A few of our stories and columns are now in front of the paywall. We at The Chief remain committed to independent reporting on labor and civil service. It's been our mission since 1897. You can have a hand in ensuring that our reporting remains relevant in the decades to come. Consider supporting The Chief, which you can do for as little as $3.20 a month.
The author writes in regard to the proposed sharing of municipal worker pharmacy data with insurance companies as discussed in a Sept. 11 article in the The Chief: "Union calls out MLC for 'veiled threat' over worker health data sharing."
The vast majority of individuals comprehend the implications of a breach of Personally Identifiable Information (PII) such as one's name in association with a Social Security number, driver's license number or financial account number; so much so, many have become desensitized to each and every breach notification received in the mail, posted on web sites or discussed by public media.
Unfortunately, the preponderance of individuals are, to no fault of their own, uninformed about the immeasurable, profound and permanent impacts of a breach or misuse of one's Protected Health Information (PHI), which is qualitatively different from PII. PHI includes clinical lab test results, imaging reports, diagnoses or propensities to experience dreaded diseases and, importantly, individuals’ pharmacy data.
A breach of financial data may temporarily result in harm or disruptions such as frozen bank accounts, stolen credentials and the like. Most of these situations are eventually resolved, granted often with a lot of aggravation, lost money and lost time
A breach or misuse of PHI, on the other hand, may result in discrimination that can have cross-generational impacts. If, for example, you are an employer paying the bulk of costs for your employees’ healthcare insurance and you are considering two equally qualified candidates but the knowledge had been shared with you that one of those individuals was being treated for cancer, would that sway your decision?
Even though employers may balk at this scenario, the ugly truth is that hiring discrimination can and does occur on many bases, including determinations of a candidate’s health; this country has the court cases and constitutional amendments to prove it. Access to sensitive health information opens up yet another avenue of employer discrimination in the hiring process.
And the impacts aren’t limited to the candidate’s health alone; if a prospective employee’s child or partner has a serious illness, an employer with access to that information may, whether intentionally or not, factor that into their decision-making process.
If you learned through a breach of PHI on the internet that someone close to you in your life had an extremely high likelihood of being severely incapacitated in a matter of years due to ALS, Parkinson's or another horrible disease, or if you yourself had this information shared with both loved ones and strangers without your consent, this would likely feel like a massive breach of autonomy.
Who would want to relinquish their control over when, and how, they shared such sensitive information? It is not overly dramatic to say that this could be a relationship and life changing breach of information.
PHI, such as pregnancy results, family planning, abortions, mental health, HIV or genetic predispositions to dreaded diseases deserve to be protected by the strongest safeguards possible.
In one's personal life, individuals ideally have autonomy in choosing who knows what about their health. In professional settings, the fewest number of people having a need to know and right to know this information should be granted access to it...and then, only the minimally necessary access to perform authorized work (i.e. access, use, sharing, transmission and eventually, secure destruction).
We all have experienced linkages of our seemingly insignificant information being made available on the internet. And with increasing frequency of data breaches coupled with the almost incomprehensible amounts of data being used in the application of artificial intelligence, strands of our information are being woven together to make a tapestry that is unique to us. Advertisements on TV, streaming services and print media are literally targeted to you, and your family, with ever increasing precision.
If NYC and the union bosses agree to share your PHI with one or more insurance companies, regardless of their good intentions, one can only imagine the permanent harm that could come if this data accidentally, or even maliciously escapes the vessel in which it is stored—which, even if it is as impenetrable as Fort Knox, will still always have the potential to be breached. And to the extent the data is "de-identified" in the context of contemporary data protection standards--unfortunately, artificial intelligence is supported by massive data centers both in the US and abroad, and globally countries are struggling to create and enforce appropriate regulations for this burgeoning technology.
The lack of regulations and enforcement plays out in many different ways and could involve substantial breaches of PHI and other sensitive data.
Pharmacy data captured in any fashion other than for the original and understood purpose, in my opinion, is a tragic, irresponsible and irreversible catastrophic accident waiting to happen.
As a former information security official, I have tremendous respect and appreciation for the work professional privacy officers and information protection professionals do to safeguard strangers’ sensitive data. Unfortunately, the highly dedicated professionals in these careers are greatly outnumbered by individuals and groups willing to do whatever it takes to wrongfully acquire PII and PHI that can then be monetized or used as leverage to blackmail individuals, groups of individuals or organizations.
The proof of this is in the news on a daily basis, in stories that often become the center of public discourse. Ultimately, any of our information can become indelible and discoverable regardless of who we are or the good intentions of the people who have captured it.
Even if you are comfortable having your PII and PHI shared for "good, legal" reasons, between insurance companies and NYC, are you comfortable with your family’s data likewise being shared? Once your data has been shared, like an egg that’s been cracked, there is no putting the yolk back in the shell.
If your PII and PHI are to be treated like a commodity on the stock market, please place a literal monetary value on your and your family's data. Demand to be properly compensated by others making use of your sacred information.
After all, this appears to be the model at play; if your pharmacy data is being shared with an insurance company NYC and/or the unions will receive monetary compensation in one form or another, so shouldn't you get your cut? For crying out loud, it is your privacy that is being negotiated away.
If you fail to speak up and speak out about this matter in a timely fashion, the decision will be made on your behalf by people who have reassured us that they are "very smart" but have yet to demonstrate that they take the risks of these choices seriously enough to warrant us trusting them with our most private information.
I’ve made my choice, and I urge you to consider yourself and your family when you make yours.
1 comment on this item Please log in to comment by clicking here
DOTHERIGHTTHING
Shame on DC37 Henry Garrido sharing private data with Healthcare Companys of his members. First Garrido Sold Out NYC Medicare Retirees Earned Healthcare to FUND active raises now this????? Makes NO Sense. Garrido needs to be voted out ASAP!
Tuesday, September 22 Report this