Welcoming Remarks. Commissioner Brill



Similar documents
December Federal Employees Health Benefits (FEHB) Program Report on Health Information Technology (HIT) and Transparency

Data Use and the Liquid Grids Model

Get More Information Where can I get personalized help? Get information 24 hours a day, including weekends

BCSC Health Center Information

Proposal for Demonstrating at California Connects 2014

How To Prepare For A Patient Care System

Federal Employees Health Benefits Program Report on Health Information Technology (HIT) and Transparency. September 2007

Direct Messaging and Individual s Right of Access through Their Personal Health Record

Frequently Asked Questions About Quality Data Reporting

YOUR PERSONAL HEALTH RECORD

HIPAA Compliance Issues and Mobile App Design

Understanding. Your Medical Record

The Patient Portal Ecosystem: Engaging Patients while Protecting Privacy and Security

NATIONAL HEALTH POLICY FORUM. January 2010

Open Platform. Clinical Portal. Provider Mobile. Orion Health. Rhapsody Integration Engine. RAD LAB PAYER Rx

Electronic Medical Records

Meaningful Use and Engaging Patients: Beyond Checking the Box

Advanced Diagnostics Limited ( We ) are committed to protecting and respecting your privacy.

Patient-Generated Health Data and its Impact on Health Information Management

Stage 1 measures. The EP/eligible hospital has enabled this functionality

Health Information Technology in Healthcare: Frequently Asked Questions (FAQ) 1

The EP/eligible hospital has enabled this functionality

1. Introduction - Nevada E-Health Survey

LANES. A key component of the LANES Initiative is to develop a Health Information Exchange.

Achieving Value from Diverse Healthcare Data

PATIENT REGISTRATION FORM

CMS Data Transparency Activities. Niall Brennan, Acting Director Office of Enterprise Management

Eric Jamoom and Chun-Ju Hsiao National Center for Health Statistics

Data Analytics: The Next Wave in Health IT. Big Data Conference June 17, Robert Wah, MD. Global Chief Medical Officer CSC

Is a Personal Health Record Right for You? Considerations for Californians

Health Information Technology Resource Toolkit for Nurses as Health Care Consumers

Faculty Group Practice Patient Demographic Form

The EP/eligible hospital has enabled this functionality. At least 80% of all unique patients. seen by the EP or admitted to the

Consumer Guide to Understanding and Using the PHR Model Privacy Notice on PHR Company Data Practices

Medweb Telemedicine 667 Folsom Street, San Francisco, CA Phone: Fax:

Overview of an Enterprise HIE at Virtua Health

ROI through Quality Improvement: Davies Winner Lessons from the Field Steve Robertson Dale Glenn, MD

Latham & Watkins Corporate Department

Session 1: Core Pharmaceutical Datasets Retail and Non Retail Laura Jenkins Jirele

Current and Future State of Health Informatics for Veterans Health Administration

HIPAA and Big Data Twenty Third National HIPAA Summit. March 17, 2015 Mitchell W. Granberg, Optum Chief Privacy Officer

Glossary of Terms. Account Number/Client Code. Adjudication ANSI. Assignment of Benefits

Networked Personal Health Records

April 22, RE: Advancing Interoperability and Health Information Exchange. Dear Dr. Mostashari:

Kaiser Permanente Comments on Health Information Technology, by James A. Ferguson

PATIENTS WANT A HEAVY DOSE OF DIGITAL

Faculty Group Practice Patient Demographic Form

Practices. Effective Date: 4/2003.Revised.11/2014

Empowering Value-Based Healthcare

EHR Incentive Program Updates. Jason Felts, MS HIT Practice Advisor

ACCIDENTAL INJURY CLAIM FORM

Toward Meaningful Use of HIT

Secondary Uses of Health Data IMPAC s Oncology Data Alliance Program

Consumer Engagement with Health Information Technology Summary of NeHC Survey Results

2013 Meaningful Use Dashboard Calculation Guide

Health Information Exchange: Reality and Future Kenneth A. Kleinberg, FHIMSS Managing Director, The Advisory Board Company

Mobile Medical Applications: An Overview of FDA Regulation

Patient Reported Outcome Data: Why PROs Will Be The Next Wave in Big Data. Neil B. Minkoff, M.D. Chief Medical Officer EmpiraMed

An Update in Electronic Health Records

Electronic Medical Records and Public Health

Health Information Technology and the National Quality Agenda. Daphne Ayn Bascom, MD PhD Chief Clinical Systems Officer Medical Operations

MEDICAL BENEFITS CLASS ACTION SETTLEMENT NOTICE OF INTENT TO SUE

An Important Message on Medicare Prescription Drug Plans Coming to the U.S. Virgin Islands in 2006

Health Care Coverage Directory for People with Medicare

Nephrology Associates New Patient Registration Forms

Street Address Apt. or Post Office Box. City State Zip. Telephone Primary: ( ) Home Work Cell. Date of Birth / / Social Security # - -

National perceptions of barriers, benefits, and federal policies impacting EHR adoption in physician offices, 2011

Revision to the Executive Director for Health Care Policy and Financing Rule Concerning the All-Payers Claims Database, Section 1.

Christopher Powers, Acting Director

Commonwealth Coordinated Care Enrollment Application Form

OFFICE POLICIES. Please note that NO controlled substance requests can be filled via phone as per DEA regulations. (initial)

Privacy Policy. If you have questions or complaints regarding our Privacy Policy or practices, please see Contact Us. Introduction

HEALTHCARE CHANGES AFFECTING YOUR PRACTICE. Vinay Kumar MD, FACS, ABVM Endovascular options Dallas, Texas

THE HIPAA PRIVACY RULE AND THE NATIONAL HOSPITAL CARE SURVEY

Health Information Technology (IT) Simplified

Where to Begin? Auditing the Current EHR System

HL7 & Meaningful Use. Charles Jaffe, MD, PhD CEO Health Level Seven International. HIMSS 11 Orlando February 23, 2011

HIE, RHIOs and EHR Interoperability The Journey to Meaningful Use, Interoperable Health Care Delivery and Improved Quality of Care

Empowering Value-Based Healthcare

The Use of Patient Records (EHR) for Research

How Do Key Stakeholders View Transparency?

POPULATION HEALTH. Annual Wellness Visit (AWV) Matthew Brown, MD Chief Medical Officer Presence Health Partners

Advance Health Care Directive Instructions

Emerging Trends in Health Information Technology: Personal Health Record(PHR) uphr. Nazir Ahmed Vaid ehealth Services (Pvt) Ltd.

BEST PRACTICES FOR MANAGING THE EVOLUTION OF EHRS

Combined Client Agreement, Authorization for Release of Personal Health Information & Notice of Privacy Practices

PRELIMINARY LIFE INSURANCE APPRAISAL REQUEST

SECTION I ELIGIBILITY

Company Presentation. October 2013

How To Get A Physical Therapy At West Point Physical Therapy Center

Health IT: Better Information for Better Decisions. HSE Healthcare Leaders Masterclass April Robert Wah, MD

Registration Forms (Please leave NO blanks, if something does not apply write N/A and if unknown write unknown)

NEBRASKA SMALL GROUP UNIFORM APPLICATION QUESTION AND ANSWERS

Damon A. Ferlazzo, MPA Clinical Use and Benefits of State Immunization Information Systems August 21, 2014

Santa Cruz HIE Proposal for Demonstrating at California Connects 2014

HealthPartners: Triple Aim Approach to ACO Development

DIVURGENT S ACORM FRAMEWORK

HIE: The Vermont Version

Implementing Prescribing Guidelines in the Emergency Department. April 16, 2013

Transcription:

Welcome

Welcoming Remarks Commissioner Brill

Health Data Flows Latanya Sweeney Chief Technologist, FTC

Transparency Establishes Trust @TechFTC lsweeney@ftc.gov thedatamap.org

Disclaimer The views and opinions in this presentation represent my own and are not necessarily those of the U.S. Federal Trade Commission. These views are for the benefit of public discourse and public education, and are not necessarily an opinion regarding any position I may take on related issues decided by the FTC.

Transparency Establishes Trust

Establishes Distrust

You, the Patient Physician, Hospital thedatamap.org

Life Insurance Company You, the Patient Physician, Hospital Employer (Yours, Spouse s) Accreditation Payer (Insurer) Consulting Physician Pharmacy Law Firms Pharmacy Benefits Manager Vital Statistics Researcher Employer s Wellness Program

Life Insurance Company Blood & Tissue Personal Transport Retirement & Disability You, the Patient Physician, Hospital ICU Management Clearing House De-identification Debt Collection Human Resources Mental & Addiction Home Health Care Facility Accreditation Employer Dental/Vision Payer (Insurer) Employee Union SSA Disease Management Online Websites Clinical Lab Consulting Physician Education Pharmacy Pharmacy Benefits Manager Discharge Data Social Services Law & Justice Law Firms Copy&Transport Registries Transcriptio Public Health n Coding Associations Financial Social Support Medical Devices Personal Health Record Employer s Wellness Program Researcher Analytics Media Federal Trade Commission Vital Statistics Prescription Analytics Health IT Licensing CDC Pharmaceutical Company Real Estate Other Government

Life Insurance Company Blood & Tissue Personal Transport Retirement & Disability You, the Patient Physician, Hospital ICU Management Clearing House De-identification Debt Collection Human Resources Mental & Addiction Home Health Care Facility Accreditation Employer Dental/Vision Payer (Insurer) Employee Union SSA Disease Management Online Websites Clinical Lab Consulting Physician Education Pharmacy Pharmacy Benefits Manager Discharge Data Social Services Law & Justice Law Firms Copy&Transport Registries Transcriptio Public Health n Coding Associations Financial Social Support Medical Devices Personal Health Record Employer s Wellness Program Researcher Analytics Media Federal Trade Commission Vital Statistics Prescription Analytics Health IT Licensing CDC Pharmaceutical Company Real Estate Other Government Flows not covered by HIPAA

Life Insurance Company Blood & Tissue Personal Transport Retirement & Disability You, the Patient Physician, Hospital ICU Management Clearing House De-identification Debt Collection Human Resources Mental & Addiction Home Health Care Facility Accreditation Employer Dental/Vision Payer (Insurer) Employee Union SSA Disease Management Online Websites Clinical Lab Consulting Physician Education Pharmacy Pharmacy Benefits Manager Discharge Data Social Services Law & Justice Law Firms Copy&Transport Registries Transcriptio Public Health n Coding Associations Financial Social Support Medical Devices Personal Health Record Employer s Wellness Program Researcher Analytics Media Federal Trade Commission Vital Statistics Prescription Analytics Health IT Licensing CDC Pharmaceutical Company Real Estate Other Government

33 States Sell or Share Personal Health Data Hooley S and Sweeney L. Survey of Publicly Available State Health Databases. Paper 1075. 2013. thedatamap.org/states.html

Only 3 States Use HIPAA Standards Hooley S and Sweeney L. Survey of Publicly Available State Health Databases. Paper 1075. 2013. thedatamap.org/states.html

Life Insurance Company Blood & Tissue Personal Transport Retirement & Disability You, the Patient Physician, Hospital ICU Management Clearing House De-identification Debt Collection Human Resources Mental & Addiction Home Health Care Facility Accreditation Employer Dental/Vision Payer (Insurer) Employee Union SSA Disease Management Online Websites Clinical Lab Consulting Physician Education Pharmacy Pharmacy Benefits Manager Discharge Data Social Services Law & Justice Law Firms Copy&Transport Registries Transcriptio Public Health n Coding Associations Financial Social Support Medical Devices Personal Health Record Employer s Wellness Program Researcher Analytics Media Federal Trade Commission Vital Statistics Prescription Analytics Health IT Licensing CDC Pharmaceutical Company Real Estate Other Government

Life Insurance Company Blood & Tissue Personal Transport Retirement & Disability You, the Patient Physician, Hospital ICU Management Clearing House De-identification Debt Collection Human Resources Mental & Addiction Home Health Care Facility Accreditation Employer Dental/Vision Payer (Insurer) Employee Union SSA Disease Management Online Websites Clinical Lab Consulting Physician Education Pharmacy Pharmacy Benefits Manager Discharge Data Social Services Law & Justice Law Firms Copy&Transport Registries Transcriptio Public Health n Coding Associations Financial Social Support Medical Devices Personal Health Record Employer s Wellness Program Researcher Analytics Media Federal Trade Commission Vital Statistics Prescription Analytics Health IT Licensing CDC Pharmaceutical Company Real Estate Other Government

Washington State Health Database 43% news stories re identified News stories have same information that others know. Employers, Creditors, Family, Friends and Neighbors Sweeney L. Matching Known Patients to Health Records in Washington State Data. Paper 1089. 2013. thedatamap.org/risks.html

Transparency Establishes Trust @TechFTC lsweeney@ftc.gov thedatamap.org

A Snapshot of Data Sharing by Select Health and Fitness Apps FTC Staff s Preliminary Observations Jah Juin Jared Ho Sheryl Novick Mobile Technology Unit Federal Trade Commission Christina Yeung Division of Planning and Information Federal Trade Commission

DOB Device Model Symptom Searches Age Language Name? CALORIES BURNED Geolocation Weight Hydration Username Gender Carrier Provider MAC

Privacy Rights Clearinghouse Mobile Health and Fitness Applications and Information Privacy July 2013 Examined 43 free and paid health and fitness apps o Wearables not included Traffic analysis and privacy policy review Findings: o o o 26% of the free apps and 40% of the paid apps did not have a privacy policy 39% of the free apps and 30% of the paid apps sent data to someone not disclosed by the developer either in-app or in any privacy policy they found 13% of the free apps and 10% of the paid apps encrypted all data connections between the app and the developer s website. Conclusion: Our research brought us to the conclusion that, from a privacy perspective, mobile health and fitness applications are not particularly safe when it comes to protecting user privacy. Source: https://www.privacyrights.org/mobile-medical-apps-privacy-consumer-report.pdf

Evidon A Healthy Data Set September 2013 Tested 20 health and fitness apps Found the presence of 70 third parties These companies are typically advertising and analytics companies, who attempt to better match advertisements to users who will buy; and who work to help app developers increase functionality and usability, respectively. Source: http://www.evidon.com/blog/healthy-data-set

WHO and WHAT? Reconceptualizing the Evidon Study :app : third party

Health & Fitness App Snapshot Methodology Twelve apps and two wearables App traffic analysis Mapped the data sets

Health & Fitness App Snapshot Limitations One device Only Free Apps Front-end testing only Did not review privacy policies

App Example One app transmitted information to 18 different 3 rd parties. Information included: *Device Information *Device & 3 rd Party Identifiers *Consumer Specific Identifiers *Workout/Route Information *Diet Information :app : third party : developer

:app : third party

Observation #1 18 third parties received Device Specific Identifiers such as: *Device ID *MAC address *IMEI :app : third party

Observation #2 14 third parties received Consumer Specific Identifiers such as: *Username *Name *Email Address :app : third party

Observation #3 22 third parties received additional information about consumers such as: *Exercise Information *Meal/Diet Information *Medical/Symptom Search Information *Zip code *Geolocation *Gender :app : third party

Summary of Observations Health and fitness apps collect and transmit to third parties sensitive information about our bodies and our habits. The 12 apps tested transmitted information to 76 different third parties. This information included: Device Information; Consumer specific identifiers; Unique device IDs capable of allowing 3 rd parties to track users devices across apps; Unique 3 rd party IDs capable of allowing 3 rd parties to track users devices across apps; and Consumer information such as exercise routine, dietary habits, and symptom searches. There are significant privacy implications where health routines, dietary habits, and symptom searches are capable of being aggregated using identifiers unique to that consumer.

Panel Discussion Christopher R. Burrow, M.D., EVP Medical Affairs, Humetrix Joseph Lorenzo Hall, Chief Technologist, Center for Democracy & Technology Sally Okun, RN, MMHS, Vice President of Advocacy, Policy & Patient Safety, PatientsLikeMe Heather Patterson, Postdoctoral Research Fellow, New York University Joy Pritts, Chief Privacy Officer, Office of the National Coordinator for Health Information Technology, Department of Health & Human Services

Mobile Anytime/Anywhere Access to Personal Health Records 36

Access to e Health Records is a Right Ensured by HIPAA Important tools like Electronic Health Records (EHRs) and Personal Health Records (PHRs) will make it easier, safer, and faster for you to get access to your health information and stay engaged.

ibluebutton Display & Aggregation of TRICARE, VA, Medicare Blue Button and EMR Records (Epic, Cerner, Allscripts etc ) Humetrix 2014

Patient Generated Data Health Care Proxy and Prior Discharge Summaries Imported into ibluebutton

Consumer Controlled Mobile Health Record Access & Exchange EHRs from diverse sources (e.g. hospitals, payers, HCP groups) 40

ibluebutton for Medicare Beneficiaries: Three Years of Medical History in Patients Hands for their Safety From Blue Button to From a 300 page Blue Button ASCII text claims record to a mobile longitudinal health record available at every Point of Care

Providers Transmit Records to their Patients Unique ibluebutton Address using the Secure Federal Direct Transport Standard susan.jones@direct.ibluebutton.com ibluebutton App generates a Direct Address for each Profile Humetrix 2014

ibluebutton: Display of Medicare, EMR, VA and TRICARE records with Real Time Aggregated View 43 Humetrix 2014

Patient Generated Data Medication and Condition Annotations and Privacy Settings Humetrix 2014

ibluebutton Privacy Policy and ONC PHR Model Privacy Notice

Panel Discussion Christopher R. Burrow, M.D., EVP Medical Affairs, Humetrix Joseph Lorenzo Hall, Chief Technologist, Center for Democracy & Technology Sally Okun, RN, MMHS, Vice President of Advocacy, Policy & Patient Safety, PatientsLikeMe Heather Patterson, Postdoctoral Research Fellow, New York University Joy Pritts, Chief Privacy Officer, Office of the National Coordinator for Health Information Technology, Department of Health & Human Services