Slashdot Log In
Google Health Opens To the Public
Posted by
kdawson
on Tue May 20, 2008 02:11 PM
from the take-two-aspirin-and-don't-call-me-ever dept.
from the take-two-aspirin-and-don't-call-me-ever dept.
Several readers noted that the limited pilot test of Google Health has ended, and Google is now offering the service to the public at large. Google Health allows patients to enter health information, such as conditions and prescriptions, find related medical information, and share information with their health care providers (at the patient's request). Information may be entered manually or imported from partnered health care providers. The service is offered free of charge, and Google won't be including advertising. The WSJ and the NYTimes provide details about Google's numerous health partners.
Related Stories
[+]
Google to Offer Online Personal Health Records 242 comments
hhavensteincw writes "Less than two weeks after Microsoft announced plans to offer personal health records, Google announced today that it plans to offer online personal health records to help patients tote and store their own x-rays and other health data. Google made the announcement Wednesday at the Web 2.0 Summit in San Francisco."
[+]
Science: Google to Begin Storing Patients' Health Records 214 comments
mytrip writes with news that Google's health record archive is about to be tested with the assistance of the Cleveland Clinic. Thousands of patients (who must approve the transfer of information) will have access to everything from their medical histories to lab results through what Google considers a "logical extension" of their search engine. We discussed the planning of this system last year.
"Each health profile, including information about prescriptions, allergies and medical histories, will be protected by a password that's also required to use other Google services such as e-mail and personalized search tools. The health venture also will provide more fodder for privacy watchdogs who believe Google already knows too much about the interests and habits of its users as its computers log their search requests and store their e-mail discussions. Prodded by the criticism, Google last year introduced a new system that purges people's search records after 18 months. In a show of its privacy commitment, Google also successfully rebuffed the U.S. Justice Department's demand to examine millions of its users' search requests in a court battle two years ago."
[+]
Science: Delving Into Google Health's Privacy Concerns 121 comments
SecureThroughObscure writes "Security researcher Robert 'RSnake' Hansen discusses numerous concerns with Google's new Google Health application, which aims to integrate user's medical records online. We discussed Google Health's opening to the public earlier this week. RSnake mentions that Google has found a loophole allowing them to provide this service without having to follow HIPAA regulations, which, combined with Google's track record of having numerous flaws leading to private information disclosure, draws serious concern. Security researcher Nate McFeters of ZDNet's Zero-Day Security Blog also commented on the article, mentioning several past vulnerabilities: ownership of content issues, Google Docs theft, a cross-domain hole, Google XSS, and a Google Picasa protocol handler issue leading to the theft of user images. He and fellow researcher Billy Rios disclosed these issues to Google, including the ability to steal GMail contact list information. McFeters says it's likely that similar unpatched bugs would allow an attacker to view medical records if a user was also using Google Health. Both McFeters and Hansen tend to agree that Google's vulnerability disclosure/notification is non-existent and really needs to be improved. Currently, Google does not report vulnerabilities it has fixed to its user base, for the obvious reason of trying to hide the fact that user data could have been stolen."
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
Privacy (Score:5, Insightful)
Re: (Score:3, Insightful)
Maybe the laws need to be re-written.
I can't imagine that Federal & State Law foresaw 3rd party control of medical files.
Exactly (Score:5, Informative)
I agree 100% with GP. I even wrote Google to that effect. Not that I expect them to do anything with my feedback other than send it to the bitbucket.
This is a horrible, horrible precedent to set, allowing a 3rd party to have access to people's medical records without any protection under the law.
HIPPA *does* need to be updated, immediately, to cover online databases.
Parent
You misunderstand HIPPA (Score:5, Informative)
The way Google Health works is you give them your data and they store it.
Parent
Re: (Score:3, Informative)
Only online access provided by medical providers that are explicitly covered under the Act. This new generation of info-providers such as Google, MS, etc. are NOT covered by HIPPA. Even the Government has said so (link is posted elsewhere in this discussion by someone).
That is the third time in a row you've referred to the HIPAA (Health Insurance Portability and Accountability Act) [wikipedia.org] as "HIPPA", even after being corrected by someone else. Is there some reason you keep doing this?
Re: (Score:2)
Re: (Score:2)
Re: (Score:3, Informative)
Re:Privacy (Score:5, Insightful)
I don't trust Google. I'm of the opinion that companies have to obey the rules/laws of government. I'd rather "trust" the government if they said that HIPAA doesn't apply to Google rather than Google saying that HIPAA doesn't apply to them. There is a part of me that actually hopes that Google gets slapped by the government for violating HIPAA.
Parent
Re:Privacy (Score:5, Informative)
Parent
Why not? (Score:5, Insightful)
Parent
Re:Why not? (Score:4, Informative)
Google is NOT a healthcare clearinghouse (you might reasonably think it meets the definition - I used to think it would as well, but covered clearinghouses are directly linked to care providers, the definition does not cover third party service providers (of medical devices, Customized off the shelf software etc.).
Regarding HIPAA applicability to google: any HIPAA CE (Covered Entity, which includes most of your health care providers who also use or maintain electronic patient data) MUST include terms in a contractual relationship with a BA (Business Associate - anyone the CE does business with involving patient data) which mirror HIPAA requirements (this is the "Business Associate Rule").
YOU can release your records to Google, this would involve NO HIPAA issues.
If your Primary Care Provider is a CE (likely) and they contract with Google (as a health partner etc.) then the terms of that contract MUST include HIPAA protections (i.e. the CE must require, contractually, that the BA meet the same HIPAA requirements which the CE is subject to).
Parent
Re: (Score:3, Informative)
Re:Privacy (Score:5, Interesting)
Parent
Re:Privacy (Score:4, Informative)
Parent
Re: (Score:3, Insightful)
I find the privacy concerns a bit off beat.
I do online banking.
I file my taxes online...
When is there such sensitivity about my health data. As far I see, it is password protected, and as long as the data is not shared with people outside my 'approved list', I have no issue with it. Google might eventually adopt HIPAA, but I seriously doubt Google will be freely sharing your private information with health insurance providers without your
Wow (Score:2, Insightful)
I'm quite torn here. On the one hand, having so much information readily available in one spot is rather exciting. This is especially true if Google doesn't just cave in to "Big Pharma" and allows you to see "alternative" or "herbal" remedies for prescriptions or OTC drugs you have entered.
OTHO, Google having all that information about my medical condition in one place is somewhat disturbing... Aside from rational or irrational fears about Google having this information, aren't there HIPPA issues to be
Re: (Score:3, Interesting)
Given that there exists hardware to inspect packets for p2p traffic, how hard would it be to for a person of unpleasant intent to get hold of some of that and start mining 'encrypted' health information.
I can see it now, 'want to get health insurance again? Pay us x dollars or we expose condition y to your health insurance provider.'
Come to think of it, all they'd need to do is pretend they had the info, someone woul
Re: (Score:2)
Re:Wow (Score:4, Interesting)
In other words, if you are in their State, you have to follow their rules, and their rules say your price isn't affected by "condition y".
On a related note, I read an article [slate.com] stating that part of a McCain proposal would allow insurance companies to change their legal residency for the purpose of using another State's insurance rules. In other words, a New York insurance company can pay taxes in Arizona and use their insurance rules.
Parent
Re: (Score:3, Insightful)
Re:Wow (Score:4, Insightful)
Parent
Re:Wow (Score:5, Insightful)
Parent
Re:Wow (Score:5, Funny)
Parent
Re:Wow (Score:4, Informative)
Parent
Re:Wow (Score:4, Funny)
Parent
Uh oh... (Score:4, Funny)
Re:Uh oh... (Score:5, Funny)
Parent
Re: (Score:2)
Umm (Score:2)
I don't feel good, time for Google! (Score:2, Funny)
This is actually Google's spam fighting measure (Score:4, Funny)
Just wait till you hear about the plan they have to go after the Nigerian 409 scammers.
April Fools, right (Score:2)
Google Organ Search (Score:3, Interesting)
Disclaimer Needed (Score:2, Interesting)
Re:Disclaimer Needed (Score:4, Interesting)
It exists to alleviate line ups in walk-in clinics and emergency rooms by keeping some of the people with less serious problems from having to go down and see a doctor. This service looks like it will serve a similar purpose.
Parent
google information horde (Score:5, Insightful)
Re: (Score:3, Insightful)
Yes, it has advertising, through "affiliates". (Score:5, Informative)
Yes, Google Health supports advertising. Spamming, even. Read the developer guidelines. [google.com] Google just doesn't run the ads themselves. That's outsourced to "affiliates".
There are some rules for affiliates, like "one spam per week per user" and "no popups or popunders". Other than that, consumers are fair game. In particular, affiliates are not prohibited from using Google health data to target ads, as long as they "disclose" that somewhere in their "privacy policy". The policy says "Only use Google Health user data for the purposes disclosed in your privacy policy, and obtain users' opt-in consent if personally identifiable health data will be used for ad targeting." So a bit of fine print, and the affiliate 0wns your health history.
It's a typical slimeball tactic - pretend to be the good guy, encourage "affiliates" to do the bad stuff.
Re:Yes, it has advertising, through "affiliates". (Score:5, Informative)
And, Google isn't protecting your information via HIPAA because it can't - it's not a "covered entity" under the definition [hhs.gov] outlined in the law. (That is, they aren't a health provider, billing clearinghouse, or health plan.) Instead, they provide the Google Health Privacy Policy [google.com], which seems pretty reasonable. Like HIPAA, it allows them to disclose information when it seems like the government (US, in this case, as that's where the service is limited to) compels it. Before you get hot and bothered, HIPAA allows this too - it's how we tell get to CPS about abused children, for example.
I'm not new here, but I'm used to Slashdot readers being somewhat more informed before having a fit. As a covered entity myself (I'm a physician), I look forward to the day when the patients who come in saying they doubled the pink pills but lost the yellow ones they took for that surgery to remove that thigamajig have a hope of a secure information repository to clarify their history, and potentially save their bacon.
Parent
Re: (Score:3, Funny)
Re: (Score:3, Funny)
pick one and be consistent.
missing drug side effects (Score:5, Interesting)
I know for a fact that there is explicit warnings on the packages about this particular reaction and I'm livid it isn't warning about it on the package insert in google. Especially since it can be permanent.
I've racked up a couple thousand dollars in medical bills already from this side effect, and it was a pain to get doctors to admit it happened until I went to a major university hospital. At that hospital they diagnosed me right away and basically said I'd have to wait it out.
If you are curious, basically I couldn't walk for over a week, terrible joint pain for months along with numbness in my hands, face, and body. Its a known side effect with this class. Rare, but known.
"How does Google make money off Google Health?" (Score:5, Insightful)
Much like other Google products we offer, Google Health is free to anyone who uses it. There are no ads in Google Health. Our primary focus is providing a good user experience and meeting our users' needs.
I've heard enough. I don't know what their long-term plan for monetizing Google Health is, and I don't really care now. I don't trust Google enough to consider even for a second entrusting my health care information to them (and I say this as someone who has thought very highly of the company since the beginning). And their weasly answer to the obvious question above, I think, justifies my mistrust.
Every for-profit company's primary focus is - making a profit. There's nothing whatsoever wrong with this, and the ideal situation arises when "providing a good user experience and meeting [...] users' needs" is aligned with the profit motive.
So why they can't be honest about their motivations in undertaking an expensive, large-scale project like this -- whatever those motivations are -- instead of trying to make us believe that they're doing it "out of the goodness of their hearts?" All their mealy-mouthedness accomplishes is to raise the suspicion that they've got something nasty up their sleeves. And that ensures that many users, including me, will never entrust their most private of private data to Google.
Re:"How does Google make money off Google Health?" (Score:5, Insightful)
Parent
Google Sex Life (Score:3, Funny)
Note to users: Change your GMail password (Score:3, Insightful)
Well, now you just got a shinny new Penile Prosthesis Insertion - Non-inflatable AND a Penile Prosthesis Insertion- Inflatable.
Have a nice day.
This can help us find the "bad" doctors & loca (Score:3, Interesting)
Let Google Health be modified to compile results of medical procedures - by the practitioner(s), who perform them - and compare longer-term performance with expected failure & complication rates across the hospital...
and then compare each hospital's rates to "best practice" -
We could also get very useful (even valuable) data on risks of working / living in certain areas, eg, by post code... if correlations between location and diseases are available to all via Google Health.
Mapping sources of pollutions & overlaying incidence rate contour lines onto the same maps, might affect property prices... giving folks another [if economic] reason to cleanup the mess before people would move to a new development/location.
Gov't-held data is already held & analyzed, around the world, to support such analyses; eg:
While in South Australia, attending a Data Mining seminar (atop the EDS building in Adelaide), I heard some public sector IT managers report how Data Mining - even in -existing- Public Health Service databases - showed useful patterns of disease occuramces vs postcode...
but another public sector IT manager was quick to poit out that such results would not be made known to members of the public.
(Tell me: Does this kind of data hiding happen in such places as Sweden? I hope not... but give me the facts & some URLs where they are available; yes, some of us read Swedish here...
Re: (Score:2, Funny)
Good to know.
Also good to know that companies will be using our health history against us. Because they all care about us, individually.
Weasel words... (Score:3, Interesting)
However, Google may only use health information you provide as permitted by the Google Health Privacy Policy, your Sharing Authorization, and applicable law.
"YOU did not provide this information. Your doctor's office provided the information, so it is exempt from these policies."
See? It took me just a quick glance to find a huge conditional that is subject to interpretation. Don't think that