Bad Actors Getting Your Health Data Is the FBI’s Latest Worry
In February 2015, the health insurer Anthem revealed that criminal hackers had gained access to the company's servers, exposing the personal information of nearly 79 million patients. It's the largest known healthcare breach in history.
FBI agents worry that the vast amounts of healthcare data being generated for precision medicine efforts could leave the U.S. vulnerable to cyber and biological attacks.
That year, the data of millions more would be compromised in one cyberattack after another on American insurers and other healthcare organizations. In fact, for the past several years, the number of reported data breaches has increased each year, from 199 in 2010 to 344 in 2017, according to a September 2018 analysis in the Journal of the American Medical Association.
The FBI's Edward You sees this as a worrying trend. He says hackers aren't just interested in your social security or credit card number. They're increasingly interested in stealing your medical information. Hackers can currently use this information to make fake identities, file fraudulent insurance claims, and order and sell expensive drugs and medical equipment. But beyond that, a new kind of cybersecurity threat is around the corner.
Mr. You and others worry that the vast amounts of healthcare data being generated for precision medicine efforts could leave the U.S. vulnerable to cyber and biological attacks. In the wrong hands, this data could be used to exploit or extort an individual, discriminate against certain groups of people, make targeted bioweapons, or give another country an economic advantage.
Precision medicine, of course, is the idea that medical treatments can be tailored to individuals based on their genetics, environment, lifestyle or other traits. But to do that requires collecting and analyzing huge quantities of health data from diverse populations. One research effort, called All of Us, launched by the U.S. National Institutes of Health last year, aims to collect genomic and other healthcare data from one million participants with the goal of advancing personalized medical care.
Other initiatives are underway by academic institutions and healthcare organizations. Electronic medical records, genetic tests, wearable health trackers, mobile apps, and social media are all sources of valuable healthcare data that a bad actor could potentially use to learn more about an individual or group of people.
"When you aggregate all of that data together, that becomes a very powerful profile of who you are," Mr. You says.
A supervisory special agent in the biological countermeasures unit within the FBI's weapons of mass destruction directorate, it's Mr. You's job to imagine worst-case bioterror scenarios and figure out how to prevent and prepare for them.
That used to mean focusing on threats like anthrax, Ebola, and smallpox—pathogens that could be used to intentionally infect people—"basically the dangerous bugs," as he puts it. In recent years, advances in gene editing and synthetic biology have given rise to fears that rogue, or even well-intentioned, scientists could create a virulent virus that's intentionally, or unintentionally, released outside the lab.
"If a foreign source, especially a criminal one, has your biological information, then they might have some particular insights into what your future medical needs might be and exploit that."
While Mr. You is still tracking those threats, he's been traveling around the country talking to scientists, lawyers, software engineers, cyber security professionals, government officials and CEOs about new security threats—those posed by genetic and other biological data.
Emerging threats
Mr. You says one possible situation he can imagine is the potential for nefarious actors to use an individual's sensitive medical information to extort or blackmail that person.
"If a foreign source, especially a criminal one, has your biological information, then they might have some particular insights into what your future medical needs might be and exploit that," he says. For instance, "what happens if you have a singular medical condition and an outside entity says they have a treatment for your condition?" You could get talked into paying a huge sum of money for a treatment that ends up being bogus.
Or what if hackers got a hold of a politician or high-profile CEO's health records? Say that person had a disease-causing genetic mutation that could affect their ability to carry out their job in the future and hackers threatened to expose that information. These scenarios may seem far-fetched, but Mr. You thinks they're becoming increasingly plausible.
On a wider scale, Kavita Berger, a scientist at Gryphon Scientific, a Washington, D.C.-area life sciences consulting firm, worries that data from different populations could be used to discriminate against certain groups of people, like minorities and immigrants.
For instance, the advocacy group Human Rights Watch in 2017 flagged a concerning trend in China's Xinjiang territory, a region with a history of government repression. Police there had purchased 12 DNA sequencers and were collecting and cataloging DNA samples from people to build a national database.
"The concern is that this particular province has a huge population of the Muslim minority in China," Ms. Berger says. "Now they have a really huge database of genetic sequences. You have to ask, why does a police station need 12 next-generation sequencers?"
Also alarming is the potential that large amounts of data from different groups of people could lead to customized bioweapons if that data ends up in the wrong hands.
Eleonore Pauwels, a research fellow on emerging cybertechnologies at United Nations University's Centre for Policy Research, says new insights gained from genomic and other data will give scientists a better understanding of how diseases occur and why certain people are more susceptible to certain diseases.
"As you get more and more knowledge about the genomic picture and how the microbiome and the immune system of different populations function, you could get a much deeper understanding about how you could target different populations for treatment but also how you could eventually target them with different forms of bioagents," Ms. Pauwels says.
Economic competitiveness
Another reason hackers might want to gain access to large genomic and other healthcare datasets is to give their country a leg up economically. Many large cyber-attacks on U.S. healthcare organizations have been tied to Chinese hacking groups.
"This is a biological space race and we just haven't woken up to the fact that we're in this race."
"It's becoming clear that China is increasingly interested in getting access to massive data sets that come from different countries," Ms. Pauwels says.
A year after U.S. President Barack Obama conceived of the Precision Medicine Initiative in 2015—later renamed All of Us—China followed suit, announcing the launch of a 15-year, $9 billion precision health effort aimed at turning China into a global leader in genomics.
Chinese genomics companies, too, are expanding their reach outside of Asia. One company, WuXi NextCODE, which has offices in Shanghai, Reykjavik, and Cambridge, Massachusetts, has built an extensive library of genomes from the U.S., China and Iceland, and is now setting its sights on Ireland.
Another Chinese company, BGI, has partnered with Children's Hospital of Philadelphia and Sinai Health System in Toronto, and also formed a collaboration with the Smithsonian Institute to sequence all species on the planet. BGI has built its own advanced genomic sequencing machines to compete with U.S.-based Illumina.
Mr. You says having access to all this data could lead to major breakthroughs in healthcare, such as new blockbuster drugs. "Whoever has the largest, most diverse dataset is truly going to win the day and come up with something very profitable," he says.
Some direct-to-consumer genetic testing companies with offices in the U.S., like Dante Labs, also use BGI to process customers' DNA.
Experts worry that China could race ahead the U.S. in precision medicine because of Chinese laws governing data sharing. Currently, China prohibits the exportation of genetic data without explicit permission from the government. Mr. You says this creates an asymmetry in data sharing between the U.S. and China.
"This is a biological space race and we just haven't woken up to the fact that we're in this race," he said in January at an American Society for Microbiology conference in Washington, D.C. "We don't have access to their data. There is absolutely no reciprocity."
Protecting your data
While Mr. You has been stressing the importance of data security to anyone who will listen, the National Academies of Sciences, Engineering, and Medicine, which makes scientific and policy recommendations on issues of national importance, has commissioned a study on "safeguarding the bioeconomy."
In the meantime, Ms. Berger says organizations that deal with people's health data should assess their security risks and identify potential vulnerabilities in their systems.
As for what individuals can do to protect themselves, she urges people to think about the different ways they're sharing healthcare data—such as via mobile health apps and wearables.
"Ask yourself, what's the benefit of sharing this? What are the potential consequences of sharing this?" she says.
Mr. You also cautions people to think twice before taking consumer DNA tests. They may seem harmless, he says, but at the end of the day, most people don't know where their genetic information is going. "If your genetic sequence is taken, once it's gone, it's gone. There's nothing you can do about it."
How Can We Decide If a Biomedical Advance Is Ethical?
"All fixed, fast-frozen relations, with their train of ancient and venerable prejudices and opinions, are swept away, all new-formed ones become antiquated before they can ossify. All that is solid melts into air, all that is holy is profaned…"
On July 25, 1978, Louise Brown was born in Oldham, England, the first human born through in vitro fertilization, through the work of Patrick Steptoe, a gynecologist, and Robert Edwards, a physiologist. Her birth was greeted with strong (though not universal) expressions of ethical dismay. Yet in 2016, the latest year for which we have data, nearly two percent of the babies born in the United States – and around the same percentage throughout the developed world – were the result of IVF. Few, if any, think of these children as unnatural, monsters, or freaks or of their parents as anything other than fortunate.
How should we view Dr. He today, knowing that the world's eventual verdict on the ethics of biomedical technologies often changes?
On November 25, 2018, news broke that Chinese scientist, Dr. He Jiankui, claimed to have edited the genomes of embryos, two of whom had recently become the new babies, Lulu and Nana. The response was immediate and overwhelmingly negative.
Times change. So do views. How will Dr. He be viewed in 40 years? And, more importantly, how should we view him today, knowing that the world's eventual verdict on the ethics of biomedical technologies often changes? And when what biomedicine can do changes with vertiginous frequency?
How to determine what is and isn't ethical is above my pay grade. I'm a simple law professor – I can't claim any deeper insight into how to live a moral life than the millennia of religious leaders, philosophers, ethicists, and ordinary people trying to do the right thing. But I can point out some ways to think about these questions that may be helpful.
First, consider two different kinds of ethical commands. Some are quite specific – "thou shalt not kill," for example. Others are more general – two of them are "do unto others as you would have done to you" or "seek the greatest good for the greatest number."
Biomedicine in the last two centuries has often surprised us with new possibilities, situations that cultures, religions, and bodies of ethical thought had not previously had to consider, from vaccination to anesthesia for women in labor to genome editing. Sometimes these possibilities will violate important and deeply accepted precepts for a group or a person. The rise of blood transfusions around World War I created new problems for Jehovah's Witnesses, who believe that the Bible prohibits ingesting blood. The 20th century developments of artificial insemination and IVF both ran afoul of Catholic doctrine prohibiting methods other than "traditional" marital intercourse for conceiving children. If you subscribe to an ethical or moral code that contains prohibitions that modern biomedicine violates, the issue for you is stark – adhere to those beliefs or renounce them.
If the harms seem to outweigh the benefits, it's easy to conclude "this is worrisome."
But many biomedical changes violate no clear moral teachings. Is it ethical or not to edit the DNA of embryos? Not surprisingly, the sacred texts of various religions – few of which were created after, at the latest, the early 19th century, say nothing specific about this. There may be hints, precedents, leanings that could argue one way or another, but no "commandments." In that case, I recommend, at least as a starting point, asking "what are the likely consequences of these actions?"
Will people be, on balance, harmed or helped by them? "Consequentialist" approaches, of various types, are a vast branch of ethical theories. Personally I find a completely consequentialist approach unacceptable – I could not accept, for example, torturing an innocent child even in order to save many lives. But, in the absence of a clear rule, looking at the consequences is a great place to start. If the harms seem to outweigh the benefits, it's easy to conclude "this is worrisome."
Let's use that starting place to look at a few bioethical issues. IVF, for example, once proven (relatively) safe seems to harm no one and to help many, notably the more than 8 million children worldwide born through IVF since 1978 – and their 16 million parents. On the other hand, giving unknowing, and unconsenting, intellectually disabled children hepatitis A harmed them, for an uncertain gain for science. And freezing the heads of the dead seems unlikely to harm anyone alive (except financially) but it also seems almost certain not to benefit anyone. (Those frozen dead heads are not coming back to life.)
Now let's look at two different kinds of biomedical advances. Some are controversial just because they are new; others are controversial because they cut close to the bone – whether or not they violate pre-established ethical or moral norms, they clearly relate to them.
Consider anesthesia during childbirth. When first used, it was controversial. After all, said critics, in Genesis, the Bible says God told Eve, "I will greatly multiply Your pain in childbirth, In pain you will bring forth children." But it did not clearly prohibit pain relief and from the advent of ether on, anesthesia has been common, though not universal, in childbirth in western societies. The pre-existing ethical precepts were not clear and the consequences weighed heavily in favor of anesthesia. Similarly, vaccination seems to violate no deep moral principle. It was, and for some people, still is just strange, and unnatural. The same was true of IVF initially. Opposition to all of these has faded with time and familiarity. It has not disappeared – some people continue to find moral or philosophical problems with "unnatural" childbirth, vaccination, and IVF – but far fewer.
On the other hand, human embryonic stem cell research touches deeper issues. Human embryos are destroyed to make those stem cells. Reasonable people disagree on the moral status of the human embryo, and the moral weight of its destruction, but it does at least bring into play clear and broadly accepted moral precepts, such as "Thou shalt not kill." So, at the far side of an individual's time, does euthanasia. More exposure to, and familiarity with, these practices will not necessarily lead to broad acceptance as the objections involve more than novelty.
The first is "what would I do?" The second – what should my government, culture, religion allow or forbid?
Finally, all this ethical analysis must work at two levels. The first is "what would I do?" The second – what should my government, culture, religion allow or forbid? There are many things I would not do that I don't think should be banned – because I think other people may reasonably have different views from mine. I would not get cosmetic surgery, but I would not ban it – and will try not to think ill of those who choose it
So, how should we assess the ethics of new biomedical procedures when we know that society's views may change? More specifically, what should we think of He Jiankui's experiment with human babies?
First, look to see whether the procedure in question violates, at least fairly clearly, some rule in your ethical or moral code. If so, your choice may not be difficult. But if the procedure is unmentioned in your moral code, probably because it was inconceivable to the code's creators, examine the consequences of the act.
If the procedure is just novel, and not something that touches on important moral concerns, looking at the likely consequences may be enough for your ethical analysis –though it is always worth remembering that predicting consequences perfectly is impossible and predicting them well is never certain. If it does touch on morally significant issues, you need to think those issues through. The consequences may be important to your conclusions but they may not be determinative.
And, then, if you conclude that it is not ethical from your perspective, you need to take yet another step and consider whether it should be banned for people who do not share your perspective. Sometimes the answer will be yes – that psychopaths may not view murder as immoral does not mean we have to let them kill – but sometimes it will be no.
What does this say about He Jiankui's experiment? I have no qualms in condemning it, unequivocally. The potential risks to the babies grossly outweighed any benefits to them, and to science. And his secret work, against a near universal scientific consensus, privileged his own ethical conclusions without giving anyone else a vote, or even a voice.
But if, in ten or twenty years, genome editing of human embryos is shown to be safe (enough) and it is proposed to be used for good reasons – say, to relieve human suffering that could not be treated in other good ways – and with good consents from those directly involved as well as from the relevant society and government – my answer might well change. Yours may not. Bioethics is a process for approaching questions; it is not a set of universal answers.
This article opened with a quotation from the 1848 Communist Manifesto, referring to the dizzying pace of change from industrialization and modernity. You don't need to be a Marxist to appreciate that sentiment. Change – especially in the biosciences – keeps accelerating. How should we assess the ethics of new biotechnologies? The best we can, with what we know, at the time we inhabit. And, in the face of vast uncertainty, with humility.
This Brain Doc Has a “Repulsive” Idea to Make Football Safer
What do football superstars Tom Brady, Drew Brees, Philip Rivers, and Adrian Peterson all have in common? Last year they wore helmets that provided the poorest protection against concussions in all the NFL.
"You're only as protected as well as the worst helmet that's out there."
A Dangerous Policy
Football helmets are rated on a one-star to five-star system based on how well they do the job of protecting the player. The league has allowed players to use their favorites, regardless of the star rating.
The Oxford-trained neuroscientist Ray Colello conducted a serious analysis of just how much the protection can vary between each level of star rating. Colello and his team of graduate students sifted through two seasons of game video to identify which players were wearing what helmets. There was "a really good correlation with position, but the correlation is much more significant based on age."
"The average player in the NFL is 26.6 years old, but the average age of a player wearing a one-star helmet is 34. And for anyone who knows football, that's ancient," the brain doc says. "Then for our two-star helmet, it's 32; and for a three-star helmet it's 29." Players were sticking with the helmets they were familiar with in college, despite the fact that equipment had improved considerably in recent years.
"You're only as protected as well as the worst helmet that's out there," Colello explains. Offering an auto analogy, he says, "It's like, if you run into the back of a Pinto, even if you are in a five-star Mercedes, that gas tank may still explode and you are still going to die."
It's one thing for a player to take a risk at scrambling his own brain; it's another matter to put a teammate or opponent at needless risk. Colello published his analysis early last year and the NFL moved quickly to ban the worst performing helmets, starting next season.
Some of the 14 players using the soon-to-be-banned helmets, like Drew Brees and Philip Rivers, made the switch to a five-star helmet at the start of training camp and stayed with it. Adrian Peterson wore a one-star helmet throughout the season.
Tom Brady tried but just couldn't get comfortable with a new bonnet and, after losing a few games, switched back to his old one in the middle of the season; he says he's going to ask the league to "grandfather in" his old helmet so he can continue to use it.
As for Colello, he's only just getting started. The brain doc has a much bigger vision for the future of football safety. He wants to prevent concussions from even occurring in the first place by creating an innovative new helmet that's unlike anything the league has ever seen.
Oxford-trained neuroscientist Ray Colello is on a mission to make football safer.
(Photo credit: VCU public affairs)
"A Force Field" of Protection
His inspiration was serendipitous; he was at home watching a football game on TV when Denver Bronco's receiver Wes Welker was hit, lay flat on the field with a concussion, and was carted off. As a commercial flickered on the screen, he ambled into the kitchen for another beer. "What those guys need is a force field protecting them," he thought to himself.
Like so many households, the refrigerator door was festooned with magnets holding his kids' school work in place. And in that eureka moment the idea popped into his head: "Maybe the repulsive force of magnets can put a break on an impact before it even occurs." Colello has spent the last few years trying to turn his concept into reality.
Newton's laws of physics – mass and speed – play out graphically in a concussion. The sudden stop of a helmet-to-helmet collision can shake the brain back and forth inside the skull like beans in a maraca. Dried beans stand up to the impact, making their distinctive musical sound; living brain tissue is much softer and not nearly so percussive. The resulting damage is a concussion.
The risk of that occurring is greater than you might think. Researchers using accelerometers inside helmets have determined that a typical college football player experiences about 600 helmet-to-helmet contacts during a season of practice and games. Each hit generates a split second peak g-force of 20 to 150 within the helmet and the odds of one causing a concussion increase sharply over 100 gs of force.
By comparison, astronauts typically experience a maximum sustained 3gs during lift off and most humans will black out around 9gs, which is why fighter pilots wear special pressure suits to counter the effects.
"It stretches the time line of impact quite dramatically. In fact in most instances, it doesn't even hit."
The NFL's fastest player, Chris Johnson, can run 19.3 mph. A collision at that speed "produces 120gs worth of force," Colello explains. "But if you can extend that time of impact by just 5 milliseconds (from 12 to 17msec) you'll shift that g-force down to 84. There is a very good chance that he won't suffer a concussion."
The neuroscientist dived into learning all he could about the physics magnets. It turns out that the most powerful commercially available magnet is an alloy made of neodymium, iron, and boron. The elements can be mixed and glued together in any shape and then an electric current is run through to make it magnetic; the direction of the current establishes the north-south poles.
A 1-pound neodymium magnet can repulse 600 times its own weight, even though the magnetic field extends less than an inch. That means it can push back a magnet inside another helmet but not affect the brain.
Crash Testing the Magnets
Colello couldn't wait to see if his idea panned out. With blessing from his wife to use their credit card, he purchased some neodymium magnets and jury-rigged experiments at home.
The reinforced plastics used in football helmets don't affect the magnetic field. And the small magnets stopped weights on gym equipment that were dropped from various heights. "It stretches the time line of impact quite dramatically. In fact in most instances, it doesn't even hit," says Colello. "We are dramatically shifting the curve" of impact.
Virginia Commonwealth University stepped in with a $50,000 innovation grant to support the next research steps. The professor ordered magnets custom-designed to fit the curvature of space inside the front and sides of existing football helmets. That makes it impossible to install them the wrong way, and ensures the magnets' poles will always repel and not attract. It adds about a pound and a half to the weight of the helmet.
a) The brain in a helmet. b) Placing the magnet. c) Measuring the impact of a helmet-to-helmet collision. d) How magnets reduce the force of impact.
(Courtesy Ray Colello)
Colello rented crash test dummy heads crammed with accelerometers and found that the magnets performed equally well at slowing collisions when fixed to a pendulum in a test that approximated a helmet and head hitting a similarly equipped helmet. It impressively reduced the force of contact.
The NFL was looking for outside-the-box thinking to prevent concussions. It was intrigued by Colello's approach and two years ago invited him to submit materials for review. To be fair to all entrants, the league proposed to subject all entries to the same standard crush test to see how well each performed in lessening impact. The only trouble was, Colello's approach was designed to avoid collisions, not lessen their impact. The test wouldn't have been a valid evaluation and he withdrew from consideration.
But Colello's work caught the attention of Stefan Duma, an engineering professor at Virginia Tech who developed the five-star rating system for football helmets.
"In theory it makes sense to use [the magnets] to slow down or reduce acceleration, that's logical," says Duma. He believes current helmet technology is nearing "the end of the physics barrier; you can only absorb so much energy in so much space," so the field is ripe for new approaches to improve helmet technology.
However, one of Duma's concerns is whether magnets "are feasible from a weight standpoint." Most helmets today weigh between two and four pounds, and a sufficiently powerful magnet might add too much weight. One possibility is using an electromagnet, which potentially could be lighter and more powerful, particularly if the power supply could be carried lower in the body, say in the shoulder pads.
Colello says his lab tests are promising enough that the concept needs to be tried out on the playing field. "We need to make enough helmets for two teams to play each other in a regulation-style game and measure the impact forces that are generated on each, and see if there is a significant reduction." He is waiting to hear from the National Institutes of Health on a grant proposal to take that next step toward dramatically reducing the risk of concussions in the NFL.
Just five milliseconds could do it.