DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Transparency is no substitute for informed consent in health records privacy

Posted on October 26, 2010 by Dissent

William Pewen wrote a terrific commentary a few weeks ago. If you didn’t read it, read it now. Here’s a snippet:

Unfortunately, the congressional approach to medical records has failed to be a truly patient-centered one. Republicans largely view medical information through a business lens and assert that the marketplace will be self-correcting; many Democrats have been convinced to accept risk of individual harm by the promise of scientific progress and resulting improvements in public health. The result is that lobbying on both fronts has eroded an ethical foundation built on bulwarks such as the Hippocratic Oath, the Nuremberg Code, and the Helsinki Declaration. The full ramifications of that erosion have an insidious impact upon civil rights and require a more comprehensive treatment.

Suffice it to say, the public’s interest in medical records has often been subordinated to lobbying by health sector interests in recent years. This occurs at the same time that health IT promises to increase information exchange exponentially, raising the stakes. Two prerequisites to implementation should be obvious – data must be appropriately secured and restricted, and uses without consent must be limited to those that are necessary. In the absence of patient consent, access to medical data should follow the principle of need to know, not want to use.

Not surprisingly, I agree with him and have felt like a broken record repeating the mantra that entities need consent to share information or data. Informed consent (not just unknowing consent as might occur when a patient signs a bunch of papers so they can get in to see the doctor when they’re ill) is a cornerstone of trust between patient and doctor. Some of the most vociferous advocates on this issue are all professionals who are or who have been clinicians. That politicians and business people who are not health care professionals trained in the concept of privacy and confidentiality don’t fully “get it” does not surprise me, but it scares me as they have more clout on a day-to-day basis than those of us who are trying to get the adoption of new technologies to be privacy- and patient-centric.

Today, Frank Pasquale writes about a shift from a consent-based paradigm to a transparency paradigm. He writes, in part:

A collective commitment to privacy is far more valuable than a private, transactional approach that all but guarantees a race to the bottom. If such a collective commitment does not materialize, record systems will only deserve trust if they become as transparent as the patients and research subjects they profile. Given corporate assertion of trade secrecy (and even privacy rights), reciprocal transparency will not be easy to achieve. Nevertheless, repeated breaches, fraud, and data meltdowns in the US should provoke an alliance of socially responsible researchers to lobby the US government to set minimal standards of reciprocal transparency and auditing. Consumers can only trust innovators if they can understand what is being done with data. As we become “transparent citizens” (as Joel Reidenberg puts it), we should demand that the corporate, university, and governmental authors of that trend reciprocate, and become more open about the data they gather.

While that may sound reasonable, it is unsatisfactory, as transparency and audits are not a substitute for informed consent. They are helpful and they are important, but they are not a substitute for consent.

It is clear that people are still trying to do an end-run around consent by offering alternatives that make lack of consent more palatable. But those approaches are simply not consistent with the oath we take to keep what we learn about a patient confidential and private – an oath most of us take pretty damned seriously.

Category: Uncategorized

Post navigation

← Consent and privacy in HIT, redux
UK: Moving on from the 2007 data loss by HMRC →

1 thought on “Transparency is no substitute for informed consent in health records privacy”

  1. Anonymous says:
    October 26, 2010 at 9:18 am

    As always Dissent, you are RIGHT ON TARGET.

    Transparency cannot possibly make patients trust electronic health systems. Only control over personal health information will make systems trustworthy.

    Being told what corporations and government agencies will see and use our sensitive health records and–thanks to the Coalition for Patient Privacy—federal law now enabling us to get an accounting of all disclosures of our health information for the past years DOES help, but does not solve the BIG trust problem.

    The trust problem that must be solved is patients are NOT OK with others deciding when to use, disclose, or sell their personal health information. The ONLY solution is putting patients BACK in control of their health information. We STILL have very strong existing rights to control who can see and use health information, but the health data mining industry, the government, and the research industry have been working around the clock to take our rights away.

    Sign up for the Do Not Disclose petition and tell Congress to restore your control over personal health information at: http://patientprivacyrights.org/do-not-disclose/

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Western intelligence agencies unite to expose Russian hacking campaign against logistics and tech firms
  • Disrupting Lumma Stealer: Microsoft leads global action against favored cybercrime tool
  • Researchers Scrape 2 Billion Discord Messages and Publish Them Online
  • Privilege Under Fire: Protecting Forensic Reports in the Wake of a Data Breach
  • Hacker who breached communications app used by Trump aide stole data from across US government
  • Massachusetts hacker to plead guilty to PowerSchool data breach (1)
  • Cyberattack brings down Kettering Health phone lines, MyChart patient portal access (1)
  • Gujarat ATS arrests 18-year-old for cyberattacks during Operation Sindoor
  • Hackers Nab 15 Years of UK Legal Aid Applicant Data
  • Supplier to major UK supermarkets Aldi, Tesco & Sainsbury’s hit by cyber attack with ransom demand

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Researchers Scrape 2 Billion Discord Messages and Publish Them Online
  • GDPR is cracking: Brussels rewrites its prized privacy law
  • Telegram Gave Authorities Data on More than 20,000 Users
  • Police secretly monitored New Orleans with facial recognition cameras
  • Cocospy stalkerware apps go offline after data breach
  • Drugmaker Regeneron to acquire 23andMe out of bankruptcy
  • Massachusetts Senate Committee Approves Robust Comprehensive Privacy Law

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.