Showing posts with label HIPAA. Show all posts
Showing posts with label HIPAA. Show all posts

Tuesday, November 12, 2019

Google’s ‘Project Nightingale’ Secretly Gathers Personal Health Data on Millions of Americans - Time to Refuse Use Of EMR's In Your Healthcare?

I have long written that leadership of EMR technology by the wrong people will create exceptionally adverse outcomes, clinically speaking. 

The same appears true socially.  In fact, adverse social outcomes (especially with regard to societal power structures) is one of the pillars of the domain of Social Informatics, the field that studies social impacts of new information & communication technologies (ICTs), about which I've taught and written.  (See http://www.dlib.org/dlib/january99/kling/01kling.html)

Now there's this stunning new story regarding clinical data trafficking. 

Original article is at the WSJ by Gerald F. Seib here: https://www.wsj.com/articles/google-s-secret-project-nightingale-gathers-personal-health-data-on-millions-of-americans-11573496790, but it's behind a paywall:

Google’s ‘Project Nightingale’ Secretly Gathers Personal Health Data on Millions of Americans

November 12, 2019

https://www.theepochtimes.com/googles-project-nightingale-secretly-gathers-personal-health-data-on-millions-of-americans_3143843.html

Google has been working with one of the largest healthcare systems in the U.S. to collect and analyze the personal health information of millions of citizens across 21 states, The Wall Street Journal reports.  The Tech giant reportedly teamed up with St. Louis-based Ascension, the largest non-profit health system in the country, last year, and the data sharing has accelerated since summer.

Code-named Nightingale, the project saw both companies collect personal data from patients, which included lab results, doctor diagnoses, and hospitalization records, as well as patient names and dates of birth.
Google said it plans to use the data to create new software that will improve patient care and suggest changes to their care.

First and foremost, the focus of this "project" is the hackneyed cybernetic miracle we've been promised for decades, the "Artificial Intelligence" that will "revolutionize" medicine. 

I view this concept as massively over-hyped and likely fraudulent, an effort to salvage the very same promises made of the entire EMR project on which has been spent hundreds of billions of dollars (more likely beyond the trillion range by now), while waiting for Godot. 

Those monies could have been better used to provide world-class healthcare for an entire population, especially considering the lack of evidence of the miracles promised.


   
CMS: "we do not have any information that supports or refutes claims that a broader adoption of EHRs can save lives."  [But let's spend hundreds of billions of dollars anyway.]  Click to enlarge.

... Patients and doctors were not notified that their data is being shared, and did not give their consent, according to the report.

One individual who was familiar with the project told the Journal that at least 150 Google employees already have access to much of the data on tens of millions of patients.
I have already written that the entire national EMR project is a mass human-subjects experiment without informed consent that can maim or kill patients in many different ways, including clinician distraction and IT error, among others.  I also note that as I've been involved in litigation support over the past decade, I've been exposed to what really happens without the filter of the press and the IT industry.  (The verdict in the last case in which I testified about Bad Health IT, for example, went to the deceased plaintiff's heirs - amounting to more than $16 million; others were in a lower but still multi-million dollar range.  Yet, you likely will never read about these in the HIT literature)

I believe this new account of clinical data trafficking is, more likely than not, true. It is a development I've fully been expecting for at least a decade now. (See my February 26, 2012 post "Proposed new Consumer Privacy Bill of Rights: Is It Too Late For Healthcare?" at https://hcrenewal.blogspot.com/2012/02/proposed-new-consumer-privacy-bill-of.html and my Oct. 7. 2009 post "Health IT Vendors Trafficking in Patient Data?" at https://hcrenewal.blogspot.com/2009/10/health-it-vendors-trafficking-in.html).

This new development would represent an invitation to massive deliberate or inadvertent abuse, and is likely a massive violation of the HIPAA Privacy Act, despite claims to the contrary.

Just hours after the secret project was revealed, the two companies announced the collaboration in a press release, in which they said the joint project would see Ascension’s data moved onto Google’s Cloud platform.
The statement said the joint project aims to “optimize the health and wellness of individuals and communities and deliver a comprehensive portfolio of digital capabilities that enhance the experience of Ascension consumers, patients, and clinical providers across the continuum of care.”

More cybernetic miracles promised for the true believers, expressed in the typical IT-magic phraseology.  Plenty of profits, too.

Eduardo Conrado, Executive Vice President of Strategy and Innovations at Ascension, said: “As the healthcare environment continues to rapidly evolve, we must transform to better meet the needs and expectations of those we serve as well as our own caregivers and healthcare providers.

The "transformations" needed are to scale back the IT and the bureaucracy that burdens good clinicians and consumes massive amounts of $, and the reduction of waste on worse-than-useless Bad Health IT (http://cci.drexel.edu/faculty/ssilverstein/cases/):

Bad Health IT is IT that is ill-suited to purpose, hard to use, unreliable, loses data or provides incorrect data, is difficult and/or prohibitively expensive to customize to the needs of different medical specialists and subspecialists, causes cognitive overload, slows rather than facilitates users, lacks appropriate alerts, creates the need for hypervigilance (i.e., towards avoiding IT-related mishaps) that increases stress, is lacking in security, compromises patient privacy, lacks evidentiary soundness or otherwise demonstrates suboptimal design and/or implementation. 

More corporate mumbo-jumbo:

“Doing that will require the programmatic integration of new care models delivered through the digital platforms, applications, and services that are part of the everyday experience of those we serve.”
The partnership will also explore artificial intelligence and machine learning applications to help improve clinical quality, and effectiveness, patient safety and increase consumer and provider satisfaction, according to the statement.

The data collected by today's EMRs is subject to inaccuracy for multiple reasons mentioned at this blog, including perverse incentives, clinician harassment and cognitive overload, time limitations, forced entry of some data to move further on in the record, and others.  Further,  the Bad Health IT systems used to collect and display it exposes patients to risk and injury.  "AI" will not solve these "issues."

Tariq Shaukat, President of Google Cloud, added: “Ascension is a leader at increasing patient access to care across all regions and backgrounds, particularly those in disadvantaged communities. We’re proud to partner with them on their digital transformation.

"Digital transformation" is, quite frankly, the same BS as "IT revolutionizing healthcare" that I'd heard since at least the mid-1990s (see my post "Bill, Have You Lost Your Mind?" at https://hcrenewal.blogspot.com/2006/07/bill-have-you-lost-your-mind.html where I reposted my earlier memorialization of such baldly overwrought and preposterous claims.)
 
“By working in partnership with leading healthcare systems like Ascension, we hope to transform the delivery of healthcare through the power of the cloud, data analytics, machine learning, and modern productivity tools—ultimately improving outcomes, reducing costs, and saving lives.”

More billions of dollars are to be transferred from patient care to the IT industry. 

These $ could be far better spent, IMHO, on care delivery, including to the disadvantaged and minorities, and in rethinking the current health IT morass.  (See my Jan,. 2018 post "The inevitable downgrading of burdensome, destructive EHRs back to paper & document imaging" at http://hcrenewal.blogspot.com/2018/01/the-inevitable-downgrading-of.html).

I have passed the newly-released articles on this matter to attorneys with access to the national trial lawyers' listservs, where the merits of "Project Nightingale" can be considered from the perspective of non-toothless patient's rights advocates.

FINALLY:

I believe invasive healthcare data trafficking projects like this, with potential for massive abuses, provide reasonable justification for patients to REFUSE the use of EHR's in their care.  Paper works just fine.  In fact, when the IT goes down, it's what hospitals and doctors go right back to, and the PR always claims that "patient care was not compromised."

-- SS

11/15/2019 Addendum:

There is a whistleblower (https://www.theguardian.com/commentisfree/2019/nov/14/im-the-google-whistleblower-the-medical-data-of-millions-of-americans-is-at-risk):

I didn’t decide to blow the whistle on Google’s deal, known internally as the Nightingale Project, glibly. The decision came to me slowly, creeping on me through my day-to-day work as one of about 250 people in Google and Ascension working on the project.

When I first joined Nightingale I was excited to be at the forefront of medical innovation. Google has staked its claim to be a major player in the healthcare sector, using its phenomenal artificial intelligence (AI) and machine learning tools to predict patterns of illness in ways that might some day lead to new treatments and, who knows, even cures.

Here I was working with senior management teams on both sides, Google and Ascension, creating the future. That chimed with my overall conviction that technology really does have the potential to change healthcare for the better.

But over time I grew increasingly concerned about the security and privacy aspects of the deal. It became obvious that many around me in the Nightingale team also shared those anxieties.

After a while I reached a point that I suspect is familiar to most whistleblowers, where what I was witnessing was too important for me to remain silent. Two simple questions kept hounding me: did patients know about the transfer of their data to the tech giant? Should they be informed and given a chance to opt in or out?

The answer to the first question quickly became apparent: no. The answer to the second I became increasingly convinced about: yes. Put the two together, and how could I say nothing?
-- SS

Monday, December 09, 2013

But Don't Worry, Your Health Information is Secure: the Enforcers are Themselves Incompetent and Broke

Another in my "But Don't Worry, Your Health Information is Secure" series (see http://hcrenewal.blogspot.com/search/label/medical%20record%20privacy) ... a promise blindly made by the healthcare information technology hyper-enthusiasts.

The Office of the Inspector General for HHS just issued a report finding that the Office of Civil Rights (OCR), which is charged with enforcing the HIPAA/HITECH law, had itself failed to adequately protect the security of the health information it handled. Specifically OIG found that OCR “focused on system operability to the detriment of system and data security.”

From “The Office for Civil Rights Did Not Meet All Federal Requirements in Its Oversight and Enforcement of the Health Insurance Portability and Accountability Act Security Rule”, p. ii (Nov. 2013).  http://oig.hhs.gov/oas/reports/region4/41105025.asp

Summary:

The Office for Civil Rights (OCR) did not meet certain Federal requirements critical to the oversight and enforcement of the Health Insurance Portability and Accountability Act Security Rule (Security Rule). OCR had not assessed risks, established priorities, or implemented controls for its Federal requirements to provide for periodic audits of covered entities to ensure their compliance with Security Rule requirements. In addition, OCR's Security Rule investigation files did not contain required documentation supporting key decisions made because management had not implemented sufficient controls, including supervisory review and documentation retention, to ensure investigators follow investigation policies and procedures for properly initiating, processing, and closing Security Rule investigations. Further, OCR had not fully complied with Federal cybersecurity requirements for its information systems used to process and store investigation data because it focused on system operability [I presume they mean 'interoperability' - ed.] to the detriment of system and data security.

We recommended that OCR (1) assess the risks, establish priorities, and implement controls for its HITECH auditing requirements; (2) provide for periodic audits in accordance with HITECH to ensure Security Rule compliance at covered entities; (3) implement sufficient controls, such as supervisory reviews and documentation retention, to ensure policies and procedures for Security Rule investigations are followed; and (4) implement the National Institute of Standards and Technology Risk Management Framework for systems used to oversee and enforce the Security Rule. In its comments on our draft report, OCR generally concurred with our recommendations and described the actions it has taken to address them. In specific comments on our second recommendation, however, OCR explained that no funds had been appropriated for it to maintain a permanent audit program and that funds used to support audit activities previously conducted were no longer available.

The enforcers are themselves negligent, incompetent and broke.  And hospitals are expected to keep electronic protected health information secure?

I comment no further.  What more could I possibly write?

-- SS

Dec. 9, 2013 Addendum:

This woman would probably agree that this is a problem

Dec. 9, 2013
http://www.thestar.com/news/gta/2013/11/28/disabled_woman_denied_entry_to_us_after_agent_cites_supposedly_private_medical_details.html

Disabled woman denied entry to U.S. after agent cites supposedly private medical details

A Toronto woman is shocked after she was denied entry into the U.S. because she had been hospitalized for clinical depression.

Ellen Richardson went to Pearson airport on Monday full of joy about flying to New York City and from there going on a 10-day Caribbean cruise for which she’d paid about $6,000.

But a U.S. Customs and Border Protection agent with the Department of Homeland Security killed that dream when he denied her entry.

“I was turned away, I was told, because I had a hospitalization in the summer of 2012 for clinical depression,’’ said Richardson, who is a paraplegic and set up her cruise in collaboration with a March of Dimes group of about 12 others.

The Weston woman was told by the U.S. agent she would have to get “medical clearance’’ and be examined by one of only three doctors in Toronto whose assessments are accepted by Homeland Security. She was given their names and told a call to her psychiatrist “would not suffice.’’

At the time, Richardson said, she was so shocked and devastated by what was going on, she wasn’t thinking about how U.S. authorities could access her supposedly private medical information.

“I was so aghast. I was saying, ‘I don’t understand this. What is the problem?’ I was so looking forward to getting away . . . I’d even brought a little string of Christmas lights I was going to string up in the cabin. . . . It’s not like I can just book again right away,’’ she said, referring to the time and planning that goes into taking a trip as a disabled person.

Richardson said she’d had no discussion whatsoever with the agent at the airport about her medical history or background.

Read the whole thing.

-- SS

Friday, May 01, 2009

Was Google lobbying Washington for HIPAA exclusion of their PHR effort?

At "Should Google Seek the Resignations of Those Responsible for This Healthcare IT Debacle?" I expressed great concern about what I term the cross occupational intrusion of the IT industry into healthcare.

My major concern in that post was how the information technologists at Google, even with nearly unlimited access to capital (and therefore to the world's informatics expertise) badly mismanaged a Personal Health Records (PHR) project through commission of a most fundamental biomedical information science blunder (quite distinct from IT; most IT technologists and MIS personnel really stink at biomedical information science). They tried to map relatively ungranular, imprecise, and often misused billing codes back to enduser-viewable diagnoses, resulting in easily predictable patient panic and mayhem.

As usual in HIT: it's possibly even worse.


I am quite concerned about a letter from the consumer education and advocacy organization Consumer Watchdog.org and their allegations that Google has been lobbying Congress to be excluded from HIPAA provisions on privacy and forbidding sales of medical records. The letter, dated April 22, is here (http://www.consumerwatchdog.org/resources/LtrSchmidt042209.pdf).

Considering that Google is heavily into the PHR space, and even worse, considering they made an Informatics 101 error in attempting to map billing codes into user-viewable diagnostic data, I would (and I'm sure others would as well) view such attempts if they indeed occurred as ominous, a true heavy handed intrusion of the IT industry not only into the affairs of medicine but into what really is another human rights issue. (I'd pointed out another potential HIT-related human rights issue at the post "
UPMC as Proving Ground for IT Tests On Children".)

I would be interested in additional information on the Google lobbying issue, especially from those at Harvard and other academic centers who have been involved in the Google PHR initiative.

I have shared these concerns with the American Medical Informatics Association (AMIA) clinical information systems workgroup (cis-wg) and the people & organizational issues workgroup (poi-wg) as well.

I hope the Consumer Watchdog allegations are not accurate, because if they are valid, the implications of national EHR grow increasingly unsettling.