The P in HIPAA stands for Portability. At it's heart, the act was supposed to guarantee patients have access to their health information, not bring health data liquidity to it's knees.
This is Jonathan Bush, of Athena, testifying (read: ranting) a couple weeks ago about regulations and innovation in healthcare. The big take away is that healthcare specifically sets these rules with incredibly high barriers of entry, and then at the last minute does a complete 180. We've seen it every step of the way with the EHR incentive program, CEHRT, ICD-10, payment reimbursement, etc. https://www.youtube.com/watch?v=CekfvGDiab8
Also, whether or not people care about their privacy doesn't mean it shouldn't be protected. Not just for themselves, but for their family as well. --Let's say I don't allow my medical information to be used, by my brother does. If he has a genetic disease and a potential employer finds out about it, they might decide not to hire me because there's a chance I may have it as well, which could cause problems if it ended up needing treatment. Laws that prevent discrimination are all well and good, but the problem can be proving the reason they decided not to hire you.
And even with the new rule, there are currently no regulations surrounding de-identified PHI being used for marketing purposes, research, or sold for whatever other purposes. So now you have data wharehousers like IMS spinning up software dev depts with the specific goal of harvesting patient data.
As far as identity vs membership vs attribute disclosure, I linked to a good study below.
I find it interesting that there are more comments in the average HN healthcare-related thread than on any of the recent NPRM. Hell, there are more comments here than people who actually showed up for FDASIA.
I support regulation in a lot of cases, and feel that that FDA took a reasonable approach to the recent mobile medical device guidelines. What I, and pretty much everyone else (other than the AMA) rails against is the indiscriminate flip flopping of what regulations, standards, etc will be required, and on what time horizon.
The first part of the sentence is flawed, so the latter doesn't follow. It implicitly assumes that people even understand how things work (they don't, imho) and therefore can make a sound judgment, based on that knowledge.
For example, I could argue that people simply don't value their future selves (ie 30+yrs), otherwise they wouldn't be eating all this junk food now and never exercising. In some sense that's true, but it's mainly driven by ignorance.
This notion suggests that the right place to start the kind of big-data medical disruption that could work would be a nation with a weaker or nonexistent medical insurance framework.
Just cause I'm feeling particularly paranoid today.
Once there is a single large integrated database it's a HUGE target for people to creatively re-interpret the rules such that they can sell access to it. It's also a hacking target too since doctors tend to be a real pain in the ass about collecting all kinds of information that's not medically necessary but perhaps necessary for billing or in case you try not to pay your bill.
Right now this information is federated meaning that there's no one single point of failure. Hospital X's systems might go down, but Hospital Y's systems are still up. That means that unless something REALLY BAD happens across all the hospitals you're not going to die because a computer crashes.
I am far more on-board with good interchange protocols (Diaspora) than with one large centrally managed database (Facebook).
I'd prefer to retain my privacy and take my chances on the medical miscommunication front, thanks.
And how common, as a ratio, are crippling medical screwups related to multi-practice miscommunication? I'm sure the absolute number is non-zero, but risks must be weighed. If one person having a crippling issue saves 100,000 people from having their personal data released against their will...
Crippling medical screwups that could have been prevented by having the right information available at the right time are actually shockingly common. I don't remember the specifics, but I've seen claims to the effect of a five digit annual death toll in the US alone.
As it is, I only get to see my doctor for three and a half minutes when I need help, after 5 minutes with a PA, and I don't know if the PA has even had a chance to communicate any of what I told her to the physician, so I have to write everything down lest I forget to repeat something important. Now it sounds like you want to remove the chance they might have actually reviewed my history before I get there, by having me carry it around in my pocket with me?
Who can of course store the data on their network, for the duration of your treatment?
Not everything has to be put into global data-silos.
That doesn't make any sense at all. Large companies are either A) already past any barriers to entry or B) have enough money to bust through any barriers to entry. There are probably very few real world situations where being "nimble" is enough to overcome onerous regulations. The reality of the matter is that you just need a lot of money to pay lawyers.
I don't mean to downplay the ridiculous bureaucratic and regulatory crap, but I don't think it's fair to lay the blame at it's feet either.
Honestly, health is just a Ripe For Disruptions™ as any startup-interesting vertical. Takes more stomach and open-mindedness than anything.
It's a bummer. Page/Google are being limp and lazy on this. With opportunities as broad as they have they can afford to Do Hard Things, where Hard is something a little bit out of their wheelhouse. That's okay I guess, but it's a big shame cause health IT could really use some shops with lots of leverage and actual engineering talent to help move the needle when it comes to the constantly backward standards.
[FWIW - I'm a decade and a half long healthcare startup hacker]
In verticals like this don't dismiss the advantage of being lean, nimble, and wholly stocked with incredible and enthusiastic people.
I wish more people saw healthcare this way, and I guess now I'll probably use Uber and AirBnb as an analogy to help them to. THIS is the way to think about health, and how to treat it's risks and limitations.
Same principle, different domain.
Another way to interpret what you said is: Google and other large companies can't apply large quantities of resources to health.
This is a forum for/about startups. He made a statement relevant to startups. What exactly are you mad at?
The answer being.
1) Quite an abstract question
2) A pronoun
It's relevant. It's the conclusion that's concerning!
Again.
'Another way to interpret what you said is: Google and other large companies can't apply large quantities of resources to health.'
I apologize about this thread.
Then.
> Allow me to put words in your mouth... I don't want you people talking about other ideas related to this article.
Consistency?
> I (Multics) would like to talk about how regulating industries like medicine prevents Google and others from investing in them and potentially benefiting society.
I think you understand my position. Except, what I said was framed in the context of the parent comment. And it was an assertion, not a request.
Well, c'est la vie!