Bad Actors Getting Your Health Data Is the FBI’s Latest Worry
In February 2015, the health insurer Anthem revealed that criminal hackers had gained access to the company's servers, exposing the personal information of nearly 79 million patients. It's the largest known healthcare breach in history.
FBI agents worry that the vast amounts of healthcare data being generated for precision medicine efforts could leave the U.S. vulnerable to cyber and biological attacks.
That year, the data of millions more would be compromised in one cyberattack after another on American insurers and other healthcare organizations. In fact, for the past several years, the number of reported data breaches has increased each year, from 199 in 2010 to 344 in 2017, according to a September 2018 analysis in the Journal of the American Medical Association.
The FBI's Edward You sees this as a worrying trend. He says hackers aren't just interested in your social security or credit card number. They're increasingly interested in stealing your medical information. Hackers can currently use this information to make fake identities, file fraudulent insurance claims, and order and sell expensive drugs and medical equipment. But beyond that, a new kind of cybersecurity threat is around the corner.
Mr. You and others worry that the vast amounts of healthcare data being generated for precision medicine efforts could leave the U.S. vulnerable to cyber and biological attacks. In the wrong hands, this data could be used to exploit or extort an individual, discriminate against certain groups of people, make targeted bioweapons, or give another country an economic advantage.
Precision medicine, of course, is the idea that medical treatments can be tailored to individuals based on their genetics, environment, lifestyle or other traits. But to do that requires collecting and analyzing huge quantities of health data from diverse populations. One research effort, called All of Us, launched by the U.S. National Institutes of Health last year, aims to collect genomic and other healthcare data from one million participants with the goal of advancing personalized medical care.
Other initiatives are underway by academic institutions and healthcare organizations. Electronic medical records, genetic tests, wearable health trackers, mobile apps, and social media are all sources of valuable healthcare data that a bad actor could potentially use to learn more about an individual or group of people.
"When you aggregate all of that data together, that becomes a very powerful profile of who you are," Mr. You says.
A supervisory special agent in the biological countermeasures unit within the FBI's weapons of mass destruction directorate, it's Mr. You's job to imagine worst-case bioterror scenarios and figure out how to prevent and prepare for them.
That used to mean focusing on threats like anthrax, Ebola, and smallpox—pathogens that could be used to intentionally infect people—"basically the dangerous bugs," as he puts it. In recent years, advances in gene editing and synthetic biology have given rise to fears that rogue, or even well-intentioned, scientists could create a virulent virus that's intentionally, or unintentionally, released outside the lab.
"If a foreign source, especially a criminal one, has your biological information, then they might have some particular insights into what your future medical needs might be and exploit that."
While Mr. You is still tracking those threats, he's been traveling around the country talking to scientists, lawyers, software engineers, cyber security professionals, government officials and CEOs about new security threats—those posed by genetic and other biological data.
Emerging threats
Mr. You says one possible situation he can imagine is the potential for nefarious actors to use an individual's sensitive medical information to extort or blackmail that person.
"If a foreign source, especially a criminal one, has your biological information, then they might have some particular insights into what your future medical needs might be and exploit that," he says. For instance, "what happens if you have a singular medical condition and an outside entity says they have a treatment for your condition?" You could get talked into paying a huge sum of money for a treatment that ends up being bogus.
Or what if hackers got a hold of a politician or high-profile CEO's health records? Say that person had a disease-causing genetic mutation that could affect their ability to carry out their job in the future and hackers threatened to expose that information. These scenarios may seem far-fetched, but Mr. You thinks they're becoming increasingly plausible.
On a wider scale, Kavita Berger, a scientist at Gryphon Scientific, a Washington, D.C.-area life sciences consulting firm, worries that data from different populations could be used to discriminate against certain groups of people, like minorities and immigrants.
For instance, the advocacy group Human Rights Watch in 2017 flagged a concerning trend in China's Xinjiang territory, a region with a history of government repression. Police there had purchased 12 DNA sequencers and were collecting and cataloging DNA samples from people to build a national database.
"The concern is that this particular province has a huge population of the Muslim minority in China," Ms. Berger says. "Now they have a really huge database of genetic sequences. You have to ask, why does a police station need 12 next-generation sequencers?"
Also alarming is the potential that large amounts of data from different groups of people could lead to customized bioweapons if that data ends up in the wrong hands.
Eleonore Pauwels, a research fellow on emerging cybertechnologies at United Nations University's Centre for Policy Research, says new insights gained from genomic and other data will give scientists a better understanding of how diseases occur and why certain people are more susceptible to certain diseases.
"As you get more and more knowledge about the genomic picture and how the microbiome and the immune system of different populations function, you could get a much deeper understanding about how you could target different populations for treatment but also how you could eventually target them with different forms of bioagents," Ms. Pauwels says.
Economic competitiveness
Another reason hackers might want to gain access to large genomic and other healthcare datasets is to give their country a leg up economically. Many large cyber-attacks on U.S. healthcare organizations have been tied to Chinese hacking groups.
"This is a biological space race and we just haven't woken up to the fact that we're in this race."
"It's becoming clear that China is increasingly interested in getting access to massive data sets that come from different countries," Ms. Pauwels says.
A year after U.S. President Barack Obama conceived of the Precision Medicine Initiative in 2015—later renamed All of Us—China followed suit, announcing the launch of a 15-year, $9 billion precision health effort aimed at turning China into a global leader in genomics.
Chinese genomics companies, too, are expanding their reach outside of Asia. One company, WuXi NextCODE, which has offices in Shanghai, Reykjavik, and Cambridge, Massachusetts, has built an extensive library of genomes from the U.S., China and Iceland, and is now setting its sights on Ireland.
Another Chinese company, BGI, has partnered with Children's Hospital of Philadelphia and Sinai Health System in Toronto, and also formed a collaboration with the Smithsonian Institute to sequence all species on the planet. BGI has built its own advanced genomic sequencing machines to compete with U.S.-based Illumina.
Mr. You says having access to all this data could lead to major breakthroughs in healthcare, such as new blockbuster drugs. "Whoever has the largest, most diverse dataset is truly going to win the day and come up with something very profitable," he says.
Some direct-to-consumer genetic testing companies with offices in the U.S., like Dante Labs, also use BGI to process customers' DNA.
Experts worry that China could race ahead the U.S. in precision medicine because of Chinese laws governing data sharing. Currently, China prohibits the exportation of genetic data without explicit permission from the government. Mr. You says this creates an asymmetry in data sharing between the U.S. and China.
"This is a biological space race and we just haven't woken up to the fact that we're in this race," he said in January at an American Society for Microbiology conference in Washington, D.C. "We don't have access to their data. There is absolutely no reciprocity."
Protecting your data
While Mr. You has been stressing the importance of data security to anyone who will listen, the National Academies of Sciences, Engineering, and Medicine, which makes scientific and policy recommendations on issues of national importance, has commissioned a study on "safeguarding the bioeconomy."
In the meantime, Ms. Berger says organizations that deal with people's health data should assess their security risks and identify potential vulnerabilities in their systems.
As for what individuals can do to protect themselves, she urges people to think about the different ways they're sharing healthcare data—such as via mobile health apps and wearables.
"Ask yourself, what's the benefit of sharing this? What are the potential consequences of sharing this?" she says.
Mr. You also cautions people to think twice before taking consumer DNA tests. They may seem harmless, he says, but at the end of the day, most people don't know where their genetic information is going. "If your genetic sequence is taken, once it's gone, it's gone. There's nothing you can do about it."
How 30 Years of Heart Surgeries Taught My Dad How to Live
[Editor's Note: This piece is the winner of our 2019 essay contest, which prompted readers to reflect on the question: "How has an advance in science or medicine changed your life?"]
My father did not expect to live past the age of 50. Neither of his parents had done so. And he also knew how he would die: by heart attack, just as his father did.
In July of 1976, he had his first heart attack, days before his 40th birthday.
My dad lived the first 40 years of his life with this knowledge buried in his bones. He started smoking at the age of 12, and was drinking before he was old enough to enlist in the Navy. He had a sarcastic, often cruel, sense of humor that could drive my mother, my sister and me into tears. He was not an easy man to live with, but that was okay by him - he didn't expect to live long.
In July of 1976, he had his first heart attack, days before his 40th birthday. I was 13, and my sister was 11. He needed quadruple bypass surgery. Our small town hospital was not equipped to do this type of surgery; he would have to be transported 40 miles away to a heart center. I understood this journey to mean that my father was seriously ill, and might die in the hospital, away from anyone he knew. And my father knew a lot of people - he was a popular high school English teacher, in a town with only three high schools. He knew generations of students and their parents. Our high school football team did a blood drive in his honor.
During a trip to Disney World in 1974, Dad was suffering from angina the entire time but refused to tell me (left) and my sister, Kris.
Quadruple bypass surgery in 1976 meant that my father's breastbone was cut open by a sternal saw. His ribcage was spread wide. After the bypass surgery, his bones would be pulled back together, and tied in place with wire. The wire would later be pulled out of his body when the bones knitted back together. It would take months before he was fully healed.
Dad was in the hospital for the rest of the summer and into the start of the new school year. Going to visit him was farther than I could ride my bicycle; it meant planning a trip in the car and going onto the interstate. The first time I was allowed to visit him in the ICU, he was lying in bed, and then pushed himself to sit up. The heart monitor he was attached to spiked up and down, and I fainted. I didn't know that heartbeats change when you move; television medical dramas never showed that - I honestly thought that I had driven my father into another heart attack.
Only a few short years after that, my father returned to the big hospital to have his heart checked with a new advance in heart treatment: a CT scan. This would allow doctors to check for clogged arteries and treat them before a fatal heart attack. The procedure identified a dangerous blockage, and my father was admitted immediately. This time, however, there was no need to break bones to get to the problem; my father was home within a month.
During the late 1970's, my father changed none of his habits. He was still smoking, and he continued to drink. But now, he was also taking pills - pills to manage the pain. He would pop a nitroglycerin tablet under his tongue whenever he was experiencing angina (I have a vivid memory of him doing this during my driving lessons), but he never mentioned that he was in pain. Instead, he would snap at one of us, or joke that we were killing him.
I think he finally determined that, if he was going to have these extra decades of life, he wanted to make them count.
Being the kind of guy he was, my father never wanted to talk about his health. Any admission of pain implied that he couldn't handle pain. He would try to "muscle through" his angina, as if his willpower would be stronger than his heart muscle. His efforts would inevitably fail, leaving him angry and ready to lash out at anyone or anything. He would blame one of us as a reason he "had" to take valium or pop a nitro tablet. Dinners often ended in shouts and tears, and my father stalking to the television room with a bottle of red wine.
In the 1980's while I was in college, my father had another heart attack. But now, less than 10 years after his first, medicine had changed: our hometown hospital had the technology to run dye through my father's blood stream, identify the blockages, and do preventative care that involved statins and blood thinners. In one case, the doctors would take blood vessels from my father's legs, and suture them to replace damaged arteries around his heart. New advances in cholesterol medication and treatments for angina could extend my father's life by many years.
My father decided it was time to quit smoking. It was the first significant health step I had ever seen him take. Until then, he treated his heart issues as if they were inevitable, and there was nothing that he could do to change what was happening to him. Quitting smoking was the first sign that my father was beginning to move out of his fatalistic mindset - and the accompanying fatal behaviors that all pointed to an early death.
In 1986, my father turned 50. He had now lived longer than either of his parents. The habits he had learned from them could be changed. He had stopped smoking - what else could he do?
It was a painful decade for all of us. My parents divorced. My sister quit college. I moved to the other side of the country and stopped speaking to my father for almost 10 years. My father remarried, and divorced a second time. I stopped counting the number of times he was in and out of the hospital with heart-related issues.
In the early 1990's, my father reached out to me. I think he finally determined that, if he was going to have these extra decades of life, he wanted to make them count. He traveled across the country to spend a week with me, to meet my friends, and to rebuild his relationship with me. He did the same with my sister. He stopped drinking. He was more forthcoming about his health, and admitted that he was taking an antidepressant. His humor became less cruel and sadistic. He took an active interest in the world. He became part of my life again.
The 1990's was also the decade of angioplasty. My father explained it to me like this: during his next surgery, the doctors would place balloons in his arteries, and inflate them. The balloons would then be removed (or dissolve), leaving the artery open again for blood. He had several of these surgeries over the next decade.
When my father was in his 60's, he danced at with me at my wedding. It was now 10 years past the time he had expected to live, and his life was transformed. He was living with a woman I had known since I was a child, and my wife and I would make regular visits to their home. My father retired from teaching, became an avid gardener, and always had a home project underway. He was a happy man.
Dancing with my father at my wedding in 1998.
Then, in the mid 2000's, my father faced another serious surgery. Years of arterial surgery, angioplasty, and damaged heart muscle were taking their toll. He opted to undergo a life-saving surgery at Cleveland Clinic. By this time, I was living in New York and my sister was living in Arizona. We both traveled to the Midwest to be with him. Dad was unconscious most of the time. We took turns holding his hand in the ICU, encouraging him to regain his will to live, and making outrageous threats if he didn't listen to us.
The nursing staff were wonderful. I remember telling them that my father had never expected to live this long. One of the nurses pointed out that most of the patients in their ward were in their 70's and 80's, and a few were in their 90's. She reminded me that just a decade earlier, most hospitals were unwilling to do the kind of surgery my father had received on patients his age. In the first decade of the 21st century, however, things were different: 90-year-olds could now undergo heart surgery and live another decade. My father was on the "young" side of their patients.
The Cleveland Clinic visit would be the last major heart surgery my father would have. Not that he didn't return to his local hospital a few times after that: he broke his neck -- not once, but twice! -- slipping on ice. And in the 2010's, he began to show signs of dementia, and needed more home care. His partner, who had her own health issues, was not able to provide the level of care my father needed. My sister invited him to move in with her, and in 2015, I traveled with him to Arizona to get him settled in.
After a few months, he accepted home hospice. We turned off his pacemaker when the hospice nurse explained to us that the job of a pacemaker is to literally jolt a patient's heart back into beating. The jolts were happening more and more frequently, causing my Dad additional, unwanted pain.
My father in 2015, a few months before his death.
My father died in February 2016. His body carried the scars and implants of 30 years of cardiac surgeries, from the ugly breastbone scar from the 1970's to scars on his arms and legs from borrowed blood vessels, to the tiny red circles of robotic incisions from the 21st century. The arteries and veins feeding his heart were a patchwork of transplanted leg veins and fragile arterial walls pressed thinner by balloons.
And my father died with no regrets or unfinished business. He died in my sister's home, with his long-time partner by his side. Medical advancements had given him the opportunity to live 30 years longer than he expected. But he was the one who decided how to live those extra years. He was the one who made the years matter.
At the “Apple Store of Doctor’s Offices,” Preventive Care Is High Tech. Is it Worth $150 a Month?
What if going to the doctor's office could be … nice?
If you didn't have to wait for your appointment, but were ushered right in; if your medical data was all collated and easily searchable on an iPhone app; if a remote scribe took notes while you spoke with your doctor so you could make eye contact with them; if your doctor didn't seem horribly rushed.
Would you go to the doctor to get help staying healthy, rather than just to stop being sick?
Would that change the way you thought about your health? Would you go to the doctor to get help staying healthy, rather than just to stop being sick? And would that, in the long run, be much better for you?
Those are the animating questions for Forward, a healthcare startup devoted to preventive care. Led by founder Adrian Aoun, formerly of Google/Sidewalk labs, Forward opened its first office in San Francisco in 2016 and has since expanded to Los Angeles, Orange County, New York, and Washington, D.C., with a San Diego location opening soon.
It's been described as the "Apple Store of doctor's offices," which in some ways is a reaction to Forward's vibe: Patients have described the offices as having blonde wood, minimalist design, sparkling water on tap — and lots of high-tech gadgets, like the full-body scanner that replaces the standard scale and stethoscope.
The interior of a Forward office.
(Courtesy Forward)
The more crucial difference, though, is its model of care. Forward doesn't take insurance. Instead, patients, or "members," pay a flat $149 per month, along the lines of a subscription service like Netflix or a gym membership. That fee covers visits, messaging with medical staff through the Forward app, the use of a wearable (like a Fitbit or a sleep tracker) if the physician recommends it, plus any bloodwork or diagnostic tests run in the on-site labs. (The company declined to disclose how many people have signed up for memberships.)
Predictability is Forward's other significant, distinguishing feature: No surprise co-pays, or extra charges showing up on a billing statement months later. Everything is wrapped up in the $149 membership fee, unless the physician recommends visiting an outside specialist.
That caveat isn't a small one. It's important to note that Forward is in no way meant to replace standard health insurance. The service is strictly focused on preventive care, so it wouldn't be much use in case of an emergency; it's meant to help people, as far as is possible, avoid that emergency at all.
Ani Okkasian's family recently went through such an emergency. Her 62-year-old father, an active and seemingly healthy man living with diabetes, had been feeling unwell for a while, but struggled to receive constructive follow-up or tests from his doctor. It finally emerged that his liver was severely damaged, and he suffered a stroke — the risk of which can be elevated by liver disease. He seemed to deteriorate completely within mere weeks, Okkasian said, and in January he passed away.
"He was someone who'd go to the doctor regularly and listen to what they said and follow it," Okkasian said. "I shouldn't have had to bury my father at 62. I still believe to my core that his death could have been avoided if the primary care was adequate."
"I could tell that the people who designed [Forward] had lost someone to the legacy system; it was so streamlined and so much clearer."
Okkasian began researching, looking for a better alternative, and discovered Forward. Founder Aoun lost his grandfather to a heart attack; his brother's heart attack at age 31 was the impetus to start Forward.
"I could tell that that was the genesis," Okkasian said. "Having just lost someone, and having had to deal with different aspects of the healthcare industry — how complicated and convoluted that all is — I could tell that the people who designed [Forward] had lost someone to the legacy system; it was so streamlined and so much clearer."
So Who Is Forward For?
The Affordable Care Act mandates that evidence-based preventive care must be covered by insurers without any cost to the patient. Today, 30 million Americans are still living without health insurance; but for most of the population, cost shouldn't prevent access to standard, preventive care, says Benjamin Sommers, a physician and professor at the Harvard T.H. Chan School of Public Health who has studied the effect of the ACA on preventive care access.
For Okkasian and her family, it wasn't a lack of access to primary care that was at issue; it was the quality of that primary care. In 2019, that's probably true for a lot of people.
"How come all other industries have been disturbed except the medical industry?" Okkasian asked. "It's disturbing the most people. We're so advanced in so many ways, but when it comes to the healthcare system, we're not prioritizing the wellness of a person."
Is Forward the answer? Well, probably not for everyone. Its office are only in a handful of cities, and there are limits to how scalable it would be; it's unavoidable that the $149 per month charge restricts access for a lot of people. Those who have insurance through their employer might have a flexible spending account (FSA) that would cover some or all of the membership fee, and Forward has said that 15 percent of their early members came from underserved communities and were offered free plans; but for many others, that's just an unworkable extra cost.
Sommers also sounded a dubious note about a maximalist attitude toward data collection.
"Even though some patients may think that 'more is always better' — more testing, more screening, etc. — this isn't true," he said. "Some types of cancer screening, ovarian cancer screening for instance, are actually harmful or of no benefit, because studies have shown that they don't improve survival or health outcomes, but can lead to unnecessary testing, pain, false positives, anxiety, and other side effects.
"It's really great for people who are in good health, looking to make it better."
"I'm generally skeptical of efforts to charge people more to get 'extra testing' that isn't currently supported by the medical evidence," he added.
But relatively healthy people who want to take a more active approach to their health — or people who have frequent testing needs, like those using the HIV-prevention drug PrEP, and want to avoid co-pays — might benefit from the on-demand, low-friction experience that Forward offers.
"It's really great for people who are in good health, looking to make it better," Okkasian said. "Your experience is simplified to a point where you feel empowered, not scared."