AUDIENCE EXPECTATIONS
You make some excellent points, but I partially disagree with some of your assumptions. I don’t think it’s universally a given that people who listen to or read Carissa Véliz are primed for “extreme” examples just because she’s an expert on the matter.
Firstly, a lot of the people who are introduced to her are not necessarily privacy enthusiasts. Secondly, she has appeared on many podcasts that are not about privacy, so the audience didn’t expect this to be a topic.
I personally don’t think the Holocaust example is an extreme example to give. It’s a powerful and arresting example for sure, but mentioning it is not extreme. Context matters. How I do it matters.
Are there insensitive ways to bring it up?
Yes, absolutely.
Just as there are insensitive ways to talk about murder or sexual assault or death in general. However, that is not my goal or intention.
TAILORING YOUR MESSAGE TO YOUR AUDIENCE IS IMPORTANT
The core identity of the audience is healthcare workers…
My audience in this case is doctors, who are used to dealing with other people’s trauma. I once had a doctor share with me that dealing with patients who are going through terminal illness can take its toll on her, which is why she goes to therapy. I really appreciated that vulnerability.
I don’t disagree with the idea of nudging, primarily because I recognize that sometimes, people relate more to smaller examples than big ones. Bringing up the Holocaust was never going to be the first example I used, and I want to remind everyone, that I have already given other examples to my doctor’s receptionist.
…but other identity markers are also relevant and could have more impact
My goal is to persuade, not to upset. My reasoning was that because my doctor is Jewish, she might be more receptive to this example. Similarly, because my doctor is a healthcare worker, focusing on examples of privacy breaches in the healthcare sector might also be a good idea. I think this is where I should start.
I am not going to use the Holocaust example for now. After thinking more about it, I don’t think it’s the most compelling example to use with a healthcare worker regardless of whether they are Jewish or not. But I do think it’s possible that if the healthcare examples fail, a Jewish doctor could be moved by the Holocaust example. It will likely still be a long shot, though. There are many angles to explore based on the specifics of who I am talking to.
ARGUMENTS I INTEND TO USE
- By default, neither Gmail nor WhatsApp are considered HIPAA compliant in the US.
Gmail can be HIPAA compliant, but it requires a paid business account and a Business Associate Agreement, which is a formal contract.
Even if this is US-specific, I think it’s worth mentioning. Fun fact: despite being E2EE and collecting the least amount of metadata, Signal is not considered HIPAA compliant either. They need a Business Associate Agreement in order to be, and to my understanding, that is currently not possible for general messaging apps like WhatsApp and Signal.
- Neither Gmail nor WhatsApp are considered compliant with GDPR and Health Data Hosting standards.
GDPR requires enhanced data protection for healthcare and must comply with the health data hosting certification (HDS) according to the article linked above.
Even if you don’t live in the EU either, using this example can help doctors understand the importance of privacy in healthcare as it relates to tools like Gmail and WhatsApp. Just because something may be legal, doesn’t mean it’s ethical.
And it is very likely that if you live in a country with data privacy laws and a data privacy authority, neither Gmail nor WhatsApp are considered compliant with those laws. I intend to contact my local data protection agency, and have them confirm in writing if Gmail and WhatsApp in healthcare are considered compliant.
EXAMPLES I INTEND TO USE:
- Both Google and Meta were sued for collecting healthcare data from Flo, a menstrual tracking app, without consent.
They collected the data from the menstrual and ovulation monitoring app Flo, which was also sued for mishandling the data because they claim not to share it with any third parties. The case was investigated by the FTC. Google and Flo settled for $56 million, and Meta was fined.
- Blue Shield Insurance Privacy Breach
Health insurance firm Blue Shield has revealed a data breach exposed protected health data of over 4.7 million members via Google Analytics.
The information was leaked to Google’s analytics and advertisement platforms following a misconfiguration of Google analytics on Blue Shield sites.
- Father gets wrongly flagged to authorities by Google for CSAM after sharing an intimate picture of his child with a doctor during a healthcare emergency.
I would like to believe that these examples are compelling enough to at the very least make my doctor agree not to share sensitive information about my care and medical history via Google or WhatsApp.
Even though it is not compliant with healthcare data privacy laws, I would also hope that my doctor would agree to communicate with me via Signal, because it collects the least amount of metadata.