The App That Lets You Sell Your Personal Healthcare Data

IBM and a start-up have launched a blockchain-based app that lets patients eventually sell anonymised data to pharmaceutical companies, researchers and others while retaining greater control over privacy.

Most people don't know it but there is a multi-billion dollar industry that collects  healthcare information, strips it of basic personal identifiers such as name, address and Social Security Number, and then sells it off to researchers, drug developers, marketers and others.

Medical informatics companies, such as Iqvia (IMS Health), Optum, and Symphony Health reap the profits of selling the healthcare data while the people from whom it's collected have no control over how it's used. Nor do they get any compensation for it.

Start-up Hu-manity.co has partnered with IBM to develop an electronic ledger that gives consumers the cryptographic key to grant to their personal data, even allowing patients or others to control the specific purpose for which it's used, while also allowing them to eventually profit from it.

The new Global Consent Ledger will initially begin with healthcare data from U.S. residents and provide a digital data trail stored on the IBM Blockchain Platform, which uses the Hyperledger Fabric specification.
How the Global Consent Ledger works

New Jersey-based Hu-manity.co expects its consent ledger to act as the broker for all kinds of consumer information, from geolocation data garnered from streaming services to credit reports and even browser history, according to Richie Etwaru, CEO and co-founder of Hu-manity.co.

"We're not the dealer of the data but the broker," Etwaru said. "We're a title company for your digital identity. We're not in business of building a big data lake or collecting data."

The #My31 Android App, which will allow users to sign up to have their anonymized healthcare data shared, went live today and is available in the Google Play Store. An iOS app is currently being reviewed by the Apple review team and is expected to launch at a later date, according to Hu-manity.co.

Once a user has signed up for the app, there's a short on-boarding process that sets up the blockchain user with their private key and a "title" for their data.

Users are also connected to a point system, similar to a retail store's rewards card, where each time they authorize use of their data they receive points that can be redeemed for products, such as clothing in an online store. Eventually, Etwaru said, he hopes to be able to reward users with money – as much as $100 to $200 a year depending on the amount and type of data being leased.

"When enough people get involved in the movement, we'll start to negotiate with the healthcare industry on price," Etwaru said.

Hu-manity's stated – and somewhat lofty – goal is to establish personal data as having the same rights as other forms of property, real or intellectual, and to eventually allow owners to be involved in fair market negotiation for its use. That would allow it to be leased, donated or passed on as part of an estate.

"And, if it's stolen, it's a completely different type of offense," Etwaru said. "Right now, data's in this weird state. When it's stolen, you can't go to the police station and report someone stole your medical data like someone stole your car.

"Our vision is to bring people and the enterprise together in a place where data can be respected as property," Etwaru added.
The #My31 App got its name from personal data ownership being pitched as a 31st human right by Hu-manity.co. In 1948, the United Nations listed 30 basic human rights as part of its Universal Declaration of Human Rights, which was created to provide a global understanding of how individuals should be treated.

Better quality data, and compensation for the owner
The upside of creating a blockchain-based ledger through which all kinds of personal data can be sold is that it allows consumers to profit and businesses buying it to get higher quality information, Etwaru said.

"I was chief digital officer of an $8 billion company up until six months ago. And we sold about $4 billion a year of healthcare data, which was 'de-identified,'" said Etwaru, referring to his executive position with Iqvia. "They're selling some terrible quality data. They're also really nervous about re-identification."

In other words, personal medical information is being sold – and in the process of making that transaction legal it is stripped of 18 types of information; doing so meets HIPAA de-identification requirements, but significantly reduces the data's value for legitimate research.

"And there is evidence that bad actors can still surreptitiously re-identify it," said Dan Karlin, Hu-manity.co's chief transformation officer. Karlin is formerly the head of clinical, informatics and regulatory strategy at Pfizer Pharmaceuticals.
Hu-manity.co has already established relationships with data brokers, the healthcare and insurance companies that already sell anonymized patient data. Hu-manity will not itself be holding medical info; its role is to offer permissioned records and to create the means by which the patient can set permissions and receive compensation.

"With explicit permission, the data is more useful to researchers, there is the ability to correct, refine, and enhance the data with your consent and cooperation and now you're being compensated for its use," Karlin said via email.
Hu-manity.co is betting pharmaceutical companies and other organizations that use the data to develop products or conduct research will be willing to pay for higher quality information.

While the personally identifiable information (PII) by law must be "de-identified," data brokers, such as insurance companies that sell claims data, also often add unique numbers to keep track of disparate pieces of information coming from the same person. At the same time, today's powerful data analytics software is capable of piecing the trail data breadcrumbs back to their origin: the patient.

"In other words, a truly anonymized record does not really exist," said Mutaz Shegewi, an IDC research director.
The key to real privacy

Cynthia Burghard, also an IDC research director, said document service LexusNexus can take around 40 data elements from a healthcare organization at the patient level and match it to their social determinants database, so "it is not hard to imagine reverse engineering that, unless the anonymized data were really stripped."

Once a person has ownership of their own anonymized data via an encrypted electronic ledger, the possibility of a person's identity being exposed decreases, Etwaru said, because it is hidden behind a hashed number on the blockchain. The owner is certified, but the identity of that owner rests behind an encrypted key.

The data's owner can also authorize access to greater amounts of data, depending on what they want to share, and the data is more trustworthy data because it's been confirmed and verified to be real through the blockchain.

"So, there's no question the data is better and more valuable for pharmaceutical companies and other companies interested in purchasing it," Karlin said.

While Hu-manity.co's proposal is new and unusual, it's not completely unique. Start-up SimplyVital Health built a new Blockchain-based service called Health Nexus that offer's a personal crypto key for access to electronic health data, which can then be sold only with patient consent.

"Despite all the HIPAA regulations, your health data can also be utilized without your permission and for profit if it is anonymized," said Kat Kuzmeskas, CEO and co-founder of SimplyVital Health. "It's not fair. Everyone else is benefiting from that data, and you're not."

Health Nexus enables different levels of access to patient health information. For example, a patient could grant access to data related to cancer treatments they're receiving but restrict demographic or historical healthcare data.
Patients who share data earn a HLTH cryptocurrency token created by SimplyVital Health; the tokens currently have no intrinsic value.

A second product SimplyVital health created is called ConnectingCare, a blockchain ledger that creates an audit trail for healthcare providers to use in tracking post-acute care to patients regardless of where the care was performed. The app also gives them estimates of the care costs for Medicaid/Medicare reimbursement.

Both SimplyVital Health and Hu-manity.co blockchain ledgers must first create a marketplace where data can be traded, and to do that, they need data owners to sign up. With enough users, Etwaru believes a new economy can be created.

"Once we help enough people, we can begin to earn money. But, we have to help people and change the world first," Etwaru said. "It is a very lofty goal, but it is the foundation of the way our business is set up."

Computerworld:

You Might Also Read:

Blockchain To Secure Storage Of Sensitive Data:

 

« Blockchain Is Being Applied to Human Rights
N. Korean Hacker Fingered For Wannacry Attacks »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

FT Cyber Resilience Summit: Europe

FT Cyber Resilience Summit: Europe

27 November 2024 | In-Person & Digital | 22 Bishopsgate, London. Business leaders, Innovators & Experts address evolving cybersecurity risks.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

LEXFO

LEXFO

LEXFO specializes in the security of information systems, assisting clients in protecting information assets using an offensive and innovative approach.

ABB

ABB

ABB is a pioneering technology leader in industrial digitalization. Services include cyber security for industrial control systems IoT.

CyberArts

CyberArts

CyberArts is founded on the belief that every single organization deserves and requires the creme de la creme when there is a need for Cyber services.

DeviceAssure

DeviceAssure

DeviceAssure enables organizations to reliably identify counterfeit and non-standard devices with a real-time check on a device's authenticity.

Liongard

Liongard

Liongard automates the management and protection of modern IT environments at scale for IT MSPs - Managed Service Providers and Enterprise IT Operations.

KrCERT/CC

KrCERT/CC

KrCERT/CC is the National Computer Emergency Response Team in Korea.

Crypto International

Crypto International

Crypto International offers comprehensive services for the operation of our customers’ IT and communication infrastructure, with a focus on cybersecurity and encryption solutions.

Cybermerc

Cybermerc

Cybermerc's services, training programmes and cyber security solutions are designed to forge collaborations across industry, government and academia, for collective defence of our digital borders.

Force Majeure

Force Majeure

Force Majeure specializes in cybersecurity, incident response, and digital forensics, with experience spanning more than a decade.

TwoThreeFour

TwoThreeFour

ThreeTwoFour provide tailored cyber security solutions, delivered by highly-skilled, experienced consultants who respond to the real needs of you and your business.

Laneden

Laneden

Laneden specialise in helping organisations identify security concerns and quantify the risks you may have across your assets, using Penetration Testing, Threat Simulation and Compliance Testing.

aFFirmFirst

aFFirmFirst

aFFirmFirst is a unique software solution offering a simple yet effective way for businesses to protect and control their online images and logo, as well as allowing one-click website verification.

ClearSky Cyber Security

ClearSky Cyber Security

ClearSky cyber security provides cyber solutions, focused on threat intelligence services, mainly for the financial sector, critical infrastructure, public sector and the pharma sector.

Trustack

Trustack

Trustack services cover connectivity, infrastructure services, security, unified comms, agile working and more. Our team of consultants deliver customised solutions tailored to your needs.

TriVigil

TriVigil

TriVigil offer a full-service, comprehensive cybersecurity approach specifically tailored to meet the unique needs of educational institutions.

Black Duck Software

Black Duck Software

Black Duck (formerly the Synopsys Software Integrity Group) is the market leader in application security testing (AST).