// COMPLETE THREAD

Re: Health Care Privacy Alert

5 expanded posts ยท every known parent and child

NODE c5425917Re: Health Care Privacy Alert
At 09:57 AM 8/10/94 EDT, Gerald M. Phillips, Ph.D. wrote:
>Posted for general interest

>Subject: Health Care Privacy Alert

>     The health care legislation proposed by Gephardt in the House and
>Mitchell in the Senate contains provisions which would establish a
>national health care data network and override most state medical
>confidentiality laws.  All health care providers, whether paid by
>insurance or not, will be required to provide the network with data
>from the patient medical record after every clinical encounter.


*Any* bill that passes will have all sorts of juicy, privacy-invading
provisions.

Leftists in the "privacy community" will have to decide which they like
better:  privacy or "health security."

There's no way you can have a government-directed, third-party-paid, health
care "system" without throwing privacy out the window.  Bureaucracies *keep*
records, they don't destroy them.  

Our president likes the "German System" -- 'nuff said.

DCF

"According to the CBO report on the 'Clinton-Mitchell Bill,' the effective
marginal tax rate on some lucky moderate income families ($20K-$30K) will be
85%(!) due to 1) ordinary taxes, (2) phase out of the earned income tax
credit, and (3) phase out of health insurance subsidies under the
'Clinton-Mitchell Bill'."
NODE 7d023570Re: Health Care Privacy Alert
Duncan Frissell wrote:

> There's no way you can have a government-directed, third-party-paid, health
> care "system" without throwing privacy out the window. Bureaucracies *keep*
> records, they don't destroy them.

Yes, this is a lesson history tells us. But maybe, theoretically, strong
crypto could make a change. Nested information with keys known only to
parties with legitimate interest in a specific info layer and the master
key only known to the patient and programs for self destruction (including
backups) of data no longer needed. I repeat, theoretically that is.

Mats
NODE 1edba3c8Why Cash is So Important (was: National Health Care)
Mats Bergstrom writes:
> 
> Duncan Frissell wrote:
> 
> > There's no way you can have a government-directed, third-party-paid, health
> > care "system" without throwing privacy out the window. Bureaucracies *keep*
> > records, they don't destroy them.
> 
> Yes, this is a lesson history tells us. But maybe, theoretically, strong
> crypto could make a change. Nested information with keys known only to
> parties with legitimate interest in a specific info layer and the master
> key only known to the patient and programs for self destruction (including
> backups) of data no longer needed. I repeat, theoretically that is.

The simplest solution is *cash*. It's worth taking a minute to see why
cash is so important in this context, and why accounting-based systems
that compile records are inherently insecure.

The beauty of a cash transaction, throughout history, is *immediate
settelement*. Parties have to examine a deal, look for flaws, and then
make a judgement about whether to complete the deal. Once completed,
it's hard to change one's mind, go back on the deal, complain, etc.
This enforces a kind of due diligence. Cash on the barrelhead, as they
say.

Non-cash systems are of course sometimes desirable: credit cards,
insurance schemes, contractual relationships, leases, etc. All kinds
of variants.

However, these contractual relationships involved *time extent*, that
is, they are not settled immediately, on the spot. This has many
potentially negative effects:

- confusion of time...people evolve different expectations of a
contract, causing disputes

- people often fail to do the due diligence of a cash transaction (for
example, the very same people who are good at haggling at a flea
market, and understand "caveat emptor" implicitly, will bitch and
moan and complain about contracts...seeking more, changes,
adjustments, etc.--an interesting contrast).

- temporal extent implies record-keeping, such as insurance records,
hospital visits, etc. This is automatically a potential privacy
concern.

(And when the contract is more than just patient-doctor, but involves
other payers, the records-keeping mushrooms. When the government is
the ultimate payer, through mandatory plans, they'll have the records.
No amount of crypto can possibly change that.)

- efficiency. Parties in cash transactions get what they paid for,
else they wouldn't have made the transaction.

- fraud. While cash transactions can have fraud (con jobs, fake
merchandise, etc.), the opportunities for fraud increase dramatically
with non-cash systems. When others are paying, such as for health
care, the temptation to participate in frauds is higher. 

(When a patient pays cash, no problem. When a central service is used,
opportunities for fraud increase. Doctors with ghost patients,
kickbacks, etc. Any central-payment system must then have records and
investigations at that central point. Hence, a central bureaucracy.
Hence, a loss of privacy at that level.)

And so on. My point is mostly that cash has certain elegant properties
which are lost when replaced with a central accounting scheme.
"Locality of reference" is the computer-related equivalent.

Why should this matter to Cypherpunks, if you've read this far? (By
the way, yes, Hal, I *did* read to your "Has anyone read this far?"
question a few days ago.)

Systems which preserve this cash/locality of reference feature, such
as digital cash, digital postage, and the "Digital Silk Road" proposal
of Hardy and Tribble, have likely advantages over centralized,
record-oriented systems.

You all know that digital cash is important. This is why the National
Health Care Plan is a bad idea, will destroy privacy, and basically
can't be fixed by band-aids that allegedly protect patient records.

--Tim May


-- 
..........................................................................
Timothy C. May         | Crypto Anarchy: encryption, digital money,  
tcmay@netcom.com       | anonymous networks, digital pseudonyms, zero
408-688-5409           | knowledge, reputations, information markets, 
W.A.S.T.E.: Aptos, CA  | black markets, collapse of governments.
Higher Power: 2^859433 | Public Key: PGP and MailSafe available.
"National borders are just speed bumps on the information superhighway."
NODE 76914450Re: Why Cash is So Important
Timothy C. May wrote:

<good arguments for using cash deleted>

> - temporal extent implies record-keeping, such as insurance records,
> hospital visits, etc. This is automatically a potential privacy
> concern.

Yes, but...  An insurance company would hardly accept a totally
anonymous agent as a customer, for obvious reasons (how would they
know that the agent was paid for by the body needing repair and not
used for an unfortunate uninsured friend?). Now, if there was only
one insurance agency thad had to pay for everyone anyway, that
agency wouldn't have to trust the patients, 'only' the doctors (to
deliver the true figures of their care production) and so wouldn't
necessarily have to be given the identities of patients. Such a
system has other implications not belonging in this discussion but
this is just to show that no simle rules apply.

(In the present situation all insurance companies are so mixed up
with each other in reinsurances that in a way they are a single entity.)

> (And when the contract is more than just patient-doctor, but involves
> other payers, the records-keeping mushrooms. When the government is
> the ultimate payer, through mandatory plans, they'll have the records.
> No amount of crypto can possibly change that.)

Yes, since doctors are not to be trusted the ultimate payer needs
records. So they get to know that unit SSN XYZ has been given treatment
amounting to DRG (Diagnose Related Group - the system widely used by
insurance entities to equalize and minimize costs, which can be used by
doctors to 'diagnose' mostly the profitable entries) 384 (abortion,
spontaneous or provocated - detailed like this to enable easy record-
raiding by the DRG police, I guess).

Crypto no use? Perhaps, but ... Suppose those Central Records
are encrypted in layers. The DRG Paymasters have the key to the
outermost layer so they can read: A patient, anon-9Aq7r, was
treated by dr Bob Livingstone for DRG-New XY, where XY only points
to the costs without diagnose, at a specified date. They pay Joe
what they owe him. If they suspect him of grand fraud he is asked to 
reveal the key to the next layer, where the identity (no SNN needed,
only name and address) of Alice is in the open. The Paymasters
can now ask Alice if she was treated by Bob Livingstone at the
specified date. If they suspect Bob of salting his bills they
have to ask a court for permission to request his second key,
further opening the records to reveal DRG-Old 384, making it possible
to check with Alice if she was treated for abortion, spontaneous  
or (e g AND) provocated. If they suspect Alice of collaborating
with Bob in a scam they have to ask another (higher) court for
permission to request Alice's key, the only key to open the actual
treatment records (if these are falsified, well...).

This scheme is not a proposal, I just thought it up for the moment,
and has several obvious flaws. Like if Alice lies when the Paymasters
approach her, or just says 'no comment' or refuses to give away her
key. But some scheme might be possible that at least makes it more
difficult for the ultimate payer to invade privacy, still keeping
an eye on money-hungry doctors. 

> (When a patient pays cash, no problem. When a central service is used,
> opportunities for fraud increase. Doctors with ghost patients,
> kickbacks, etc. Any central-payment system must then have records and
> investigations at that central point. Hence, a central bureaucracy.
> Hence, a loss of privacy at that level.)

One problem with cash here is of course the high costs of helth care,
making it necessary for almost everybody to be insured if they are
not suicidal or willing to gamble their lifes. Another problem is the
unconsious-patient situation - or half-consious, might be hard to
remember the password to the e$ anonymous account. 

These are general arguments. I have no opinion in the specific case
of the NHCP, a very domestic US discussion.


Mats
NODE 8b967ba0Re: Why Cash is So Important
> Timothy C. May wrote:
> 
> <good arguments for using cash deleted>
> 
> > - temporal extent implies record-keeping, such as insurance records,
> > hospital visits, etc. This is automatically a potential privacy
> > concern.
> 
> Yes, but...  An insurance company would hardly accept a totally
> anonymous agent as a customer, for obvious reasons (how would they
> know that the agent was paid for by the body needing repair and not
> used for an unfortunate uninsured friend?). Now, if there was only

I wasn't arguing that insurance companies would take anonymous
customers, per se, though I suspect a privacy-preserving system could
in fact be designed. In systems where a customer and insurance
provider work out a mutually-beneficia contract, and where there is no
requirement to forward records to the government, then privacy is
mostly maintained.

The concern many of us have is with systems in which governments
demand to be "silent partners" in all contractual relationships.

> > (When a patient pays cash, no problem. When a central service is used,
> > opportunities for fraud increase. Doctors with ghost patients,
> > kickbacks, etc. Any central-payment system must then have records and
> > investigations at that central point. Hence, a central bureaucracy.
> > Hence, a loss of privacy at that level.)
> 
> One problem with cash here is of course the high costs of helth care,
> making it necessary for almost everybody to be insured if they are
> not suicidal or willing to gamble their lifes. Another problem is the
> unconsious-patient situation - or half-consious, might be hard to
> remember the password to the e$ anonymous account. 

I'm not insured. Most health-care costs are payable directly...unless
and until the U.S. gets a socialist health care system, in which case
I'll still be uninsured (I'm not employed, I'm not indigent, so I
won't be covered by any of the current proposals, as I understand it).

I'm not going to digress further into insurance issues, except to say
that insurance has had the bad effect of decoupling payments and
services, a la the well-known "tragedy of the commons." People pay for
insurance, or their companies do, and then they try to demand the
largest number of services...it's game-theoretically advantageous for
them to do so. Hence the $2000 almost-obligatory CAT scan upon
entering a hospital in the U.S. (fed also by the malpractice
racket--doctors order these $2000 CAT scans to cover their asses
against lawsuits and because they get legal kickbacks for these
services).

Life expectancy, in the U.S. at least, has remained at roughly 72-74
years for the past couple of decades, so this huge health care
industry has had little real effect on our chances of living longer.
For the rare person who is in fact saved by this expensive system, it
is "worth it," of course. But the aggregate benefits tell a different
story.

The relevance to Cypherpunks? I don't know, but it's partly connected
to issues of whether centralized systems and record-keeping are a good
idea.

I actually see no reason why we as potential patients should not carry
around our medical records ourselves. Perhaps in a smart card...the
technology has existed for years. Or in a "medical bracelet" which
either directly contains local storage (flash memory, for example) or
contains a pointer to a file on the Net--and access information, if
encrypted, as it should be--which contains relevant medical
information and perhaps even financial payment instructions.


Selective disclosure of credentials, a la Chaum, should apply quite
naturally to medical care. A dossier society is not needed.

(I don't demand that others use such a system, only that I and my
medical contractor not be required to use someone else's idea of a
system. Seems fair to me.)

--Tim May




-- 
..........................................................................
Timothy C. May         | Crypto Anarchy: encryption, digital money,  
tcmay@netcom.com       | anonymous networks, digital pseudonyms, zero
408-688-5409           | knowledge, reputations, information markets, 
W.A.S.T.E.: Aptos, CA  | black markets, collapse of governments.
Higher Power: 2^859433 | Public Key: PGP and MailSafe available.
"National borders are just speed bumps on the information superhighway."