Showing posts with label Data Breach and Theft. Show all posts
Showing posts with label Data Breach and Theft. Show all posts

Friday, September 23, 2011

Old data learns new tricks: Managing patient security and privacy on a new data-sharing playground


Data is quickly becoming one of the health industry’s most treasured commodities. Yet, health organizations are acutely aware that sensitive data can be easily compromised. In just the last year and a half, a breach of personal health information occurred, on average, every other day. Breaches erode productivity and patient trust. They’re costly, unpredictable, and unfortunately quite common. More than half of healthcare organizations surveyed by PwC have had at least one privacy/security-related issue in the last two years

·        Download: Old data learns new tricks (1.24mb)
·       Download: Old data learns new tricks: Chart pack (58kb)

Monday, September 19, 2011

NYTimes on ID

Call It Your Online Driver’s License

By NATASHA SINGER  NYT   9/18/11

Consumers who still pay bills via snail mail. Hospitals leery of making treatment records available online to their patients. Some state motor vehicle registries that require car owners to appear in person — or to mail back license plates — in order to transfer vehicle ownership.

But the White House is out to fight cyberphobia with an initiative intended to bolster confidence in e-commerce.

The plan, called the National Strategy for Trusted Identities in Cyberspace and introduced earlier this year, encourages the private-sector development and public adoption of online user authentication systems. Think of it as a driver’s license for the Internet. The idea is that if people have a simple, easy way to prove who they are online with more than a flimsy password, they’ll naturally do more business on the Web. And companies and government agencies, like Social Security or the I.R.S., could offer those consumers faster, more secure online services without having to come up with their own individual vetting systems.

“What if states had a better way to authenticate your identity online, so that you didn’t have to make a trip to the D.M.V.?” says Jeremy Grant, the senior executive adviser for identity management at the National Institute of Standards and Technology, the agency overseeing the initiative.

But authentication proponents and privacy advocates disagree about whether Internet IDs would actually heighten consumer protection — or end up increasing consumer exposure to online surveillance and identity theft.

If the plan works, consumers who opt in might soon be able to choose among trusted third parties — such as banks, technology companies or cellphone service providers — that could verify certain personal information about them and issue them secure credentials to use in online transactions.

Industry experts expect that each authentication technology would rely on at least two different ID confirmation methods. Those might include embedding an encryption chip in people’s phones, issuing smart cards or using one-time passwords or biometric identifiers like fingerprints to confirm substantial transactions. Banks already use two-factor authentication, confirming people’s identities when they open accounts and then issuing depositors with A.T.M. cards, says Kaliya Hamlin, an online identity expert known by the name of her Web site, Identity Woman.

The system would allow Internet users to use the same secure credential on many Web sites, says Mr. Grant, and it might increase privacy. In practical terms, for example, people could have their identity authenticator automatically confirm that they are old enough to sign up for Pandora on their own, without having to share their year of birth with the music site.

The Open Identity Exchange, a group of companies including AT&T, Google, Paypal, Symantec and Verizon, is helping to develop certification standards for online identity authentication; it believes that industry can address privacy issues through self-regulation. The government has pledged to be an early adopter of the cyber IDs.

But privacy advocates say that in the absence of stringent safeguards, widespread identity verification online could actually make consumers more vulnerable. If people start entrusting their most sensitive information to a few third-party verifiers and use the ID credentials for a variety of transactions, these advocates say, authentication companies would become honey pots for hackers.

“Look at it this way: You can have one key that opens every lock for everything you might need online in your daily life,” says Lillie Coney, the associate director of the Electronic Privacy Information Center in Washington. “Or, would you rather have a key ring that would allow you to open some things but not others?”

Even leading industry experts foresee challenges in instituting across-the-board privacy protections for consumers and companies.

For example, people may not want the banks they might use as their authenticators to know which government sites they visit, says Kim Cameron, whose title is distinguished engineer at Microsoft, a leading player in identity technology. Banks, meanwhile, may not want their rivals to have access to data profiles about their clients. But both situations could arise if identity authenticators assigned each user with an individual name, number, e-mail address or code, allowing companies to follow people around the Web and amass detailed profiles on their transactions.

“The whole thing is fraught with the potential for doing things wrong,” Mr. Cameron says.

But next-generation software could solve part of the problem by allowing authentication systems to verify certain claims about a person, like age or citizenship, without needing to know their identities. Microsoft bought one brand of user-blind software, called U-Prove, in 2008 and has made it available as an open-source platform for developers.

Google, meanwhile, already has a free system, called the “Google Identity Toolkit,” for Web site operators who want to shift users from passwords to third-party authentication. It’s the kind of platform that makes Google poised to become a major player in identity authentication.

But privacy advocates like Lee Tien, a senior staff lawyer at the Electronic Frontier Foundation, a digital rights group, say the government would need new privacy laws or regulations to prohibit identity verifiers from selling user data or sharing it with law enforcement officials without a warrant. And what would happen if, say, people lost devices containing their ID chips or smart cards?

“It took us decades to realize that we shouldn’t carry our Social Security cards around in our wallets,” says Aaron Titus, the chief privacy officer at Identity Finder, a company that helps users locate and quarantine personal information on their computers.

Carrying around cyber IDs seems even riskier than Social Security cards, Mr. Titus says, because they could let people complete even bigger transactions, like buying a house online. “What happens when you leave your phone at a bar?” he asks. “Could someone take it and use it to commit a form of hyper identity theft?”

For the government’s part, Mr. Grant acknowledges that no system is invulnerable. But better online identity authentication would certainly improve the current situation — in which many people use the same one or two passwords for a dozen or more of their e-mail, e-tail, online banking and social network accounts, he says.

Mr. Grant likens that kind of weak security to flimsy locks on bathroom doors.

“If we can get everyone to use a strong deadbolt instead of a flimsy bathroom door lock,” he says, “you significantly improve the kind of security we have.”

But not if the keys can be compromised.
A version of this article appeared in print on September 18, 2011, on page BU4 of the New York edition with the headline: Call It Your Online Driver’s License.

Monday, July 18, 2011

CDT Justin Brookman: Why the US needs a data privacy law-and why it might finally get one

Why the US needs a data privacy law—and why it might finally get one
By Justin Brookman | Published July 18, 2011  ARS

The general public and Congress have both discovered geolocation, data breaches, and tracking cookies—and they're worried about the privacy implications. In this op-ed, the Center for Democracy & Technology's Justin Brookman argues that this could be the moment at which everything comes together to make comprehensive privacy reform possible. The opinions in this op-ed do not necessarily represent those of Ars Technica.

With the understandable exceptions of the national debt and the deployments of our troops abroad, privacy is possibly the hottest issue in Congress today. After ten years of limited interest in the subject, we’ve recently seen a spate of legislation introduced to give consumers rights over how their information is collected and shared.

In the House of Representatives, Reps. Bobby Rush (D-IL) and Cliff Stearns (R-FL) have each introduced separate comprehensive bills. In the Senate, John Kerry (D-MA) and John McCain (R-AZ) recently introduced the "Commercial Privacy Bill of Rights" with similar goals. The (Democrat-led) Senate Commerce Committee recently held a hearing on the topic of privacy; the next week, the (Republican-led) House Energy and Commerce Committee looked at the same thing.

In a town where positions on issues are often deeply divided along partisan lines, it’s encouraging to see that there appears to be at least one issue that both parties recognize as a problem that needs to be addressed.

Not much company
Here’s why Congress is interested: today, the United States and Turkey are the only developed nations in the world without a comprehensive law protecting consumer privacy. European citizens have privacy rights, Asian citizens have privacy rights, Latin American citizens have privacy rights. In the US, however, in lieu of a comprehensive approach, we have a handful of inconsistent, sector-specific laws around particularly sensitive information like health and financial data. For everything else, the only rule for companies is just “don’t lie about what you’re doing with data.”

The Federal Trade Commission enforces this prohibition, and does a pretty good job with this limited authority, but risk-averse lawyers have figured out that the best way to not violate this rule is to not make explicit privacy promises at all. For this reason, corporate privacy policies tend to be legalistic and vague, reserving rights to use, sell, or share your information while not really describing the company’s practices. Consumers who want to find out what’s happening to their information often cannot, since current law actually incentivizes companies not to make concrete disclosures.

This has been the case for years, of course, but in the modern era of constant connectivity, social networking, and cheap data storage and processing, the stakes are remarkably higher. Before the advent of the Internet, there were only so many data points for marketers and information brokers to collect about you, and bookstores and libraries didn’t share what you were reading. Even just a few years ago, when you went to a major publisher website, there might have been a couple third-party trackers on the site who could drop a cookie on your computer to “anonymously” track you across other sites. Today, these same sites may deploy hundreds of trackers from dozens of different companies, many of which know your offline identity as well. What happens to all that information? With whom is it shared? No one really knows, and there is no framework to regulate it.

Bad for business
This black box into which our data flows is bad for consumers, but it’s increasingly an impediment to US businesses as well. As Silicon Valley companies encourage consumers to store their personal data in “the cloud,” people are legitimately asking, “Why? What’s going to happen to my data there?” Today, the US is the undisputed leader in cloud computing services, but international competitors are increasingly advertising the fact that their services aren’t US-based. The Department of Commerce recently issued a report arguing that the lack of privacy protections threatens both the adoption of new technologies by worried consumers and the ability to have international data sent to the US. Last week, Forrester Research released a study showing that privacy concerns were the biggest impediment to the growth of e-commerce on mobile technologies.

Companies would be better off if they all provided meaningful privacy protections for consumers, but privacy is a collective action problem for them: many companies would love to see the ecosystem fixed, but no one wants to put themselves at a competitive disadvantage by imposing unilateral limitations on what they can do with user data. It’s fantastic to see companies endeavoring to compete on privacy (such as Google touting the privacy features of its new social network), but so far such competition has been spotty and often takes place at the margins. Many companies that touch and store consumer data don’t have consumer-facing sides (like the ever-increasing number of intermediaries in the behavioral advertising space), so it’s hard to see the Internet ecosystem fixing itself on its own.

And let’s be frank: so far, self-regulation hasn’t been enough. Increasingly, leading multinational corporations have recognized this problem, and companies like Microsoft, Intel, and HP that have heavily invested in cloud technologies have endorsed specific legislative solutions such as the Kerry-McCain and Rush bills to provide consumers with comprehensive privacy protections.

Any privacy law that is enacted doesn’t need to, and shouldn’t, prohibit data sharing or invalidate business models. However, consumers have a right to know what’s happening with their information and to have a say in how it gets shared. If a company insists on sharing data about a consumer as a condition of doing service, fine. As long as that fact is clearly conveyed, and the consumer decides to accept the terms, we shouldn’t put limits on what consumers are willing to do with their own information. Unfortunately, consumers today aren’t even told what’s happening, so they can’t exercise meaningful control over their data unless they take extreme measures to anonymize their surfing though services like Tor or block third-party content (which surely isn’t the right result for anyone).

So will a new law be passed? As with anything in Washington, it’s hard to say what will happen—Congress has a lamentable tendency to kick problems down the road for another day. However, with tremendous attention to privacy issues and widespread consumer support for basic consumer protections, we have the best opportunity in memory to enact basic rules to give people control of their personal information and to give them confidence in an increasingly complex data ecosystem. We should take advantage of this moment to develop a considered consensus on reasonable baseline protections that work for both consumers and businesses.

Justin Brookman is Director of the Consumer Privacy Project at the Center for Democracy & Technology in Washington, DC.

Privacy Isn't Dead. Just Ask Google+.

July 18, 2011, 12:59 pm
Privacy Isn’t Dead. Just Ask Google+.
By NICK BILTON
http://bits.blogs.nytimes.com/2011/07/18/privacy-isnt-dead-just-ask-google/?smid=tw-nytimesbits&seid=auto#h[]

Some people have a very hard time trusting Facebook.

After dozens of privacy problems over the years, they’ve grown extremely weary of what the company is doing with my personal information.  I, for one, rarely use Facebook anymore, beyond a rare comment or “Like.”

My Facebook fears stem from the several instances when the company has added new features to the site and chose to automatically opt-in hundreds of millions of users, most of whom don’t even know they’ve been signed up for the new feature. I’ve also been sapped by the company’s hyper-confusing privacy policy, which requires users to navigate a labyrinth of buttons and menus when hoping to make their personal information private.

For Facebook, these breaches on people’s personal privacy rarely result in any repercussions: the negative press is usually temporary, and users have mostly stayed with the service, saying that there isn’t a viable alternative social network to talk to family and friends.
That is, until now.

Enter Google+, which started last month and has already grown to 10 million users. Rather than focus on new snazzy features — although it does offer several — Google has chosen to learn from its own mistakes, and Facebook’s. Google decided to make privacy the No. 1 feature of its new service.

I learned this lesson accidentally last week. When I signed up for Google+, I quickly posted a link to a New York Times article I wanted to share with people. Several hours later my Google+ link lay dormant. No comments. No +1 clicks. And no resharing the link.

It wasn’t until later that I realized that my post had been made private by default; a Google+ user has to specifically say they want to share a post publicly. By doing this, Google has chosen to opt users out of being public, rather than the standard practice by most other services to automatically opt users in.

This isn’t to say Google is perfect. Last year the company has had its fair share of privacy problems. This happened most recently when it started Google Buzz, a social networking service, which turned into a privacy disaster and resulted in calls in Congress to investigate the company.

With Google’s latest offering, it seems that the company not only learned its lesson about the importance of privacy for consumers online, but also realized that Facebook hasn’t learned about the importance of this issue either.

Wednesday, July 13, 2011

How Google and Data-Mining Drive Economic Inequality in Our Nation

Nathan Newman, July 11, 2011  Huffington Post

This is the first part in a three-part series that will run this week at HuffPost on why lost privacy online matters for economic equity in our economy.
Why has economic inequality increased so radically in the United States over the last generation?
General explanations range from globalization to the decline in trade unions to rising returns to education -- and therefore the loss of income to the less educated. These all no doubt play a role, but in an age of information what is unquestionably true is that control of that information is extremely unequal -- and that inequality drives broader economic inequality in our economy.

Information is power and as companies know more and more about us, while the products they sell become more opaque and complicated -- think mortgage-based Collateralized Debt Obligations (CDOs) -- inequality in information begets a massive transfer of wealth from individuals to corporations and to their shareholders. Companies figure out not just what to sell you but the maximum price you and other people like you will pay for that product.

Privacy is About Economic Power and Inequality: The debate on privacy online is therefore not about whether you think it's creepy that corporations are tracking your online activities. You may not have a strong "ick" factor from corporate surveillance per se -- I don't myself -- but what you should care about is that lost privacy is converted by those companies into information that ultimately drives greater economic inequality in our country.

One original promise of the Internet was that "no one knows you're a dog on the Internet" but we have instead evolved through data-mining and online surveillance into a world where not only do companies know what you are, they know where you are and what you are most interested in. For the economically privileged, that may not seem like much of a problem and even a benefit since companies may be able to service your needs more effectively. But for those who already suffer discrimination and exploitation, whether because of race, poverty or other factors, it means that the Internet can just magnify and target that discriminatory treatment and exploitation.

Which brings us to the Federal Trade Commission antitrust investigation into Google. The problem with Google is not that users don't have enough competing options on search engines but that Google's dominance of search and other online products allows them to extract the most massive quantities of private information from users of any corporation. And as I described in my piece back in March, You're Not Google's Customer, You're the Product, Google's real customers are the whole array of corporations who buy access to that user information to know how to effectively market their products and increase their profits.

Google at the Nexus of the Marketing of Privacy: Google is the key nexus in the information age, pricing individual privacy and monetizing it for the benefit of global corporations. They are the dominant middleman between hundreds of millions of people -- even approaching billions globally -- and the corporations using that Google-generated profiling to market their products and extract profit for their shareholders.

And it is that global market power over private individual data by Google that antitrust regulators need to investigate in order to counteract the rising inequality in the information economy. The cost of lost privacy driven by Google is corporate data-mining and manipulated prices across a whole array of markets and the exacerbation of multiple forms of discrimination in the marketplace. Google's monopoly dominance of personal information thereby helps leverage the broader corporate dominance of our lives by the companies using its data.

Why Free is a Bad Deal: The first step in how lost privacy increases economic inequality begins at the moment users give away their private information in the first place. Google offers the enticement of free services in exchange for users turning over a whole range of basic personal data and even what their basic desires are in the form of the whole record of what they search for on Google's pages.

What could be better than free, most users think, as they take the deal offered? It's a bit like how early bank customers might have felt, being told the bank would keep their money safe for free, only later figuring out that the bank was making tons of money lending that money to other people. The free Google tools into which users drop their private information are like the vault banks offered to store your money: it's not a service but a honeypot that allows both banks and Google to resell what users deposit there. Bank customers now expect actual payment in the form of interest for money deposited in banks but most Google customers don't even recognize that their private information has a monetary value that has economic value.
To put it another way, the fact that users are de facto involved in barter with Google, trading privacy for individual tools, should tell you this is an exploitative situation. Like most barter economies, pricing is opaque and creates massive opportunities for economic arbitrage by the sophisticated side of the barter transaction -- i.e. Google. Essentially, Google users are the primitive tribes of the Internet, accepting the shiny trinkets of Gmail and free search in exchange for their privacy.

Google then takes that private information and monetizes it with advertisers who pay very precise dollar terms in the modern part of the Google economy. And those advertisers pay prices far above the costs spent by Google on the tools provided to users -- as highlighted by Google's massive profits year after year. That advertising side of Google's internal economy is actually a monument to converting privacy into a modern currency, with sophisticated auctions for key words and phrases based on particular user demographics and backgrounds that the advertiser may be looking for. One analyst describes this as less the sale of privacy itself by Google, but rather the sale of a "privacy derivative", where companies invest in Google's appraisal of customers' needs and wants.(See Karl T. Muth's Googlestroika: Privatizing Privacy for more on how Google monetizes user privacy).

So the first step in the transfer of wealth via Google is from users selling their privacy for too little and Google arbitraging user ignorance for profit. If Google had less dominance of the online advertising field, there would be far greater pressure for Google to develop as sophisticated a market for users to be compensated for their privacy as the markets in which it resells that lost privacy.

To get some sense of the value of user information, look at the recent controversy over another big Internet player, namely Apple, when it demanded that sellers of subscriptions to apps on the iPhone had to give Apple not just 30% of sales, but sole control of user information as well. Lauren Idvik at Mashable noted that publishers like the Financial Times may not have liked the 30% cut Apple wanted from subscriptions, but "the main problem is that Apple will not share subscriber data with publishers, long one of publishers' most valuable assets, particularly to advertisers." Think about it -- your personal data is worth potentially more than 30% of the cost of what you are purchasing and most users give it away for free to companies like Google and Apple.

And Google is looking to leverage its position at the nexus of the Internet to further expand its data collection of users -- and the opportunities for marketing that data in Internet commerce. Most recently, Google is making a play for inserting what's called NFC technology into every smartphone and turn them into wireless credit cards -- and a substitute for every other card you carry -- that would make all commerce easier for users, while giving Google information on every transaction you make and providing even more expanded data on user shopping habits. Google is marching from dominance over information about online commerce to trying to dominate information about offline shopping as well.

In part 2 of this series, I'll look at why this personal information is so valuable to advertisers and how it empowers what economists call "price discrimination" and just plain old racial discrimination. Part 3 will look at the role of Google in the subprime mortgage debacle and its aftermath, as well as the broader antitrust implications of the company's dominant role as an intermediary for behavioral targeting of consumers by advertisers.

Nathan Newman, a lawyer and Ph.D., has an extensive history of supporting local policy campaigns, from coalition organizing work to drafting legislation. Previously Executive Director of Progressive States, an Associate Counsel at the Brennan Center for Justice, Program Director of NetAction's Consumer Choice Campaign, and co-director of the UC-Berkeley Center for Community Economic Research, he has also been a labor and employment lawyer, freelance columnist and technology consultant. He received his J.D. from Yale Law School and his Ph.D. in Sociology from the University of California at Berkeley and has written extensively about public policy and the legal system in a range of academic and popular journals, including publishing a book, Net Loss: Internet Prophets, Private Profits and the Costs to Community, detailing the relationship between telecommunications public policy and local economic development. His writing and organizing has been cited in the New York Times, USA Today. San Jose Mercury News, Baltimore Sun, Wired, Village Voice, ZDNet, CNet News, San Francisco Chronicle, TheStreet.com, Chronicle of Higher Education, MIT’s Technology Review, The Nation and the American Prospect. He runs his own site at www.nathannewman.org and a technology policy site, www.tech-progress.org.

Tuesday, May 31, 2011

NYTimes: Breaches Lead to Push to Protect Medical Data

by Milt Freudenheim  •    NY Times    May 30, 2011

Federal health officials call it the Wall of Shame. It’s a government Web page that lists nearly 300 hospitals, doctors and insurance companies that have reported significant breaches of medical privacy in the last couple of years.

Such lapses, frightening to consumers, could impede the Obama administration’s effort to shift the nation to electronic health care records.

“People need to be assured that their health records are secure and private,” Kathleen Sebelius, secretary of health and human services, said in an interview by phone. “I feel equally strongly that conversion to electronic health records may be one of the most transformative issues in the delivery of health care, lowering medical errors, reducing costs and helping to improve the quality of outcomes.”

So the administration is making new efforts to enforce existing rules about medical privacy and security. But some health care experts wonder if the current rules are enough or whether stronger laws are needed, for example making it a crime for someone to use information obtained improperly.

“The consequences of breaches matter,” conceded Dr. Farzad Mostashari, a former New York public hospitals official who recently became the Obama administration’s national coordinator for health information technology. “People say they are afraid that if their private information becomes known, they may not be able to get health insurance.”

In the last two years, personal medical records of at least 7.8 million people have been improperly exposed, according to the government data. One particularly egregious case involved information about 1.7 million patients, staff members, contractors and suppliers of Bronx hospitals and clinics operated by the Health and Hospitals Corporation, the New York public health agency. Their electronic files were stolen from an unlocked van belonging to a record management company.

The affected patients got the disquieting news that their medical and personal information, like Social Security numbers, had been violated when their health care providers notified them under federal rules.

Showing just how lax security can be, the inspector general of the Department of Health and Human Services said two weeks ago that the agency had found dozens of vulnerabilities in systems to protect records of patients at seven large hospitals in New York, California, Illinois, Texas, Massachusetts, Georgia and Missouri. Auditors cited such problems as personal information that was not encrypted and was stored on computers that could be easily used by unauthorized users.

Auditing teams are now inspecting eight more hospitals, said Lori Pilcher, an assistant inspector general at Health and Human Services. The hospitals are not being identified to avoid alerting hackers, she said.

Another big breach was reported in March on the official Web site by Health Net, a California-based insurance company, which notified 1.9 million health plan members that records with their personal information were missing.
Health Net said I.B.M., which was managing its information system, told the insurer that the records could not be found.

“The health care industry is not as vigilant as they should be about protecting private information in a patient’s medical records,” said Representative Joe L. Barton, a Texas Republican who is co-chairman of the Bipartisan Privacy Caucus in the House.

Mr. Barton knows from personal experience. His own records after a heart attack, along with several thousand others from a research project at the National Institutes of Health, were “on a disk in a laptop in somebody’s trunk that disappeared,” he recalled. “I was stunned.”

The Obama administration has levied a string of stringent penalties for egregious violations of patient rights under the most commonly cited law, the Health Insurance Portability and Accountability Act, or HIPAA, of 1996. Health information is supposed to stay private under those rules, but research has shown that it is not that difficult to connect names and addresses to nominally anonymous data with Internet searches and computerized matchups.

The Office of Civil Rights at Health and Human Services, which took over enforcement of the law, imposed a $1 million fine on Massachusetts General Hospital in March after a hospital employee left paper records of 192 patients on a Boston subway train. The hospital agreed in a settlement, without admitting wrongdoing, to report twice a year on its efforts to tighten patient protections.

Earlier this year, the civil rights office fined a Maryland health plan, Cignet Health, $4.3 million, saying that it had denied patients the right to see their own records in violation of HIPAA provisions. It was the first civil penalty levied under the HIPAA law. “We have ramped up our enforcement,” said Georgina C. Verdugo, director of the civil rights office.

But Dr. David Brailer, a Bush appointee as the first national coordinator of health information technology, is skeptical about whether such efforts will curb security breaches. “We can’t just lock health care data away — because of its role in lifesaving treatment,” Dr. Brailer said.
He said that even with the best technology it would be hard to make health systems secure. “It’s a huge challenge. Break-ins and hacks are unfortunately going to be part of the landscape,” he said.

One protection, he suggested, would be laws to make it illegal for an insurer or employer to discriminate against a person based on information about health conditions like H.I.V./AIDS, cancer and mental health problems.

As a model, he pointed to the antidiscrimination law to prevent the misuse of genetic information that was passed with bipartisan support in the Bush administration. He also said he believed the laws should say “patients own the data, period, and decide what happens to it. The patient should be able to say to Hospital X: ‘send my data to Hospital Y because I’m changing hospitals,’ “ he said.

Today, the information belongs to whoever possesses it, under ideas inherited from 17th-century English common law, he said. “If it gets into your database, essentially you own it,” he added, “and you can pass it on.”

“Today HIPAA makes no sense,” Dr. Brailer added. “The law didn’t anticipate a world where your data passes through many, many hands.”

Wes Rishel, a longtime health care analyst for Gartner, the technology consulting firm, and an adviser to the national coordinator’s office, has a similar view. “Your ability to control access to your information is a horse that is already out of the stable,” he said. “What is really needed is legislation that controls use of it.”

On that score, researchers at Carnegie Mellon University have shown that at least 30 people and organizations have access to the health data of a typical person with private insurance through an employer. They range from pharmacies and drug companies to an employer’s wellness programs and a spouse’s self-insured employer.

“Only you, your doctor and hundreds of others know,” said Latanya Sweeney, a health privacy expert at Harvard and Carnegie Mellon who is also an adviser to the office headed by Dr. Mostashari.

Since HIPAA was enacted there has been “an explosion in data sharing,” Ms. Sweeney said. “And after electronic records are widely adopted, there will be another big explosion.”

Friday, May 13, 2011

Can the U.S. Get Its Act Together?

After years of ignoring the issue, Washington is full of ideas on how to protect privacy

By Sara Forden, Businessweek, May 12, 2011

On May 10 executives from Google (GOOG) and Apple (AAPL) participated in the time-tested Washington ritual of a congressional grilling. Alarmed by revelations that smartphones store data on users' locations, legislators demanded details on the companies' privacy policies. "Consumers have a fundamental right to know what data is being collected about them," said Minnesota Democrat Al Franken, who called the hearing. "They have a right to decide whether they want to share that information, with whom they want to share it, and when."

Alan Davidson, Google's director of public policy, and Apple's vice-president for software technology, Bud Tribble, defended their employers' handling of user-location information and said the companies do not track individual customers.

Lawmakers are trying to determine what new rules are needed in the era of 24/7 connectivity. "The flash point is the mobile device," says Jeff Chester, executive director of the Washington-based Center for Digital Democracy. "The ability to combine one's behavior with one's location is about to create a political firestorm."

A series of high-profile data-security breaches have heightened concern about privacy. Sony (SNE) shut down its PlayStation Network last month after its online entertainment and game systems were hacked, compromising some 100 million personal accounts. JPMorgan Chase (JPM), Best Buy (BBY), and Target (TGT), along with some 17 other companies, disclosed last month that customers' e-mail addresses were exposed after cyber thieves hacked into databases at Alliance Data System's (ADS) Epsilon Data Management. "The recent spate of security breaches is off the charts," says Marc Rotenberg, executive director of the Electronic Privacy Information Center (EPIC).

A consensus has formed in Washington that the patchwork of federal and state privacy laws has not kept pace with the development of the Internet. The U.S. lags Europe, where broad safeguards of personal digital information have been in place since 1995.

One proposal by Senator Jay Rockefeller (D-W. Va.) would create a "do not track" mechanism, similar to the "do not call" list that freed U.S. households from the tyranny of telemarketers. Under the Rockefeller bill, consumers could elect whether to have their browsing data collected.

Such proposals may indicate that the era of the freewheeling Web is drawing to a close. "The original policy was to treat the Internet like a hothouse flower that had to be protected," says Cameron F. Kerry, general counsel to the Commerce Dept. The agency is now calling for a Consumer Bill of Rights that would establish baseline privacy practices and bring the U.S. more in line with Europe. At present, European companies can't send personal data to countries that lack equivalent levels of protection.

At the Federal Trade Commission, Chairman Jon Leibowitz has made privacy a priority. The agency issued a report in December calling for a "do not track" mechanism. The report also pressed companies to make their data policies easy for consumers to understand. "Privacy policies don't translate well to smartphones," says David Vladeck, head of the FTC's Bureau of Consumer Protection. "They are already hard to read on the Internet, but if you are in the car in the middle of Nebraska Avenue, it can be even harder."

In the wake of the FTC report, Microsoft (MSFT), Mozilla, and Google all incorporated tracking-protection features into the latest versions of their browsers. The Digital Advertising Alliance, a coalition of trade associations, in October introduced an opt-out button that allows consumers to indicate they don't want their online behavior collected. Google in March also unveiled a tool that lets users block unwanted websites.

Although some technology companies have taken action in hopes of forestalling additional regulation, it's unlikely that the industry on its own can agree on adequate policies that balance privacy and profits. Spending on online advertising is projected to almost double to $44 billion in 2016, from $26 billion last year, according to Alex Feldman, manager of global forecasting at MagnaGlobal (IPG), a media researcher. Mobile advertising revenue is projected to grow more than fourfold, to $1.8 billion by 2016, while the value of online video advertising could nearly triple, to $3.7 billion, over the same period, according to Feldman.

In several instances, the FTC has acted to curb what it considers unfair and deceptive practices. The agency reached a settlement with Google in March related to privacy breaches associated with the introduction of its Buzz social networking service last year. The 20-year agreement, hailed as a landmark by industry watchers, bars Google from misrepresenting how it handles information, obliges the company to protect consumer data in new products, and requires periodic government reviews. Also in March, the agency forged a similar settlement with Twitter after hackers obtained control of the Internet messaging service.

As a whole, a new federal privacy law should come down to a simple proposition, says EPIC's Rotenberg: "If you can't protect it, you shouldn't collect it."

The bottom line: A spate of high-profile data security breaches may finally compel Washington to draft a comprehensive privacy policy.

With Eric Engleman, Adam Satariano, and Stephanie Bodoni. Forden is a reporter for Bloomberg News.

Saturday, April 30, 2011

Data Privacy, Put to the Test

BIG Oil. Big Food. Big Pharma.

By Natasha Singer, NYTimes, April 30, 2011

To the catalog of corporate "bigs" that worry a lot of us little people, add this: Big Data. It was not a good week for those who guard their privacy. First, we learned that Apple and Google have been using our smartphones to collect location data. Then Sony acknowledged that its PlayStation network had been hacked — the latest in a string of troubling data breaches. You'd have to be living off the grid not to realize that just about everything there is to know about you — what you buy, where you go — is worth something to someone. And the more we live online, the more companies learn about us.

But to what extent do others have a right to share and sell that information? That is the crux of a data-mining case that had arguments last Tuesday before the Supreme Court. The case, Sorrell v. IMS Health, is ostensibly about medical privacy: Vermont passed a law in 2007 that lets each doctor decide whether pharmacies can, for marketing purposes, sell prescription records linking him or her by name to the kinds and amounts of drugs prescribed. State legislators passed the law after the Vermont Medical Society said that such marketing intruded on doctors and could exert too much influence on prescriptions.

But three health information firms, including IMS Health and Verispan, along with a pharmaceutical industry trade group, challenged the law, saying it restricted commercial free speech. Access to prescription records, IMS Health says, helps pharmaceutical companies market efficiently to doctors whose patients would most benefit from specific drugs. Now the justices are to decide whether the Vermont law is constitutional.

But with the recent headlines about privacy invasion — the PlayStation hack followed a recent breach at the online marketing company Epsilon that exposed e-mail addresses of customers of Citibank, Walgreens, Target and other companies — the Vermont case is tapping into a much broader conversation about consumer protection and informed consent.

The case raises questions about who is collecting, managing, storing, sharing and selling all that data. Just as important, privacy advocates say, it raises questions about whether data brokers are adequately safeguarding it.

People generally don't have much control over who collects and sells information about them. Moreover, says Christopher Calabrese, a legislative counsel at the American Civil Liberties Union, they also don't even know the names of the data brokers who compile those electronic profiles. And, so, consumer advocates are setting their sights on Big Data.

"Without government intervention, we may soon find the Internet has been transformed from a library and playground to a fishbowl," Mr. Calabrese testified in March during a Senate hearing on consumer privacy, "and that we have unwittingly ceded core values of privacy and autonomy."

There are a few laws, like the Video Privacy Protection Act, that prohibit businesses from releasing personally identifiable records, like video rental histories, without customer consent. The Digital Advertising Alliance, a coalition of online marketing groups, introduced a program last year that notifies consumers about online tracking and allows them to opt out of advertising tailored to them. The Vermont law amounts to a kind of do-not-call option for doctors who may welcome visits from pharmaceutical sales reps but don't want drug marketing based on their own prescription records.

That marketing practice is possible because pharmacies, which are required by law to collect detailed information about prescriptions they fill, can sell doctor-specific prescription records to data brokers. (According to federal privacy regulations, personal information about patients, like names and addresses, must be removed before the records can be sold for marketing.) Firms like IMS Health then combine the records, and pharmaceutical reps often use them to tailor presentations to individual doctors.

The central concern is privacy — of both doctors and their patients. While pharmacies remove the names of patients before selling the records, those names are replaced with unique codes that track patients over time from doctor to doctor, according to the Vermont complaint. That means data firms could create a profile that includes a person's prescriptions as well as the names of the pharmacies and dates at which the person picked up the medications, says Latanya Sweeney, a visiting professor of computer science at Harvard.

"It ends up building a detailed prescription profile of individuals," says Professor Sweeney, whose research on data re-identification was cited by several briefs in the case. "Those extended profiles tend to be very unique."

The concern, she says, particularly in a small state like Vermont, is that a nameless prescription record could theoretically be enough to identify someone who might not want others to know that he takes, say, anti-depressants. Moreover, Professor Sweeney argues, data miners could collate those files with public information, like voter registration and hospital discharge records, to link prescriptions to specific people.

Federal health privacy regulation, she says, does not protect patient records once they have been de-identified. Nor does the law prohibit re-identification. But IMS Health says it isn't aware of any case of re-identifying patients whose prescription records were de-identified in accordance with federal rules. The company says it doubly encrypts each patient's identity and gives the encryption keys to several third parties — meaning that no single entity can decode a file by itself, says Kimberly Gray, chief privacy officer at IMS Health.

The company typically sells combined reports that show how many patients received a certain drug from a certain doctor, but not the specific drugstores those patients frequent, Ms. Gray says. IMS never uses public information or outside data sets to try to re-identify patients, she says, and when it does provide encoded patient histories to others for research purposes, it prohibits those third parties from making such attempts. "We would never want to re-identify someone," Ms. Gray says. "No good can come from that."

Still, it is hard to prevent people from trying to re-identify patients, says Lee Tien, a staff lawyer at the Electronic Frontier Foundation, a digital civil liberties group that filed a brief in support of Vermont. It would be easier, he says, if Congress passed a law that went further than Vermont's, giving people the right to consent before their encrypted prescription records were sold for marketing purposes. "In Vermont, the doctor can decide," Mr. Tien says. "But we'd prefer it if the patient were able to say, 'Don't sell my data.' " 

Wednesday, April 27, 2011

"Data trading is the new information economy"

Welcome to the age of data
By: Molly Wood, CNET, April 25, 2011
 In Daniel Suarez's book "Freedom," he describes a world in which members of a revolutionary "darknet" use glasses with heads-up displays to literally visualize the publicly available information about every person on earth.

It floats above them as a callout: Social Security numbers, bank balances, cell phone numbers, addresses, purchasing history, baby pictures, social network posts. That data is visible by anyone with the means to harvest it, and it can be manipulated at will by malicious hackers (like Loki, the Suarez character who "data curse" on someone who annoys him), by governments, and by companies.


Hopefully, you've all realized that Suarez's vision is hardly one of the future: it's a vision of the present. Welcome to the age of data. It's time to get control of your assets.
Caption: Yeah, dude. They're watching you.

Yeah, dude. They're watching you.
This week's iPhone location tracking scandal is just the latest glaring spotlight on how much of your personal information is gushing out the door, whether unprotected on your own devices and ripe for the picking, or into corporate and botnet servers worldwide. And despite reports of a Steve Jobs e-mail declaring that Apple doesn't track anyone, Apple's general counsel told a congressional inquiry in June 2010 that "(t)o provide the high-quality products and services that its customers demand, Apple must have access to the comprehensive location-based information."
Apple is hardly alone in demanding this level of comprehensive personal information. The iOS location-tracking revelations come on the heels of a federal investigation into mobile application data sharing. Investigators charge that seemingly harmless apps like Pandora are, while they're streaming you highly customized media, are also sending "age, gender, location and phone identifiers to various ad networks," according to the Wall Street Journal. The Journal report found that the majority of the 101 apps it tested sent some personal information to a third-party data broker, largely without your knowledge.


Subsequent investigations found that most Android phones transmit some user information, including location data, back to the mother ship, as well, with Google saying only that the data wasn't "traceable to a specific user." (The merits of that argument are up for debate, to say the least.) Even Microsoft is gathering location data on Windows phones.

Sadly, this informational espionage should hardly come as a surprise.
Caption: The iPhone 4: talk about a Trojan Horse.
The iPhone 4: talk about a Trojan Horse.
(Credit: EMMANUEL DUNAND/AFP/Getty Images)
The new cost of "free"
Personal information is the currency of the post-technological age, and the cost of "free" has never been higher. Your data, on an increasingly minute and personal level, powers every Web or network-based company, from start-up to monolith.
Google maintains literally acres of servers dedicated to storing your communications--from e-mail to texts to the transcripts of your voice mail; your browsing and shopping habits; your blog posts; your photos; your calendar appointments; and of course, your intensely personal search histories. If you're logged in to a Google service, that information is all tied to your IP address. Only the thinnest of artificial technical barriers--a sort of loose privacy honor system--keeps Google from combining the data into a scarily accurate digital version of you (like the first digital Cylon, if you will).
But pity poor Google, which must gather all this information by increasingly intrusive means, like the DoubleClick ad cookie that tracks your browsing all across the Web, surreptitious Wi-Fi sniffing, and sending location information about you back to its data centers even when you're not running location apps.

On the other side of the aisle lies Facebook, which has cleverly cajoled 500 million users (and growing) into giving up virtually all the same information for free. Profiles, Places, Deals, and of course, the ever-present Like button, which lets you easily record your preferences for everything from opinions to shoes to celebrities and bands...you can almost imagine Facebook whispering a little "thank you" every time you click that little blue button.

Want to understand why Google is so desperate to get into social that it's tied part of every employee's bonus to the success or failure of that strategy in 2011? It has nothing to do with helping you share your photos and restaurant check-ins, and everything to do with data collection--and data connections.
Caption: Connected, we stand.
Connected, we stand.
(Credit: Google)
The real magic of the new world of data collection is far more than just hoovering up reams of anonymous or semi-anonymous information. The real magic is in using that data to draw connections between action and reaction, consideration and purchase, brand and affinity, and to sip from the holiest of all commerce grails: recommendation.

The Web as real-time recommendation engine is the ultimate goal of initiatives ranging from the Amazon recommendation queue to Netflix's $1 million prize to the team who improved its recommendation algorithm by 10 percent or more to Facebook's original Beacon program.
Foursquare is working hard to integrate recommendations into its check-in service; Yahoo just spent a reported $20 million to $30 million on a TV check-in and recommendation service called IntoNow that's just 12 weeks old. It's a pretty simple equation: if they can figure out what you like, they can sell you more of what you like.

And the key to recommendation is scale. You can't do the math until you aggregate as many likes, dislikes, check-ins, one, two, and four stars as possible. All of these services depend, first and foremost, on you providing the data for them to crunch. And thanks to your life online, and, increasingly, the phone in your pocket, that data is as ever-present as the air we breathe.

Who's buying?
See, but Google, Facebook, and Apple are the companies we "trust," like we trusted that Pandora was just delivering great '80s tunes on my now-dusty Bon Jovi station. So, where's all our information going? To a silent but deadly collection of data brokers, marketers, and data aggregation services.

These ranks include Epsilon, recently the subject of what Computer World called "the hack of the century." No one knows how many e-mail addresses were exposed in the Epsilon breach, or the full scope of what else may have been revealed, but it has more than 2,000 clients and handles 40 billion e-mails a year. Its database of active shoppers (which included those who opted out but were retained in the database, if not actively emailed) was a gold mine for hackers and spear phishers, and there are 25 more companies where they came from--and that's just email marketing. Merlin Information Services: for all your massive personal information database needs
What should you do?
What can you do? The short answer is, not a lot. Sure, you can go opt out of every data broker on the list, you can stay off the grid, you can give false names and live on cash. But the real question is: do you need to? Or, should we accept that we're in the age of data and embrace--nay, demand--that the data transparency go both ways?

Take the time to own your own data and clear the Web of any information you'd rather not be out there--you can at least try to opt out of sites like Spokeo and other aggregators, if only to protect the most sensitive information. And you don't have to trust the cloud. Ironically, despite its aggregation of information at a scale that would make Skynet envious, Google has engineers in-house who've created the Data Liberation Front, which lets you freely export your own information from the big G. Facebook lets you download everything you've ever posted (surprising, right?).

If you just want to back up and retain your data, services like Backupify index your cloud data and back it up, while Greplin lets you index the cloud services and search them, too (yes, I'm aware that both sites may engage in the same kind of ad targeting or data brokering I'm complaining about: read your terms of service, folks!).

And hey, as long as start-ups are making money brokering data, I'd like to see one that lets you see, say, your Data Score. If Greplin or Backupify can index your cloud information, why can't a company index it and parse it? A Data Score could tell you how risky your overshares are: does it make you unemployable, or just questionable? It could tell you what data is unintentionally public, like the cell phone number you thought you were hiding behind Facebook's byzantine wall of privacy settings. It could even perform a TurboTax like audit, and warn you when publicly available information about you might lead to easy identity theft or obvious phishing attempts.

The best disaster mitigation is preparedness. At some point, data trading is the new information economy, our privacy expectations will adjust accordingly, and yes, there are benefits. But we shouldn't stumble blindly into it--we ought to at least be willing and informed partners in managing our digital identities. Then we can click the ad for those perfect nude pumps in relative peace. After all, they do go with everything.

Monday, April 18, 2011

What's next for privacy on the Hill?

By Hayley Tsukayama  Wash Post   4/15/2011
http://www.washingtonpost.com/blogs/post


New bills and discussion about the recent Epsilon data breach have made privacy a popular talking point on the Hill. But a lot of politics stands between the talk and actual movement on legislation.

Four major privacy proposals have been floated on the Hill this session. In February, Reps. Bobby Rush (D-Ill.) and Jackie Speier (D-Calif.) each introduced privacy legislation. Earlier this week, Sens. John Kerry (D-Mass.) and John McCain (R-Ariz.) and Reps. Cliff Stearns (R-Fla.) and Jim Matheson (D-Utah) offered privacy bills for each chamber.

The privacy bills have some key differences. Stearns’s bill promotes industry self-regulation and requires companies to notify consumers about privacy policies and data use. The bill from Kerry and McCain encourages self-regulation but also requires an opt-in measure to share sensitive personal information, or information that could harm a person if released, depending on the situation.

Rush’s reintroduced bill requires companies to provide an opt-out option before they can share data with other companies. Speier’s privacy package includes the only proposed legislation with a do-not-track measure; the other bill is aimed at protecting financial information.

Having bipartisan bills in the House and Senate is a key step forward, said Justin Brookman, a privacy expert from the Center for Democracy and Technology. That at least gives this week’s bills a chance to move along, he said.

Even that, though, might not be enough. “Both bills have an overwhelming amount of momentum, but my enthusiasm is tempered by the calendar, given the looming election season,” said Amy Mushahwar, a lawyer and privacy expert at Reed Smith law firm.

Staffers for Kerry and Rush have said both offices are trying to schedule privacy hearings. A person in Kerry’s office said that they are trying to schedule a hearing on the consumer privacy act as soon as possible, likely after the April recess.

“I think we’ll see action in the Senate sooner,” Brookman said, as the House’s new Republican majority hasn’t had as much time to work on privacy issues.

There are a lot of players in this debate. In the Senate, privacy issues have traditionally been the jurisdiction of the Senate Commerce, Science and Transportation committee. But in February, Sen. Al Franken (D-Minn.) was tapped to lead the chamber’s new Judiciary subcommittee on privacy, adding more voices to the mix.

And with two bills already proposed in the House, Rep. Mary Bono Mack (R-Calif.), who chairs the subcommittee with jurisdiction over consumer privacy issues, has also highlighted privacy issues as main concern.

Stearns has said he will work closely with Mack, but that the Kerry/McCain bill should not be viewed as a companion to his bill.

“I believe that our approach of greater consumer notice and choice balances the needs of privacy and innovation,” Stearns said in a statement. “Our bill provides the necessary flexibility and avoids one size fits all regulations and unnecessary government intervention.”

With all the high-minded, conceptual talk about privacy, Mushahwar said that it’s also important to concentrate on basic definitions in the bills, and not lose sight of how companies can actually apply the language to their own business practices.

“These bills have to be implemented by data centers and require a practical mindset,” she said.

Wednesday, April 13, 2011

Brookings Paper on Privacy

Databuse: Digital Privacy and the Mosaic
by Benjamin Wittes Senior Fellow, Governance Studies The Brookings Institution   •  April, 2011

Introduction

The question of privacy lies at, or just beneath, the surface of a huge range of contemporary policy disputes. It binds together the American debates over such disparate issues as counter-terrorism and surveillance, online pornography, abortion, and targeted advertising. It captures something deep that a free society necessarily values in our individual relations with the state, with companies, and with one another. And yet we see a strange frustration emerging in our debates over privacy, one in which we fret simultaneously that we have too much of it and too little.

This tendency is most pronounced in the counter-terrorism arena, where we routinely both demand—with no apparent irony—both that authorities do a better job of “connecting the dots” and worry about the privacy impact of data-mining and collection programs designed to connect those dots.

The New Republic on its cover recently declared 2010 “The Year We Were Exposed” and published an article by Jeffrey Rosen subtitled “Why Privacy Always Loses.”[1] By contrast, in a book published earlier in 2010, former Department of Homeland Security policy chief Stewart Baker described privacy concerns as debilitating counter-terrorism efforts across a range of areas:

Even after 9/11, privacy campaigners tried to rebuild the wall [between intelligence and law enforcement] and to keep DHS from using [airline] reservation data effectively. They failed; too much blood had been spilled. But in the fields where disaster has not yet struck—computer security and biotechnology—privacy groups have blocked the government from taking even modest steps to head off danger.[2]

Both of these theses cannot be true. Privacy cannot at once be always losing—a value so at risk that it requires, for so Rosen contends, “a genuinely independent [government] institution” dedicated to its protection—and be simultaneously impeding the government from taking even “modest steps” to prevent catastrophes.

Unless, that is, our concept of privacy is so muddled, so situational, and so in flux, that we are not quite sure any more what it is or how much of it we really want.

In this paper, I explore the possibility that technology’s advance and the proliferation of personal data in the hands of third parties has left us with a conceptually outmoded debate, whose reliance on the concept of privacy does not usefully guide the public policy questions we face. And I propose a different vocabulary for that debate—a concept I call “databuse.” When I say here that privacy has become obsolete, to be clear, I do not mean this in the crude sense that we have as a society abandoned privacy in the way that, say, we have abandoned once-held moral anxieties about lending money for interest. Nor do I mean that we have moved beyond privacy in the sense that we moved beyond the need for a constitutional protection against the peacetime quartering of soldiers in private houses without the owner’s consent.[3] Privacy still represents a deep value in our society and in any society committed to liberalism.

Rather, I mean to propose something more precise, and more subtle: that the concept of privacy as we have traditionally understood it in law no longer describes well or completely the actual value at stake in the set of issues we continue to argue in privacy’s name. The notion of privacy was always vague and hard to pin down as an operational matter in law. But this problem has grown dramatically worse as a result of the proliferation of data about all of us and the ability to analyze and cross-reference that data systematically and instantly. To put the matter bluntly, the concept of privacy will no longer bear the weight we are placing upon it. And because the term covers such a huge range of ground, its imprecision with respect to these new problems creates great indeterminacy as to what the value we are trying to protect really is, whether it is gaining or losing ground, and whether that is a good thing or a bad.

In this paper, I examine privacy’s conceptual obsolescence with respect only to a single area, albeit one that is by itself hopelessly sprawling: data about individuals held in the hands of third parties. Our lives, as I have elsewhere argued, are described by a mosaic of such data—an ever-widening array of digital fingerprints reflecting nearly all of life’s many aspects. Our mosaics record our transactions, our media consumption, our locations and travel, our communications, and our relationships. They are, quite simply, a detailed portrait of our lives—vastly more revealing than the contents of our underwear drawers yet protected by a weird and incoherent patchwork of laws that reflect no coherent value system.[4]

We tend to discuss policy issues concerning control over our mosaics in the language of privacy for the simple reason that privacy represents the closest value liberalism has yet articulated to the one we instinctively wish in this context both to protect and to balance against other goods—goods such as commerce, security, and the free exchange of information. And there is no doubt an intuitive logic to the use of the term in this context. If one imagines, for example, the malicious deployment of all of the government’s authorities to collect the components of a person’s mosaic and then the use of those components against that person, one is imagining a police state no less than if one imagines an unrestricted power to raid people’s homes. If one imagines the unrestricted commerce in personal information about people’s habits, tastes, and behaviors—innocent and deviant alike—one is imagining an invasion of personal space as destructive of a person's privacy as the breaking into that person's home and the selling of all the personal information one can pilfer there.

Yet the construction of these issues as principally implicating privacy is not inevitable; indeed, privacy itself is not inevitable as a legal matter. It was, as I shall argue, created in response to the obsolescence of previous legal constructions designed to shield individuals from government and one another, and it was created because technological developments made those earlier constructions inadequate to describe the violations people were feeling. Ironically, today it is privacy itself that no longer adequately describes the violations people are feeling with respect to the mosaic—and it describes those violations less and less well as time goes on. Much of the material that makes up the mosaic, after all, involves records of events that take place in public, not in private; driving through a toll booth or shopping at a store, for example, are not exactly private acts.

Most mosaic data is sensitive only in aggregation; it is often trivial in and of itself—and we consequently think little of giving it, or the rights to use it, away. Indeed, mosaic data by its nature is material we have disclosed to others, often in exchange for some benefit, and often with the understanding, implicit or explicit, that it would be aggregated and mined for what it might say about us. It takes a feat of intellectual jujitsu to construct a cognizable and actionable set of privacy interests out of the amalgamation of public activities which one transacted knowingly with a stranger in exchange for a benefit. The term privacy has become a crutch—a description of many different values of quite-different weights—that does not usefully describe the harms we fear.

The more sophisticated privacy scholars and advocates appreciate this. In his exhaustive effort to create a “Taxonomy of Privacy,” Daniel Solove argues up front that “The concept of ‘privacy’ is far too vague to guide adjudication and lawmaking”[5] and that “it is too complicated a concept to be boiled down to a single essence.” Rather, he treats privacy as “an umbrella term, referring to a wide and disparate group of related things.”[6] Just how wide becomes clear over the course of his 84-page article. His taxonomy contains four principal parts, each consisting of multiple subparts—creating, all in all, a 16-part typology that ranges from blackmail to data “aggregation” and “decisional interference.” And he concedes in the end that although all of the privacy harms he identifies “are related in some way, they are not related in the same way—there is no common denominator that links them all.”[7] Solove’s heroic effort to salvage privacy’s coherence through comprehensive cataloguing has the unintended effect of revealing its unsalvagability.

My purpose here is to propose a different vocabulary for discussing the mosaic—in some ways a simpler, cruder one, but one that both more accurately describes than privacy our behavior with respect to the mosaic and that offers more useful guidance than the concept of privacy does as to what activities we should and should not tolerate. The relevant concept is not, in my judgment, protecting some elusive positive right of user privacy but, rather, protecting a negative right—a right against the unjustified deployment of user data in a fashion adverse to the user's interests, a right, we might say, against databuse.

 The databuse conception of the user’s equity in the mosaic is more modest than privacy. It doesn’t ask to be “let alone.” It asks, rather, for a certain protection against tangible harms as a result of a user’s having entrusted elements of his or her mosai c to a third party. Sometimes, to be sure, these tangible harms will implicate privacy as traditionally understood, but sometimes, as I will explain, they will not. Think of it as a right to not have your data rise up and attack you.

Thinking about mosaic questions we currently debate in the language of privacy in terms of databuse has a clarifying effect on a number of contemporary public policy disputes. In some cases, it will tend to suggest policy outcomes roughly congruent with those suggested by a more conventional privacy analysis. In other cases, by contrast, it suggests both more and less aggressive policy interventions and market developments on behalf of users. In some areas, it argues for a complacent attitude towards data uses and acquisitions that have traditionally drawn the skeptical eye of privacy activists. Yet it also suggests more intense focus on a subset of privacy issues that are currently under-emphasized in privacy debates—specifically, issues that genuinely implicate personal security.

Full paper at http://www.brookings.edu/papers/2011/0401_databuse_wittes.aspx