Re: Health Care Privacy Alert
At 09:57 AM 8/10/94 EDT, Gerald M. Phillips, Ph.D. wrote:
Posted for general interest
Subject: Health Care Privacy Alert
The health care legislation proposed by Gephardt in the House and Mitchell in the Senate contains provisions which would establish a national health care data network and override most state medical confidentiality laws. All health care providers, whether paid by insurance or not, will be required to provide the network with data from the patient medical record after every clinical encounter.
*Any* bill that passes will have all sorts of juicy, privacy-invading provisions. Leftists in the "privacy community" will have to decide which they like better: privacy or "health security." There's no way you can have a government-directed, third-party-paid, health care "system" without throwing privacy out the window. Bureaucracies *keep* records, they don't destroy them. Our president likes the "German System" -- 'nuff said. DCF "According to the CBO report on the 'Clinton-Mitchell Bill,' the effective marginal tax rate on some lucky moderate income families ($20K-$30K) will be 85%(!) due to 1) ordinary taxes, (2) phase out of the earned income tax credit, and (3) phase out of health insurance subsidies under the 'Clinton-Mitchell Bill'."
Duncan Frissell wrote:
There's no way you can have a government-directed, third-party-paid, health care "system" without throwing privacy out the window. Bureaucracies *keep* records, they don't destroy them.
Yes, this is a lesson history tells us. But maybe, theoretically, strong crypto could make a change. Nested information with keys known only to parties with legitimate interest in a specific info layer and the master key only known to the patient and programs for self destruction (including backups) of data no longer needed. I repeat, theoretically that is. Mats
Mats Bergstrom writes:
Duncan Frissell wrote:
There's no way you can have a government-directed, third-party-paid, health care "system" without throwing privacy out the window. Bureaucracies *keep* records, they don't destroy them.
Yes, this is a lesson history tells us. But maybe, theoretically, strong crypto could make a change. Nested information with keys known only to parties with legitimate interest in a specific info layer and the master key only known to the patient and programs for self destruction (including backups) of data no longer needed. I repeat, theoretically that is.
The simplest solution is *cash*. It's worth taking a minute to see why cash is so important in this context, and why accounting-based systems that compile records are inherently insecure. The beauty of a cash transaction, throughout history, is *immediate settelement*. Parties have to examine a deal, look for flaws, and then make a judgement about whether to complete the deal. Once completed, it's hard to change one's mind, go back on the deal, complain, etc. This enforces a kind of due diligence. Cash on the barrelhead, as they say. Non-cash systems are of course sometimes desirable: credit cards, insurance schemes, contractual relationships, leases, etc. All kinds of variants. However, these contractual relationships involved *time extent*, that is, they are not settled immediately, on the spot. This has many potentially negative effects: - confusion of time...people evolve different expectations of a contract, causing disputes - people often fail to do the due diligence of a cash transaction (for example, the very same people who are good at haggling at a flea market, and understand "caveat emptor" implicitly, will bitch and moan and complain about contracts...seeking more, changes, adjustments, etc.--an interesting contrast). - temporal extent implies record-keeping, such as insurance records, hospital visits, etc. This is automatically a potential privacy concern. (And when the contract is more than just patient-doctor, but involves other payers, the records-keeping mushrooms. When the government is the ultimate payer, through mandatory plans, they'll have the records. No amount of crypto can possibly change that.) - efficiency. Parties in cash transactions get what they paid for, else they wouldn't have made the transaction. - fraud. While cash transactions can have fraud (con jobs, fake merchandise, etc.), the opportunities for fraud increase dramatically with non-cash systems. When others are paying, such as for health care, the temptation to participate in frauds is higher. (When a patient pays cash, no problem. When a central service is used, opportunities for fraud increase. Doctors with ghost patients, kickbacks, etc. Any central-payment system must then have records and investigations at that central point. Hence, a central bureaucracy. Hence, a loss of privacy at that level.) And so on. My point is mostly that cash has certain elegant properties which are lost when replaced with a central accounting scheme. "Locality of reference" is the computer-related equivalent. Why should this matter to Cypherpunks, if you've read this far? (By the way, yes, Hal, I *did* read to your "Has anyone read this far?" question a few days ago.) Systems which preserve this cash/locality of reference feature, such as digital cash, digital postage, and the "Digital Silk Road" proposal of Hardy and Tribble, have likely advantages over centralized, record-oriented systems. You all know that digital cash is important. This is why the National Health Care Plan is a bad idea, will destroy privacy, and basically can't be fixed by band-aids that allegedly protect patient records. --Tim May -- .......................................................................... Timothy C. May | Crypto Anarchy: encryption, digital money, tcmay@netcom.com | anonymous networks, digital pseudonyms, zero 408-688-5409 | knowledge, reputations, information markets, W.A.S.T.E.: Aptos, CA | black markets, collapse of governments. Higher Power: 2^859433 | Public Key: PGP and MailSafe available. "National borders are just speed bumps on the information superhighway."
Timothy C. May wrote: <good arguments for using cash deleted>
- temporal extent implies record-keeping, such as insurance records, hospital visits, etc. This is automatically a potential privacy concern.
Yes, but... An insurance company would hardly accept a totally anonymous agent as a customer, for obvious reasons (how would they know that the agent was paid for by the body needing repair and not used for an unfortunate uninsured friend?). Now, if there was only one insurance agency thad had to pay for everyone anyway, that agency wouldn't have to trust the patients, 'only' the doctors (to deliver the true figures of their care production) and so wouldn't necessarily have to be given the identities of patients. Such a system has other implications not belonging in this discussion but this is just to show that no simle rules apply. (In the present situation all insurance companies are so mixed up with each other in reinsurances that in a way they are a single entity.)
(And when the contract is more than just patient-doctor, but involves other payers, the records-keeping mushrooms. When the government is the ultimate payer, through mandatory plans, they'll have the records. No amount of crypto can possibly change that.)
Yes, since doctors are not to be trusted the ultimate payer needs records. So they get to know that unit SSN XYZ has been given treatment amounting to DRG (Diagnose Related Group - the system widely used by insurance entities to equalize and minimize costs, which can be used by doctors to 'diagnose' mostly the profitable entries) 384 (abortion, spontaneous or provocated - detailed like this to enable easy record- raiding by the DRG police, I guess). Crypto no use? Perhaps, but ... Suppose those Central Records are encrypted in layers. The DRG Paymasters have the key to the outermost layer so they can read: A patient, anon-9Aq7r, was treated by dr Bob Livingstone for DRG-New XY, where XY only points to the costs without diagnose, at a specified date. They pay Joe what they owe him. If they suspect him of grand fraud he is asked to reveal the key to the next layer, where the identity (no SNN needed, only name and address) of Alice is in the open. The Paymasters can now ask Alice if she was treated by Bob Livingstone at the specified date. If they suspect Bob of salting his bills they have to ask a court for permission to request his second key, further opening the records to reveal DRG-Old 384, making it possible to check with Alice if she was treated for abortion, spontaneous or (e g AND) provocated. If they suspect Alice of collaborating with Bob in a scam they have to ask another (higher) court for permission to request Alice's key, the only key to open the actual treatment records (if these are falsified, well...). This scheme is not a proposal, I just thought it up for the moment, and has several obvious flaws. Like if Alice lies when the Paymasters approach her, or just says 'no comment' or refuses to give away her key. But some scheme might be possible that at least makes it more difficult for the ultimate payer to invade privacy, still keeping an eye on money-hungry doctors.
(When a patient pays cash, no problem. When a central service is used, opportunities for fraud increase. Doctors with ghost patients, kickbacks, etc. Any central-payment system must then have records and investigations at that central point. Hence, a central bureaucracy. Hence, a loss of privacy at that level.)
One problem with cash here is of course the high costs of helth care, making it necessary for almost everybody to be insured if they are not suicidal or willing to gamble their lifes. Another problem is the unconsious-patient situation - or half-consious, might be hard to remember the password to the e$ anonymous account. These are general arguments. I have no opinion in the specific case of the NHCP, a very domestic US discussion. Mats
Timothy C. May wrote:
<good arguments for using cash deleted>
- temporal extent implies record-keeping, such as insurance records, hospital visits, etc. This is automatically a potential privacy concern.
Yes, but... An insurance company would hardly accept a totally anonymous agent as a customer, for obvious reasons (how would they know that the agent was paid for by the body needing repair and not used for an unfortunate uninsured friend?). Now, if there was only
I wasn't arguing that insurance companies would take anonymous customers, per se, though I suspect a privacy-preserving system could in fact be designed. In systems where a customer and insurance provider work out a mutually-beneficia contract, and where there is no requirement to forward records to the government, then privacy is mostly maintained. The concern many of us have is with systems in which governments demand to be "silent partners" in all contractual relationships.
(When a patient pays cash, no problem. When a central service is used, opportunities for fraud increase. Doctors with ghost patients, kickbacks, etc. Any central-payment system must then have records and investigations at that central point. Hence, a central bureaucracy. Hence, a loss of privacy at that level.)
One problem with cash here is of course the high costs of helth care, making it necessary for almost everybody to be insured if they are not suicidal or willing to gamble their lifes. Another problem is the unconsious-patient situation - or half-consious, might be hard to remember the password to the e$ anonymous account.
I'm not insured. Most health-care costs are payable directly...unless and until the U.S. gets a socialist health care system, in which case I'll still be uninsured (I'm not employed, I'm not indigent, so I won't be covered by any of the current proposals, as I understand it). I'm not going to digress further into insurance issues, except to say that insurance has had the bad effect of decoupling payments and services, a la the well-known "tragedy of the commons." People pay for insurance, or their companies do, and then they try to demand the largest number of services...it's game-theoretically advantageous for them to do so. Hence the $2000 almost-obligatory CAT scan upon entering a hospital in the U.S. (fed also by the malpractice racket--doctors order these $2000 CAT scans to cover their asses against lawsuits and because they get legal kickbacks for these services). Life expectancy, in the U.S. at least, has remained at roughly 72-74 years for the past couple of decades, so this huge health care industry has had little real effect on our chances of living longer. For the rare person who is in fact saved by this expensive system, it is "worth it," of course. But the aggregate benefits tell a different story. The relevance to Cypherpunks? I don't know, but it's partly connected to issues of whether centralized systems and record-keeping are a good idea. I actually see no reason why we as potential patients should not carry around our medical records ourselves. Perhaps in a smart card...the technology has existed for years. Or in a "medical bracelet" which either directly contains local storage (flash memory, for example) or contains a pointer to a file on the Net--and access information, if encrypted, as it should be--which contains relevant medical information and perhaps even financial payment instructions. Selective disclosure of credentials, a la Chaum, should apply quite naturally to medical care. A dossier society is not needed. (I don't demand that others use such a system, only that I and my medical contractor not be required to use someone else's idea of a system. Seems fair to me.) --Tim May -- .......................................................................... Timothy C. May | Crypto Anarchy: encryption, digital money, tcmay@netcom.com | anonymous networks, digital pseudonyms, zero 408-688-5409 | knowledge, reputations, information markets, W.A.S.T.E.: Aptos, CA | black markets, collapse of governments. Higher Power: 2^859433 | Public Key: PGP and MailSafe available. "National borders are just speed bumps on the information superhighway."
participants (3)
-
frissell@panix.com -
Mats Bergstrom -
tcmay@netcom.com