Advances in artificial intelligence have created new threats to the privacy of health data, a new UC Berkeley study shows.
The study, led by professor Anil Aswani of the Industrial Engineering & Operations Research Department (IEOR) in the College of Engineering and his team, suggests current laws and regulations are nowhere near sufficient to keep an individual’s health status private in the face of AI development. The research was released today on JAMA Network Open.
In the work, which was funded in part by UC Berkeley’s Center for Long-Term Cybersecurity, Aswani shows that by using artificial intelligence, it is possible to identify individuals by learning daily patterns in step data (like that collected by activity trackers, smartwatches and smartphones) and correlating it to demographic data. The mining of two years’ worth of data covering more than 15,000 Americans led to the conclusion that the privacy standards associated with 1996’s HIPAA (Health Insurance Portability and Accountability Act) legislation need to be revisited and reworked.
“We wanted to use NHANES (the National Health and Nutrition Examination Survey) to look at privacy questions because this data is representative of the diverse population in the U.S.,” Aswani says. “The results point out a major problem. If you strip all the identifying information, it doesn’t protect you as much as you’d think. Someone else can come back and put it all back together if they have the right kind of information.”
“In principle, you could imagine Facebook gathering step data from the app on your smartphone, then buying health care data from another company and matching the two,” he explains. “Now they would have health care data that’s matched to names, and they could either start selling advertising based on that or they could sell the data to others.”
Aswani makes it clear that the problem isn’t with the devices, but with how the information the devices capture can be misused and potentially sold on the open market.
“I’m not saying we should abandon these devices,” he says. “But we need to be very careful about how we are using this data. We need to protect the information. If we can do that, it’s a net positive.”
Though the study specifically looked at step data, Aswani says the results suggest a broader threat to the privacy of health data. “HIPAA regulations make your health care private, but they don’t cover as much as you think,” he says. “Many groups, like tech companies, are not covered by HIPAA, and only very specific pieces of information are not allowed to be shared by current HIPAA rules. There are companies buying health data. It’s supposed to be anonymous data, but their whole business model is to find a way to attach names to this data and sell it.”
Aswani says he is worried that as advances in AI make it easier for companies to gain access to health data, the temptation for companies to use it in illegal or unethical ways will increase. Employers, mortgage lenders, credit card companies and others could potentially use AI to discriminate based on pregnancy or disability status, for instance.
“Ideally, what I’d like to see from this are new regulations or rules that protect health data,” he says. “But there is actually a big push to even weaken the regulations right now. For instance, the rule-making group for HIPAA has requested comments on increasing data sharing. The risk is that if people are not aware of what’s happening, the rules we have will be weakened. And the fact is the risks of us losing control of our privacy when it comes to health care are actually increasing and not decreasing.”
Learn more: Advancement of artificial intelligence opens health data privacy to attack
The Latest on: Health data privacy
[google_news title=”” keyword=”health data privacy” num_posts=”10″ blurb_length=”0″ show_thumb=”left”]
via Google News
The Latest on: Health data privacy
- What apps do with your health data when you're not lookingon May 3, 2024 at 3:24 am
You shouldn’t be so quick to trust your pregnancy app or others with your health data. The Ethical Tech Project’s Jonathan Joseph explains.
- Abortion data bill raises concerns among providers, privacy advocateson May 1, 2024 at 2:19 pm
During a hearing in the House Health and Human Services Committee, Hennessey asked lawmakers to expand the data collected to include any post-abortion complications, and to amend the bill to include ...
- Medical research is changing, data privacy laws have noton April 30, 2024 at 6:12 am
Congressional inaction regarding health privacy laws robs Americans’ control of ownership of their health data, according to Senator Bill Cassidy, ranking member of the Senate HELP committee.
- 3 ways healthcare marketers can navigate the shifting data privacy landscapeon April 30, 2024 at 5:37 am
For The Drum's Healthcare & Pharma Focus Week, Acxiom's Brady Gadberry (SVP, head of data products) and Jordan Abbott (chief data privacy officer) talk data compliance and audience engagement in the ...
- Healthcare providers are failing to protect the privacy of people living with HIV, watchdog warnson April 29, 2024 at 5:03 pm
Healthcare providers are failing to protect the privacy of people living with HIV, the UK’s data watchdog has warned. The Information Commissioner’s Office said it has been forced to hand fines worth ...
- Ohio Dems introduce bill to safeguard IVF, protect personal digital health care dataon April 29, 2024 at 8:52 am
Ohio House Bill 502, introduced April 25 and sponsored by Anita Somani (D-Dublin), a practicing OB/GYN, is the minority party’s attempt to head off any challenge to assisted reproductive treatment ...
- Biden Administration Finalizes Rule To Support Reproductive Health Care Privacyon April 29, 2024 at 8:44 am
On April 26, 2024, the Department of Health and Human Services published a final rule to strengthen privacy protections for people accessing and providing reproductive health care. The final rule adds ...
- Nuanced Privacy Laws Means Healthcare Organizations Should Prioritize Protecting Personal Informationon April 28, 2024 at 5:00 pm
The healthcare industry is among the most highly regulated industries when it comes to privacy protections. In addition to the federal Health Insurance Portability and Accountability Act (HIPAA), ...
- Commit to Your Data Privacy in Retirementon April 28, 2024 at 1:59 am
As we wrap up tax season, it’s a good time to consider your data and privacy. Often, data collectors say that the vast amount of information they take in is tightly secured or anonymized before it is ...
- FTC finalizes changes to data privacy rule to step up scrutiny of digital health appson April 26, 2024 at 1:30 pm
The Federal Trade Commission (FTC) finalized a rule Friday that aims to tighten the reins on digital health apps sharing consumers' sensitive medical data with tech companies. | The FTC finalized a ...
via Bing News