Monday, February 14, 2011

Healthcare Social Media Sites Neglect Privacy Protections

Analysis of diabetes sites indicates that many lack scientific accuracy and put users' personal information at risk.

By Nicole Lewis,  InformationWeek Feb. 14, 2011

As the Internet in general and social networking in particular are used as a point of reference for gathering and sharing health information, a study that examined 10 diabetes-focused social networking sites has found that the quality of clinical information, as well as privacy policies, significantly varied across these sites.

The study, "Social but safe? Quality and safety of diabetes-related online social networks," was conducted by researchers in the Children's Hospital Boston informatics program who performed an in-depth evaluation of the sites and found that only 50% presented content consistent with diabetes science and clinical practice.

The research, published in late January in the Journal of the American Medical Informatics Association, also revealed that sites lacked scientific accuracy and other safeguards such as personal health information privacy protection, effective internal and external review processes, and appropriate advertising.

For example, misinformation about a diabetes cure was found on four moderated sites. Additionally, of the nine sites with advertising, transparency was missing on five, and ads for unfounded cures were present on three. Technological safety was poor, with almost no use of procedures for secure data storage and transmission.

The study found that only three sites support member controls over personal information. Additionally, privacy policies were difficult to read and only three sites (30%) demonstrated better practice, wrote the study's authors.

Elissa R. Weitzman, lead author of the study and assistant professor at Harvard Medical School, told InformationWeek that she was surprised at the high use of online health-related social networking among people with diabetes, and noted that the healthcare community and key stakeholders at these sites should implement policies to protect member privacy and align site content with medical science and clinical practice.

"Exchanging information on these sites has the potential to accelerate what we know about this disease and to rapidly disseminate vital information and support. However, the spread of information throughout online communities poses a safety concern for patients," Weitzman observed. "I'm surprised that the clinical healthcare system seems to be lagging behind patients and consumers in engaging with this medium and finding ways to support them, synergistically -- without trying to replace or control them."


"I think a sustainable standard for how these communities operate with respect to privacy, security, and honesty will come about because the communities themselves and their users will adopt and enforce norms of transparency and protection," Weitzman predicted. "One way this could happen is for stakeholders of these sites to develop a system of 'peer review' around these issues to support better or best practices."

The study evaluated diabetes Web sites that appeared prominently in Google searches and allowed members to create personal profiles and interact with each other. The study examined four key factors:

-- agreement of content with diabetes science and clinical practice standards,
-- practices for auditing content and supporting transparency,
-- accessibility and readability of privacy policies, and
-- the degree of control members had over the sharing of personal data.

The average number of members per Web site was 6,707. Activity ranged widely among the sites, from over 100 new posts per day to less than 5 new posts per day.

Other findings were that the majority of sites did not include a "disclaimer" encouraging patients to discuss their care regimen with a healthcare provider. Several sites did not post essential diabetes information, such as the definition of "A1c" -- a biomarker commonly used by diabetics to access blood glucose levels.

In addition to recommending improvements in these areas, the authors saw a need for increased moderation, for the credentials of moderators to be more visible, and for periodic external review. Further, potential conflicts of interest -- such as ties to the pharmaceutical industry -- needed to be more clearly disclosed, and privacy policies easier to understand.

Weitzman is an assistant professor in the laboratory of Kenneth Mandl, who also co-authored the study. Last year the two developed an application for the social networking website TuDiabetes that allows users to submit their A1c levels to be displayed in a worldwide map, as part of an effort to encourage diabetes management and inform public health efforts and research.

Researchers said they chose to study diabetes-related networks because they were among the earliest to emerge and remain among the most active. The research team in the Children's Hospital informatics program will further study how these sites are used -- how people choose to interact with them and how specifically they share their medical information.
Weitzman also said the Web is a notoriously difficult sphere to regulate with respect to issues of privacy, information security, and honesty in advertising, but said she is hopeful that these sites will improve.

California Supreme Court Finds that ZIP Codes Are Personal Identification Information Under Song-Beverly Act

Posted at 3:14 PM on February 14, 2011 by Hunton & Williams LLP

California Supreme Court Finds that ZIP Codes Are Personal Identification Information Under Song-Beverly Act

On February 10, 2011, the California Supreme Court ruled in Pineda v. Williams-Sonoma Stores, Inc. that ZIP codes are “personal identification information” under the state’s Song-Beverly Credit Card Act of 1971 (the “Credit Card Act”).  This finding effectively prohibits California businesses from requesting and recording cardholders’ ZIP codes during credit card transactions.

When the plaintiff made a purchase by credit card at the defendant retailer, a cashier requested her ZIP code and she provided it, believing that it was necessary to complete the transaction.  The plaintiff alleged that the store then used her name and ZIP code to locate her home address, which it added to a marketing database. 

The Court of Appeals affirmed the trial court’s dismissal of the claim, holding that a ZIP code, without more, does not constitute personal identification information under the Credit Card Act.  The California Supreme Court reversed and remanded.

The Court first looked to statutory construction in its analysis of whether ZIP codes constitute personal identification information.  The Credit Card Act defines personal identification information as “information concerning the cardholder, other than information set forth on the credit card, and including, but not limited to, the cardholder’s address and telephone number.” 

The Court found that the word “address” in the statute should be construed as encompassing not only a complete address, but also its components.  Furthermore, the Court rejected the lower court’s conclusion that a ZIP code is not personal identification information because it pertains to a group, rather than a specific individual.  The Court found that ZIP codes are like addresses or telephone numbers in that such information is “unnecessary to the sales transaction” and “alone or together with other data such as a cardholder’s name or credit card number, can be used for the retailer’s business purposes.” 

The Court noted that this interpretation is also consistent with the Credit Card Act’s provision which allows businesses to require the cardholder to provide a form of identification, such as a driver’s license, “provided that none of the information contained thereon is written or recorded.”

In addition to examining the statute’s provisions, the Court reviewed the legislative history of the Credit Card Act.  The Court found that the California Legislature “intended to provide robust consumer protections by prohibiting retailers from soliciting and recording information about the cardholder that is unnecessary to the credit card transaction.”  A primary issue motivating the creation of the statute was how retailers acquired additional personal information, unnecessary to the transaction, to build mailing and telephone lists for its in-house marketing or to sell or others.  Later amendments of the statute prohibited businesses from recording information in consumers’ provided identification; the purpose of which was to prevent retailers from matching this information with the consumer’s credit card number.

The Court rejected the defendant’s argument that its construction of the Credit Card Act violates due process, and found that a broad interpretation of the Credit Card Act did not render the statute unconstitutionally vague because the law includes adequate notice of prohibited conduct.

Trackbacks (0) Links to blogs that reference this article Trackback URL

http://www.huntonprivacyblog.com/admin/trackback/239896


Comments (0) Read through and enter the discussion with the form at the end
© Hunton & Williams LLP 2011 - ATTORNEY ADVERTISING. Case results depend upon a variety of factors unique to each case. Case results do not guarantee or predict a similar result in any future case.
Unless otherwise noted, attorneys not certified by the Texas Board of Legal Specialization.

Friday, February 11, 2011

Civil rights office seeks review of privacy rule

       
The Office for Civil Rights at HHS has sent to the White House Office of Management and Budget for review a new privacy rule covering an expanded requirement that healthcare providers track and be able to report to patients any disclosures of their medical records.

Patients have long had limited rights under the privacy provisions of the Health Insurance Portability and Accountability Act of 1996 to demand that providers and other “covered entities” provide them with an accounting of disclosures of their personally identifiable medical information.

The American Recovery and Reinvestment Act of 2009, however, expanded patients' privacy rights and closed a HIPAA exemption that covered entities were not required to audit and account for disclosures for treatment, payment and a broad, catch-all category known as other “healthcare operations,” if the covered entity uses an electronic health-record system. The ARRA eliminated that exemption and the new rule before the OMB provides language to implement the rule change. Patients can demand an accounting of disclosures going back three years from the date the demand is made. The accounting requirement also applies to business associates of covered entities.

In a May 3, 2010, request for
public comment on the disclosure rules (PDF), the Office for Civil Rights at HHS noted that the new rule would require covered entities who have acquired an EHR after Jan. 1, 2009, to comply with the new accounting requirement by Jan. 1, 2011, unless the OCR extends the deadline, which is allowed but only no later than 2013. - Joseph Conn    

Thursday, February 10, 2011

FTC Commissioner: If Companies Don't Protect Privacy, We'll Go To Congress

As the FTC gathers comments on its proposed privacy rules, including a “Do Not Track” proposal, FTC Commissioner Julie Brill told a crowd of privacy researchers and policy wonks gathered at UC Berkeley that her agency was willing to go to Congress if online advertisers and analytics companies don’t clean up their act.

While Do Not Track has become a buzz phrase that has been getting a lot of attention, there’s more that’s needed beyond implementing a good no-tracking option, Brill said. First, companies need to start considering “privacy by design.” That means that companies building new products need to think about privacy from the get-go, not just “retrofitting” privacy features once there’s a problem. Online companies also need to think about collecting less information about their users and holding it for a shorter period of time, Brill added. That’s a suggestion that puts the FTC in direct conflict with the data-retention policies desired by the Department of Justice and law-enforcement agencies.

Second, privacy choices need to be simplified for consumers. Privacy policies are too cluttered and confusing, and tend to be full of information that’s barely relevant to the consumer. For example, an online shopper already knows that his address will be shared with FedEx or another shipper when he buys something.

Privacy policies need to address the collection of the data itself, not just how the data is used. For example, plenty of companies, such as ad networks, are holding large amounts of consumer data and could stop using it for behavioral advertising if consumers opt out. But they might be less willing to not collect the info at all. That’s because they can still sell or share that data with others.

Finally, data practices need to be transparent. Not only should consumers know what kind of data companies are collecting about them, but the FTC is actually proposing that consumers should get access to that data, Brill said.

While the commission originally called for an approach that involved a persistent “header” alerting websites to the data-collection preferences of users who visit those sites—exactly the mechanism that Mozilla just unveiled in its new Firefox browser—the FTC is open to considering other strategies, she said. 

Brill also addressed a question she’s been getting frequently: what does she think about industry response to the FTC privacy report so far? Her answer: It’s nice to be getting some reaction at all. The commission called for industry to self-regulate back in February of 2009, she noted. “Industry has been kind of slow to deal with this issue… We’ve been very pleased that since we released our report two months ago, we seemed to have caught industry’s attention now.”

If the self-regulation proposals coming in aren’t sufficient to protect consumers, “we will ask Congress to take up the issue,” Brill concluded.

http://paidcontent.org/article/419-ftc-commissioner-if-companies-dont-protect-privacy-well-go-to-congress/

Monday, February 7, 2011

Survey: The best privacy advisers of 2010

This year's survey finds law firms still tops

Jay Cline  Computerworld  February 3, 2011
 
Who are the best people and firms at providing privacy advice? It's a question I've been asking since 2006, before privacy was cool. Since then, a plethora of new privacy rules and penalties and a tsunami of new technologies and risks have placed privacy among the top handful of corporate concerns. Doing privacy wrong now takes a bigger bite off the bottom line than it did when I first started asking this question. So have the answers changed?

Not when the question is which type of outside privacy practice you prefer. Lawyers are still the top choices, with law firms grabbing six of the top 10 spots in the survey. And for the fourth consecutive time, Hunton & Williams garnered the most votes. This may be a case of success breeding more success: Hunton attracted more than twice as many votes as its nearest challenger.

Second-place Morrison & Foerster still is highly regarded, followed by Foley & Lardner and Privacy & Information Management Services. Hogan Lovells and Covington & Burling round out the law firms ranking in the top 10 of all firms.

What does this say about the corporate privacy agenda? Two things, I think: Regulatory compliance is still the first step to take for many companies, and the firms that were the best at assisting with this first step five years ago are still the go-to destinations for in-house privacy officers.

Other firms gaining ground
Even though law firms took six of the top 10 places, that was down from the last survey, in 2008, when they accounted for eight spots. Indeed, consulting firms now account for half of the top 12.

Which were the top consultancies? As in past years, it was a mix of large audit and accounting firms, such as PriceWaterhouseCoopers and Ernst & Young, and boutique shops.

The stronger showing of consultancies may reflect the emerging consensus in the privacy profession that doing privacy right is bigger than regulatory compliance. Particularly for industries such as healthcare and technology, which involve an intensive use of personal information, creating privacy-friendly products and services involves meeting customer and social expectations. "Organizations need to 'do' privacy better, faster and cheaper," noted Brian Tretick, managing director for Athena Privacy, a new boutique firm. "That means more formal, repeatable processes, automation and active monitoring."

The survey also showed that firms may be looking for services beyond traditional advice from experts. New entrants to the list of top vote-getters include service providers, a certification firm and a professional association. Among them:

• San Francisco-based Truste is the provider of the popular Web-privacy seal and a number of other privacy-verification products and services.
• Portland, Ore.-based ID Experts and Austin-based Debix provide data-breach response services.
• Toronto-based Nymity provides an information portal for privacy content.
•Seattle-based MediaPro offers computer-based training for privacy and security.

The International Association of Privacy Professionals organizes the best-attended privacy conferences and offers the CIPP certification for the privacy profession.

Friday, February 4, 2011

Shiny Objects

Rep. Speier to introduce 'do not track' bill next week

By Sara Jerome -    The Hill   02/03/11 03:02 PM ET

Rep. Jackie Speier (D-Calif.) plans to introduce an online privacy bill next week directing the Federal Trade Commission (FTC) to begin a "do not track" program for online advertisers, a Speier aide told The Hill. 

The program would enable consumers to "opt out" of tracking by online advertisers. The aide said the bill is narrowly tailored to address tracking issues only, rather than the broader question of online privacy. It provides a floor, rather than a ceiling, for privacy law, so it does not pre-empt additional legislation in the future.

Speier's office worked with a host of pro-privacy groups on the bill, including Consumer Watchdog, the Consumer Federation of America, Consumers Union and the Electronic Frontier Foundation, among others. 

Rep. Bobby Rush (D-Ill.) is also planning to reintroduce his privacy bill next week. His bill does not include a "do not track" mechanism; however, it provides a safe harbor for marketers who participate in such a federal program if one is created. Speier's bill does not include a safe harbor. 

The FTC released its own privacy report last year, throwing its weight behind a "do not track" system. David Vladeck, the FTC consumer protection director, told Congress in a December hearing that "do not track" legislation could help protect consumers, since many are unaware they are being tracked. It might also simplify individuals' efforts to keep their online data private. 

In Europe, a Right to Be Forgotten Trumps the Memory of the Internet

Why is it that two sprawling yet similar Western cultures -- those on both sides of the Atlantic -- respond so differently to Internet privacy?

A quarter-century after coming to the United States, Franz Werro still thinks like a European. The 54-year-old Georgetown law professor, born and raised in Switzerland, is troubled when ads in French automatically pop up on his American laptop. The computer assumes that's what he wants. We live naked on the Internet, Werro knows, in a brave new world where our data lives forever. Google your name, and you'll stumble onto drunken photos from college, a misguided quote given to a reporter five years ago, court records, ancient 1 a.m. blog comments, that outdated Friendster profile ... the list goes on, a river of data creating a profile of who you are for anyone searching online: friend, merchant, or potential future employer. Werro's American students rarely mind.

But America is not Europe, and despite our no-secrets age of WikiLeaks, Europe wants to enshrine a special form of privacy into law. Individuals should, according to many in Europe, possess what they call a "right to be forgotten" on the Internet.

How do you create a space where we're free to analyze the data but not free to abuse the data? We've been asking the wrong questions.

How would this even be possible? This developing right, authorities in several European countries suggest, would allow an individual to control and sometimes eliminate his or her data trail and allow him or her to ask Google to remove select search results -- a newspaper article, say, which once painted him or her in a bad light. A look at recent news events guarantees that this right will only become more relevant in 2011.

On January 19, Google refused Spain's request that the ubiquitous, California-based search engine remove 90 links. Many of the links Spain wanted to remove included newspaper articles and information from public record, often painting the plaintiffs in a bad light. Google called Spain's request "disappointing" in its official statement and emphasized that as a search engine, it should not be responsible for curating Internet content. Removing links would be expensive, Google argued in court, and violate the "objectivity" of the Internet search. Last November, the European Union announced data protection goals for 2011, which include "clarifying the so-called 'right to be forgotten', i.e. the right of individuals to have their data no longer processed and deleted when they are no longer needed for legitimate purposes" (PDF).

The EU explicitly said that users should have the right. It has already been heavily discussed and praised in countries such as France, whose President Sarkozy said last year: "Regulating the Internet to correct the excesses and abuses that come from the total absence of rules is a moral imperative!" France's leadership at the coming G8 summit also signifies more dialogue, as Sarkozy hopes to discuss the right on an international stage.

These European concerns rarely come up in the United States. People may worry about Facebook's privacy settings, but few would suggest an individual has a right to remove an offending Gawker post from Google's index. After all, who decides? A person might want an embarrassing photo removed from record, but what if the photo features not only that person but four others? The question of censorship is inevitable. The closest manifestation on this side of the Atlantic is likely a paper from the ACLU lobbying for a "right to delete" (PDF). Why, then, have our two sprawling yet similar Western cultures responded so differently to Internet privacy?

In Europe, the idea that privacy should overrule free expression is nothing new. Professor Franz Werro keenly highlights the historical difference in a 2009 academic paper and points to a 1983 case in Switzerland. Swiss TV had planned to air a documentary about a criminal from the 1930s. Swiss law, however, forbade the airing of the program -- the European court "held that the documentary would unjustifiably violate plaintiff's privacy right to keep his feelings as a son from being trampled." Yale law professor James Whitman sees the differing concepts of privacy as a battle between liberty and dignity (here, the PDF of his 2004 journal article).

Transatlantic clashes over privacy in recent years have included the use of Google's Street View in Germany, Switzerland, the Czech Republic, and elsewhere. German criminals sued Wikipedia in 2009 to have their names scrubbed. A little less than a year ago, an Italian court successfully sued Google for allowing a user to post offensive video. The fact that many of the Internet companies such as Facebook and Google are located in the United States (where, as Werro says, there is "fetishization" of the constitutional First Amendment of free speech) creates deeper problems in the courtroom, as it did in Google's recent refusal in Madrid.

American companies favor American law if possible, no matter what country they operate in. In Europe, the courts balance a right to a free press with rights of privacy, of personality, and of dignity, protected in Article 8 of the European Convention on Human Rights. In America, the implicit right to privacy always fell flat when running against the Supreme Court's fidelity to the First Amendment.

A right to be forgotten raises practical concerns as well as theoretical. "It's almost absurd to say we have the right to disappear from public domain," said Martin Abrams, a policy director with leading global privacy think tank Hunton & Williams. "We're really talking about the right not to be observed in the first place.... We've been focused on symptoms rather than the underlying issues."

"The Americans run their show, but can they impose their rights on the rest of the planet?

Abrams is far from enthusiastic about Europe's proposed right to be forgotten -- he'd rather people focus on what he considers the real issues of Internet accountability and the increasingly popular notion of "data stewardship" among corporations. Data will inevitably be out there, Abrams believes, and what matters now is a dialogue about how to retire certain data. There is great value, he emphasizes, in using Internet data to model the future and permit innovation -- he brings up positive examples of this, such as Google-supported HealthMap, which tracks infectious diseases around the globe by synthesizing public data. You can't go west and not be known anymore, Abrams believes, but we can move beyond a "rhetoric hump" and reach a more realistic and practical level of dialogue on data responsibility.

"How do you create a space where we're free to analyze the data but not free to abuse the data?" Abrams considers. "We've been asking the wrong questions."

And why is Europe asking questions about the right? Because, Abrams said, Europe is used to legally processing all its data, whereas America grants far more permissive rights of observation of behavior and its data -- which, when extended to the Internet, affect how companies observe and model our activity. The Europeans resist this digital observation without consent. But the European model runs strongly against American traditions of free press and expression. Up until now, the fight for the right to be forgotten has remained largely within the province of Europe. That can't last forever though -- especially given how many global Internet titans remain based in the U.S.

"The Americans run their show," Werro said, "but can they impose their rights on the rest of the planet?" Europeans are, Werro continues, equally sensitive to the use of personal images and especially the "merchantability" of personal data by corporations. A European sensibility would not, he added, easily accept the invasion of privacy that occurs so frequently in American media. He brings up Fox News, which to keep coverage of the Eliot Spitzer scandal alive, chased after the prostitute-in-question's grandfather at 9 p.m. on a Saturday.

Yet on both continents the discussion of Internet privacy is evolving. In December, the U.S. Department of Commerce recommended establishing a Privacy Policy Office, its potential role "acting as both a convener of diverse stakeholders and a center of Administration commercial data privacy policy expertise" to address what it calls "a continuum of risks to personal privacy" (PDF). Another U.S. goal is to establish "global privacy interoperability" to reduce the friction and costs American companies have been incurring as they face the "omnibus privacy laws" adopted in the European Union. In late January, both Google and Mozilla presented people with an option to opt out of being tracked online for advertising purposes.

These basic privacy concerns are universal, but the right to be forgotten -- and the potential precedent its adoption could set -- takes the concern over privacy many steps further. As in Madrid this January, the European sensibility is colliding in powerful ways directly with U.S.-based, transnational corporations bred on American values of both expression and profit. The fight is hardly over.

"I wonder at times," Werro said, "if this conception of privacy in Europe could be wiped out."

http://www.theatlantic.com/technology/archive/2011/02/in-europe-a-right-to-be-forgotten-trumps-objectivity-of-the-internet/70643/