Showing posts with label Medical Privacy. Show all posts
Showing posts with label Medical Privacy. Show all posts

Wednesday, June 6, 2012

Health Data Map (Latanya Sweeney) Launched

As Health Records Go Digital, Where They End Up Might Surprise You

Jordan Robertson, Data Privacy Lab, Harvard University, June 5, 2012 8:08 

From Latanya Sweeney, Data Privacy Lab, Harvard University, 2010
A graphic depicting the sharing of a person's health data.

Two years ago, Latanya Sweeney created a graphic on the widespread sharing of medical files that shocked lawmakers, technologists and doctors.

Sweeney, who founded the Data Privacy Lab at Harvard University, produced a “health data map” that looks like a windshield cracked by a few big rocks. At the center is someone’s health record, medical provider and insurance company. Emanating from them are webs of more than two dozen organizations that could have legitimate access to the file, including transcription services, medical researchers, and even data-mining firms and pharmaceutical companies.

“Collectively, you’d hear a gasp and then a moment of silence — that was pretty universal,” she said, describing the reaction during her congressional testimony and presentations to privacy summits, academic conferences and medical schools.

However, Sweeney said there are limitations in tracking the movement of medical data, and many doctors are in the dark about where their patients’ data go. So at the Health Privacy Summit in Washington, D.C., which starts Wednesday, she plans to unveil a new project to harness the collective knowledge of doctors, data-breach victims, whistle-blowers, technology specialists and others to build a new, more comprehensive health data map.

“If we can get a lot of people to march in this direction and keep them there and entertained and incentivized, I think what we’ll uncover will be mind-blowing,” said Sweeney, who is a computer scientist.

Her project comes amid a U.S. push to digitize patient records, which has created lifesaving benefits but has also made it easier for medical files to end up in unexpected places. As I reported last month in a special report for Bloomberg.com, loopholes in the federal law have allowed the collection and sharing of private medical information without patients’ consent.

Sweeney’s work has focused on identifying those unexpected places and on showing that it’s possible to determine some people’s identities from medical data, even after the records have been stripped of personal information. Adding to the alarm, she said the number of third-party entities receiving medical data has more than doubled in the past decade, and some firms that once received only “anonymized” data now get records that identify people.

While Sweeney’s earlier mapping effort drew on her experience as a legal expert and her work with the privacy center, her new project, thedatamap.org, needs submissions from others to help sketch a more complete picture of how medical data are shared.

At first, she’s seeking submissions of Internet links that show data-sharing relationships between medical providers and others. People will sign up with an e-mail address to be “data detectives,” and the accuracy of their submissions will be checked by other people who have signed up to submit links. Eventually, the map could include information from other sources.

Deborah Peel, a physician and founder of Patient Privacy Rights, the Austin, Texas-based group putting on the conference, said a promising aspect of Sweeney’s project is its open nature, which will help ensure accuracy by allowing organizations that are mentioned on the map to respond.

“There’s some self-regulation there — we’re pretty hopeful that if somebody says something wrong about a hospital or a corporation, that they’d respond and provide the right information,” Peel said.  “It’s kind of ridiculous we’re forced to resort to this because there’s no chain of custody for our data.”

Even if the project gets little public input, the research can still be used to pressure lawmakers into mandating that data-sharing arrangements become more transparent, Peel said.

Sweeney said a goal of the research is to identify areas where patient data might be vulnerable to theft or abuse. It’s not to prevent the sharing of medical data entirely, she said.
“Because you don’t know where your data is going, harms are almost impossible to report and detect,” she said. “We don’t want to stop data sharing. There are a lot of uses and benefits that come from it. But how do we do it in a responsible way? As long as the data sharing is invisible, you can’t possibly do that.”

Monday, January 23, 2012

Unique ID Debate at WSJ

Should Every Patient Have a Unique ID Number for All Medical Records?
The WSJ Debate

·       Yes: It means better care, says Michael F. Collins.
·       No: Privacy would suffer, says Deborah C. Peel.
·       Read the complete Big Issues: Health Care report .

As the U.S. invests billions of dollars to convert from paper-based medical records to electronic ones, has the time come to offer everyone a unique health-care identification number?

Proponents say universal patient identifiers, or UPIs, deserve a serious look because they are the most efficient way to connect patients to their medical data. They say UPIs not only facilitate information sharing among doctors and guard against needless medical errors, but may also offer a safety advantage in that health records would never again need to be stored alongside financial data like Social Security numbers. UPIs, they say, would both improve care and lower costs.

Privacy activists aren't buying it. They say that information from medical records already is routinely collected and sold for commercial gain without patient consent and that a health-care ID system would only encourage more of the same. The result, they say, will be more patients losing trust in the system and hiding things from their doctors, resulting in a deterioration in care. They agree that it's crucial to move medical records into the digital age. But they say it can be done without resorting to universal health IDs.

Yes: It Means Better Care
By Michael F. Collins
The U.S. health-care industry has an identity crisis.

Lacking an easy, uniform way to identify patients and link them to their health data, doctors, hospitals, pharmacies, insurance plans and others throughout health care have created a sea of unrelated patient-identity numbers that are bogging down our medical-records system.

'An ID system 'could be the safest and most efficient way to manage health-care data.' -- MICHAEL F. COLLINS

Indeed, in an age when it's possible to pay for a cup of coffee using a cellphone, transferring a single patient's medical data from one health provider to another is often a struggle, sometimes resulting in treatment delays and even needless medical errors.

That is why, as the nation invests billions of dollars to convert from paper-based medical records to an electronic system, the time has come to offer everyone a universal patient identifier, or UPI.

A UPI system, using one number that seamlessly connects a person to all of his or her records, could be the safest and most efficient way to manage health-care data. It would guard against misidentification and make it much easier to pull together a patient's records from disparate providers. Using today's best technologies and practices, UPIs could help dramatically improve the quality of health care, lower costs, accelerate medical discovery and better preserve privacy.

That last point is by far the most contentious. It was privacy advocates who stopped the move toward UPIs more than a decade ago, leading to a ban on the use of federal funds just to study this approach. Enough has changed that UPIs deserve another look.

Cases of Mistaken Identity
In the 2010 federal health-care law, substantial resources are dedicated to promoting technology in medicine. We are investing billions of dollars to convert from paper to electronic health records, and to connect health-information hubs across the nation.

UPIs could make such systems more efficient. Currently, health-care providers and administrators struggle daily to match patients to records organized by disparate systems that rely on names, addresses, birth dates and sometimes Social Security numbers. Names can be presented in numerous formats, leading to duplicative records that cost money and lead to errors. As our population grows, the number of people with the same name and other similar personal data multiplies. Research cited by RAND Corp. indicates patients are misidentified at a rate of about 7% to more than 10% during record searches. As databases grow, the problem will only worsen. UPIs can correct this situation.

What about data security? It is difficult—especially without being able to study UPIs—to know what the safest approach is. Admittedly, no IT system is immune to breaches.
That said, patients with UPIs hold a distinct and important advantage in that their medical information is compiled and stored according to that unique identifier, separate from financial data typically coveted by thieves. UPIs can even be set up so that patients could choose to have no identifying data in their record, making it completely anonymous UPIs can be created with built-in checks against typing errors and counterfeiting, and if a UPI is compromised, patients can "retire" it and obtain a new one. Without a UPI, one can only regain medical privacy by changing one's identity, not dissimilar from participation in a witness-protection program!

Could the UPI be co-opted, the way the Social Security number has been, and used for other things? That's something we must guard against. By establishing a system where patients request the number through their doctor's office, and from a third party, not the government, we can help keep the UPI associated with medical data only.

Gaining Patients' Trust
Critics contend that UPIs will only make it easier for companies and others to use medical data for commercial purposes. To protect against this, they say, we need a system where physicians have to ask patients for permission to access their information. Because there has been so little study of UPIs, it's difficult to say whether those fears are valid. But having patients decide which doctor gets which data is the wrong choice. Doctors need full access to all of a patient's data, so they can deliver the appropriate care. That is the essence of the doctor-patient covenant. Furthermore, in critical-care situations, the patient might be unconscious and, therefore, unable to grant access to essential health information.

While narrowing access isn't optimal for patient care, new UPI technology does make it possible. For example, one type of UPI could be used for patients who want all of their physicians to have broad access to their medical data, while another would indicate the patient must first authorize access. Patients get to choose.

Even with all these protections, not every person will trust the system. Studies show that many people already refuse testing and treatment because they are worried it could be used to discriminate against them. UPI critics say a universal health-care ID system will only undermine trust further, but I would argue the opposite is true. Problems related to misidentifying patients and accessing their health information in a timely manner have eroded trust in the current low-tech system, which is why we need a new approach. Building an efficient records system that is more secure and offers better coordinated care can only enhance trust between patients and providers.

Congress should lift the ban on federal funding for UPI research, and we should better inform patients about the benefits of UPIs. No one wants medical data to fall into the wrong hands, but neither do we want patients to suffer because their medical information cannot be accessed.

Dr. Collins, a board-certified physician in internal medicine, is chancellor of the University of Massachusetts Medical School in Worcester, Mass. He can be reached at reports@wsj.com.

No: Privacy Would Suffer
By Deborah C. Peel

Doctors and patients need to find a better way to collect and share personal medical records from the innumerable places health data are collected and stored. But linking people to their health data via a unique identifying number isn't the answer.

'History shows that universal IDs are always used in unintended ways.' -- DEBORAH C. PEEL

Yes, assigning everyone a universal patient identifier, or UPI, would improve doctors' ability to share information and make it easier for hospitals to differentiate one John Smith from another. But a universal health ID system would empower government and corporations to exploit the single biggest flaw in health-care technology today: Patients can't control who sees, uses and sells their sensitive health data.

Searching for sensitive patient information would take just one number, not dozens of account numbers at professional offices, hospitals, pharmacies, labs, treatment facilities, government agencies and health plans. UPIs would make it vastly easier for government, corporations and others to use the nation's health information for their own gain without patients even knowing it.

What's more, any benefits associated with UPIs would be erased when patients, knowing their doctors have no control over where health-care data go, refuse to share sensitive information about their minds and bodies. This is a very real issue: Without privacy, patients won't trust doctors. In 2005, a California Healthcare Foundation survey found that due to the lack of privacy, one in eight patients lies, omits critical details, refuses tests or otherwise keeps sensitive health information private. Six hundred thousand people per year avoid early diagnosis for cancer alone.

Invitation to Snoop
We are in the midst of an unprecedented data-privacy crisis. Changes to federal regulations in 2002 eliminated patient control over who sees personal health information and led to explosive growth in the data-mining industry. Pharmacies, health-care IT vendors, insurers and others routinely sell and commercialize prescription records, genetic tests, hospital and office records, and claims data to drug companies and any willing purchasers. Even with names and key identifiers stripped off, it's simple to reidentify patients. Under the guise of improving health, lowering costs or promoting innovation, even government agencies sell and give away large databases of patient records.

Universal health-care IDs would only exacerbate such practices.

Further, UPIs would encourage the government and corporations to build massive, centralized databases of health information, rich targets for data theft and abuse. UPIs would become a de facto universal identification system far more harmful than Social Security numbers, enabling millions of government and corporate workers to snoop into anyone's medical records.

But concerns about health IDs go much deeper. UPIs exacerbate the commoditization of patients by encouraging the perspective that government agencies and corporations have superior rights to decide and control core aspects of who we are. A unique ID system is like giving master keys to millions who work in health care—they no longer need to ask patients to see records.

In the end, cutting out the patient will mean the erosion of patient trust. And the less we trust the system, the more patients will put health and life at risk to protect their privacy.
Such an obvious outcome makes a mockery of claims that UPIs would "reduce errors" and improve "patient safety." Similarly, claims that UPIs will be kept separate from personal and financial IDs are wishful thinking. All health records have financial records attached. But more important, history shows that universal IDs are always used in unintended ways. Social Security numbers were to be used only for payroll taxes, but morphed into universal IDs for health and commerce. UPIs will share the same fate.

Patients in Control
If a single ID number isn't the answer, what is? The best way to share sensitive health information is to build electronic-records systems where patients are in control of their own medical records, not government and industry. Health professionals should seek permission to see personal data, but only patients should release or link it. This is how it works with paper records systems, and there's no reason we should be less concerned about privacy in the digital age.

Existing technologies can allow patients to set default rules to govern data exchanges electronically, such as: "In emergencies, treating physicians may access my entire medical record" or "Anytime I receive health treatment, send copies to my family doctor." Consent rules can be changed instantly online, and sensitive information can be selectively withheld at the patient's discretion.

Unique patient IDs are unnecessary for this system. Much like using online banking to pay bills, patients can use online health systems to send encrypted information from medical accounts to whomever they choose.

Decentralized systems with smaller data sets protect privacy because if any account is broken into, only some information is compromised. More important, they require mediation by the patient. Imagine a universal ID system for all financial transactions where all retailers had our IDs. Commercial transactions would be more efficient if retailers could see and debit our accounts without consent. But it would be unacceptable—and it should also be unacceptable for others to use your health records without permission.

I agree that we need to transform the health-IT system so health professionals and researchers can electronically tap into complete and accurate health information. But any such technology should allow professionals to treat patients as individuals whose needs come first. That won't happen if we create an electronic medical-record system that no one trusts.

Dr. Peel, a psychiatrist and health-privacy expert in Austin, Texas, is the founder of Patient Privacy Rights and leader of the bipartisan Coalition for Patient Privacy. She can be reached at reports@wsj.com.

Monday, October 31, 2011

Privacy and Security in the Implementation of Health Information Technology (Electronic Health Records): U.S. and EU Compared

      Privacy and Security in the Implementation of Health Information Technology (Electronic Health Records): U.S. and EU Compared, B.U. J. SCI. & TECH. L., Vol. 17, Winter 2011. "The importance of the adoption of Electronic Health Records (EHRs) and the associated cost savings cannot be ignored as an element in the changing delivery of health care. However, the potential cost savings predicted in the use of EHR are accompanied by potential risks, either technical or legal, to privacy and security. The U.S. legal framework for healthcare privacy is a combination of constitutional, statutory, and regulatory law at the federal and state levels. In contrast, it is generally believed that EU protection of privacy, including personally identifiable medical information, is more comprehensive than that of U.S. privacy laws. Direct comparisons of U.S. and EU medical privacy laws can be made with reference to the five Fair Information Practices Principles (FIPs) adopted by the Federal Trade Commission and other international bodies. The analysis reveals that while the federal response to the privacy of health records in the U.S. seems to be a gain over conflicting state law, in contrast to EU law, U.S. patients currently have little choice in the electronic recording of sensitive medical information if they want to be treated, and minimal control over the sharing of that information. A combination of technical and legal improvements in EHRs could make the loss of privacy associated with EHRs de minimis. The EU has come closer to this position, encouraging the adoption of EHRs and confirming the application of privacy protections at the same time. It can be argued that the EU is proactive in its approach; whereas because of a different viewpoint toward an individual’s right to privacy, the U.S. system lacks a strong framework for healthcare privacy, which will affect the implementation of EHRs. If the U.S. is going to implement EHRs effectively, technical and policy aspects of privacy must be central to the discussion."

Friday, September 23, 2011

Old data learns new tricks: Managing patient security and privacy on a new data-sharing playground


Data is quickly becoming one of the health industry’s most treasured commodities. Yet, health organizations are acutely aware that sensitive data can be easily compromised. In just the last year and a half, a breach of personal health information occurred, on average, every other day. Breaches erode productivity and patient trust. They’re costly, unpredictable, and unfortunately quite common. More than half of healthcare organizations surveyed by PwC have had at least one privacy/security-related issue in the last two years

·        Download: Old data learns new tricks (1.24mb)
·       Download: Old data learns new tricks: Chart pack (58kb)

Friday, September 16, 2011

Privacy Law Would Help U.S. Compete, Official Says

Privacy Law Would Help U.S. Compete, Official Says
By Juliana Gruenwald    Updated: September 15, 2011 | 5:59 p.m.  National Journal

U.S. firms would be more competitive and better able to comply with foreign privacy laws if the United States had a broad law protecting consumer privacy online, a Commerce Department official told a House panel on Thursday.

“It would be helpful and I think it would help the competitiveness of our businesses if we had baseline privacy protections that are flexible and take into account really the changing economy, [and] changing technologies,” Nicole Lamb-Hale of Commerce’s International Trade Administration told the Energy and Commerce Subcommittee on Commerce, Manufacturing and Trade.

Some privacy advocates have called on the EU to get tougher with the United States and require it to harden up the current mix of industry self-regulation and some specific privacy laws related to health and finance. They say industry self-regulation has failed to protect Internet users who are increasingly being tracked  by companies that collect information for advertising purposes. The Obama administration and even some tech firms such as Intel and Microsoft have called on Congress to pass legislation that would establish baseline privacy protections.

The House panel examined how the European Union’s privacy law, which was first adopted in 1995, affects U.S. firms and what lessons it may provide U.S. policymakers. The law bars the flow of personal data about EU citizens to countries that do not have “adequate” privacy protections.

To ensure that U.S. firms would not be harmed by the law, the U.S. government negotiated a “safe harbor” in the late 1990s with the EU that allows companies to be deemed in compliance with the EU privacy law if they follow an agreed set of privacy principles.

Paula Bruening, vice president for global policy for the Center for Information Policy Leadership, said the EU law has not been implemented or enforced consistently among member states. She said it imposes burdensome administrative requirements on U.S. companies.

The EU is currently considering changes to the law to respond to some of these criticisms, but may also make it tougher. Lamb-Hale said it is unclear whether the European Union would continue to recognize the safe harbor after it revises its privacy law.

The Trans Atlantic Consumer Dialogue, a coalition of nearly 80 European and U.S. consumer groups, wrote the subcommittee earlier this week saying there is much the United States could learn from the Europeans on privacy given the rising levels of privacy breaches in the United States.

Ohio State University law professor Peter Swire, a privacy adviser in the Clinton administration, noted that countries outside of Europe have been passing privacy laws based on the EU directive. He said U.S. companies could face problems moving data out of those countries as well.

However, Consumer Data Industry Association President Stuart Pratt told National Journal after the hearing that he believes the cost of complying with a U.S. privacy law would far outweigh any benefits companies would receive from it.

Subcommittee Chairwoman Mary Bono Mack, R-Calif., said she has not decided whether Congress should pass privacy legislation. She plans more hearings to explore the issue. “My purpose in holding this hearing is not to point fingers,” she said. “Instead, my goal is to point to a better way to protect privacy online and promote e-commerce.”

Want to stay ahead of the curve? Sign up for National Journal's AM & PM Must Reads. News and analysis to ensure you don't miss a thing.

Monday, August 29, 2011

The PII Problem: Privacy and a New Concept of Personally Identifiable Information

The PII Problem: Privacy and a New Concept of Personally Identifiable Information

Paul M. Schwartz
University of California, Berkeley - School of Law
Daniel J. Solove
George Washington University Law SchoolNew York University Law Review, Vol. 86, 2011

Abstract:     Personally identifiable information (PII) is one of the most central concepts in information privacy regulation. The scope of privacy laws typically turns on whether PII is involved. The basic assumption behind the applicable laws is that if PII is not involved, then there can be no privacy harm. At the same time, there is no uniform definition of PII in information privacy law. Moreover, computer science has shown that in many circumstances non-PII can be linked to individuals, and that de-identified data can, in many circumstances, be re-identified. PII and non-PII are thus not immutable categories, and there is a risk that information deemed non-PII at one point in time can be transformed into PII at a later juncture. Due to the malleable nature of what constitutes PII, some commentators have even suggested that PII be abandoned as the means to define the boundaries of privacy law.

In this Article, Professors Paul Schwartz and Daniel Solove argue that although the current approaches to PII are flawed, the concept of PII should not be abandoned. They develop a new approach called “PII 2.0,” which accounts for PII’s malleability. Based upon a standard rather than a rule, PII 2.0 is based upon a continuum of risk of identification. PII 2.0 regulates information that relates to either an “identified” or “identifiable” individual, and it establishes different requirements for each category. To illustrate their theory, Schwartz and Solove use the example of regulating behavioral marketing to adults and children. They show how existing approaches to PII impede the effective regulation of behavioral marketing and how PII 2.0 would resolve these problems.

Monday, July 18, 2011

CDT Justin Brookman: Why the US needs a data privacy law-and why it might finally get one

Why the US needs a data privacy law—and why it might finally get one
By Justin Brookman | Published July 18, 2011  ARS

The general public and Congress have both discovered geolocation, data breaches, and tracking cookies—and they're worried about the privacy implications. In this op-ed, the Center for Democracy & Technology's Justin Brookman argues that this could be the moment at which everything comes together to make comprehensive privacy reform possible. The opinions in this op-ed do not necessarily represent those of Ars Technica.

With the understandable exceptions of the national debt and the deployments of our troops abroad, privacy is possibly the hottest issue in Congress today. After ten years of limited interest in the subject, we’ve recently seen a spate of legislation introduced to give consumers rights over how their information is collected and shared.

In the House of Representatives, Reps. Bobby Rush (D-IL) and Cliff Stearns (R-FL) have each introduced separate comprehensive bills. In the Senate, John Kerry (D-MA) and John McCain (R-AZ) recently introduced the "Commercial Privacy Bill of Rights" with similar goals. The (Democrat-led) Senate Commerce Committee recently held a hearing on the topic of privacy; the next week, the (Republican-led) House Energy and Commerce Committee looked at the same thing.

In a town where positions on issues are often deeply divided along partisan lines, it’s encouraging to see that there appears to be at least one issue that both parties recognize as a problem that needs to be addressed.

Not much company
Here’s why Congress is interested: today, the United States and Turkey are the only developed nations in the world without a comprehensive law protecting consumer privacy. European citizens have privacy rights, Asian citizens have privacy rights, Latin American citizens have privacy rights. In the US, however, in lieu of a comprehensive approach, we have a handful of inconsistent, sector-specific laws around particularly sensitive information like health and financial data. For everything else, the only rule for companies is just “don’t lie about what you’re doing with data.”

The Federal Trade Commission enforces this prohibition, and does a pretty good job with this limited authority, but risk-averse lawyers have figured out that the best way to not violate this rule is to not make explicit privacy promises at all. For this reason, corporate privacy policies tend to be legalistic and vague, reserving rights to use, sell, or share your information while not really describing the company’s practices. Consumers who want to find out what’s happening to their information often cannot, since current law actually incentivizes companies not to make concrete disclosures.

This has been the case for years, of course, but in the modern era of constant connectivity, social networking, and cheap data storage and processing, the stakes are remarkably higher. Before the advent of the Internet, there were only so many data points for marketers and information brokers to collect about you, and bookstores and libraries didn’t share what you were reading. Even just a few years ago, when you went to a major publisher website, there might have been a couple third-party trackers on the site who could drop a cookie on your computer to “anonymously” track you across other sites. Today, these same sites may deploy hundreds of trackers from dozens of different companies, many of which know your offline identity as well. What happens to all that information? With whom is it shared? No one really knows, and there is no framework to regulate it.

Bad for business
This black box into which our data flows is bad for consumers, but it’s increasingly an impediment to US businesses as well. As Silicon Valley companies encourage consumers to store their personal data in “the cloud,” people are legitimately asking, “Why? What’s going to happen to my data there?” Today, the US is the undisputed leader in cloud computing services, but international competitors are increasingly advertising the fact that their services aren’t US-based. The Department of Commerce recently issued a report arguing that the lack of privacy protections threatens both the adoption of new technologies by worried consumers and the ability to have international data sent to the US. Last week, Forrester Research released a study showing that privacy concerns were the biggest impediment to the growth of e-commerce on mobile technologies.

Companies would be better off if they all provided meaningful privacy protections for consumers, but privacy is a collective action problem for them: many companies would love to see the ecosystem fixed, but no one wants to put themselves at a competitive disadvantage by imposing unilateral limitations on what they can do with user data. It’s fantastic to see companies endeavoring to compete on privacy (such as Google touting the privacy features of its new social network), but so far such competition has been spotty and often takes place at the margins. Many companies that touch and store consumer data don’t have consumer-facing sides (like the ever-increasing number of intermediaries in the behavioral advertising space), so it’s hard to see the Internet ecosystem fixing itself on its own.

And let’s be frank: so far, self-regulation hasn’t been enough. Increasingly, leading multinational corporations have recognized this problem, and companies like Microsoft, Intel, and HP that have heavily invested in cloud technologies have endorsed specific legislative solutions such as the Kerry-McCain and Rush bills to provide consumers with comprehensive privacy protections.

Any privacy law that is enacted doesn’t need to, and shouldn’t, prohibit data sharing or invalidate business models. However, consumers have a right to know what’s happening with their information and to have a say in how it gets shared. If a company insists on sharing data about a consumer as a condition of doing service, fine. As long as that fact is clearly conveyed, and the consumer decides to accept the terms, we shouldn’t put limits on what consumers are willing to do with their own information. Unfortunately, consumers today aren’t even told what’s happening, so they can’t exercise meaningful control over their data unless they take extreme measures to anonymize their surfing though services like Tor or block third-party content (which surely isn’t the right result for anyone).

So will a new law be passed? As with anything in Washington, it’s hard to say what will happen—Congress has a lamentable tendency to kick problems down the road for another day. However, with tremendous attention to privacy issues and widespread consumer support for basic consumer protections, we have the best opportunity in memory to enact basic rules to give people control of their personal information and to give them confidence in an increasingly complex data ecosystem. We should take advantage of this moment to develop a considered consensus on reasonable baseline protections that work for both consumers and businesses.

Justin Brookman is Director of the Consumer Privacy Project at the Center for Democracy & Technology in Washington, DC.

Wednesday, July 13, 2011

The Importance of FIPs in data exchange

Channel: RHIOs/HIEs
Source: Lorraine Fernandes, global healthcare ambassador, IBM
Date: Jul 12, 2011
http://www.nhinwatch.com/perspective/importance-fips-data-exchange


Many of the Department of Health and Human Services, Office of the National Coordinator, Privacy and Security Tiger Team discussions over the past year have invoked the FTC's Fair Information Practices. Why? Because the Health Insurance Portability and Accountability Act (HIPAA) does not address one of today's most critical healthcare issues - data sharing. In the absence of updated regulations, the FIPs offer a comprehensive framework for moving forward.

The best way to move forward is to remove the emotion from the privacy and consent debate and instead look at this in a practical, constructive fashion. Perhaps Paul Tang, vice chair of the HIT Policy committee and member of numerous workgroups, said it best during one of the Tiger Team meetings last summer: "What would a patient expect?"

The Markle Foundation submitted a letter to the Department of Commerce on February 18, 2011, concisely articulating the importance of FIPs in today's society. As suggested in the letter, titled "The Need for a Coordinated Department of Commerce Policy on Consumer Protection and Privacy," we must look at data in a broader fashion and recognize that when we talk about data, we are really talking about consumer data, not healthcare data. This broader consumer framework paves the way for us to move away from our current prescriptive system, which focuses too much on regulations, toward a set of principles that allows us to respond to innovation and changing technology. There is a place for regulations, but let's have that dialogue after we have a solid foundation.

Let's ponder for a moment the FIPs and how we can use them to help achieve the goals of improving individual and population health.

Openness and Transparency - Consumers should be able to readily access data-usage policies, understand the collection and use of their data, and be able to limit the use of their data if they choose to do so. This can be achieved by public notices, website postings, social media and other more traditional approaches. Full transparency is crucial to building consumer trust.

Purpose Specification and Minimization - Data use should be specified at the time of collection and use should be limited only to those stated purposes. And if there is a proposed change in the use, the consumer should be notified. The classic "bait and switch" should never occur with consumer data.

Collection Limitation - This might also be coined "minimum data necessary." Don't collect more data than what is needed for the purpose at hand. This is particularly true when dealing with sensitive data like social security number, certain clinical conditions and past histories in a treatment setting. Perhaps the standard question when developing new data collection practices should be: "Do I really need this data to achieve my goals?"

Use Limitation - Data should be used only for the stated purpose. No dissemination or re-use should be undertaken unless consistent with the use limitation. For example, personally identifiable information should not be used for research unless the patient has been notified.

Individual Participation and Control - Consumers should understand how their data will be used. I think Dr. Tang's "What would the patient expect?" question really articulates a clear practice matching this FIP. Consumers should be notified on a timely basis if there is a data breach. The Phase 1 Meaningful Use requirement for patient access to their data also nicely matches this principle. Patients should be able to conduct a "consumer audit" to find out where their data has been used, whether that data is identifiable, de-identified or limited.

Data Integrity and Quality - Data collected (consistent with the other FIPs) should be accurate, complete and up to date. It should also include attribution (the originating source of the data). If problems are identified with the data quality, then the consumer should have remedies consistent with the FIPs.

Security Safeguards and Controls - Reasonable safeguards should be employed to protect against data theft, breach and unauthorized access. Clearly this is a problematic area, given the incidences of laptop thefts that frequently expose unencrypted data.

Accountability and Oversight - Those in control of consumer information must be accountable for following the FIPs. If breaches occur, those responsible must be disciplined consistent with policies and remedies.

Remedies - Remedies should be documented, transparent and must address what happens if there is a breach or privacy violation.

Following these basic practices and associated principles, and tying all discussions about data collection and exchange to the FIPs, would go a long way to building consumer trust and confidence. If we used these practices as a framework, the discussions could be more rationale, pragmatic, understandable and results oriented.  And, we can't pick and choose; we must use the FIPS as a whole.

When the FIPS are "front and center," consumers are front and center, and that is the only path that leads to trust in electronic health records and data exchange.

Lorraine Fernandes, RHIA, is the global Healthcare ambassador for IBM.

Friday, July 1, 2011

FTC: Consumer Confidence in Internet Marketplace Depends on Privacy Protections FTC Tells Senate Commerce Committee

: 06/29/2011

The Federal Trade Commission today told Congress that consumers must be confident that their privacy will be protected if they are to be willing to take advantage of all the benefits offered by the Internet marketplace.

Commission testimony to the Senate Committee on Commerce, Science and Transportation, delivered by Commissioner Julie Brill, states that, “Privacy has been an important component of the Commission’s consumer protection mission for 40 years. During this time, the Commission’s goal in the privacy arena has remained constant: to protect consumers’ personal information and ensure that they have the confidence to take advantage of the many benefits offered by the dynamic and ever-changing marketplace.”

The FTC’s testimony states that the FTC has taken a three-pronged approach to preserving consumers’ privacy – law enforcement actions, consumer and business education efforts and policy initiatives.

It notes that in the last 15 years, the agency has brought more than 300 privacy-related actions, including: 34 data security cases; 84 Fair Credit Reporting Act cases; 97 spam cases; 15 spyware cases; and 16 cases enforcing the Children’s Online Privacy Protection Act.
In addition, the testimony states that the agency has distributed millions of copies of consumer and business education materials that address basic privacy issues and security and privacy threats.

Policy initiatives to advance the agency’s privacy agenda include three privacy roundtables that involved privacy experts, business representatives, and academics who examined the implications of new technologies and business practices on consumer privacy. Based on the roundtable discussions, FTC staff issued a preliminary report proposing a privacy framework with three main concepts, the testimony states.

“Staff recommended that companies should adopt a ‘privacy by design’ approach by building privacy protections into their everyday business practices, such as collecting or retaining only the data they need to provide a requested service or transaction, and implementing reasonable security for such data,” according to the testimony.

The staff report also called for companies to provide an easy way for consumers to control the collection and use of their personal information. “One example of how choice may be simplified for consumers is through a universal, one-stop choice mechanism for online behavioral tracking, often referred to as “Do Not Track.” The testimony explained that “any Do Not Track system should not undermine the benefits that online behavioral advertising has to offer, by funding online content and services and providing personalized advertisements that many consumers value.” Any Do Not Track mechanism should be “flexible” and “should allow companies to explain the benefits of tracking and to take the opportunity to convince consumers not to opt out of tracking,” and “could include an option that enables consumers to control the types of advertising they want to receive and the types of data they are willing to have collected about them, in addition to providing the option to opt out completely.” The testimony notes that the industry “appears to be receptive to the demand for simple choices.”

In addition, the staff report recommended that “companies should improve their privacy notices so that consumers, advocacy groups, regulators, and others can compare data practices and choices across companies, thus promoting competition,” the testimony states.

The testimony notes that while the FTC has not taken positions advocating any particular legislative proposals, it favors data security legislation “that would (1) impose data security standards on companies, and (2) require companies, in appropriate circumstances, to provide notification to consumers when there is a security breach.” The testimony states that the Commission is committed to protecting consumers privacy -both online and off, and looks forward to working with Congress to achieve that goal

The Commission vote to issue the testimony was 5-0, with Commissioner J. Thomas Rosch issuing a separate statement recommending that the Commission and Congress learn more about Do Not Track before proceeding.

The Federal Trade Commission works for consumers to prevent fraudulent, deceptive, and unfair business practices and to provide information to help spot, stop, and avoid them. To file a complaint in English or Spanish, visit the FTC’s online Complaint Assistant or call
1-877-FTC-HELP (1-877-382-4357). The FTC enters complaints into Consumer Sentinel, a secure, online database available to more than 2,000 civil and criminal law enforcement agencies in the U.S. and abroad. The FTC’s website provides free information on a variety of consumer topics. Like the FTC on
Facebook and follow us on Twitter.
MEDIA CONTACT:
      Claudia Bourne Farrell Office of Public Affairs 202-326-2181

Friday, June 24, 2011

Peter Swire: Why privacy legislation is hot now

By Peter Swire - 06/23/11 07:50 PM ET

More than at any time in the past decade, privacy hearings and proposed legislation are spreading across Capitol Hill. Until now, you could always make money betting against a privacy law passing in Congress. Today, many experts are saying that momentum is building for major legislation, although the shape of that legislation is still unclear.

This round of privacy action is driven by three historic trends, plus other factors that are coming together now.

First is location data. While Apple’s Steve Jobs called the Android a “probe in your pocket,” Apple itself has been brought before both the Senate Judiciary and Commerce committees to try to explain why it was collecting detailed location information on the iPhone. For the first time in history, most Americans are carrying a tracking device — a cell phone — with them in their daily lives. There is great uncertainty about who gets to see that tracking information, including for advertising and law enforcement purposes.

Second is social networking. Facebook has gone from nothing to half a billion users in only a few years. The social networks point out that users voluntarily put that incredible amount of material up on the sites. But this is all so new that the rules of the road are not yet clear.

Third is online behavioral advertising. The Wall Street Journal ran a major series showing the astonishing range of ways that companies can track your activity on the Web — even if you turn off cookies and try to stay anonymous. The companies say that this data is benign, because computers simply choose which ads to show you. Privacy advocates, though, say that these databases give unprecedented insight into what we read and how we think, leading to a scary potential of misuse down the road.

Along with these three mega-trends, Congress is seriously considering federal data-breach legislation, to harmonize state laws and address the Sony PlayStation and other high-profile recent breaches. Major cloud computing companies and civil liberties groups are supporting the Digital Due Process Coalition, which favors a judicial search warrant before law enforcement can gain access to the exabytes of data stored in the cloud. And, there is pressure on the international front, as the European Union considers tightening its own data privacy laws and as India, Mexico and other countries are in the process of putting EU-style privacy laws on the books.

A flashpoint for action could be children’s privacy, where family-values Republicans and consumer-protection Democrats can most easily come together politically. Mark Zuckerberg has publicly discussed bringing under-13s directly into Facebook, but no one knows with what rules. Reps. Edward Markey (D-Mass.) and Joe Barton (R-Texas) have released a discussion draft of the “Do Not Track Kids Act of 2011” to offer the choice not to have behavioral advertising and related tracking for those under the age of 13. And no one knows who will get to see the location information of children — parents will and stalkers won’t, but there are still-to-be-developed rules for those in-between. On June 27, the Center for American Progress will host an event highlighting children’s privacy issues, called “Tracking: Where you are, what you see, and what you do.”

The biggest legislative question might be whether to go with general privacy principles or sector-specific rules. For the first time in history, the administration itself has come out in favor of broad-based privacy legislation for the private sector. The closest fit to the administration vision is the Kerry-McCain “Commercial Privacy Bill of Rights,” which notably would provide individuals with the legal right to opt out of having their information shared for marketing purposes. This sort of general legislation contrasts with sector-specific proposals, such as a recent bill by Sens. Al Franken (D-Minn.) and Richard Blumenthal (D-Conn.) that targets smartphone location information.

With the convergence of all of these technical changes, the current period most resembles the late 1990s. At that time, Congress approved sector-specific laws for medical privacy (HIPAA) and financial services (Gramm-Leach-Bliley), but held off on a general law to protect privacy on the Internet. With so many sectors having specific laws by now, however, the time may well be ripe for a bill that provides basic privacy protections more generally.

Swire was chief counselor for privacy to former President Clinton and served in the National Economic Council under President Obama. He is now a law professor at Ohio State and a fellow with the Center for American Progress and the Future of Privacy Forum.

Thursday, June 16, 2011

Dispelling the Myths Surrounding De-identification: Anonymization Remains a Strong Tool for Protecting Privacy

Dispelling the Myths Surrounding De-identification: Anonymization Remains a Strong Tool for Protecting Privacy

Introduction

Recently, the value of de-identification of personal information as a tool to protect privacy has come into question. Repeated claims have been made regarding the ease of re-identification. We consider this to be most unfortunate because it leaves the mistaken impression that there is no point in attempting to de-identify personal information, especially in cases where de-identified information would be sufficient for subsequent use, as in the case of health research.

The goal of this paper is to dispel this myth — the fear of re-identification is greatly overblown. As long as proper de-identification techniques, combined with re-identification risk measurement procedures, are used, de-identification remains a crucial tool in the protection of privacy. De-identification of personal data may be employed in a manner that simultaneously minimizes the risk of re-identification, while maintaining a high level of data quality. De-identification continues to be a valuable and effective mechanism for protecting personal information, and we urge its ongoing use.

In this paper we illustrate the importance of de-identifying personal information before it is used or disclosed, and at times, prior to its collection. We will demonstrate that, contrary to what has been suggested in recent articles, re-identification of properly de-identified information is not in fact an “easy” or “trivial” task. It requires concerted effort, on the part of skilled technicians. The paper will also describe a tool that minimizes the risk of the re-identification of de-identified information while also enabling a high level of data quality to be maintained. Our objective is to shatter the myth that de-identification is not a strong tool to protect privacy and to ensure that organizations that collect, use and disclose personal information understand the importance of de-identification for the protection of privacy, and continue to use this tool to the greatest extent possible to minimize potential risks. While our primary focus in this paper is on the value of de-identification in the context of personal health information that is used and disclosed for secondary purposes, the same arguments apply in the broader context of personal information.

Wednesday, June 8, 2011

New Paper: Much Ado About Data Ownership

Much Ado About Data Ownership

Barbara J. Evans

University of Houston Law Center
Harvard Journal of Law and Technology, Vol. 25, Fall 2011
University of Houston Law Center

Abstract:    
Recently there have been calls to clarify ownership of data held in large health information networks. This article explores the realities of what patient data ownership would imply to explain why a clearer allocation of entitlements to raw health data would neither enhance patient privacy nor promote access to valuable data resources for public health and research. It updates the debate to account for the 2009 HITECH Act, which correctly recognized that raw patient data are not the valuable resource; these data acquire value only through the application of infrastructure services. The HITECH Act drew on a long tradition of American infrastructure regulation that offers real promise in resolving the infrastructure bottlenecks which (rather than the unresolved status of data ownership) have been the key impediment to data access. Despite this progress there are two unresolved problems, both heretofore neglected in the literature:


First, the existing federal regulatory framework governing data access conceives the state’s police power to use data to promote public health much more narrowly than the police power is conceived in all other legal contexts.

Second, existing regulatory provisions allowing nonconsensual access to data for research fail to incorporate any “public use” requirement to ensure that unconsented research uses of data are justified by a publicly beneficial purpose. As things stand, persons whose health data are used in research have no assurance that the use will serve any socially beneficial purpose at all. This article reframes the debate. The right question is not who owns health data. Instead, the debate should be about appropriate public uses of private data and how best to facilitate them while adequately protecting individuals’ interests.


Download at http://papers.ssrn.com/sol3/papers.cfm?abstract_id=1857986

Tuesday, May 31, 2011

NYTimes: Breaches Lead to Push to Protect Medical Data

by Milt Freudenheim  •    NY Times    May 30, 2011

Federal health officials call it the Wall of Shame. It’s a government Web page that lists nearly 300 hospitals, doctors and insurance companies that have reported significant breaches of medical privacy in the last couple of years.

Such lapses, frightening to consumers, could impede the Obama administration’s effort to shift the nation to electronic health care records.

“People need to be assured that their health records are secure and private,” Kathleen Sebelius, secretary of health and human services, said in an interview by phone. “I feel equally strongly that conversion to electronic health records may be one of the most transformative issues in the delivery of health care, lowering medical errors, reducing costs and helping to improve the quality of outcomes.”

So the administration is making new efforts to enforce existing rules about medical privacy and security. But some health care experts wonder if the current rules are enough or whether stronger laws are needed, for example making it a crime for someone to use information obtained improperly.

“The consequences of breaches matter,” conceded Dr. Farzad Mostashari, a former New York public hospitals official who recently became the Obama administration’s national coordinator for health information technology. “People say they are afraid that if their private information becomes known, they may not be able to get health insurance.”

In the last two years, personal medical records of at least 7.8 million people have been improperly exposed, according to the government data. One particularly egregious case involved information about 1.7 million patients, staff members, contractors and suppliers of Bronx hospitals and clinics operated by the Health and Hospitals Corporation, the New York public health agency. Their electronic files were stolen from an unlocked van belonging to a record management company.

The affected patients got the disquieting news that their medical and personal information, like Social Security numbers, had been violated when their health care providers notified them under federal rules.

Showing just how lax security can be, the inspector general of the Department of Health and Human Services said two weeks ago that the agency had found dozens of vulnerabilities in systems to protect records of patients at seven large hospitals in New York, California, Illinois, Texas, Massachusetts, Georgia and Missouri. Auditors cited such problems as personal information that was not encrypted and was stored on computers that could be easily used by unauthorized users.

Auditing teams are now inspecting eight more hospitals, said Lori Pilcher, an assistant inspector general at Health and Human Services. The hospitals are not being identified to avoid alerting hackers, she said.

Another big breach was reported in March on the official Web site by Health Net, a California-based insurance company, which notified 1.9 million health plan members that records with their personal information were missing.
Health Net said I.B.M., which was managing its information system, told the insurer that the records could not be found.

“The health care industry is not as vigilant as they should be about protecting private information in a patient’s medical records,” said Representative Joe L. Barton, a Texas Republican who is co-chairman of the Bipartisan Privacy Caucus in the House.

Mr. Barton knows from personal experience. His own records after a heart attack, along with several thousand others from a research project at the National Institutes of Health, were “on a disk in a laptop in somebody’s trunk that disappeared,” he recalled. “I was stunned.”

The Obama administration has levied a string of stringent penalties for egregious violations of patient rights under the most commonly cited law, the Health Insurance Portability and Accountability Act, or HIPAA, of 1996. Health information is supposed to stay private under those rules, but research has shown that it is not that difficult to connect names and addresses to nominally anonymous data with Internet searches and computerized matchups.

The Office of Civil Rights at Health and Human Services, which took over enforcement of the law, imposed a $1 million fine on Massachusetts General Hospital in March after a hospital employee left paper records of 192 patients on a Boston subway train. The hospital agreed in a settlement, without admitting wrongdoing, to report twice a year on its efforts to tighten patient protections.

Earlier this year, the civil rights office fined a Maryland health plan, Cignet Health, $4.3 million, saying that it had denied patients the right to see their own records in violation of HIPAA provisions. It was the first civil penalty levied under the HIPAA law. “We have ramped up our enforcement,” said Georgina C. Verdugo, director of the civil rights office.

But Dr. David Brailer, a Bush appointee as the first national coordinator of health information technology, is skeptical about whether such efforts will curb security breaches. “We can’t just lock health care data away — because of its role in lifesaving treatment,” Dr. Brailer said.
He said that even with the best technology it would be hard to make health systems secure. “It’s a huge challenge. Break-ins and hacks are unfortunately going to be part of the landscape,” he said.

One protection, he suggested, would be laws to make it illegal for an insurer or employer to discriminate against a person based on information about health conditions like H.I.V./AIDS, cancer and mental health problems.

As a model, he pointed to the antidiscrimination law to prevent the misuse of genetic information that was passed with bipartisan support in the Bush administration. He also said he believed the laws should say “patients own the data, period, and decide what happens to it. The patient should be able to say to Hospital X: ‘send my data to Hospital Y because I’m changing hospitals,’ “ he said.

Today, the information belongs to whoever possesses it, under ideas inherited from 17th-century English common law, he said. “If it gets into your database, essentially you own it,” he added, “and you can pass it on.”

“Today HIPAA makes no sense,” Dr. Brailer added. “The law didn’t anticipate a world where your data passes through many, many hands.”

Wes Rishel, a longtime health care analyst for Gartner, the technology consulting firm, and an adviser to the national coordinator’s office, has a similar view. “Your ability to control access to your information is a horse that is already out of the stable,” he said. “What is really needed is legislation that controls use of it.”

On that score, researchers at Carnegie Mellon University have shown that at least 30 people and organizations have access to the health data of a typical person with private insurance through an employer. They range from pharmacies and drug companies to an employer’s wellness programs and a spouse’s self-insured employer.

“Only you, your doctor and hundreds of others know,” said Latanya Sweeney, a health privacy expert at Harvard and Carnegie Mellon who is also an adviser to the office headed by Dr. Mostashari.

Since HIPAA was enacted there has been “an explosion in data sharing,” Ms. Sweeney said. “And after electronic records are widely adopted, there will be another big explosion.”

Saturday, April 30, 2011

Data Privacy, Put to the Test

BIG Oil. Big Food. Big Pharma.

By Natasha Singer, NYTimes, April 30, 2011

To the catalog of corporate "bigs" that worry a lot of us little people, add this: Big Data. It was not a good week for those who guard their privacy. First, we learned that Apple and Google have been using our smartphones to collect location data. Then Sony acknowledged that its PlayStation network had been hacked — the latest in a string of troubling data breaches. You'd have to be living off the grid not to realize that just about everything there is to know about you — what you buy, where you go — is worth something to someone. And the more we live online, the more companies learn about us.

But to what extent do others have a right to share and sell that information? That is the crux of a data-mining case that had arguments last Tuesday before the Supreme Court. The case, Sorrell v. IMS Health, is ostensibly about medical privacy: Vermont passed a law in 2007 that lets each doctor decide whether pharmacies can, for marketing purposes, sell prescription records linking him or her by name to the kinds and amounts of drugs prescribed. State legislators passed the law after the Vermont Medical Society said that such marketing intruded on doctors and could exert too much influence on prescriptions.

But three health information firms, including IMS Health and Verispan, along with a pharmaceutical industry trade group, challenged the law, saying it restricted commercial free speech. Access to prescription records, IMS Health says, helps pharmaceutical companies market efficiently to doctors whose patients would most benefit from specific drugs. Now the justices are to decide whether the Vermont law is constitutional.

But with the recent headlines about privacy invasion — the PlayStation hack followed a recent breach at the online marketing company Epsilon that exposed e-mail addresses of customers of Citibank, Walgreens, Target and other companies — the Vermont case is tapping into a much broader conversation about consumer protection and informed consent.

The case raises questions about who is collecting, managing, storing, sharing and selling all that data. Just as important, privacy advocates say, it raises questions about whether data brokers are adequately safeguarding it.

People generally don't have much control over who collects and sells information about them. Moreover, says Christopher Calabrese, a legislative counsel at the American Civil Liberties Union, they also don't even know the names of the data brokers who compile those electronic profiles. And, so, consumer advocates are setting their sights on Big Data.

"Without government intervention, we may soon find the Internet has been transformed from a library and playground to a fishbowl," Mr. Calabrese testified in March during a Senate hearing on consumer privacy, "and that we have unwittingly ceded core values of privacy and autonomy."

There are a few laws, like the Video Privacy Protection Act, that prohibit businesses from releasing personally identifiable records, like video rental histories, without customer consent. The Digital Advertising Alliance, a coalition of online marketing groups, introduced a program last year that notifies consumers about online tracking and allows them to opt out of advertising tailored to them. The Vermont law amounts to a kind of do-not-call option for doctors who may welcome visits from pharmaceutical sales reps but don't want drug marketing based on their own prescription records.

That marketing practice is possible because pharmacies, which are required by law to collect detailed information about prescriptions they fill, can sell doctor-specific prescription records to data brokers. (According to federal privacy regulations, personal information about patients, like names and addresses, must be removed before the records can be sold for marketing.) Firms like IMS Health then combine the records, and pharmaceutical reps often use them to tailor presentations to individual doctors.

The central concern is privacy — of both doctors and their patients. While pharmacies remove the names of patients before selling the records, those names are replaced with unique codes that track patients over time from doctor to doctor, according to the Vermont complaint. That means data firms could create a profile that includes a person's prescriptions as well as the names of the pharmacies and dates at which the person picked up the medications, says Latanya Sweeney, a visiting professor of computer science at Harvard.

"It ends up building a detailed prescription profile of individuals," says Professor Sweeney, whose research on data re-identification was cited by several briefs in the case. "Those extended profiles tend to be very unique."

The concern, she says, particularly in a small state like Vermont, is that a nameless prescription record could theoretically be enough to identify someone who might not want others to know that he takes, say, anti-depressants. Moreover, Professor Sweeney argues, data miners could collate those files with public information, like voter registration and hospital discharge records, to link prescriptions to specific people.

Federal health privacy regulation, she says, does not protect patient records once they have been de-identified. Nor does the law prohibit re-identification. But IMS Health says it isn't aware of any case of re-identifying patients whose prescription records were de-identified in accordance with federal rules. The company says it doubly encrypts each patient's identity and gives the encryption keys to several third parties — meaning that no single entity can decode a file by itself, says Kimberly Gray, chief privacy officer at IMS Health.

The company typically sells combined reports that show how many patients received a certain drug from a certain doctor, but not the specific drugstores those patients frequent, Ms. Gray says. IMS never uses public information or outside data sets to try to re-identify patients, she says, and when it does provide encoded patient histories to others for research purposes, it prohibits those third parties from making such attempts. "We would never want to re-identify someone," Ms. Gray says. "No good can come from that."

Still, it is hard to prevent people from trying to re-identify patients, says Lee Tien, a staff lawyer at the Electronic Frontier Foundation, a digital civil liberties group that filed a brief in support of Vermont. It would be easier, he says, if Congress passed a law that went further than Vermont's, giving people the right to consent before their encrypted prescription records were sold for marketing purposes. "In Vermont, the doctor can decide," Mr. Tien says. "But we'd prefer it if the patient were able to say, 'Don't sell my data.' " 

Tuesday, March 15, 2011

Medical Identity Theft: The Growing Cost of Indifference

Second annual study reveals medical identity theft is on the rise, yet consumers remain unmoved by the risks

IRVINE, Calif., March 15, 2011 /PRNewswire/ -- While consumers grasp the importance of protecting their medical and personal information, few individuals take the necessary precautions to avoid medical identity theft. This finding comes from the second annual National Study on Medical Identity Theft by The Ponemon Institute(1) and sponsored by Experian's ProtectMyID™, a leading, full-service provider of identity theft detection, protection and fraud resolution.  

It is estimated that nearly 1.5 million Americans are victims of medical identity theft, up slightly from last year, according to this comprehensive study.(2) Alarmingly, the average cost to resolve a case of medical identity theft stands at $20,663, up from $20,160 in 2010. Other key findings from the survey include:  

Recognizing the importance of privacy does not equate to action
      Despite consumer desires for medical data privacy and statistical findings of data vulnerability, people are not taking action to protect their valuable health information. Nearly 70 percent of study respondents felt it was important to have personal control over their medical records, and 80 percent felt that healthcare organizations should ensure the privacy of these records.

However, these beliefs do not translate to action, as 49 percent of victims took no new steps to protect themselves after a crime.                              
Consumer indifference is fueled by lack of understanding of repercussions             
Fifty percent of former victims chose not to report the incident to law enforcement at all, up from 46 percent in the 2010 study. The number one reason for this failure to report was the lack of resulting harm and the desire to not make it a big deal (43 percent). In fact, more victims fear embarrassment (37 percent) than the loss of medical coverage (21 percent) or a diminished credit score (18 percent) as a potential result of medical identity theft.              
                       

"Our study shows that the risk and high cost of medical identity theft are not resonating with the public, revealing a serious need for greater education and awareness," said Dr. Larry Ponemon, chairman and founder of The Ponemon Institute. "We also feel these results put an even greater onus on healthcare organizations to make the security of sensitive personal health information a priority in order to protect patient privacy."

 Medical data breach notification fails to protect the consumer        
The risk of medical identity theft lies beyond consumer control, as health care organization data breach accounts for a significant portion of reported incidents. When a breach occurs, the organization normally is required to inform the affected people, depending on state law notification requirements. However, only 5 percent of victims learned of their theft from a data breach notification, which is especially troubling when considering that data breach accounted for 14 percent of all theft instances. This includes breaches involving health care providers, insurers or other related organizations.          
                       

"The results of this study shed a troubling light on not only the pervasiveness and consumer perceptions of medical identity theft, but also the dangers of data breach," said Jennifer Leuer, general manager of Experian's ProtectMyID. "These factors can be unnerving, but luckily there are products like ProtectMyID that give people peace of mind, knowing that they are not alone in the fight to keep their identities safe."

 Consumers are uninformed of new health care reform policies           
The majority of survey respondents (55 percent) are not familiar or have no knowledge of the new policies, and 79 percent are not aware of the creation of a national electronic database of Americans' health information. Furthermore, 33 percent believe that a national electronic database will increase the risk of medical identity theft. The lack of general awareness makes consumer education about medical identity protection all the more critical in the face of shifting policy.              
                      
Medical identity theft is a family affair             
The study also revealed the startling rate at which medical identity theft occurs between family members. In fact, theft of this nature accounted for 36 percent of all victim responses, making it the most common type of theft. The frequency of family-related medical identity theft contributed to the most commonly stated reason (51 percent) why victims elected not to report a given incident: the victim discovered that he or she knew the thief and did not want to report him or her.          
                       

Based on the results of the second annual National Study on Medical Identity Theft, it is clear that the threat of medical identity theft poses a multitude of risks to consumers. In order to combat these risks, ProtectMyID offers assistance that can help victims of medical identity theft. The following features are currently available:

Medical Identity Theft Resource Center — Provides members with valuable information about how to protect themselves, obtain medical reports, understand Explanation of Benefits notifications and much more.

Dedicated Identity Theft Resolution Agents — These agents are trained to notify and work with health care providers on behalf of customers to resolve any theft-related issue. This removes the mystery and uncertainty from dealing with providers.

Lost Wallet Identity Protection — The ProtectMyID Lost Wallet and Card Protection protects members' credit, charge, debit, ATM and medical cards in the event that they are lost, stolen or misused.

Alerts — These inform members quickly when medically related collection actions occur. Forty-six percent of respondents learned of the medical identity theft from a collection letter. This number is up from 40 percent in 2010.

About the study
Fieldwork for this research was concluded in January 2011. More than 1,672 consumers in the United States participated in this study, completing a Web-based survey. Of these, 718 have been victims of identity theft. Fifty-one percent of respondents have private insurance, and 21 percent have Medicare or Medicaid. Fifty percent have a college or advanced educational degree.

About The Ponemon Institute®
The Ponemon Institute is dedicated to advancing responsible information and privacy management practices in business and government. To achieve this objective, the Institute conducts independent research, educates leaders from the private and public sectors, and verifies the privacy and data protection practices of organizations in a variety of industries.

About Experian's ProtectMyID
ProtectMyID™ is a leading, full-service provider of identity theft detection, protection and fraud resolution. ProtectMyID offers comprehensive identity theft protection products supported by experienced identity theft resolution professionals who deliver personal attention that customers can rely on. ProtectMyID.com is a Website owned by ConsumerInfo.com, Inc., an Experian company.

For more information about how ProtectMyID helps consumers protect themselves against identity theft, please visit http://www.protectmyid.com/.

About Experian
Experian® is the leading global information services company, providing data and analytical tools to clients in more than 90 countries. The company helps businesses to manage credit risk, prevent fraud, target marketing offers and automate decision making. Experian also helps individuals to check their credit report and credit score and protect against identity theft.
Experian plc is listed on the London Stock Exchange (EXPN) and is a constituent of the FTSE 100 index. Total revenue for the year ended March 31, 2010, was $3.9 billion. Experian employs approximately 15,000 people in 40 countries and has its corporate headquarters in Dublin, Ireland, with operational headquarters in Nottingham, UK; Costa Mesa, California; and Sao Paulo, Brazil.
For more information, visit http://www.experianplc.com/.
Experian and the Experian marks used herein are service marks or registered trademarks of Experian Information Solutions, Inc. Other product and company names mentioned herein are the property of their respective owners.
(1) Study was conducted in January 2011 by The Ponemon Institute.
(2) Data extrapolated from survey respondents and current U.S. population multipliers.
Contact:              
Matt Lifson           
Edelman PR            
1 323 202 1047        
matthew.lifson@edelman.com            
              
Becky Frost           
Experian Consumer Direct              
1 9495676594          
bfrost@experianconsumerdirect.com