I've been meaning to blog this once since I saw it a couple of weeks ago: Perlegen Sciences, a spinoff of Affymetrix and a "recognized leader in genomics" (by their own lights) recently signed a deal with an electronic medical records (EMR) company for rights to the medical data of 4 million patients. According to the Perlegen press release, the data will be mined for "genetic markers that could help predict patient response to certain treatments." Patients who meet defined criteria will be sought--through their personal physicians, no less--to obtain samples of their DNA.
The EMR company isn't identified--a smart PR decision, I'm sure--but they will receive subscription and program fees, as well as "milestone payments" for new products that are developed as a result of the collaboration.
I hardly know where to start with this. First, patients' records are being provided, without consent, to a third party. Not for the common good, but for corporate profit. The EMR company will supposedly not share patients' identities with Perlegen--just their records--but it's unclear what happens down the road with genetic information (which is, as I have mentioned here before, not capable of being wholly de-identified). The fact that physicians are being recruited into this process as well--and that they will presumably get their cut--is problematic. The more old-fashioned among us still think that doctors have a fiduciary responsibility to patients that would preclude this kind of behavior.
All this money will likely come from pharmaceutical companies that are vying to produce tailored drugs. When the drugs hit the market, you can bet that the patients whose records were used will not be receiving a price break.
The final straw? The EMR company is not named, and won't be--so patients have absolutely no recourse or ability to opt out of this project.
*******
Edited to add this link to a story on Pharmacogenomics Reporter and another from Healthcare IT News. Apparently I'm not the only person who has a problem with this development: Patient Privacy Rights doesn't like it either.
Showing posts with label privacy rights. Show all posts
Showing posts with label privacy rights. Show all posts
Tuesday, April 08, 2008
Friday, March 07, 2008
The Right to Be Sick...and Private
In our youth we proclaim and revel in our seemingly never-ending vitality and "immortality".As a cub reporter many, many years ago, I felt pretty hardy working on stories until 5 in the morning--working almost a full 12 hours several days a week, and simply leaving the newsroom to go home for a quick shower, change of clothes, bite to eat and refreshing of makeup, to return and do the very same thing the next day. Abusing myself on less than 2 hours of sleep 3 days out of 7 made me feel exclusive and "special". I boasted to colleagues about never being ill with colds or flu, or even getting tired. My work kept me energized too busy to worry about missing days of work. One week I spent 8 hours in below zero cold, in mid-January Philadelphia, doing man-on-the-street interviews with Diane Sawyer, until my fingers were blue. Aah, the good old days...
Today, I have to be careful that some of the life challenges I've been forced to face, don't cause me to get depressed--because to get depressed, for me, means a sore throat, lowered metabolism, little energy, headaches, muscle aches and--if it continues--general malaise erupts into major gum infections, and an arthritic flare that requires bed rest and just gets steadily worse. News one would never share with a potential employer.
The question I pose in this post, however, is how much of the information about the illnesses we harbor is private information, not the business of employers or potential employers?
When does an employer desiring to know, or deciding to penalize an employee who either has a certain illness, or requires certain provisions because of an illness (not considered a disability), cross the line of violations of privacy? When does an employer or co-workers truly "need to know"?
Read the entire article in the NYT here:
Tuesday, March 04, 2008
How Private is Private? Is Google a covered entity?
Back in 1996, the Health Insurance Portability and Accountability Act (HIPAA) was enacted by Congress for the purposes of ensuring continuity of healthcare benefits for workers changing or losing their jobs (Title 1) and to establish national standards (Title 2) for electronic health care transactions, maintenance of privacy about so-called protected health information (PHI) and security of that information maintained in electronic repositories (e.g. hospital information systems and other data bases).
Since the actual implementation of the Privacy and Security Rules in 2003, there have been considerable efforts on the part of healthcare organizations (providers, health plans and so-called healthcare clearing houses) to develop policies and procedures which adhere to federal law while still carrying out patient care effectively as well as managing clinical research productively. Of course, nothing is perfect and there have been a plethora of papers and media articles on the barriers to patient care (Gross 2007) and to important large population based clinical research (Armstrong, Kline-Rogers et al. 2005; Wolf and Bennett 2005; Wilson 2006). Further, the security of PHI is not so great either (Freudenheim and Pear 2006).
Therefore, health insurance might be portable for some workers, but PHI is not!
With all the recent hoopla about Microsoft wanting to purchase, somewhat hostilely, Yahoo in order to “corner” the market on search engines, it might have been easy to overlook 10 second sound bites on the morning radio news, or the little technology tidbit in the New York Times (Lohr 2008) which was NOT on the front page.
So it seems that Google actually will scoop Microsoft in implementing a web based interface with a major healthcare system, in this case the Cleveland Clinic with its some 100,000 patients. The deal is, if one has a Google e-mail account, one can use the same sign-in and password to access and transmit one’s medical records. Apparently, the pilot phase will involve only some “innocuous” data such as allergies and prescription records. However, prescription records can certainly allow inferences about underlying health conditions for specific patients which, if leaked, could have problematic consequences. Funny how Google mail accounts are encryption proof (Stone 2007) to corporate electronic security walls. Does that provide some clues as to how undone PHI privacy could become?
And what about HIPAA? There is some debate about whether Google could be considered a healthcare clearing house or other entity which information repositories containing people’s PHI would be considered protected and would have an obligation to protect under current federal regulations. The World Privacy Forum (Gellman 2008) thinks not.
Other dicey questions: will Google patients be subject to advertising spam or other intrusive advertisement adduced from their prescription lists? What guarantees that the “client” (read patient lists) won’t be sold to Pharma companies as yet another means of developing data bases about physician prescribing patterns? Who is going to regulate these issues? Google is a great search engine—I use it all the time! But I’m not sure I want to use it to manage my healthcare information. I’d rather continue to keep it on my PDA!
Armstrong, D., E. Kline-Rogers, et al. (2005). "Potential impact of the HIPAA privacy rule on data collection in a registry of patients with acute coronary syndrome." Archives of Internal Medicine 165(10): 1125-1129.
Freudenheim, M. and R. Pear (2006). Health hazard: computers spilling your history. New York times. New York.
Gellman, R. (2008). Personal health records: why many PHRs threaten privacy, The World Privacy Forum.
Gross, J. (2007). Keeping patients' details private, even from kin. New York Times. New York.
Lohr, S. (2008). Google Health begins its preseason at Cleveland Clinic. New York Times. New York.
Stone, B. (2007). Firms fret as office e-mail jumps security walls. New York Times. New York.
Wilson, J. F. (2006). "Health insurance portability and accountability act privacy rule causes ongoing concerns among clinicians and researchers." Annals of Internal Medicine 145(4): 313-316.
Wolf, M. S. and C. L. Bennett (2005). "Local perspective of the impact of the HIPAA privacy rule on research." Cancer 106(2): 474-479.
Since the actual implementation of the Privacy and Security Rules in 2003, there have been considerable efforts on the part of healthcare organizations (providers, health plans and so-called healthcare clearing houses) to develop policies and procedures which adhere to federal law while still carrying out patient care effectively as well as managing clinical research productively. Of course, nothing is perfect and there have been a plethora of papers and media articles on the barriers to patient care (Gross 2007) and to important large population based clinical research (Armstrong, Kline-Rogers et al. 2005; Wolf and Bennett 2005; Wilson 2006). Further, the security of PHI is not so great either (Freudenheim and Pear 2006).
Therefore, health insurance might be portable for some workers, but PHI is not!
With all the recent hoopla about Microsoft wanting to purchase, somewhat hostilely, Yahoo in order to “corner” the market on search engines, it might have been easy to overlook 10 second sound bites on the morning radio news, or the little technology tidbit in the New York Times (Lohr 2008) which was NOT on the front page.
So it seems that Google actually will scoop Microsoft in implementing a web based interface with a major healthcare system, in this case the Cleveland Clinic with its some 100,000 patients. The deal is, if one has a Google e-mail account, one can use the same sign-in and password to access and transmit one’s medical records. Apparently, the pilot phase will involve only some “innocuous” data such as allergies and prescription records. However, prescription records can certainly allow inferences about underlying health conditions for specific patients which, if leaked, could have problematic consequences. Funny how Google mail accounts are encryption proof (Stone 2007) to corporate electronic security walls. Does that provide some clues as to how undone PHI privacy could become?
And what about HIPAA? There is some debate about whether Google could be considered a healthcare clearing house or other entity which information repositories containing people’s PHI would be considered protected and would have an obligation to protect under current federal regulations. The World Privacy Forum (Gellman 2008) thinks not.
Other dicey questions: will Google patients be subject to advertising spam or other intrusive advertisement adduced from their prescription lists? What guarantees that the “client” (read patient lists) won’t be sold to Pharma companies as yet another means of developing data bases about physician prescribing patterns? Who is going to regulate these issues? Google is a great search engine—I use it all the time! But I’m not sure I want to use it to manage my healthcare information. I’d rather continue to keep it on my PDA!
Armstrong, D., E. Kline-Rogers, et al. (2005). "Potential impact of the HIPAA privacy rule on data collection in a registry of patients with acute coronary syndrome." Archives of Internal Medicine 165(10): 1125-1129.
Freudenheim, M. and R. Pear (2006). Health hazard: computers spilling your history. New York times. New York.
Gellman, R. (2008). Personal health records: why many PHRs threaten privacy, The World Privacy Forum.
Gross, J. (2007). Keeping patients' details private, even from kin. New York Times. New York.
Lohr, S. (2008). Google Health begins its preseason at Cleveland Clinic. New York Times. New York.
Stone, B. (2007). Firms fret as office e-mail jumps security walls. New York Times. New York.
Wilson, J. F. (2006). "Health insurance portability and accountability act privacy rule causes ongoing concerns among clinicians and researchers." Annals of Internal Medicine 145(4): 313-316.
Wolf, M. S. and C. L. Bennett (2005). "Local perspective of the impact of the HIPAA privacy rule on research." Cancer 106(2): 474-479.
Labels:
Google,
healthcare,
HIPAA,
patient data,
patient rights,
privacy rights
Wednesday, February 06, 2008
News: Kansas Court Blocks Records Request
The Kansas Supreme Court has temporarily ruled on an appeal filed by Dr. George Tiller's attorneys, blocking the grand jury from obtaining semi-redacted medical records of patients that had late-term abortions.
Tiller's attorneys had asked that the court squash the subpoenas and disband the jury, primarily citing serious concerns about patients' privacy, and the power and reach of the Kansas grand jury system. The Center for Reproductive Rights of New York has filed a second petition with the court, also asking that the case be dismissed on behalf of the patients affected by the records subpoena, again citing patient privacy laws and expectations of medical privacy.
The spokeswoman for Kansas For Life, one of the groups behind the grand jury formation, has said that the ruling is extremely disappointing and that
-Kelly
Tiller's attorneys had asked that the court squash the subpoenas and disband the jury, primarily citing serious concerns about patients' privacy, and the power and reach of the Kansas grand jury system. The Center for Reproductive Rights of New York has filed a second petition with the court, also asking that the case be dismissed on behalf of the patients affected by the records subpoena, again citing patient privacy laws and expectations of medical privacy.
The spokeswoman for Kansas For Life, one of the groups behind the grand jury formation, has said that the ruling is extremely disappointing and that
there is no way to determine if the reasons for these late abortions were done within the narrow legal criteria without looking at the records themselves. His lawyers say they are worried about women's privacy. They are worried about protecting Dr. Tiller.Those presiding over the grand jury have until February 11 to file their objections with the Kansas Supreme Court, who then plan on issuing a ruling by the end of February.
-Kelly
Friday, February 01, 2008
Kansas Abortion Provider Ordered to Turn Over Medical Records
What do you consider identifying personal data in your medical records? It's not a trick question, but a genuine one based on the ruling, earlier this week, that a Kansas abortion provider must turn over 2,000 patient records - the records of all women who have had late term (21 weeks or later) abortions in the past five years.
In Kansas, citizens have a right, based on an obscure 19th century law, to convene grand juries when they feel the government isn't enforcing a law. As far as I can trace back, the two citizen subpoena's are based on two separate laws that Kansas for Life feels are not being enforced, and that these records are necessary to prove it. The first law requires reporting sexual abuse in minors (and they argue that 11 and 12 year old's are receiving late term abortions without the 'abuse' being reported), while the second prohibits late term abortions unless they are medically necessary.
In other words, it's a wide dragnet to investigate abortion in Kansas.
Now, to be clear, I'm not basing this conclusion on who is behind the subpoena, or even the stated goals of the prosecuting attorneys. I'm basing it on the argument that they are looking for signs of abuse, or medical necessity - in health records that are supposedly going to be redacted of name, age, and identifying medical history.
If you take away name, age, and identifying medical history - exactly what do you have left, that allows the investigation of either of these laws that Kansas for Life says are not being enforced?
Further indications that this is a wide dragnet hidden behind other laws is the fact that they also want the records of any woman who was 22 or more weeks pregnant who came in and even consulted about an abortion, even if she didn't have one. Where's the necessary information here in enforcing laws? I can't see one - and the request is construed broadly enough that it sounds as if even mentioning abortion (even to say "well, I know it's an option because the fetus has XYZ problem, tell me more about it... mm, I don't think that's for me, but thanks") is enough to flag your record.
So the question then becomes - can you truly redact medical records that will remove personal and identifying information, and still leave meaningful data that will tell them what they want to know about abortions in Kansas? Your medical history is a map across your body, building a record that's unique to each individual. Every scar I have leads the way to a story, every surgery, every break and set of bone, every time my lungs decide to stop working. Every medication taken is a marker along the path, all of which will build to create a single individual.
Yes, in theory Tiller, the abortion provider, will be passing these files to another doctor and attorney to independently review and redact. But I remove identifying data from papers all the time, and I know how easy it is to miss just a single word that clearly flags who the person is. Attempting to redact 2,000 medical records in 68 days? The magnitude of error possible is staggering.
As of yesterday, Tiller's attorneys have filed an appeal to the Kansas Supreme Court, and refused to hand over any files until after the Supreme Court makes their ruling.
-Kelly
In Kansas, citizens have a right, based on an obscure 19th century law, to convene grand juries when they feel the government isn't enforcing a law. As far as I can trace back, the two citizen subpoena's are based on two separate laws that Kansas for Life feels are not being enforced, and that these records are necessary to prove it. The first law requires reporting sexual abuse in minors (and they argue that 11 and 12 year old's are receiving late term abortions without the 'abuse' being reported), while the second prohibits late term abortions unless they are medically necessary.
In other words, it's a wide dragnet to investigate abortion in Kansas.
Now, to be clear, I'm not basing this conclusion on who is behind the subpoena, or even the stated goals of the prosecuting attorneys. I'm basing it on the argument that they are looking for signs of abuse, or medical necessity - in health records that are supposedly going to be redacted of name, age, and identifying medical history.
If you take away name, age, and identifying medical history - exactly what do you have left, that allows the investigation of either of these laws that Kansas for Life says are not being enforced?
Further indications that this is a wide dragnet hidden behind other laws is the fact that they also want the records of any woman who was 22 or more weeks pregnant who came in and even consulted about an abortion, even if she didn't have one. Where's the necessary information here in enforcing laws? I can't see one - and the request is construed broadly enough that it sounds as if even mentioning abortion (even to say "well, I know it's an option because the fetus has XYZ problem, tell me more about it... mm, I don't think that's for me, but thanks") is enough to flag your record.
So the question then becomes - can you truly redact medical records that will remove personal and identifying information, and still leave meaningful data that will tell them what they want to know about abortions in Kansas? Your medical history is a map across your body, building a record that's unique to each individual. Every scar I have leads the way to a story, every surgery, every break and set of bone, every time my lungs decide to stop working. Every medication taken is a marker along the path, all of which will build to create a single individual.
Yes, in theory Tiller, the abortion provider, will be passing these files to another doctor and attorney to independently review and redact. But I remove identifying data from papers all the time, and I know how easy it is to miss just a single word that clearly flags who the person is. Attempting to redact 2,000 medical records in 68 days? The magnitude of error possible is staggering.
As of yesterday, Tiller's attorneys have filed an appeal to the Kansas Supreme Court, and refused to hand over any files until after the Supreme Court makes their ruling.
-Kelly
Wednesday, January 23, 2008
Should genetic researchers be able to share your DNA?

As promised (or warned--I guess it depends on whether you think this is an interesting issue), here is another thing to think about with regard to genetic biobanking studies.
So: say you've agreed to participate in a research study that is trying to identify whether there is a genetic contribution to breast cancer. In this particular study, the researchers will follow a cohort of women who have not developed breast cancer at the time of enrollment. The researchers will take blood samples and do physical exams periodically. They will also sequence your DNA. As time goes on, some number of women in the study cohort will develop breast cancer, and some won't. The researchers will look at the DNA sequences to see whether there are different patterns in the genetics of the women who develop cancer as compared with those who don't. If they find such patterns, they'll go on to investigate what those specific mutations do.
This kind of research, which is called a genome-wide association study, GWAS for short--because it's looking for associations between genetic patterns and disease--is a lot like a fishing expedition. (You can learn more about these studies in this archived Science Friday audio panel with Ira Flatow.) How GWAS's work has a couple of important implications. One is that, for such studies to work at all, researchers need really big datasets to sift through. Another is that the same dataset could be used for lots of different purposes.
For these reasons, and for efficiency and cost-effectiveness reasons as well, the National Human Genome Research Institute (NHGRI) is trying to develop plans to pool or share such datasets across different projects.
Think back to our breast cancer study example. If you'd consented to participate in that study at your local research university, how would you feel about your (de-identified) information being used by researchers somewhere else? Would you feel that you needed to be offered the chance to opt out of this "wide data sharing?" Or would you feel that your original consent covered such subsequent uses?
Here's another permutation to think about. Say the researchers did the breast cancer study, and in the course of that work they noticed that there seemed to be a correlation between certain genetic patterns and alcoholism or schizophrenia. Would it be ok with you for them to pursue this line of inquiry using your genetic information? Would you feel that you needed to be offered the chance to opt out?
You can read about the NHGRI policy, and the scientific community's reaction, in The Scientist, here. Salon.com ran an article a few years ago about a much smaller open-source approach to genetics, here (which is where the nifty kitty photo came from).
Labels:
biobanking,
DNA,
genes,
genetic mapping,
genetic research,
genetics,
privacy rights
Subscribe to:
Posts (Atom)




