Shadow health records meet new data privacy laws
- PMID: 30705168
- PMCID: PMC6417878
- DOI: 10.1126/science.aav5133
Shadow health records meet new data privacy laws
Abstract
Large sets of health data can enable innovation and quality measurement but can also create technical challenges and privacy risks. When entities such as health plans and health care providers handle personal health information, they are often subject to data privacy regulation. But amid a flood of new forms of health data, some third parties have figured out ways to avoid some data privacy laws, developing what we call “shadow health records”—collections of health data outside the health system that provide detailed pictures of individual health—that allow both innovative research and commercial targeting despite data privacy rules. Now that space for regulatory arbitrage is changing. The long arms of Europe’s new General Data Protection Regulation (GDPR) and California’s new Consumer Privacy Act (CCPA) will reach shadow health records in many companies. In this article, we lay out the contours of the GDPR’s and CCPA’s impact on shadow health records and health data more broadly, highlight critical remaining uncertainty, and call for increased clarity from lawmakers and industry on the use of such data for research.
Similar articles
-
Health records privacy and confidentiality: pending questions.J Contemp Health Law Policy. 2002 Fall;18(3):685-91. J Contemp Health Law Policy. 2002. PMID: 12491664 No abstract available.
-
HIPAA at 25 - A Work in Progress.N Engl J Med. 2021 Jun 10;384(23):2169-2171. doi: 10.1056/NEJMp2100900. Epub 2021 Jun 5. N Engl J Med. 2021. PMID: 34110114 No abstract available.
-
Privacy as an enabler, not an impediment: building trust into health information exchange.Health Aff (Millwood). 2009 Mar-Apr;28(2):416-27. doi: 10.1377/hlthaff.28.2.416. Health Aff (Millwood). 2009. PMID: 19275998
-
Privacy, Data Sharing, and Other Legal Considerations.Surg Clin North Am. 2023 Apr;103(2):347-356. doi: 10.1016/j.suc.2022.12.003. Surg Clin North Am. 2023. PMID: 36948723 Review.
-
Privacy Protection and Secondary Use of Health Data: Strategies and Methods.Biomed Res Int. 2021 Oct 7;2021:6967166. doi: 10.1155/2021/6967166. eCollection 2021. Biomed Res Int. 2021. PMID: 34660798 Free PMC article. Review.
Cited by
-
Principles for Health Information Collection, Sharing, and Use: A Policy Statement From the American Heart Association.Circulation. 2023 Sep 26;148(13):1061-1069. doi: 10.1161/CIR.0000000000001173. Epub 2023 Aug 30. Circulation. 2023. PMID: 37646159 Free PMC article. Review.
-
"My Research Is Their Business, but I'm Not Their Business": Patient and Clinician Perspectives on Commercialization of Precision Oncology Data.Oncologist. 2020 Jul;25(7):620-626. doi: 10.1634/theoncologist.2019-0863. Epub 2020 Mar 13. Oncologist. 2020. PMID: 32167617 Free PMC article.
-
Addressing Online Health Privacy Risks for Older Adults: A Perspective on Ethical Considerations and Recommendations.Gerontol Geriatr Med. 2022 Apr 21;8:23337214221095705. doi: 10.1177/23337214221095705. eCollection 2022 Jan-Dec. Gerontol Geriatr Med. 2022. PMID: 35493968 Free PMC article.
-
Hospitals should act now to notify patients about research use of their data and biospecimens.Nat Med. 2020 Mar;26(3):306-308. doi: 10.1038/s41591-020-0795-6. Nat Med. 2020. PMID: 32161402 Free PMC article.
-
Protecting Privacy When Genetic Databases Are Commercialized.JAMA. 2025 Feb 25;333(8):665-666. doi: 10.1001/jama.2024.26279. JAMA. 2025. PMID: 39786753
References
-
- Gostin LO, Halabi SF, Wilson K, JAMA 320, 2334 (2018). - PubMed
-
- Price WN II, Minn. Law Rev. 102, 101 (2018).
-
- Spector-Bagdady K, Shuman AG, Otolaryngol. Head Neck Surg. 158, 405 (2018). - PubMed
-
- Tanner A, Our Bodies, Our Data: How Companies Make Billions Selling our Medical Records (Beacon Press, 2017).
-
- Molteni M, WIRED 3 August (2018); www.wired.com/story/23andme-glaxosmithklinepharma-deal.
Publication types
MeSH terms
Grants and funding
LinkOut - more resources
Full Text Sources
Medical
Miscellaneous