Each week an episode of “The THCB Gang” (this was Episode 3) is streamed live here (below) and is also preserved as a weekly podcast and available on our Itunes & Spotify channels a day or so later. Each week 4-6 semi-regular guests drawn from THCB authors and other assorted old friends of mine will shoot the shit about health care business, politics, practice, and tech. It tries to be fun but serious and informative!
This piece is part of the series “The Health Data Goldilocks Dilemma: Sharing? Privacy? Both?” which explores whether it’s possible to advance interoperability while maintaining privacy. Check out other pieces in the series here.
Early in 2019 the Office of the National Coordinator for Health IT (ONC) and the Centers for Medicare and Medicaid Services (CMS) proposed rules intended to achieve “interoperability” of health information.
In this post we point
out why extending HIPAA is not a viable solution and would potentially
undermine the purpose of enhancing patients’ ability to access their data more
seamlessly: to give them agency over
health information, thereby empowering them to use it and share it to meet
Which is better: sharing access to all health data across platforms so that interoperability is achieved, or protecting some data for the sake of privacy? Health data privacy experts Vince Kuraitis, founder of Better Health Technologies, and Deven McGraw, Chief Regulatory Officer at Ciitzen, are crowdsourcing opinions and insights on what they are calling The Health Data Goldilocks Dilemma. How much data protection is ‘juuuust right’? What should be regulated? And, by whom? The duo talks through their views on the data protection conversation and urge others to join in the conversation via their blog series called, “The Health Data Goldilocks Dilemma,” on The Health Care Blog.
Filmed at the HIMSS Health 2.0 Conference in Santa Clara, CA in September 2019.
This post is part of the series “The Health Data Goldilocks Dilemma: Privacy? Sharing? Both?”
In our previous post, we described the “Wild West of Unprotected Health Data.” Will the cavalry arrive to protect the vast quantities of your personal health data that are broadly unprotected from sharing and use by third parties?
Congress is seriously considering legislation to better
protect the privacy of consumers’ personal data, given the patchwork of
existing privacy protections. For the most part, the bills, while they may
cover some health data, are not focused just on health data – with one
exception: the “Protecting Personal Health Data Act” (S.1842), introduced by
Senators Klobuchar and Murkowski.
In this series, we committed to looking across all of the
various privacy bills pending in Congress and identifying trends,
commonalities, and differences in their approaches. But we think this bill,
because of its exclusive health focus, deserves its own post. Concerns about
health privacy outside of HIPAA are receiving increased attention in light of
the push for interoperability, which makes this bill both timely and
potentially worth of your attention.
For example, greater interoperability with patients means that even more medical and claims data will flow outside of HIPAA to the “Wild West.” The American Medical Association noted:
“If patients access their health
data—some of which could contain family history and could be sensitive—through
a smartphone, they must have a clear understanding of the potential uses of
that data by app developers. Most patients will not be aware of who has access
to their medical information, how and why they received it, and how it is being
used (for example, an app may collect or use information for its own purposes,
such as an insurer using health information to limit/exclude coverage for
certain services, or may sell information to clients such as to an employer or
a landlord). The downstream consequences of data being used in this way may
ultimately erode a patient’s privacy and willingness to disclose information to
his or her physician.”
The McKinsey “2,750 times” statistic is a pretty
good proxy for the amount of your personal health data that is NOT protected by
HIPAA and currently is broadly unprotected from sharing and use by third
However, there is bipartisan legislation in front of Congress that offers expanded privacy protection for your personal health data. Senators Klobuchar & Murkowski have introduced the “Protecting Personal Health Data Act” (S.1842). The Act would extend protection to much personal health data that is currently not already protected by HIPAA (the Health Insurance Portability and Accountability Act of 1996).
In this essay, we will look in the rear-view mirror to see
how HIPAA has provided substantial protections for personal clinical data — but
with boundaries. We’ll also take a look out the windshield — the Wild West of
unprotected health data.
Then in a separate post, we’ll describe and comment on the
pending “Protect Personal Health Data Act”.
On Episode 3 of HardCore Health, Jess & I start off by discussing all of the health tech companies IPOing (Livongo, Phreesia, Health Catalyst) and talk about what that means for the industry as a whole. Zoya Khan discusses the newest series on THCB called, “The Health Data Goldilocks Dilemma: Sharing? Privacy? Both?”, which follows & discuss the legislation being passed on data privacy and protection in Congress today. We also have a great interview with Paul Johnson, CEO of Lemonaid Health, an up-and-coming telehealth platform that works as a one-stop-shop for a virtual doctor’s office, a virtual pharmacy, and lab testing for patients accessing their platform. In her WTF Health segment, Jess speaks to Jen Horonjeff, Founder & CEO of Savvy Cooperative, the first patient-owned public benefit co-op that provides an online marketplace for patient insights. And last but not least, Dr. Saurabh Jha directly address AI vendors in health care, stating that their predictive tools are useless and they will not replace doctors just yet- Matthew Holt
Matthew Holt is the founder and publisher of The Health Care Blog and still writes regularly for the site.
This post is part of the series “The Health Data Goldilocks Dilemma: Privacy? Sharing? Both?”
In our initial blog post of February 20th, “For Your Radar – Huge Implications for Healthcare in Pending Privacy Legislation,” we broadly discussed six key issues for healthcare stakeholders in the potential federal privacy and data protection legislation. We committed to future posts comparing and contrasting specific legislative proposals.
The buzz around federal privacy legislation continues, but as of yet there appear to be no proposals or bills that have emerged as the lead bills.
In the meantime, the clock is ticking. As we mentioned in our February 20th post, a significant catalyst for federal privacy legislation is the desire of companies covered by the California Consumer Privacy Act (CCPA) to have that broadly-applicable, stringent state law preempted by a more company-friendly federal law. The CCPA, which sets stringent consent and other requirements for large companies, or companies collecting or monetizing large amounts of consumer data from California residents, goes into effect January 1, 2020 – less than six months from today.
Is it possible for a legislative body to move quickly on such a controversial topic? Again, California’s experience may be instructive. The CCPA was passed into law and signed on June 28, 2018, about a week after it was introduced. Lawmakers were in a rush in order to keep a popular and even stricter consumer privacy ballot initiative from being put before the California voters. (The sponsors of the ballot initiative agreed to withdraw it if the CCPA were enacted by the June 28th deadline.).
“The Health Data Goldilocks Dilemma: Sharing? Privacy? Both?” series will cover a whole host of topics that discuss, clarify, and challenge the notion of sharing data and if it should be kept private or made public. On the one hand, sharing health information is essential for clinical care, powering medical discovery, and enabling health system transformation. On the other hand, the public is expressing greater concerns over the privacy of personal health data. This ‘Goldilocks Dilemma’ has pushed US policymakers towards two seemingly conflicting goals: 1) broader data interoperability and data sharing, and 2) enhanced data privacy and data protection.
But this issue is even more nuanced and is influenced by many moving parts including: Federal & State privacy legislation, health technology legislation, policy & interoperability rules, data usage from AI & machine learning tools, data from clinical research, ethical concerns, compensating individuals for their data, health data business models, & many more.
Fear not, Deven & Vince are here to walk readers through this dilemma and will be providing pieces to help explain what is going on. Most of their discussion & pieces will cover 2 specific affected areas: 1) How are policymakers addressing health data privacy risks, and 2) The impact on business models within the Health Data Goldilocks Dilemma.
Deven McGraw is one of America’s best known health privacy lawyers, including a stint at HHS running the Office of Civil Rights. But now she’s a cool startup kid living in Silicon Valley and is the Chief Regulatory Officer at Ciitizen. Ciitizen is focusing on helping people collecting, organizing, and securely sharing their personal health data to improve their care, and was founded by Anil Sethi who previously founded Glimpse and sold it to Apple (where it is now the core of Apple’s Health records product).
For more details, watch Matthew’s interview with Deven below.
Two years ago we wouldn’t have believed it — the U.S. Congress is considering broad privacy and data protection legislation in 2019. There is some bipartisan support and a strong possibility that legislation will be passed. Two recent articles in The Washington Post and AP News will help you get up to speed.
Federal privacy legislation would have a huge impact on all healthcare stakeholders, including patients. Here’s an overview of the ground we’ll cover in this post:
Six Key Issues for Healthcare
We are aware of at least 5 proposed Congressional bills and 16 Privacy Frameworks/Principles. These are listed in the Appendix below; please feel free to update these lists in your comments. In this post we’ll focus on providing background and describing issues. In a future post we will compare and contrast specific legislative proposals.