medical data in the world; a population of 70 million, and a consolidated health service dating back 80 years. No other country has this. I have no problem with that data being used by the NHS to improve existing treatments and develop new treatments. But handing it over for peanuts to J. Arthur Random really isn't on.
There are evidently civil servants in NHS England who are fanatical about sharing NHS data for commercial profit, even if that profit doesn't accrue to the NHS.
> Pseudonymisation and anonymisation are not enough: health data is so specific that re-identification can be trivial. Often a person’s social media or financial history, both widely available on today’s data markets, is sufficient to identify medical events that can easily lead to reidentifying supposedly pseudonymised or even anonymised datasets.
I agree with the sibling comment that we need more open data if (iff?) we want to increase the pace of medical research. But it seems to be a tough cookie to crack.
And that is the problem here: how do you remove enough data to make it NOT personally identifiable (or close too) AND not remove so much data that the whole thing is pretty useless.
No one has really managed that yet. People who have not tried assume it is possible. But it probably isn't except maybe in very specific cases where you only need very limited data and don't care about correlations with other factors...
There are some quite high profile examples of orgs releasing anonymised data and people linking it back to the individuals:
https://www.theguardian.com/technology/2019/jul/23/anonymise...
Interestingly the UK (I am a limey brit) actually has some really good experience with this, both from NHS medical records and public studies on Civil Servants...
As archaic as HIPAA is, the tools that we have today to obfuscate PHI (e.g. tokenization) respect the individual's privacy. The major cloud infrastructure providers are all HITRUST certified and ready to sign BAAs to keep everyone accountable.
I think we're in a good place right now for innovation with healthcare data. Multi-modal (think genome + claims + social determinants of health) are starting to become a thing. As a population, we'll benefit from more targeted therapies.
Technology is catching up with the swaths of data that has been amassed since the 2000's. I hope for more innovation vs. shackling it with uninformed regulation.
A major roadblock for our startup is getting medical information integrated into our system. It's difficult to compete with the IBMs and Epics of the world when we don't have a million developer hours to dedicate to writing plugins for every vendor. It's not just us struggling with crappy data management - it confuses hospital staff, too. Our customers are frustrated when we tell them things like "you gave us <XYZ obscure file type> which doesn't contain the information we need; do you have <ABC obscure file type> instead?". MRI scans (DICOMs) are particularly gnarly.
Even the IBMs and Epics of the world struggle to not make crappy software. How do you present a relevant medical record to a doctor at the exact right time they need it? There is so much data to sift through that medical information frequently slips through the cracks when patients transfer hospitals or their hospital merges with another.
If there isn't a standard way to query an electronic health record then companies are incentivized to just throw data at an LLM to parse it (which is exactly what we're moving towards). Trying to build AI-type solutions will just make these companies even more data-hungry and result in a less reliable solution.
I'm not opposed to continuing to hold startups/big tech accountable for keeping personal health information private and secure.
https://towardsdatascience.com/understanding-differential-pr...
Blanket bans, while sounding good, can slow down pace of innovation in an area that desperately needs more of it - esp as the world is aging.
This needs to be a combination of informed consent, clear access auditing and usage, and laws to heavily penalize misuse of this data.
Lack of information is a big challenge for doctors. When I say challenge, I mean people are dying needlessly because of their doctors don't have access to critical information and this leads to bad decision making.
Here in Germany doctors are completely in the dark. Even basic information like who I am or where people live isn't being shared. Because privacy. Every doctor you talk to first needs to take down all your basic details. Address, date of birth, etc. Every medical appointment is ground hog day. They know nothing of you, your personal details, or your medical history. And German GPs don't do a lot themselves. You get referred for even the most basic things but without them sharing information. So, all the obvious things happen on a daily basis. People receiving the wrong medications. Doctors not acting because they are unaware of the history of the person in front of them. Or wasting time on diagnosing things that have already been diagnosed. Or mis-diagnosing those things.
That's the consequence of bad data.
The standard German sentiment against any digital is "I don't like this". But the consequences are that they have to suffer bad health care, a stupendously inefficient system that they pay for through really expensive insurance every month, and preventable deaths because essential data isn't being exchanged to those who need it.
And their privacy sucks anyway, because IT security is about what you expect from a sector running on ancient hardware and software. IT incompetence/ignorance is the norm. Quite a contrast with other countries I've lived in.
If I didn't have a modicum of assurance that what happens between me and my doctor stays between me and my doctor, I would absolutely avoid going to see a doctor to the greatest extent possible.
Want to see if there's a geo cluster? Oh sorry, there's no location data. Do you want to see if something affects age band 12-14 instead of 16-18? Sorry, everyone in that group is in a HIPAA bucket. Do you want to see if there's a commonality among treatment options for obese women over 65 who are diabetic in rural communities? Nope, sorry.
Do you want to determine the success rates and outcomes for different treatments in different regions for a given condition, and if they differ bu age/gender/ethnicity/place of treatment? Nope.
If there are uses that are prohibited prohibit them. Thats what the law is for.
These laws, while well-intentioned, kill people.
If you think that's an OK tradeoff, I guess you're free to accept that. But there is very real blood on your hands, the fact that none but the most egregiously common diseases are studied. It doesn't have to be this way.
So does medical fraud, and it's not well-intentioned at all.
Just sayin'.
I have almost no faith at all in the types of folks that found and run tech companies, these days.
They have proven, over, and over, and over again, that They. Just. Can't. Be. Trusted.
If the tech industry were to create an ethics board, with real enforcement teeth (like the Bar Associations, or Medical Boards), then that could be a start.
The problem is, as soon as anyone even mentions the possibility of restricting tech companies, they are taken out behind the woodshed.
That goes both ways though. People are responding to hostage-taking actions by big tech and trying to protect themselves. There is a theoretical middle ground where data is available for research but not for abuse, but big tech typically won't allow that.
There is ample evidence for what happens when companies in the health space are allowed to make their own rules, and it isn't better health outcomes. See thalidomide
Some naive software developers and data scientists have this fantasy that if they could just data mine millions of patient charts that they could discover all sorts of medical insights that would save lives. This is almost totally false.
The real issue with using research data from multiple organizations has more to do with quality and consistency than privacy rules. Various provider organizations will record the same clinical data in different and incompatible ways, or often fail to record it at all. Researchers working with such data have to devote huge efforts to building pipelines for validation, cleansing, and normalization.
Rubbish. There's a difference between people dying because some startup can't cheaply get access to medical data, and someone being killed.
> But there is very real blood on your hands
Sounds like you work for a health-data startup? You're rather handy with the guilt-trips you're slinging around.
What this data would be used in practice? Insurance corporations would use it to identify people at greater risk of diseases and to deny them coverage (or make it difficult to obtain coverage, remove them from coverage, etc.) in order to increase their profit margins.
Now, you could have useful anonymized public databases, for example, imagine if everyone got regular monitoriing of body burden of heavy metals and industrial and agricultural organic chemicals, and that was cross-referenced to their incidence of cancer, liver disease, etc. This could reveal common associations between specific pollutants and various diseases that could then be studied in more detail. Similarly, this could be applied to pharmaceutical products (which sometimes do more harm than good to their users)
Of course, that kind of public health-centric database would open up corporations to liability and cause profit loss, which is why such body-burden assessments of pollutants are not part of your normal medical checkup.
* Hypothesis generation sped up
* Candidate participant discovery sped up - including finding controls
* large classes of analysis possible on just the data, including difference in difference and natural experiment
Do you think Big Tech shareholders (with additional holdings in pharmaceuticals, petrochemical, agribusiness etc.) would be interested in a database of rigorously anonymized patient data intended to discover relationships between things like pesticide exposure and Parkinson's disease, or unpleaseant side effects of currently profitable pharmaceutical products?
It's less about "who" and more about "how". How will we grant this access in safe and (preferably) anonymous ways.
It's both. "Who" is a very critical thing, because there are so many bad actors out there.
Another problem is that these laws (HIPAA, etc) actually CONTRIBUTE TO the leaks, because they provide a huge blackmail incentive to hackers. The penalties are so large that hackers know they can extort giant payments from companies.
Also, it's no small loss that it's so difficult to use this data for legitimate research purposes now, depriving us of all the medical gains we otherwise would have.
Certainly, I would not want my records in the newspaper - but really what's the worst outcome? Everybody finds out just how much ED medication I take?
I suspect a lot of this legislation is (as usual) motivated the the businesses that stand to gain from it. It creates a large moat around existing large businesses that can afford to cooperate. And funnels a lot of money to the consultancies and other companies that work to comply with these policies.
I disagree entirely.
> really what's the worst outcome?
Well, let's look at what's happened in the past. You could be denied employment, denied housing, denied insurance coverage, even denied essential medical treatment, for starters.
Consider this: the same argument could be applied to our endeavor to safeguard the secrecy of voting. What is the worst outcome if everyone discovers who you voted for?
Such conclusions are inherently biased because we are unable to accurately evaluate the importance of these very existing protective measures in a civilized society.
That's far from the worst outcome. You could lose your job, be sent to prison, be denied insurance.
No. The worst outcome is the police arresting a random civilian because their medical record showed they were actually a fully transitioned person living as their identified gender (and thus the only way they would know is through trawling through medical records) and are therefore in violation of, say, a bathroom law. Or a law banning "crossdressing" or other shit.
It's teenagers and young women being sent to prison because there's a medical record where they were treated for excessive bleeding which lost a pregnancy, and are put in jail until their trial for abortion is up because they're too poor for bail.
It's buying up the medical data of jewish people to "prove" they're really harvesting the blood of Christian children.
American history includes a period in the not-too-distant past where we put all people of a specific ethnicity in internment camps. So I'm gonna go with using genetic data towards those purposes probably. Maybe I could come up with even worse.
Your employer finds out that you are alcoholic?
I’d much prefer a different set of companies having access to records at scale for the purposes of improving outcomes, which they will never care about (having seen it first-hand).
Here's a simple example of what can happen with your medical data: Medical data ends up somewhere like LexisNexis -> Company looks you up before hiring -> Company sees that you have a health condition that will cost them more in health insurance costs -> Company doesn't hire you because "it's not a culture fit".
Oh, you don't have a health condition right now? Well, pray you never develop one either -- your boss will probably be able to sign up for push notifications for when there's a new diagnosis for you.
The point is they wouldn't be 'invasive'. Plug a name into a website, get a cost breakdown of how much health insurance would cost for that employee. Indeed will probably have that feature ready to go the day after it becomes legal/available. A few minutes of work for a relatively low-paid employee processing applications, or these days probably some sort of automated system doing the same.
> Secondly why are companies paying more for healthcare given a employee sickness.
They might not pay more for that single employee, but they will pay more overall. The insurance company, as much as it can, will look at how how much it's bringing in, and try to maximize that. So a company could find itself paying higher rates when they renew their health insurance contract.
Conversely, it would be easy to make that kind of thing illegal, while concomitantly more open records access would reduce healthcare costs.
You can imagine how your medical record could be used against you, I'm sure? For people that have suffered agressions, addiction, mental issues, these are all private but can be used against an individual in the public sphere.
Google is a private company with no oversight.
0: https://www.healthcaredive.com/news/google-epic-cloud-partne...
If not this is alarming, thanks for the head up
[0] https://www.businessinsider.com/google-fired-employees-abusi...