How do I compellingly advocate for my privacy with doctors and other healthcare professionals?

It is simply too complicated for a doctor’s office to manage and would come off as peculiar for making such a request.

I had limited success supporting a psychotherapist to choose privacy fist solutions, but only as long as it was a convenient (and ideally cheaper) option.

People in the healthcare system will not care as long as they don’t actually feel any strong negative consequences. And you can’t make them care.

You could be contrary and leave your doctor for another one.

  • Then you can give them negative ratings referring to bad privacy practices on doctor rating sites.
  • You could also dig into the details, if they are actually acting according to law and sue them if you find a violation.

But I don’t believe that would change much. People who care about privacy or have the capacity to understand vast abstract social systems are to much of a minority.

Yes, this type of request could work with therapists as they’re focused on your mental health and you could share how distressing it is for them to use privacy invasive tools.

One therapist I had already had a Proton email account set up which we used to communicate with. Another therapist had paperwork in which he discouraged the use of email and texts due to their lack of privacy protection. These were both independent therapists, which might be more willing to make modifications to their communication methods for a patient. When I looked at a few therapists that worked under a business operating in multiple states, I noticed that their disclosures included the use of AI to transcribe conversations. I was appalled by this and I wondered if the business had partnered with an AI provider.

The thing with AI is indeed a fast growing problem.

If psychotherapists hate one thing almost unanimously, it’s writing reports. - And they have to write reports for health insurance companies, colleagues when transfers happen and sometimes just for compliance reasons.

There is a huge (mostly illegal) market for ghost writers, which is legal, because their services are sold as proof reading. - AI companies found that market. That isn’t just a good chance for profit now. It is also a good opportunity to replace psychotherapists in the long run.

Think about it. - If you are the AI company, you get all the words spoken or at least all the notes for each session with a patient. That’s valuable training data. Your AI is writing all the reports and therefore is handling all the interactions with the health care system. If the health care providers learn of this, they are only to happy to cut down on compensations for psychotherapists, making the job for humans not viable anymore. At that point AI companies can take over.

I would be surprised if receptionist knew any better. International law degree with emphasis on privacy in combination with setting up IT infrastructure is usually not a requirement for receptionist job title (nor for MD).

You mention GDPR; if you’re in EU, your doctor’s office should have a designated DPO (Data Protection Officer), and its contact is mandated to be listed. That is the person you should be contacting with your privacy concerns; not the receptionist or the medical doctor themselves (who [hopefully] have a different field of expertise).

Failing solving the issues with the DPO; report them for violations to your country Supervisory Authority according to art.77 of the GDPR.

Then change the doctor, rinse & repeat until you get a good one – or you run out of doctors (in which case try not to get sick, or lower your privacy standards; whichever sounds less problematic).

Shall the SA also fail to address the privacy violations (or inform you of the resolution or progress within three months; you also have the “Right to an effective judicial remedy against a supervisory authority” pursuant to Art. 78 of the GDPR.

OMG what a :face_vomiting: response from the practice.

:100:

I feel exactly the same way. People are being compelled to justify their own human rights, and seeing most other people comply with the status quo makes me feel lonely.

It could be just a joke but it could be interpreted as advice for your personal safety. Referring someone to the mental health system is an act of inciting violence (detainment and involuntary “treatment”) against said person, and in a clinical setting there is some possibility that threat is carried out.

In addition to it not being about the individual patient or the practice, or even laws, I would say it’s about reality. Involving Google, WhatsApp or other third parties compromises doctor/patient confidentiality. For vulnerable people or people with sensitive medical conditions, a compromise that exposes evidence of a sensitive medical condition or evidence of appointments at specialized clinics could lead to real-world harms.

I did this a while ago. I asked for a paper consent form. I filled it out but, thinking WTF when reading the consent text, didn’t sign the consent. I handed the form back. They noticed I didn’t sign it, and and handed the form back to me. I said I’m unsure about the content of the consent part. They said I can say “no” to where there are yes/no options. I used horizontal lines to strike out consent to AI transcription and sharing of anonymized data for non-medical purposes (there were no yes/no options), inserted a clause that expressly forbids such, then signed it. They accepted it. Whether they will implement my refusals or simply ignore them (and do AI transcription and data sharing without my knowledge and consent) is another matter entirely and I may never find out.

While the above is not the making of a compelling argument to medical institutions, it does signal a refusal to comply with the status quo.

I don’t know what AI transcription even looks like. Can anyone tell me, does the doctor type notes into their computer, or is the entire consultation audio recorded?

@PurpleDime BTW, @jordan and @nateb discussed your thread https://inv.nadeko.net/watch?t=5724&v=6pQl-hsAKa4

That’s fair, but as I said, not everyone has the same options. That being said, I intend to raise the issue with my local data protection agency. I’m not going to report my doctor, at least for now, but I will inquire about them about the use of Gmail and WhatsApp in healthcare, but also other businesses that handle customer data.

I don’t believe that to be the case. I don’t think I am asking for too much.

But even if I were to agree with you that it’s too complicated, does it matter if what they are currently doing is in violation of the law and their own stated medical standards?

By “supporting them”, do you mean that you are helping them set better practices as a privacy expert?

Or were you a client of this psychotherapist who has certain privacy requests, and they were willing to meet you for some of them?

People are willing to choose convenience even if it’s a violation of law, and in the context of healthcare, that is a big problem.

There is some truth to this, but it’s not true in the absolute. We can convert some people. Some healthcare workers have better privacy practices than others.

As I explained multiple times, not everyone has that option. Especially when most doctors have bad privacy practices. If someone has to choose between the very best specialist doctor, who has poor privacy practices, and a pretty good former, even if it’s an unfortunate compromise.

Even if we fail, we should be able to respectfully express our pushback and not get flack for it. A previous doctor refused to see me because I expressed reservations about their poor privacy practices. No one should be denied care for asking questions, demanding comprehensible answers, and expressing doubt.

I am open to doing that. However, although it’s very possible and even likely that you could get pushback from other patients online because they have little awareness about privacy and are drunk on the surveillance Kool-Aid.

I have been on local online forums from my location, where I have raised issues about privacy, and I get a lot of harsh pushback from people who think it’s normal to have to share your location to make a bank transaction from your banking app. People are quick to reply with insults instead of making their case for why I’m wrong and why they’re right.

As I said earlier, I plan to contact my local data protection agency and inquire about it. I have found quite a few articles about the common use of WhatsApp and Gmail in healthcare and how, although it’s very convenient, it is not compliant with doctor-patient confidentiality laws.

I can’t afford to sue, so that is never going to happen. But if my data protection agency is willing to reprimand and hopefully launch systemic change after I make a complaint, that would be wonderful.

That may be true, but it’s still worth trying. Look at Louis Rossmann. He’s a consumer rights activist, and by extension, a privacy rights activist. Although he is very harsh on himself and doesn’t think he was able to accomplish much legislative change, he has arguably inspired millions of people. He has made a small, significant difference and is inspiring people to do the same. I believe PG and TechLore are on that very same path. The work is not done, but we are making small progress.

I don’t consider myself an expert. I don’t know if I have a strong grasp on vast abstract social systems, if I have any, but I understand some basic things about privacy. And I believe millions of regular people can do the same.

The role of PG, TechLore, and other prominent privacy voices like Carissa Véliz and Naomi Brockwell, and even journalists, is to help regular people understand these issues and make better decisions about their lives and our collective future as a society.

I don’t expect people who work in admin to have advanced IT knowledge. But I do expect them to be able to know the basics of their organization’s privacy practices and to be able to explain it in plain terms. Especially if they work in healthcare or law, where confidentiality is vital.

I once had a receptionist at a doctor’s office ask me what my medical issues were in front of all the other patients who were in the waiting room. You don’t need fancy degrees to know that that is inappropriate and violates privacy.

This is good news if true.

I disagree on this part. The information I am inquiring about is IMHO, not complicated.
It’s precisely why Carissa Véliz invites all of us to ask all the people and organizations who handle our data what their privacy practices are.

Most doctors have privacy policies in their medical forms. In fact, I do believe it’s a must, which is why I was surprised my doctor didn’t have any in hers. If I am about to sign a lease agreement with a landlord, I expect them to be able to answer any questions I have about the terms that they want me to agree to.

Similarly, if a doctor presents me with a form with a privacy policy, they should be able to answer any questions I have about the document they want me to sign. It shouldn’t be complicated. If they can’t, that is a huge red flag.

One doctor I saw had a privacy policy that said that they may share some information about you for medical research. If I want to ask about that, about who these third parties are, how my info is shared, and used, I expect you to have the answers. Otherwise, you are expecting me to sign a document that neither of us understands, which is INSANE. :flushed_face: It’s the blind leading the blind. :see_no_evil_monkey: :upside_down_face:

I once had a medical professional abruptly switch to her personal Gmail and quote chunks of correspondence that occurred over their proper email infra. It was wild, and she couldn’t understand why it’s an issue for me. I told her employer’s lawyers could probably explain it to her quite well.

I’d say it is a case of XKCD #2501.

I’d guess it is far more likely that someone who might know most of the stuff (e.g. things like differences between SMTP opportunistic TLS vs. E2E) is the IT department which set them up, and the lawyers which (hopefully with input from said IT department, and hopefully giving directions to IT detapartment) wrote the privacy policy document (_if_ they did).

That sounds like an red flag, yes. If in your jurisdiction it is mandatory, I would run away fast if they lack it.

i.e. If they disregard the law and don’t have mandated privacy policy, they might also not have a required MD training either (instead of that they might, say, just be asking ChatGPT about your illnesses and giving prescriptions based on that).

Sure. I’m just saying (at least in my experience) that what the receptionists (or MDs) at most will likely be able to do is read you the policy letter for letter, and not interpret it nor explain how specific technical implementation (e.g. gmail) fits (or doesn’t fit, as it might be) inside that legal framework.

For any such explanation, they would (should) refer to DPO (or, if not in EU - to their legal, which would then hopefully refer to their IT for clarification, instead of just repeating/rephrasing existing privacy policy, which might often happen if they think they could get away with that)

It’s actually significantly worse IMHO (as first blind person in “blind leading the blind” doesn’t generally have ulterior profit motives that depend on draining money from second blind person), :sad_but_relieved_face:

AUDIENCE EXPECTATIONS

You make some excellent points, but I partially disagree with some of your assumptions. I don’t think it’s universally a given that people who listen to or read Carissa Véliz are primed for “extreme” examples just because she’s an expert on the matter.

Firstly, a lot of the people who are introduced to her are not necessarily privacy enthusiasts. Secondly, she has appeared on many podcasts that are not about privacy, so the audience didn’t expect this to be a topic.

I personally don’t think the Holocaust example is an extreme example to give. It’s a powerful and arresting example for sure, but mentioning it is not extreme. Context matters. How I do it matters.

Are there insensitive ways to bring it up?

Yes, absolutely.

Just as there are insensitive ways to talk about murder or sexual assault or death in general. However, that is not my goal or intention.

TAILORING YOUR MESSAGE TO YOUR AUDIENCE IS IMPORTANT

The core identity of the audience is healthcare workers…

My audience in this case is doctors, who are used to dealing with other people’s trauma. I once had a doctor share with me that dealing with patients who are going through terminal illness can take its toll on her, which is why she goes to therapy. I really appreciated that vulnerability.

I don’t disagree with the idea of nudging, primarily because I recognize that sometimes, people relate more to smaller examples than big ones. Bringing up the Holocaust was never going to be the first example I used, and I want to remind everyone, that I have already given other examples to my doctor’s receptionist.

…but other identity markers are also relevant and could have more impact

My goal is to persuade, not to upset. My reasoning was that because my doctor is Jewish, she might be more receptive to this example. Similarly, because my doctor is a healthcare worker, focusing on examples of privacy breaches in the healthcare sector might also be a good idea. I think this is where I should start.

I am not going to use the Holocaust example for now. After thinking more about it, I don’t think it’s the most compelling example to use with a healthcare worker regardless of whether they are Jewish or not. But I do think it’s possible that if the healthcare examples fail, a Jewish doctor could be moved by the Holocaust example. It will likely still be a long shot, though. There are many angles to explore based on the specifics of who I am talking to.

ARGUMENTS I INTEND TO USE

  1. By default, neither Gmail nor WhatsApp are considered HIPAA compliant in the US.

Gmail can be HIPAA compliant, but it requires a paid business account and a Business Associate Agreement, which is a formal contract.

Even if this is US-specific, I think it’s worth mentioning. Fun fact: despite being E2EE and collecting the least amount of metadata, Signal is not considered HIPAA compliant either. They need a Business Associate Agreement in order to be, and to my understanding, that is currently not possible for general messaging apps like WhatsApp and Signal.

  1. Neither Gmail nor WhatsApp are considered compliant with GDPR and Health Data Hosting standards.

GDPR requires enhanced data protection for healthcare and must comply with the health data hosting certification (HDS) according to the article linked above.

Even if you don’t live in the EU either, using this example can help doctors understand the importance of privacy in healthcare as it relates to tools like Gmail and WhatsApp. Just because something may be legal, doesn’t mean it’s ethical.

And it is very likely that if you live in a country with data privacy laws and a data privacy authority, neither Gmail nor WhatsApp are considered compliant with those laws. I intend to contact my local data protection agency, and have them confirm in writing if Gmail and WhatsApp in healthcare are considered compliant.

EXAMPLES I INTEND TO USE:

  1. Both Google and Meta were sued for collecting healthcare data from Flo, a menstrual tracking app, without consent.

They collected the data from the menstrual and ovulation monitoring app Flo, which was also sued for mishandling the data because they claim not to share it with any third parties. The case was investigated by the FTC. Google and Flo settled for $56 million, and Meta was fined.

  1. Blue Shield Insurance Privacy Breach

Health insurance firm Blue Shield has revealed a data breach exposed protected health data of over 4.7 million members via Google Analytics.

The information was leaked to Google’s analytics and advertisement platforms following a misconfiguration of Google analytics on Blue Shield sites.

  1. Father gets wrongly flagged to authorities by Google for CSAM after sharing an intimate picture of his child with a doctor during a healthcare emergency.

I would like to believe that these examples are compelling enough to at the very least make my doctor agree not to share sensitive information about my care and medical history via Google or WhatsApp.

Even though it is not compliant with healthcare data privacy laws, I would also hope that my doctor would agree to communicate with me via Signal, because it collects the least amount of metadata.

HOW SOCIAL STATUS AND RESPECTABILITY POLITICS INFLUENCE YOUR ABILITY TO PERSUADE

You’ve touched on an important issue here. And it’s how people are more likely to dismiss your advocacy if you are not a certified expert even though you are well-educated about privacy and your arguments are based on the knowledge of experts that you cite.

For clarity, by certified expert, I mean someone who is either formally educated in the topic (e.g.: degree in IT & cybersecurity), teaches the topic (e.g.: professor of philosophy in ethics of privacy), or works in the topic (e.g.: works in IT with no formal education in it/known privacy activist cited in media with no formal education but with a sizeable public platform).

It’s also frustrating to observe that people who are knowledgeable but not certified experts are taken more seriously in their privacy advocacy because of their perceived respectability of their socio-economic status.

The CEO of a successful luxury hotel franchise can be as knowledgeable as a working-class plumber about privacy, even though neither is a certified expert on the topic, but the former is more likely to be heard than the latter.

I don’t expect answers with a string of technical jargon. I expect basic answers that people who are front-facing should know. If you’re a real estate agent, I don’t expect you to be an expert on construction, but I expect you to have some basic knowledge of the house you’re selling.

I forgot the details but I thought HIPAA doesn’t do much for patient privacy/confidentiality.

If your examples are not compelling enough for practices to stop using Google etc. in the interest of doctor/patient confidentiality then nothing may be. Explaining those examples to practices in a convincing and respectful manner, and recommending an alternative (Signal for instance), may be the best that can be done in the current “nothing to hide” surveillance capitalist status quo. Keep us posted about your privacy advocacy to practices :slightly_smiling_face:

Edited to add Odysee link.

I remember watching that video, but I’ll have to rewatch it again in my current context.
As I mentioned in a previous comment, even Signal is not HIPAA compliant, despite being infinitely more private, and it’s because it’s a general-purpose app. I will try suggesting it, but I suspect it won’t fly.

This is 100% true.

Most people except in Forums and Social Media Groups like this are not aware of most things. Especially technical stuff.

Trying to teach everyone would not only be time-consuming but they wouldn’t understand the significance of the matter. They just think that the software they use is approved and legal, therefore it is not a problem. And thus they don’t care.

PROCEEDING WITH CAUTION

Thank you! I just watched the stream. @jordan and @nateb made some valid points. At this early stage, staying quiet is not an option for me. I am going to speak up. But like @jordan said, I must be tactful. I do not want to come across as a crazy conspiracy theorist like @Bumbashirovich is suggesting.

I also 100% agree with @nateb when he says that taking care of your health should take precedence over your privacy concerns, especially if you do not have many options in healthcare providers.

THE ISSUE IS SYSTEMIC

I want to reiterate that I am dealing with a single practice, where there are essentially two people working. My doctor and her receptionist. My doctor’s practice is in a clinic where there are many practitioners who don’t use Gmail. This means that the choice to use Gmail and WhatsApp is entirely hers. It’s not imposed on her by the clinic.

With that being said, @nateb is right to point out that the issue is systemic because it has become very common for businesses and medical practices to use WhatsApp and Gmail.

I appreciate you sharing your experience with doctors who use Signal but are not allowed to use it for work because other people need to be able to access chats. This is probably why Signal, like WhatsApp, is not considered HIPAA compliant, despite being more private.

FIRST STEP: INQUIRY VIA DPA & LAWYERS

My current first step will be to contact my local data protection agency and ask them about the use of WhatsApp and Gmail in healthcare. I am also going to contact law firms that specialize in privacy to ask them the same thing. I don’t intend to be a client. I can’t afford it, but I hope some are willing to respond.

I’ve mentioned before that I have yet to find a law firm specialized in privacy issues that caters to regular people rather than corporations and organizations. Most of these law firms advertise their services as helping organizations be compliant with privacy laws.

That’s all fine and dandy, but we must never forget that the interests of your bank, which holds your data and arguably wants to protect it, are not the same as your interests, even though some of your concerns align.

FINAL THOUGHTS

I have weeks to prepare. My goal is to voice my concerns calmly and in the most respectful way possible. I hope I am successful.

That is exactly my point (which I tried to emphasize with that XKCD comic): you’re not asking for basic answers. You’re asking extremely complex questions, which require in-depth technical IT knowledge, which the receptionist is highly unlikely to have at hand without consulting their IT (which, as you seem to say, does not exist).

  • Simple answer would be “Our e-mail communication with patients is confidential”, which seems to be what you’re getting, yes?

  • Significantly more advanced answer would be "Our e-mail communication with patients is confidential, and is being protected by technical measure of using modern Ed25519/AES-256 encryption ciphers between our and your e-mail servers, which prevents eavesdropping by unauthorized 3rd parties in between them"

  • But the answers you seem to be wanting are waaay beyond even that, and would require receptionist to know not only the difference between how MUA and MTAs exchange messages (e.g. how the security of the message stored on local folder differs from one stored on the IMAP folder), but also why certain ways of doing encryption (e.g. transport encryption via SMTP STARTTLS between servers) which do protect against eavesdropping by unauthorized third parties, has certain disadvantages compared to end2end e-mail encryption like S/MIME or ASCII-armored OpenPGP) (which protects data even from authorized 3rd parties, i.e. e-mail storage servers like Google’s)

    Sure, such things might seem easy to you and me, but I’m quite convinced that for average receptionist those would be utterly incomprehensible; you might’ve as well asked her in Klingon.

Not to say that I approve of them not knowing (or at least, of them not having a contact where they could get answers to such questions) – to the contrary.

But I’m just trying to outline why you seem to be getting confused looks from the receptionist.

Basic, yes. E.g. “does the house have electricity in all rooms” is basic question, which real estate agent is likely to know.

But asking “Is electricity provided by TN-C, TT, or TN-S system, and is the bathroom water heater shock-protection provided by double-isolation, bootleg ground or RCD (and if RCD, at which leakage current threshold in mA)” might leave many real-estate agent somewhat overwhelmed.[1]

And you seem to be asking the equivalent of the latter, not the former.


  1. BTW, What you want for good anti-shock protection is obviously TN-S + 30mA RCD + double-isolation; surely EVERY real-estate agent knows at least that, right? ↩︎

From your explanation, you have a solid strategy.

I do IT stuff (professionally) and they were just starting their business, so I offered my support, selecting hardware, software and services and implementing stuff like the website.

I’m very much into Open Source Software, Privacy and IT-Security, all of it in a very practical way. The solutions offered solutions do reflect that.

Thank you for your very comprehensive feedback. I sincerely appreciate how you are breaking it down. Although you make very valid points, I still somewhat disagree.

I am not an expert. I am just a regular person who likes to learn about privacy issues because it’s an issue I care deeply about. I do not have the advanced technical knowledge that you seem to clearly have. You have used numerous technical terms that I am not familiar with, which is the jargon I was referring to. :sweat_smile:

I can understand why someone who is as knowledgeable as you would expect more technical answers that are very IT-centric. However, when you look at the growing knowledge of privacy expertise, you notice that there is a rich and wide tapestry of experts who come from different fields, not just IT.

Shoshanna Zuboff (Surveillance Capitalism) is a social psychologist and philosopher. Carissa Véliz is also a philosopher. Glenn Greenwald, who helped Edward Snowden, is a political journalist and former lawyer. Loira Poitras, who also told Snowden’s story, is a documentary filmmaker. Cory Doctorow is a journalist, activist, and science fiction writer. Although some of these people have strong IT knowledge (Doctorow), most of them don’t.

When you read Véliz’s book, she doesn’t talk much about IT, although of course it is mentioned. And yet we understand the privacy issues she raises. She has the rare talent that not all experts have to be able to explain privacy issues in layman’s terms.

Maybe I am wrong, but this is the kind of answer I expect from my doctor and her receptionist:

The law says X which means we don’t share your data with any unauthorized third parties. The third-party tools we use are X, Y, and Z, and most are E2EE which means they are unable to read it. All the third-party tools we use and organizations we liaise with are bound by law to protect your confidentiality.

I can appreciate that many healthcare workers do not know the answer to this question and hence are taken off guard. But to me, that is an indictment of the state of affairs because they should have some knowledge or, at the very least, refer me to a person they know and work with who can answer this question. Every job has parts of it we don’t like that we must have some competence in.

I asked my question in person the day of my appointment. But I could have asked it days or weeks before via email, and I suspect their answer would have been just as weak despite having the time to formulate a good response.

I have met many real estate agents who know the answers to questions like that. And those who don’t tell me they will find out for me.

Have you ever gone to the Apple Store or any tech store and asked about something the employees there didn’t have the answer to or gave you the wrong answer?

Have you ever experienced the same thing in a grocery store when you asked a simple question?

I’m sure we all have. The realization I came to is that many employees do not have the knowledge they are supposed to have. But also, even when they do, they don’t know everything, which is normal.

But in my view, it’s not acceptable to not know anything about your privacy practices when you work in healthcare or law.