Bad Actors Getting Your Health Data Is the FBI’s Latest Worry
In February 2015, the health insurer Anthem revealed that criminal hackers had gained access to the company's servers, exposing the personal information of nearly 79 million patients. It's the largest known healthcare breach in history.
FBI agents worry that the vast amounts of healthcare data being generated for precision medicine efforts could leave the U.S. vulnerable to cyber and biological attacks.
That year, the data of millions more would be compromised in one cyberattack after another on American insurers and other healthcare organizations. In fact, for the past several years, the number of reported data breaches has increased each year, from 199 in 2010 to 344 in 2017, according to a September 2018 analysis in the Journal of the American Medical Association.
The FBI's Edward You sees this as a worrying trend. He says hackers aren't just interested in your social security or credit card number. They're increasingly interested in stealing your medical information. Hackers can currently use this information to make fake identities, file fraudulent insurance claims, and order and sell expensive drugs and medical equipment. But beyond that, a new kind of cybersecurity threat is around the corner.
Mr. You and others worry that the vast amounts of healthcare data being generated for precision medicine efforts could leave the U.S. vulnerable to cyber and biological attacks. In the wrong hands, this data could be used to exploit or extort an individual, discriminate against certain groups of people, make targeted bioweapons, or give another country an economic advantage.
Precision medicine, of course, is the idea that medical treatments can be tailored to individuals based on their genetics, environment, lifestyle or other traits. But to do that requires collecting and analyzing huge quantities of health data from diverse populations. One research effort, called All of Us, launched by the U.S. National Institutes of Health last year, aims to collect genomic and other healthcare data from one million participants with the goal of advancing personalized medical care.
Other initiatives are underway by academic institutions and healthcare organizations. Electronic medical records, genetic tests, wearable health trackers, mobile apps, and social media are all sources of valuable healthcare data that a bad actor could potentially use to learn more about an individual or group of people.
"When you aggregate all of that data together, that becomes a very powerful profile of who you are," Mr. You says.
A supervisory special agent in the biological countermeasures unit within the FBI's weapons of mass destruction directorate, it's Mr. You's job to imagine worst-case bioterror scenarios and figure out how to prevent and prepare for them.
That used to mean focusing on threats like anthrax, Ebola, and smallpox—pathogens that could be used to intentionally infect people—"basically the dangerous bugs," as he puts it. In recent years, advances in gene editing and synthetic biology have given rise to fears that rogue, or even well-intentioned, scientists could create a virulent virus that's intentionally, or unintentionally, released outside the lab.
"If a foreign source, especially a criminal one, has your biological information, then they might have some particular insights into what your future medical needs might be and exploit that."
While Mr. You is still tracking those threats, he's been traveling around the country talking to scientists, lawyers, software engineers, cyber security professionals, government officials and CEOs about new security threats—those posed by genetic and other biological data.
Emerging threats
Mr. You says one possible situation he can imagine is the potential for nefarious actors to use an individual's sensitive medical information to extort or blackmail that person.
"If a foreign source, especially a criminal one, has your biological information, then they might have some particular insights into what your future medical needs might be and exploit that," he says. For instance, "what happens if you have a singular medical condition and an outside entity says they have a treatment for your condition?" You could get talked into paying a huge sum of money for a treatment that ends up being bogus.
Or what if hackers got a hold of a politician or high-profile CEO's health records? Say that person had a disease-causing genetic mutation that could affect their ability to carry out their job in the future and hackers threatened to expose that information. These scenarios may seem far-fetched, but Mr. You thinks they're becoming increasingly plausible.
On a wider scale, Kavita Berger, a scientist at Gryphon Scientific, a Washington, D.C.-area life sciences consulting firm, worries that data from different populations could be used to discriminate against certain groups of people, like minorities and immigrants.
For instance, the advocacy group Human Rights Watch in 2017 flagged a concerning trend in China's Xinjiang territory, a region with a history of government repression. Police there had purchased 12 DNA sequencers and were collecting and cataloging DNA samples from people to build a national database.
"The concern is that this particular province has a huge population of the Muslim minority in China," Ms. Berger says. "Now they have a really huge database of genetic sequences. You have to ask, why does a police station need 12 next-generation sequencers?"
Also alarming is the potential that large amounts of data from different groups of people could lead to customized bioweapons if that data ends up in the wrong hands.
Eleonore Pauwels, a research fellow on emerging cybertechnologies at United Nations University's Centre for Policy Research, says new insights gained from genomic and other data will give scientists a better understanding of how diseases occur and why certain people are more susceptible to certain diseases.
"As you get more and more knowledge about the genomic picture and how the microbiome and the immune system of different populations function, you could get a much deeper understanding about how you could target different populations for treatment but also how you could eventually target them with different forms of bioagents," Ms. Pauwels says.
Economic competitiveness
Another reason hackers might want to gain access to large genomic and other healthcare datasets is to give their country a leg up economically. Many large cyber-attacks on U.S. healthcare organizations have been tied to Chinese hacking groups.
"This is a biological space race and we just haven't woken up to the fact that we're in this race."
"It's becoming clear that China is increasingly interested in getting access to massive data sets that come from different countries," Ms. Pauwels says.
A year after U.S. President Barack Obama conceived of the Precision Medicine Initiative in 2015—later renamed All of Us—China followed suit, announcing the launch of a 15-year, $9 billion precision health effort aimed at turning China into a global leader in genomics.
Chinese genomics companies, too, are expanding their reach outside of Asia. One company, WuXi NextCODE, which has offices in Shanghai, Reykjavik, and Cambridge, Massachusetts, has built an extensive library of genomes from the U.S., China and Iceland, and is now setting its sights on Ireland.
Another Chinese company, BGI, has partnered with Children's Hospital of Philadelphia and Sinai Health System in Toronto, and also formed a collaboration with the Smithsonian Institute to sequence all species on the planet. BGI has built its own advanced genomic sequencing machines to compete with U.S.-based Illumina.
Mr. You says having access to all this data could lead to major breakthroughs in healthcare, such as new blockbuster drugs. "Whoever has the largest, most diverse dataset is truly going to win the day and come up with something very profitable," he says.
Some direct-to-consumer genetic testing companies with offices in the U.S., like Dante Labs, also use BGI to process customers' DNA.
Experts worry that China could race ahead the U.S. in precision medicine because of Chinese laws governing data sharing. Currently, China prohibits the exportation of genetic data without explicit permission from the government. Mr. You says this creates an asymmetry in data sharing between the U.S. and China.
"This is a biological space race and we just haven't woken up to the fact that we're in this race," he said in January at an American Society for Microbiology conference in Washington, D.C. "We don't have access to their data. There is absolutely no reciprocity."
Protecting your data
While Mr. You has been stressing the importance of data security to anyone who will listen, the National Academies of Sciences, Engineering, and Medicine, which makes scientific and policy recommendations on issues of national importance, has commissioned a study on "safeguarding the bioeconomy."
In the meantime, Ms. Berger says organizations that deal with people's health data should assess their security risks and identify potential vulnerabilities in their systems.
As for what individuals can do to protect themselves, she urges people to think about the different ways they're sharing healthcare data—such as via mobile health apps and wearables.
"Ask yourself, what's the benefit of sharing this? What are the potential consequences of sharing this?" she says.
Mr. You also cautions people to think twice before taking consumer DNA tests. They may seem harmless, he says, but at the end of the day, most people don't know where their genetic information is going. "If your genetic sequence is taken, once it's gone, it's gone. There's nothing you can do about it."
Genetically Sequencing Healthy Babies Yielded Surprising Results
Today in Melrose, Massachusetts, Cora Stetson is the picture of good health, a bubbly precocious 2-year-old. But Cora has two separate mutations in the gene that produces a critical enzyme called biotinidase and her body produces only 40 percent of the normal levels of that enzyme.
In the last few years, the dream of predicting and preventing diseases through genomics, starting in childhood, is finally within reach.
That's enough to pass conventional newborn (heelstick) screening, but may not be enough for normal brain development, putting baby Cora at risk for seizures and cognitive impairment. But thanks to an experimental study in which Cora's DNA was sequenced after birth, this condition was discovered and she is being treated with a safe and inexpensive vitamin supplement.
Stories like these are beginning to emerge from the BabySeq Project, the first clinical trial in the world to systematically sequence healthy newborn infants. This trial was led by my research group with funding from the National Institutes of Health. While still controversial, it is pointing the way to a future in which adults, or even newborns, can receive comprehensive genetic analysis in order to determine their risk of future disease and enable opportunities to prevent them.
Some believe that medicine is still not ready for genomic population screening, but others feel it is long overdue. After all, the sequencing of the Human Genome Project was completed in 2003, and with this milestone, it became feasible to sequence and interpret the genome of any human being. The costs have come down dramatically since then; an entire human genome can now be sequenced for about $800, although the costs of bioinformatic and medical interpretation can add another $200 to $2000 more, depending upon the number of genes interrogated and the sophistication of the interpretive effort.
Two-year-old Cora Stetson, whose DNA sequencing after birth identified a potentially dangerous genetic mutation in time for her to receive preventive treatment.
(Photo courtesy of Robert Green)
The ability to sequence the human genome yielded extraordinary benefits in scientific discovery, disease diagnosis, and targeted cancer treatment. But the ability of genomes to detect health risks in advance, to actually predict the medical future of an individual, has been mired in controversy and slow to manifest. In particular, the oft-cited vision that healthy infants could be genetically tested at birth in order to predict and prevent the diseases they would encounter, has proven to be far tougher to implement than anyone anticipated.
But in the last few years, the dream of predicting and preventing diseases through genomics, starting in childhood, is finally within reach. Why did it take so long? And what remains to be done?
Great Expectations
Part of the problem was the unrealistic expectations that had been building for years in advance of the genomic science itself. For example, the 1997 film Gattaca portrayed a near future in which the lifetime risk of disease was readily predicted the moment an infant is born. In the fanfare that accompanied the completion of the Human Genome Project, the notion of predicting and preventing future disease in an individual became a powerful meme that was used to inspire investment and public support for genomic research long before the tools were in place to make it happen.
Another part of the problem was the success of state-mandated newborn screening programs that began in the 1960's with biochemical tests of the "heel-stick" for babies with metabolic disorders. These programs have worked beautifully, costing only a few dollars per baby and saving thousands of infants from death and severe cognitive impairment. It seemed only logical that a new technology like genome sequencing would add power and promise to such programs. But instead of embracing the notion of newborn sequencing, newborn screening laboratories have thus far rejected the entire idea as too expensive, too ambiguous, and too threatening to the comfortable constituency that they had built within the public health framework.
"What can you find when you look as deeply as possible into the medical genomes of healthy individuals?"
Creating the Evidence Base for Preventive Genomics
Despite a number of obstacles, there are researchers who are exploring how to achieve the original vision of genomic testing as a tool for disease prediction and prevention. For example, in our NIH-funded MedSeq Project, we were the first to ask the question: "What can you find when you look as deeply as possible into the medical genomes of healthy individuals?"
Most people do not understand that genetic information comes in four separate categories: 1) dominant mutations putting the individual at risk for rare conditions like familial forms of heart disease or cancer, (2) recessive mutations putting the individual's children at risk for rare conditions like cystic fibrosis or PKU, (3) variants across the genome that can be tallied to construct polygenic risk scores for common conditions like heart disease or type 2 diabetes, and (4) variants that can influence drug metabolism or predict drug side effects such as the muscle pain that occasionally occurs with statin use.
The technological and analytical challenges of our study were formidable, because we decided to systematically interrogate over 5000 disease-associated genes and report results in all four categories of genetic information directly to the primary care physicians for each of our volunteers. We enrolled 200 adults and found that everyone who was sequenced had medically relevant polygenic and pharmacogenomic results, over 90 percent carried recessive mutations that could have been important to reproduction, and an extraordinary 14.5 percent carried dominant mutations for rare genetic conditions.
A few years later we launched the BabySeq Project. In this study, we restricted the number of genes to include only those with child/adolescent onset that could benefit medically from early warning, and even so, we found 9.4 percent carried dominant mutations for rare conditions.
At first, our interpretation around the high proportion of apparently healthy individuals with dominant mutations for rare genetic conditions was simple – that these conditions had lower "penetrance" than anticipated; in other words, only a small proportion of those who carried the dominant mutation would get the disease. If this interpretation were to hold, then genetic risk information might be far less useful than we had hoped.
Suddenly the information available in the genome of even an apparently healthy individual is looking more robust, and the prospect of preventive genomics is looking feasible.
But then we circled back with each adult or infant in order to examine and test them for any possible features of the rare disease in question. When we did this, we were surprised to see that in over a quarter of those carrying such mutations, there were already subtle signs of the disease in question that had not even been suspected! Now our interpretation was different. We now believe that genetic risk may be responsible for subclinical disease in a much higher proportion of people than has ever been suspected!
Meanwhile, colleagues of ours have been demonstrating that detailed analysis of polygenic risk scores can identify individuals at high risk for common conditions like heart disease. So adding up the medically relevant results in any given genome, we start to see that you can learn your risks for a rare monogenic condition, a common polygenic condition, a bad effect from a drug you might take in the future, or for having a child with a devastating recessive condition. Suddenly the information available in the genome of even an apparently healthy individual is looking more robust, and the prospect of preventive genomics is looking feasible.
Preventive Genomics Arrives in Clinical Medicine
There is still considerable evidence to gather before we can recommend genomic screening for the entire population. For example, it is important to make sure that families who learn about such risks do not suffer harms or waste resources from excessive medical attention. And many doctors don't yet have guidance on how to use such information with their patients. But our research is convincing many people that preventive genomics is coming and that it will save lives.
In fact, we recently launched a Preventive Genomics Clinic at Brigham and Women's Hospital where information-seeking adults can obtain predictive genomic testing with the highest quality interpretation and medical context, and be coached over time in light of their disease risks toward a healthier outcome. Insurance doesn't yet cover such testing, so patients must pay out of pocket for now, but they can choose from a menu of genetic screening tests, all of which are more comprehensive than consumer-facing products. Genetic counseling is available but optional. So far, this service is for adults only, but sequencing for children will surely follow soon.
As the costs of sequencing and other Omics technologies continue to decline, we will see both responsible and irresponsible marketing of genetic testing, and we will need to guard against unscientific claims. But at the same time, we must be far more imaginative and fast moving in mainstream medicine than we have been to date in order to claim the emerging benefits of preventive genomics where it is now clear that suffering can be averted, and lives can be saved. The future has arrived if we are bold enough to grasp it.
Funding and Disclosures:
Dr. Green's research is supported by the National Institutes of Health, the Department of Defense and through donations to The Franca Sozzani Fund for Preventive Genomics. Dr. Green receives compensation for advising the following companies: AIA, Applied Therapeutics, Helix, Ohana, OptraHealth, Prudential, Verily and Veritas; and is co-founder and advisor to Genome Medical, Inc, a technology and services company providing genetics expertise to patients, providers, employers and care systems.
Your Prescription Is Ready for Download
You may be familiar with Moore's Law, the prediction made by Intel co-founder Gordon Moore that computer chips would get faster and cheaper with each passing year. That's been borne out by the explosive growth of the tech industry, but you may not know that there is an inverse Moore's Law for drug development.
What if there were a way to apply the fast-moving, low-cost techniques of software development to drug discovery?
Eroom's Law—yes that's "Moore" spelled backward—is the observation that drug discovery has become slower and more expensive over time, despite technological improvements. And just like Moore's Law, it's been borne out by experience—from the 1950s to today, the number of drugs that can be developed per billion dollars in spending has steadily decreased, contributing to the continued growth of health care costs.
But what if there were a way to apply the fast-moving, low-cost techniques of software development to drug discovery? That's what a group of startups in the new field of digital therapeutics are promising. They develop apps that are used—either on their own or in conjunction with conventional drugs—to treat chronic disorders like addiction, diabetes and mental health that have so far resisted a pharmaceutical approach. Unlike the thousands of wellness and health apps that can be downloaded to your phone, digital therapeutics are developed and are meant to be used like drugs, complete with clinical trials, FDA approval and doctor prescriptions.
The field is hot—in 2017 global investment in digital therapeutics jumped to $11.5 billion, a fivefold increase from 2012, and major pharma companies like Novartis are developing their own digital products or partnering with startups. One such startup is the bicoastal Pear Therapeutics. Last month, Pear's reSET-O product became the first digital therapeutic to be approved for use by the millions of Americans who struggle with opioid use disorder, and the company has other products addressing addiction and mental illness in the pipeline.
I spoke with Dr. Corey McCann, Pear's CEO, about the company's efforts to meld software and medicine, designing clinical trials for an entirely new kind of treatment, and the future of digital therapeutics.
The interview has been edited and condensed for clarity and length.
"We're looking at conditions that currently can't be cured with drugs."
BRYAN WALSH: What makes a digital therapeutic different than a wellness app?
COREY MCCANN: What we do is develop therapeutics that are designed to be used under the auspices of a physician, just as a drug developed under good manufacturing would be. We do clinical studies for both safety and efficacy, and then they go through the development process you'd expect for a drug. We look at the commercial side, at the role of doctors. Everything we do is what would be done with a traditional medical product. It's a piece of software developed like a drug.
WALSH: What kind of conditions are you first aiming to treat with digital therapeutics?
MCCANN: We're looking at conditions that currently can't be cured with drugs. A good example is our reSET product, which is designed to treat addiction to alcohol, cannabis, stimulants, cocaine. There really aren't pharmaceutical products that are approved to treat people addicted to these substances. What we're doing is functional therapy, the standard of care for addiction treatment, but delivered via software. But we can also work with medication—our reSET-O product is a great example. It's for patients struggling with opioid addiction, and it's delivered in concert with the drug buprenorphine.
WALSH: Walk me through what the patient experience would be like for someone on a digital therapeutic like reSET.
MCCANN: Imagine you're a patient who has been diagnosed with cocaine addiction by a doctor. You would then receive a prescription for reSET during the same office visit. Instead of a pharmacy, the script is sent to the reSET Connect Patient Service Center, where you are onboarded and given an access code that is used to unlock the product after downloading it onto your device. The product has 60 different modules—each one requiring about a 10 to 15-minute interaction—all derived from a form of cognitive behavioral therapy called community reinforcement approach. The treatment takes place over 90 days.
"The patients receiving the digital therapeutic were more than twice as likely to remain abstinent as those receiving standard care."
Patients report their substance abuse, cravings and triggers, and they are also tested on core proficiencies through the therapy. Physicians have access to all of their data, which helps facilitate their one-on-one meetings. We know from regular urine tests how effective the treatment is.
WALSH: What kind of data did you find when you did clinical studies on reSET?
MCCANN: We had 399 patients in 10 centers taking part in a randomized clinical trial run by the National Institute on Drug Abuse. Every patient enrolled in the study had an active substance abuse disorder. The study was randomized so that patients either received the best current standard of care, which is three hours a week of face-to-face therapy, or they received the digital therapeutic. The primary endpoint was abstinence in weeks 9 to 12—if the patient had a single dirty urine screen in the last month, they counted as a failure.
In the end, the patients receiving the digital therapeutic were more than twice as likely to remain abstinent as those receiving standard care—40 percent versus 17 percent. Those receiving reSET were also much more likely to remain in treatment through the entire trial.
WALSH: Why start by focusing your first digital therapeutics on addiction?
MCCANN: We have tried to build a company that is poised to make a difference in medicine. If you look at addiction, there is little to nothing in the drug pipeline to address this. More than 30 million people in the U.S. suffer from addiction disorders, and not only is efficacy a concern, but so is access. Many patients aren't able to receive anything like the kind of face-to-face therapy our control group received. So we think digital therapeutics can make a difference there as well.
WALSH: reSET was the first digital therapeutic approved by the FDA to treat a specific disorder. What has the approval process been like?
MCCANN: It's been a learning process for all involved, including the FDA. Our philosophy is to work within the clinical trials structure, which has specific disease targets and endpoints, and develop quality software, and bring those two strands together to generate digital therapeutics. We now have two products that have been FDA-approved, and four more in development. The FDA is appropriately cautious about all of this, balancing the tradeoff between patient risk and medical value. As we see it, our company is half tech and half biotech, and we follow regulatory trials that are as rigorous as they would be with any drug company.
"This is a new space, but when you look back in 10 years there will be an entire industry of prescription digital therapeutics."
WALSH: How do you balance those two halves, the tech side and the biology side? Tech companies are known for iterating rapidly and cheaply, while pharma companies develop drugs slowly and expensively.
MCCANN: This is a new space, but when you look back in 10 years there will be an entire industry of prescription digital therapeutics. Right now for us we're combining the rigor of the pharmaceutical model with the speed and agility of a tech company. Our product takes longer to develop than an unverified health app, but less time and with less clinical risk than a new molecular entity. This is still a work in progress and not a day goes by where we don't notice the difference between those disciplines.
WALSH: Who's going to pay for these treatments? Insurers are traditionally slow to accept new innovations in the therapeutic space.
MCCANN: This is just like any drug launch. We need to show medical quality and value, and we need to get clinician demand. We want to focus on demonstrating as many scripts as we can in 2019. And we know we'll need to be persistent—we live in a world where payers will say no to anything three times before they say yes. Demonstrating value is how you get there.
WALSH: Is part of that value the possibility that digital therapeutics could be much cheaper than paying someone for multiple face-to-face therapy sessions?
MCCANN: I believe the cost model is very compelling here, especially when you can treat diseases that were not treatable before. That is something that creates medical value. Then you have the data aspect, which makes our product fundamentally different from a drug. We know everything about every patient that uses our product. We know engagement, we can push patient self-reports to clinicians. We can measure efficiency out in the real world, not just in a measured clinical trial. That is the holy grail in the pharma world—to understand compliance in practice.
WALSH: What's the future of digital therapeutics?
MCCANN: In 10 years, what we think of as digital medicine will just be medicine. This is something that will absolutely become standard of care. We are working on education to help partners and payers figure out where go from here, and to incorporate digital therapeutics into standard care. It will start in 2019 and 2020 with addiction medicine, and then in three to five years you'll see treatments designed to address disorders of the brain. And then past the decade horizon you'll see plenty of products that aim at every facet of medicine.