Patient Privacy – APRA https://www.americanpatient.org American Patient Rights Association Tue, 21 Sep 2021 01:39:35 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://www.americanpatient.org/wp-content/uploads/2018/07/favicon-APRA1-150x150.png Patient Privacy – APRA https://www.americanpatient.org 32 32 Millions of Americans’ Medical Images and Data Are Available on the Internet. Anyone Can Take a Peek. https://www.americanpatient.org/millions-of-americans-medical-images-and-data-are-available-on-the-internet-anyone-can-take-a-peek-2/?utm_source=rss&utm_medium=rss&utm_campaign=millions-of-americans-medical-images-and-data-are-available-on-the-internet-anyone-can-take-a-peek-2 Tue, 15 Oct 2019 14:18:50 +0000 https://www.americanpatient.org/?p=9313 Read More]]> By Jack Gillum, Jeff Kao and Jeff Larson, for ProPublica.  Sep 17, 2019.

Medical images and health data belonging to millions of Americans, including X-rays, MRIs and CT scans, are sitting unprotected on the internet and available to anyone with basic computer expertise.

The records cover more than 5 million patients in the U.S. and millions more around the world. In some cases, a snoop could use free software programs — or just a typical web browser — to view the images and private data, an investigation by ProPublica and the German broadcaster Bayerischer Rundfunk found.

We identified 187 servers — computers that are used to store and retrieve medical data — in the U.S. that were unprotected by passwords or basic security precautions. The computer systems, from Florida to California, are used in doctors’ offices, medical-imaging centers and mobile X-ray services.

The insecure servers we uncovered add to a growing list of medical records systems that have been compromised in recent years. Unlike some of the more infamous recent security breaches, in which hackers circumvented a company’s cyber defenses, these records were often stored on servers that lacked the security precautions that long ago became standard for businesses and government agencies.

“It’s not even hacking. It’s walking into an open door,” said Jackie Singh, a cybersecurity researcher and chief executive of the consulting firm Spyglass Security. Some medical providers started locking down their systems after we told them of what we had found.

Our review found that the extent of the exposure varies, depending on the health provider and what software they use. For instance, the server of U.S. company MobilexUSA displayed the names of more than a million patients — all by typing in a simple data query. Their dates of birth, doctors and procedures were also included.

Alerted by ProPublica, MobilexUSA tightened its security last week. The company takes mobile X-rays and provides imaging services to nursing homes, rehabilitation hospitals, hospice agencies and prisons. “We promptly mitigated the potential vulnerabilities identified by ProPublica and immediately began an ongoing, thorough investigation,” MobilexUSA’s parent company said in a statement.

Another imaging system, tied to a physician in Los Angeles, allowed anyone on the internet to see his patients’ echocardiograms. (The doctor did not respond to inquiries from ProPublica). All told, medical data from more than 16 million scans worldwide was available online, including names, birthdates and, in some cases, Social Security numbers.

Experts say it’s hard to pinpoint who’s to blame for the failure to protect the privacy of medical images. Under U.S. law, health care providers and their business associates are legally accountable for securing the privacy of patient data. Several experts said such exposure of patient data could violate the Health Insurance Portability and Accountability Act, or HIPAA, the 1996 law that requires health care providers to keep Americans’ health data confidential and secure.

Although ProPublica found no evidence that patient data was copied from these systems and published elsewhere, the consequences of unauthorized access to such information could be devastating. “Medical records are one of the most important areas for privacy because they’re so sensitive. Medical knowledge can be used against you in malicious ways: to shame people, to blackmail people,” said Cooper Quintin, a security researcher and senior staff technologist with the Electronic Frontier Foundation, a digital-rights group. “This is so utterly irresponsible,” he said.

The issue should not be a surprise to medical providers. For years, one expert has tried to warn about the casual handling of personal health data. Oleg Pianykh, the director of medical analytics at Massachusetts General Hospital’s radiology department, said medical imaging software has traditionally been written with the assumption that patients’ data would be secured by the customer’s computer security systems.

But as those networks at hospitals and medical centers became more complex and connected to the internet, the responsibility for security shifted to network administrators who assumed safeguards were in place. “Suddenly, medical security has become a do-it-yourself project,” Pianykh wrote in a 2016 research paper he published in a medical journal.

ProPublica’s investigation built upon findings from Greenbone Networks, a security firm based in Germany that identified problems in at least 52 countries on every inhabited continent. Greenbone’s Dirk Schrader first shared his research with Bayerischer Rundfunk after discovering some patients’ health records were at risk. The German journalists then approached ProPublica to explore the extent of the exposure in the U.S.

Schrader found five servers in Germany and 187 in the U.S. that made patients’ records available without a password. ProPublica and Bayerischer Rundfunk also scanned Internet Protocol addresses and identified, when possible, which medical provider they belonged to.

ProPublica independently determined how many patients could be affected in America, and found some servers ran outdated operating systems with known security vulnerabilities. Schrader said that data from more than 13.7 million medical tests in the U.S. were available online, including more than 400,000 in which X-rays and other images could be downloaded.

The privacy problem traces back to the medical profession’s shift from analog to digital technology. Long gone are the days when film X-rays were displayed on fluorescent light boards. Today, imaging studies can be instantly uploaded to servers and viewed over the internet by doctors in their offices.

In the early days of this technology, as with much of the internet, little thought was given to security. The passage of HIPAA required patient information to be protected from unauthorized access. Three years later, the medical imaging industry published its first security standards.

Our reporting indicated that large hospital chains and academic medical centers did put security protections in place. Most of the cases of unprotected data we found involved independent radiologists, medical imaging centers or archiving services.

One German patient, Katharina Gaspari, got an MRI three years ago and said she normally trusts her doctors. But after Bayerischer Rundfunk showed Gaspari her images available online, she said: “Now, I am not sure if I still can.” The German system that stored her records was locked down last week.

We found that some systems used to archive medical images also lacked security precautions. Denver-based Offsite Image left open the names and other details of more than 340,000 human and veterinary records, including those of a large cat named “Marshmallow,” ProPublica found. An Offsite Image executive told ProPublica the company charges clients $50 for access to the site and then $1 per study. “Your data is safe and secure with us,” Offsite Image’s website says.

The company referred ProPublica to its tech consultant, who at first defended Offsite Image’s security practices and insisted that a password was needed to access patient records. The consultant, Matthew Nelms, then called a ProPublica reporter a day later and acknowledged Offsite Image’s servers had been accessible but were now fixed. “We were just never even aware that there was a possibility that could even happen,” Nelms said.

In 1985, an industry group that included radiologists and makers of imaging equipment created a standard for medical imaging software. The standard, which is now called DICOM, spelled out how medical imaging devices talk to each other and share information.

We shared our findings with officials from the Medical Imaging & Technology Alliance, the group that oversees the standard. They acknowledged that there were hundreds of servers with an open connection on the internet, but suggested the blame lay with the people who were running them.

“Even though it is a comparatively small number,” the organization said in a statement, “it may be possible that some of those systems may contain patient records. Those likely represent bad configuration choices on the part of those operating those systems.”

Meeting minutes from 2017 show that a working group on security learned of Pianykh’s findings and suggested meeting with him to discuss them further. That “action item” was listed for several months, but Pianykh said he never was contacted. The medical imaging alliance told ProPublica last week that the group did not meet with Pianykh because the concerns that they had were sufficiently addressed in his article. They said the committee concluded its security standards were not flawed.

Pianykh said that misses the point. It’s not a lack of standards; it’s that medical device makers don’t follow them. “Medical-data security has never been soundly built into the clinical data or devices and is still largely theoretical and does not exist in practice,” Pianykh wrote in 2016.

ProPublica’s latest findings follow several other major breaches. In 2015, U.S. health insurer Anthem Inc. revealed that private data belonging to more than 78 million people was exposed in a hack. In the last two years, U.S. officials have reported that more than 40 million people have had their medical data compromised, according to an analysis of records from the U.S. Department of Health and Human Services.

Joy Pritts, a former HHS privacy official, said the government isn’t tough enough in policing patient privacy breaches. She cited an April announcement from HHS that lowered the maximum annual fine, from $1.5 million to $250,000, for what’s known as “corrected willful neglect” — the result of conscious failures or reckless indifference that a company tries to fix. She said that large firms would not only consider those fines as just the cost of doing business, but that they could also negotiate with the government to get them reduced. A ProPublica examination in 2015 found few consequences for repeat HIPAA offenders.

A spokeswoman for HHS’ Office for Civil Rights, which enforces HIPAA violations, said it wouldn’t comment on open or potential investigations. “What we typically see in the health care industry is that there is Band-Aid upon Band-Aid applied” to legacy computer systems, said Singh, the cybersecurity expert. 

She said it’s a “shared responsibility” among manufacturers, standards makers and hospitals to ensure computer servers are secured. “It’s 2019,” she said. “There’s no reason for this.”

How Do I Know if My Medical Imaging Data is Secure?

If you have had a medical imaging scan (e.g., X-ray, CT scan, MRI, ultrasound, etc.) ask the health care provider that did the scan — or your doctor — if access to your images requires a login and password. Ask your doctor if their office or the medical imaging provider to which they refer patients conducts a regular security assessment as required by HIPAA.

[pmpro_levels]
]]>
Is your pregnancy app sharing your intimate data with your boss? https://www.americanpatient.org/is-your-pregnancy-app-sharing-your-intimate-data-with-your-boss/?utm_source=rss&utm_medium=rss&utm_campaign=is-your-pregnancy-app-sharing-your-intimate-data-with-your-boss Wed, 17 Apr 2019 20:26:24 +0000 https://www.americanpatient.org/?p=7086 Read More]]> By Drew Harwell, The Washington Post.

Like millions of women, Diana Diller was a devoted user of the pregnancy-tracking app Ovia. When she gave birth last spring, she used the app to chart her baby’s first online medical data — including her name, her location and whether there had been any complications — before leaving the hospital’s recovery room. 

But someone else was regularly checking in, too: her employer, which paid to gain access to the intimate details of its workers’ personal lives, from their trying-to- conceive months to early motherhood. Diller’s bosses could look up aggregate data on how many workers using Ovia’s fertility, pregnancy and parenting apps had faced high-risk pregnancies or gave birth prematurely; the top medical questions they had researched; and how soon the new moms planned to return to work. 

Ovia has become a powerful monitoring tool for employers and health insurers, which under the banner of corporate wellness have aggressively pushed to gather more data about their workers’ lives than ever before. 

 Employers who pay the apps’ developer, Ovia Health, can offer their workers a special version of the apps that relays their health data — in a “de-identified,” aggregated form — to an internal employer website accessible by human resources personnel. The companies offer it alongside other health benefits and incentivize workers to input as much about their bodies as they can, saying the data can help the companies minimize health-care spending, discover medical problems and better plan for the months ahead. 

But health and privacy advocates say this new generation of “menstrual surveillance” tools is pushing the limits of what women will share about one of the most sensitive moments of their lives. The apps, they say, are designed largely to benefit not the women but their employers and insurers, who gain a sweeping new benchmark on which to assess their workers as they consider the next steps for their families and careers. 

Experts worry that companies could use the data to bump up the cost or scale back the coverage of health-care benefits, or that women’s intimate information could be exposed in data breaches or security risks. And though the data is made anonymous, experts also fear that the companies could identify women based on information relayed in confidence, particularly in workplaces where few women are pregnant at any given time. 

Ovia chief executive Paris Wallace said the company complies with privacy laws and provides the aggregate data so employers can evaluate how their workforces’ health outcomes have changed over time. 

An Ovia spokeswoman said the company does not sell aggregate data for advertising purposes. But women who use Ovia must consent to its 6,000-word “terms of use,” which grant the company a “royalty-free, perpetual, and irrevocable license, throughout the universe” to “utilize and exploit” their de-identified personal information for scientific research and “external and internal marketing purposes.” 

Ovia may also “sell, lease or lend aggregated Personal Information to third parties,” the document adds. 

With more than 10 million users, Ovia’s tracking services are now some of the most downloaded medical apps in America. Alongside competitors such as Glow, Clue and Flo, the period- and pregnancy-tracking apps have raised hundreds of millions of dollars from investors and count tens of millions of users every month. 

Founded in Boston in 2012, Ovia began as a consumer-facing app that made money in the tried-and-true advertising fashion of Silicon Valley. But three years ago, Wallace said, the company was approached by large national insurers who said the app could help them improve medical outcomes and access maternity data via the women themselves. 

Ovia pitches its app to companies as a health-care aid for women to better understand their bodies during a mystifying phase of life. In marketing materials, it says women who have tracked themselves with Ovia showed a 30 percent reduction in premature births, a 30 percent increase in natural conception and a higher rate of identifying the signs of postpartum depression. (An Ovia spokeswoman said those statistics come from an internal return-on-investment calculator that “has been favorably reviewed by actuaries from two national insurance companies.”) 

But a key element of Ovia’s sales pitch is how companies can cut back on medical costs and help usher women back to work. Pregnant women who track themselves, the company says, will live healthier, feel more in control and be less likely to give birth prematurely or via a C-section, both of which cost more in medical bills — for the family and the employer. 

Women wanting to get pregnant are told they can rely on Ovia’s  

“fertility algorithms,” which analyze their menstrual data and suggest good times to try to conceive, potentially saving money on infertility treatments. “An average of 33 hours of productivity are lost for every round of treatment,” an Ovia marketing document says. 

 For employers who fund workers’ health insurance, pregnancy can be one of the biggest and most unpredictable health-care expenses. In 2014, AOL chief executive Tim Armstrong defended the company’s cuts to retirement benefits by blaming the high medical expenses that arose from two employees giving birth to “distressed babies.” 

 Ovia, in essence, promises companies a tantalizing offer: lower costs and fewer surprises. Wallace gave one example in which a woman had twins prematurely, received unneeded treatments and spent three months in intensive care. “It was a million-dollar birth … so the company comes to us: How can you help us with this?” he said. 

 But some health and privacy experts say there are many reasons a woman who is pregnant or trying to conceive wouldn’t want to tell her boss, and they worry the data could be used in a way that puts new moms at a disadvantage. 

 Federal law forbids companies from discriminating against pregnant women and mandates that pregnancy-related health-care expenses be covered in the same way as other medical conditions. Ovia said the data helps employers provide “better benefits, health coverage and support.” 

 Ovia’s soft pastels and cheery text lend a friendly air to the process of transmitting private health information to one’s employer, and the app gives daily nudges to remind women to log their progress with messages such as, “You’re beautiful! How are you feeling today?” 

 But experts say they are unnerved by the sheer volume and detail of data that women are expected to offer up. Pregnant women can log details of their sleep, diet, mood and weight, while women who are trying to conceive can record when they had sex, how they’re feeling and the look and color of their cervical fluid. 

 After birth, the app asks for the baby’s name, sex and weight; who performed the delivery and where; the birth type, such as vaginal or an unplanned C-section; how long labor lasted; whether it included an epidural; and the details of any complications, such as whether there was a breech or postpartum hemorrhage. 

The app also allows women to report whether they had a miscarriage or pregnancy loss, including the date and “type of loss,” such as whether the baby was stillborn. 

“After reporting a miscarriage, you will have the option to both reset your account and, when you’re ready, to start a new pregnancy,” the app says. 

 Much of this information is viewable only by the worker. But the company can access a vast range of aggregated data about its employees, including their average age, number of children and current trimester; the average time it took them to get pregnant; the percentage who had high-risk pregnancies, conceived after a stretch of infertility, had C-sections or gave birth prematurely; and the new moms’ return-to- work timing. 

 Companies can also see which articles are most read in Ovia’s apps, offering them a potential road map to their workers’ personal questions or anxieties. 

 Ovia says it is compliant with government data-privacy laws such as the Health Insurance Portability and Accountability Act, or HIPAA, which sets rules for sharing medical information. The company also says it removes identifying information from women’s health data in a way that renders it anonymous and that it requires employers to reach a certain minimum of enrolled users before they can see the aggregated results. 

But health and privacy experts say it’s relatively easy for a bad actor to “re-identify” a person by cross-referencing that information with other data. The trackers’ availability in companies with few pregnant women on staff, they say, could also leave the data vulnerable to abuse. Ovia says its contract prohibits employers from attempting to re-identify employees. 

Ezzard, the benefits executive at Activision Blizzard, said offering pregnancy programs such as Ovia helps the company stand out in a competitive industry and keep skilled women in the workforce coming back. The company employs roughly 5,000 artists, developers and other workers in the United States. 

Before Ovia, the company’s pregnant employees would field periodic calls from insurance-company nurses who would ask about how they were feeling and counsel them over the phone. Shifting some pregnancy care to an app where the women could give constant check-ins made a huge difference: Nearly 20 women who had been diagnosed as infertile had become pregnant since the company started offering Ovia’s fertility app, Ezzard said.  

Roughly 50 “active users” track their pregnancies at any given time, and the average employee records more than 128 health data points a month, Ezzard said. They also open the app about 48 times a month, or more than once a day. 

Ezzard said that the company maintains strict controls on who can review the internal aggregated data and that employees’ medical claims are processed at a third-party data warehouse to help protect their privacy. The program, he added, is already paying off: Ovia and the other services in its “well-being platform” saved the company roughly $1,200 per employee in annual medical costs. 

Health experts worry that such data-intensive apps could expose women to security or privacy risks. The ovulation-tracking app Glow updated its systems in 2016 after Consumer Reports found that anyone could access a woman’s health data, including whether she’d had an abortion and the last time she’d had sex, as long as they knew her email address.

Another Ovia competitor, Flo, was found to be sending data to Facebook on when its users were having their periods or were trying to conceive, according to tests published in February in the Wall Street Journal. Ovia says it does not share or sell data with social media sites. 

 The company says it does not do paid clinical trials but provides data to researchers, including for a 2017 study that cited Ovia data from more than 6,000 women on how they chose their obstetricians. But even some researchers worry about ways the information might be used. 

 “As a clinician researcher, I can see the benefit of analyzing large data sets,” said 

Paula M. Castaño, an obstetrician-gynecologist and associate professor at Columbia University who has studied menstrual-tracking apps. But a lot of the Ovia data given to employers, she said, raises concerns “with their lack of general clinical applicability and focus on variables that affect time out of work and insurance utilization.” 

The coming years, however, will probably see companies pushing for more pregnancy data to come straight from the source. The Israeli start-up Nuvo advertises a sensor band strapped around a woman’s belly that can send real-time data on fetal heartbeat and uterine activity “across the home, the workplace, the doctor’s office and the hospital.” Nuvo executives said its “remote pregnancy monitoring platform” is undergoing U.S. Food and Drug Administration review. 

Diller, the Activision Blizzard employee, said she was never troubled by Ovia privacy worries. She loved being able to show her friends what size pastry her unborn daughter was and would log her data every night while lying in bed and ticking through her other health apps, including trackers for food, sleep and “mindfulness.” 

When she reported the birth in Ovia, the app triggered a burst of virtual confetti and then directed her to download Ovia’s parenting app, where she could track not just her health data, but her newborn daughter’s, too. It was an easy decision. On the app’s home screen, she uploaded the first photo of her newly expanded family.

Apr 10, 2019

[pmpro_levels]
]]>
Does HIPAA really protect patient privacy? https://www.americanpatient.org/does-hipaa-really-protect-patient-privacy/?utm_source=rss&utm_medium=rss&utm_campaign=does-hipaa-really-protect-patient-privacy Tue, 05 Mar 2019 13:22:10 +0000 https://www.americanpatient.org/?p=6845 Are Your Medical Records Private https://www.americanpatient.org/your-medical-records-are-not-private/?utm_source=rss&utm_medium=rss&utm_campaign=your-medical-records-are-not-private Sun, 18 Jun 2017 16:59:23 +0000 https://www.temp.americanpatient.org/?p=3972