Google Co-Founders on Healthcare: “Thanks, But No Thanks”
thehealthcareblog.com
thehealthcareblog.com
That doesn't make any sense at all. Large companies are either A) already past any barriers to entry or B) have enough money to bust through any barriers to entry. There are probably very few real world situations where being "nimble" is enough to overcome onerous regulations. The reality of the matter is that you just need a lot of money to pay lawyers.
I don't mean to downplay the ridiculous bureaucratic and regulatory crap, but I don't think it's fair to lay the blame at it's feet either.
Honestly, health is just a Ripe For Disruptions™ as any startup-interesting vertical. Takes more stomach and open-mindedness than anything.
It's a bummer. Page/Google are being limp and lazy on this. With opportunities as broad as they have they can afford to Do Hard Things, where Hard is something a little bit out of their wheelhouse. That's okay I guess, but it's a big shame cause health IT could really use some shops with lots of leverage and actual engineering talent to help move the needle when it comes to the constantly backward standards.
[FWIW - I'm a decade and a half long healthcare startup hacker]
In verticals like this don't dismiss the advantage of being lean, nimble, and wholly stocked with incredible and enthusiastic people.
I wish more people saw healthcare this way, and I guess now I'll probably use Uber and AirBnb as an analogy to help them to. THIS is the way to think about health, and how to treat it's risks and limitations.
Same principle, different domain.
The P in HIPAA stands for Portability. At it's heart, the act was supposed to guarantee patients have access to their health information, not bring health data liquidity to it's knees.
This is Jonathan Bush, of Athena, testifying (read: ranting) a couple weeks ago about regulations and innovation in healthcare. The big take away is that healthcare specifically sets these rules with incredibly high barriers of entry, and then at the last minute does a complete 180. We've seen it every step of the way with the EHR incentive program, CEHRT, ICD-10, payment reimbursement, etc. https://www.youtube.com/watch?v=CekfvGDiab8
Also, whether or not people care about their privacy doesn't mean it shouldn't be protected. Not just for themselves, but for their family as well. --Let's say I don't allow my medical information to be used, by my brother does. If he has a genetic disease and a potential employer finds out about it, they might decide not to hire me because there's a chance I may have it as well, which could cause problems if it ended up needing treatment. Laws that prevent discrimination are all well and good, but the problem can be proving the reason they decided not to hire you.
And even with the new rule, there are currently no regulations surrounding de-identified PHI being used for marketing purposes, research, or sold for whatever other purposes. So now you have data wharehousers like IMS spinning up software dev depts with the specific goal of harvesting patient data.
As far as identity vs membership vs attribute disclosure, I linked to a good study below.
I find it interesting that there are more comments in the average HN healthcare-related thread than on any of the recent NPRM. Hell, there are more comments here than people who actually showed up for FDASIA.
I support regulation in a lot of cases, and feel that that FDA took a reasonable approach to the recent mobile medical device guidelines. What I, and pretty much everyone else (other than the AMA) rails against is the indiscriminate flip flopping of what regulations, standards, etc will be required, and on what time horizon.
The first part of the sentence is flawed, so the latter doesn't follow. It implicitly assumes that people even understand how things work (they don't, imho) and therefore can make a sound judgment, based on that knowledge.
For example, I could argue that people simply don't value their future selves (ie 30+yrs), otherwise they wouldn't be eating all this junk food now and never exercising. In some sense that's true, but it's mainly driven by ignorance.
This notion suggests that the right place to start the kind of big-data medical disruption that could work would be a nation with a weaker or nonexistent medical insurance framework.
Just cause I'm feeling particularly paranoid today.
Once there is a single large integrated database it's a HUGE target for people to creatively re-interpret the rules such that they can sell access to it. It's also a hacking target too since doctors tend to be a real pain in the ass about collecting all kinds of information that's not medically necessary but perhaps necessary for billing or in case you try not to pay your bill.
Right now this information is federated meaning that there's no one single point of failure. Hospital X's systems might go down, but Hospital Y's systems are still up. That means that unless something REALLY BAD happens across all the hospitals you're not going to die because a computer crashes.
I am far more on-board with good interchange protocols (Diaspora) than with one large centrally managed database (Facebook).
I'd prefer to retain my privacy and take my chances on the medical miscommunication front, thanks.
And how common, as a ratio, are crippling medical screwups related to multi-practice miscommunication? I'm sure the absolute number is non-zero, but risks must be weighed. If one person having a crippling issue saves 100,000 people from having their personal data released against their will...
Crippling medical screwups that could have been prevented by having the right information available at the right time are actually shockingly common. I don't remember the specifics, but I've seen claims to the effect of a five digit annual death toll in the US alone.
As it is, I only get to see my doctor for three and a half minutes when I need help, after 5 minutes with a PA, and I don't know if the PA has even had a chance to communicate any of what I told her to the physician, so I have to write everything down lest I forget to repeat something important. Now it sounds like you want to remove the chance they might have actually reviewed my history before I get there, by having me carry it around in my pocket with me?
Who can of course store the data on their network, for the duration of your treatment?
Not everything has to be put into global data-silos.
Another way to interpret what you said is: Google and other large companies can't apply large quantities of resources to health.
This is a forum for/about startups. He made a statement relevant to startups. What exactly are you mad at?
The answer being.
1) Quite an abstract question
2) A pronoun
It's relevant. It's the conclusion that's concerning!
Again.
'Another way to interpret what you said is: Google and other large companies can't apply large quantities of resources to health.'
I apologize about this thread.
Then.
> Allow me to put words in your mouth... I don't want you people talking about other ideas related to this article.
Consistency?
> I (Multics) would like to talk about how regulating industries like medicine prevents Google and others from investing in them and potentially benefiting society.
I think you understand my position. Except, what I said was framed in the context of the parent comment. And it was an assertion, not a request.
Well, c'est la vie!
1. No insurance companies involved as health care gatekeepers. At the moment, they are very much an adversary to me.
2. Strong, enforced laws against employers discriminating for health. I'm sure the letter of the law currently sounds strong, but I'm assuming you have to sue to right any wrongs. Advantage employer.
Neither one of these will happen in my life time, because insurance companies make huge profits on throttling our healthcare, employers will always like flexibility to do what they want with the law, and both camps fund Congress.
It was bad enough with Netflix recommendations getting de-anonymized; imagine what could happen with actual health records leaked.
http://arstechnica.com/tech-policy/2009/09/your-secrets-live...
Other determinants of health, like your gender, food choices, lifestyle, income, driving history, family history, physical environment, education, social network, etc. have all been heavily mined.
Much legally protected stuff can largely be inferred anyway. There aren't too many people without peanut allergies that haven't bought anything containing peanuts for the past 5 years.
That is, if health data were anonymized, and was done right, and was made unable to be correlated with any other data, it likely would be sufficient. It's when you start allowing it to be correlated with personally identifiable things that it ceases to be anonymous.
That is, sure, let's take a case where you have a super rare genetic disorder. That, combined with the time in 2005 where you broke your leg, is sufficient to distinguish you from every other person in the country. In short, you have a unique health profile.
So what? Unless there is further information, that can't be traced to you. As an example, it's when we start saying "Ah, and the person is receiving treatment at (facility)" that we now know where you live. It's when we start correlating it with usernames that we start getting an internet trail. It's when we start correlating those with forum profiles that we get a real name, and now we know who you are.
The only other way someone could match that profile with you, is to have access to the profile, and to know you personally. Otherwise it links nowhere.
I agree the risk is huge; people don't do it right. But anonymous health profiles are -not- in and of themselves dangerous; it's when details linking them to further information leaks out that it's a problem.
But, pragmatically, while yes it would be incredibly hard...has anyone here read the rights they're signing away when they go to the doctor? Does everyone here trust every system a doctor uses, every system a health insurer uses, and every system used by marketers and researchers that the feds -do- allow to have access to this data? The real risk of Google would be that they could correlate it with so many other things about you; but the health insurers still have your medical history combined with all your PII.
http://webcache.googleusercontent.com/search?q=cache:1gHT-y0...
tl;dr: it does not work much.
Another possibility is they thought it was a cool idea, then found out how regulated it was, how it would be nearly impossible to add any features without massive government oversight, and got out.
1) The original codebase was a nightmarish mess of Java/GWT code that did very little (my first real-life encounter with a FactoryFactory). Most of the developers from this first version drifted away from the project and by the time I arrived there was a second team who were talented, but, unfortunately spent much of their time slowly refactoring other people's crappy code.
2) I didn't observe very much clear product vision. Instead, we had a paranoid obsession with matching the features of Microsoft Health Vault (which was equally meandering & useless).
3) There was a huge top-down pressure from Marissa M and other high level managers to make Google Health into something astoundingly successful, suffocating any possibility of incremental progress and disempowering the actual developers.
4) We had one MD on staff and very little other experience with medicine or healthcare. The developers were very far from the problem domain and relying on a game of managerial telephone to ascertain what the current state of medical record management is and what improvements are possible.
Anyway, in short, my experience was that Google screwed up.
https://webcache.googleusercontent.com/search?q=cache:http:/...
But that doesn't mean the privacy and legal concerns surrounding HIPAA regulations are unwarranted. Yea, it would be nice if we lived in an ethical utopia where we wouldn't have to feel worried about people looking through our health records. But we don't. I would not feel comfortable with my health records being easily accessible, even if that would lead to better data-mining opportunities.
And I say that as a doctor.
It doesn't really work for healthcare because you can't remove it from the jurisdiction. It isn't practical to fly to another country to receive emergency medical services or if all you need is to fill a prescription. Meanwhile the customers with the wealth to sustain research into novel health products are in the countries that impose heavy regulatory burdens on anyone who wants to service them.
Also, all land (more or less) is already in one country. Turning to split off a piece of one country into a new country is often quite deadly. Literally.
Please read this
http://www.washingtonmonthly.com/features/2010/1007.blake.ht...
Guy made a company Retractable Technologies and made medical devices that prevented infections and saved lives. Hospitals won't buy it because of the system.
Which happened partly due to regulation.
This might also be of interest
http://www.nytimes.com/2013/08/27/health/exploring-salines-s...
If you actually read the article, it happened due to the absence of regulation. Hospitals formed an entity (the GPO) to bargain collectively for lower prices from suppliers. This is a classic example of collusion. The GPO started negotiating with the suppliers for a cut of the contracts that they entered into on behalf of the hospitals. This is a classic example of the principal-agent problem. As a result, Retractable Technologies' couldn't break into the market.
Collusion and principal-agent problems arise naturally in free markets. Indeed, the usual response to them is regulation. Antitrust enforcement would've prevented the hospitals from colluding with respect to purchasing supplies, and as the article points out, Medicare's anti-kickback provision, had it been applied to the GPO, would have reduced the principal-agent problem.
To the extent that the first part is true [1], the second part is not true in any substantive way -- the privacy protections restrict what can be disclosed without your consent. So, yes, you can effectively "opt out" of any of the restrictions by consenting to disclosures.
[1] HIPAA -- the Health Insurance Portability and Accountability Act -- exists, in terms of direct goals, mainly to look after your interests as a potential purchaser of health insurance, the as-a-patient privacy protections are secondary to that, and were put in place in HIPAA, and subsequent revisions, to mitigate political opposition to the incentives for automation and related standardization of electronic transactions provisions designed to make the health insurance system -- both in terms of enrollment and claims processing -- more efficient.
I mean, yes, we don't want folks to die. Nor do we want folks making bad decisions based on information they don't understand. However, to say that it is just "people could die" ignores the fact that they have technology entering in vehicles and whatnot.
This was a huge problem we faced in Automotive. All big automotive companies are VERY cautious about safety, to what would seem like absurd levels.
The US will have to make do with their automobile deathtraps and continue to live suboptimal lifespans (35th worldwide) for a country with such a high GDP per capita (6th).
HIPAA laws protect patient rights very well. I think we are on the right track.
Oh wait.
http://www.bloomberg.com/image/iFbqs_CCtc4k.png
The VA has asked for budget increases many times, but was denied by congress. The result is completely predictable.
We do not even know how many people die every year because the increased cost of regulation and delayed time to market because of FDA.
The main reason people aren't healthy has nothing to do with the medical system or regulation. It has everything to do with lifestyle. Technology will not help at all in that regard. The mobile-device generation will be less healthy and even more physically disconnected than the current one, which is a horrifying thought given how bad the state of affairs is right now.
Man is a physical animal, and movement will always beat analysis when it comes to improving health outcomes. We already know how to improve health, we choose not to do it.
And if the patient survives, but has a debilitating condition that was a side-effect of that risky drug, then claims he was going to survive anyway and now his life has a shattered quality because the doctor prescribed an drug that hadn't been fully cleared yet? It's not as black and white as you're painting it, and drugs are not always silver bullets that save your life and send you back to playing the violin like the virtuoso you once were.
Conversely, if you didn't have that regulation, you'd have medication with a much lower quality - more people dying, and more negative side-effects for the ones who survived. Plenty of drugs look promising at the outset, then turn out to have serious issues.
Kind of like supplements? http://www.nytimes.com/2013/11/05/science/herbal-supplements...
It's also about balancing incentives. If there were no such regulations whatsoever, you'd find yourself in a situation, where a patient with a mild cancer and a broken arm is potentially "terminally ill" and needs the New Risky Drug. It could degenerate to regular, systematic experimentation on humans in the guise of "doing everything we can".
We had to do a risk analysis review recently, and figured that unless you physically dropped one of our servers onto a patient you couldn't directly cause harm.
Anyways, you'd be a lot less concerned with regulation if you knew how brainfucked and unscientific the whole field of medicine seems to be--it's not as far along as you might expect/hope.
http://sunnyday.mit.edu/papers/therac.pdf
http://courses.cs.vt.edu/professionalism/Therac_25/Therac_1....
plenty of other reading: https://www.google.com/#q=therac-25
There is a difference between embedded systems or devices (pacemakers, imaging devices, etc.) and EMR/records/data mining software.
The regulations are all calibrated to defend against a Therac-25 (well, sort of) and seemingly not to deal with modern software development or deployment.
Dengue kills poor people but we've got dick pills when you can't get it up. The regulations are just part of it...
What did an MRI cost 20 years ago, what does it cost today? No competition, no Moore's law, and that's on the technology side...
Google certainly has the cash to sit this sort of thing out, hire sales and support people etc. Microsoft and others are doing so, see Microsoft Amalga for example.
However a more intriguing area, to me, is doing some more basic research without becoming a health company. Google is doing this with the glucose contacts and things. These are novel ideas with significant IP that could be spun off into an independent company and/or licensed to to an existing drug company to push through clinical trials and bring to market.
I think this is the place that google might enter and play well. If google can develop a very high-level , fda certified development tool/operating-system ,such that developing fda certified products become much easier , they could have a very big win on their hands.
I've seen some research on such systems ,so it's a clear possibility. And since it's a new thing , it might need some changes in the fda, which google has the tools to push.
I'm in favor of protecting people from bad medcine, but I think the current regulatory structure is an overly-restrictive tool for the job. Either that, or (given that it steps on the neck of 23andme but lets GNC and homeopathic practitioners continue to operate) it's mis-tuned for modern technologies and tools.
I've worked with people involved in HIV vaccine trials overseas and, in fact, things really don't change as much as you might think.
The basic tenant "first do no harm" is ingrained at an many different ethical, institutional and legal levels that it isn't like you can, say, justify a more risky vaccine in an area with a higher risk for HIV or whatever.
In fact trials have been cut short and research into entire vectors (ie the cold virus used as a transport for the HIV related material) cut off when trials in Africa started to appear (statistically) to be slightly harmful in any way.
I feel this is a good thing. Scientists and medical people holding themselves to this high standard is the reason the anti-vaccine crowd really doesn't have a leg to stand on.
Unfortunately, the same doesn't apply to unethical treatment. More and more patients get certain treatments or recommendations by doctors or hospitals not because they need them but because they're profitable for the doctors or hospitals.
This is the insurance/financial product salesman's spirit at work, and it needs to be stopped. Right now.
I think part of the problem is the "insurance" mentality - if you don't pay for the treatment yourself, but the insurance just pays for everything, you aren't interested in an economical solution (and maybe the minimally-invasive treatment), but you take what's recommended. If you have to pay for treatment yourself, you begin asking questions. (Disclaimer: I live in Germany, a country with "free" health insurance, which I pay for with an effective 15% tax on my income.)
While it seems to go against "do no harm" ,in reality many low cost products can start at low quality, but with time and experience improve while still offering much lower costs. So the logic can make sense.
Not sure it works for vaccines thought.
Also i wonder: what were the benefits of the vaccine you described ? were they weighted against the slight harm ?
Then buy Theranos.
now imagine the same with Google having access to all medical records.
regulation around this exists for a very, very good reason.
It was a poor UI experience, but it wasn't a private-data leak.