Showing posts with label Google Health. Show all posts
Showing posts with label Google Health. Show all posts

Sunday, February 22, 2009

I'm putting my data in Google and HealthVault

I've decided to go ahead and put my data in Google Health and MicroSoft HealthVault.
(Note: MicroSoft HealthVault is a different kind of thing from Google Health. About the only thing they have in common is that I can put my health data in them. For this post I'll only discuss Google, but the concerns people have about the two are similar, and so are my thoughts.)

This is something of an earthquake on The Dave Planet. When Google Health was first announced in January 2008, I was completely distrustful and wrote What's next, Google Health??, concluding with this:

GOOG's stock is doing great and I love their free tools, but there's no way in hell I'm giving them sensitive personal data, regardless of what their policy says. New motto for 2008: Don't Be Stupid.
It was a direct slam against Google's long-professed unofficial motto "Don't Be Evil." I expressed my concern that Google might succumb to government pressure and dish out personal medical information that someone had entrusted to Google Health. I cited how Google had caved in to China's government, and how Google CEO Eric Schmidt had severely punished CNET.com for googling his personal information and publishing it. I saw hypocrisy.

Others agreed. One online forum discussed the potential for abuse, given that Google collects enormous information about each of us as we browse the web and use Google's search features – they know what you've searched for and (through ordinary marketing software that most web sites install) they know what sites you've visited.

They say they won't use that info; but... what if? What if an evil politician (take your pick: Dick Cheney, Hillary Clinton, Putin) puts the squeeze on Google to disclose such information so they can use it against you? That's less improbable than what actually did happen to Valerie Plame. In cases like that, laws will not protect you.

In online discussion groups, experts in "search engine marketing" joked about it: If Google knows you have a kidney problem, then the Google Maps "Street View" feature might point out potential donors, and the ads on the side of your screen might start promoting bathtubs and ice. (Yes, people did joke about that.)

That's a bit over the top, but you get the point.

Similar concerns continue today – this delightful image appeared on a ZDNet post this month, titled Is Google health corrupt?




So why have I gone over?

  • First, in the past year an increasingly wide range of people I trust have said "The data you're concerned about is already not as secure as you think." That doesn't leave me any more comfortable but I've come to accept that my choice of action won't make much difference.

  • Second, and more importantly, I'm concluding that we can do more good by aggregating our data into large, anonymized databanks that smart software can analyze to look for patterns. Early detection means early intervention means fewer crises.
            Diabetics are already starting to do things like this. And the Cambridge MA-based PatientsLikeMe is a full-blown example of a community (ALS / Lou Gehrig's disease) where patients are tired of waiting for the medical industry to produce results. They're uploading their data (anonymized), sharing it, looking for patterns, even creating their own clinical trials.

  • The third aspect, ultimately the deciding one, is something I see all the time in my day job, where we study new software tools: the power of "mash-ups." That's the ability to slap together two pieces of software (or data) that were created without knowing that the other one exists, and making something new out of them without anyone planning it in advance. Things can just grow in any direction people want.
            Mash-ups are a big part of what makes the Web what it is today: Anyone can put a Yahoo Map on their web site, I can take someone's YouTube video and put it on my blog, etc.

The power happens because this lets people create software gadgets without knowing how they'll be used, it lets people build tools that use data without knowing where the data will come from, and it lets people build big new systems just by assembling them out of "software Legos."

And in healthcare, that's what free public tools like Google Health and Microsoft HealthVault enable. Here's the personal example that hit me recently and tipped me:

When I was discharged from the hospital after my first week of Interleukin, I was given a complex medication schedule grid – which had to be created with pencil and ruler by a highly trained nurse.

This was not a sensible use of her time. So, being a software thinker, I spec'd out a "Med Minder" program that would take prescription instructions ("take this one 3x/day, take this one with meals," etc) and spit out a nicely printed daily schedule. I had additional ideas: "mash it up" with a database of pill images so you can see what pills to take; "mash it up" with a database of different Walgreen's pillboxes so you can see what to put in each cell of your particular pillbox.

I talked to a few people about it and hadn't found anyone interested in the idea.

But at the Google Health booth at a recent trade show, look what I saw: ePillBox.info. It takes your prescription info from Google Health and tells you how to fill your pillbox.

It was an epiphany: put my data in there, and I get access to mash-ups. All kinds of potential tools that I know could be useful become possible. The healthcare establishment isn't getting around to doing them, but ordinary data geeks are.
So here's how it boils down:

My goal is to help create a new world where healthcare is enormously more efficient than it is today, and where important new developments happen enormously faster than they do today.

And with that in mind, the advantages of uploading our data far outweigh the risks.

So I'm in.

Saturday, May 24, 2008

More on Google Health: two reasons to be wary

(For the impatient: if you read nothing else of this, be sure you read David Hamilton's Seven Reasons Google Health Is Overblown.)

As the Google Health story has fleshed out in recent days my view has become clearer and stronger. Then, yesterday at work I saw a demonstration of Google ethics that annoyed the crap out of me.

The crux of it is trust and trustworthiness. The Federal HIPAA law puts strict penalties on a provider who leaks your data, but Google's not subject to HIPAA. And their password security is really weak, unlike bank web sites.

A) Bloggers' views
B) What happened at work

My company gives Google thousands of dollars a month for Pay Per Click (PPC) advertising. (We bid to have our ads displayed when someone "googles" specific phrases, such as 'online appointment software'.) Every time someone clicks one of our ads, we pay Google, regardless of whether it turns out to be a legitimate buyer. If carefully managed, it's worth the risk, and we put a spending cap on it, which we rarely reach.


Well, yesterday my PPC consultant noticed that Google just added a feature without telling anyone that will spend our unused budget to display ads for phrases we didn't bid on.


Details in this post.


I'm all in favor of modernizing healthcare, particularly making it easier to do what I want with my data. But I think it should be done by a non-profit entity, using open source software.

Tuesday, May 20, 2008

The Launch of Google Health

There's a lot of talk this week about the launch of Google Health. As much as I love everything online, I have grave concerns about this. I wrote about it here in January, speaking on general principle. But now that the thing is finally launched, the full terms of service are out (the fine print), and my concerns are even greater.

#1 on my list is that due to some legalese (Google itself isn't a healthcare provider), Google Health is not subject to HIPAA privacy regulations. Google isn't required to observe HIPAA protections to keep your data private, and there are no legal consequences if they don't.

Of greater concern is that the whole point of Google Health is that they send your information to others you select, at which point the data is completely out of Google's control.

And that doesn't begin to get into the sociological / political concerns I raised in January - questions of what to do when Google says "Really, just trust us" in the absence of any policing.

If you want to know more, explore these posts (and comments):

  • The e-Patients blog: Google releases Google Health

  • Slashdot (a well known tech blog): Google Health opens to the public. Those people are no fools, they have lots of experience with Google (for better and worse), and they have fun attitude. Some of them are pointing out that HIPAA obviously needs a major overhaul.
I'm so concerned about this that I've written my concerns on the blogs of my hospital's CEO and his CIO (top computer guy). The CIO is on the advisory council for the whole Google Health initiative, and I really want to know why they think the privacy issue (which is enforced on everyone else who touches your data) isn't a concern with Google.

Let's hope it turns out there's actually no privacy concern. Then all we'd have to worry about is whether to trust Google in the first place, given their track record as I've described below.