Verily's COVID-19 Screening Website Leaves Privacy Questions Unanswered

Deeplinks 2020-03-25

Summary:

One week after Alphabet’s Verily launched its COVID-19 screening website, several unanswered questions remain about how exactly the project will collect, use, and retain people’s medical information.

Verily, a healthcare data subsidiary of Google's parent company Alphabet, has until now operated its Project Baseline as a way to connect potential participants with clinical research. Now, after a confused roll-out, Verily’s Baseline COVID-19 Pilot Program screening and testing website allows users to fill out a multi-question survey about their symptoms and, if they are eligible, directs them to testing locations in a few counties in California.

After a letter from Congress and multiple blog posts, press statements, and not one but two FAQs from Verily, users still do not have enough information about how using this service will affect their medical privacy. So, we have a few questions of our own.

Why does using the site require a Google account?

While the United States is in dire need of more testing, individuals’ access to this critical health service should not hinge on whether or not they have created an account and shared information with the world’s biggest advertising company.

But you can’t use the Verily screening website without a Google account: users must either log into their existing Google account, or create a new one, before filling out the screening survey. Verily representatives have claimed this is necessary to authenticate users and contact them during the screening and testing process. However, Verily has not explained why a Google account is uniquely suited to identifying patients, or why the project cannot use other less invasive forms of identification.

What will Verily do with your information?

Verily assures users that the medical information they input as part of the screening service will not be linked with their Google account data without “separate or explicit” consent. However, the screening website’s FAQ page says that information may be shared with “certain service providers engaged to perform services on behalf of Verily,” which includes—you guessed it—Google.

Verily also assures users that their information will not be used for advertising. What Verily will use that information for, however, is broad and unclear. Its privacy policy lists “commercial product research and development,” as a potential use, and the Project Baseline FAQ lists similarly vague uses, including to “provide insights about your health,” “conduct and publish research on health and disease,” and “build new tools, technologies, products, and partnerships related to health and disease.” Without explicit written documents memorializing these data use protocols, users have little reassurance that Verily’s uses of their health data will be tailored, appropriate, or privacy-protective.

Who is Verily sharing data with?

Verily states that it will not share any information with insurance or medical providers, which is a good start. However, Verily outlines other potential recipients of users’ information:

The information you choose to provide during the screening process or testing pro

Link:

https://www.eff.org/deeplinks/2020/03/verilys-covid-19-screening-website-leaves-privacy-questions-unanswered

From feeds:

Fair Use Tracker » Deeplinks
CLS / ROC » Deeplinks

Tags:

medical

Authors:

Gennie Gebhart

Date tagged:

03/25/2020, 13:19

Date published:

03/25/2020, 12:12