What is Protected Health Information?

Many laws and regulations impact health information—not just the Health Information Portability and Accountability Act (HIPAA).

But what IS Protected Health Information?

Kirk Nahra and Daniel Solove shared this example in a webinar:

Is “I drink Diet Coke” health information?

  • Maybe it’s not health information at all.
  • Maybe it indicates healthy practices (no sugar).
  • Maybe it indicates unhealthy practices (artificial sweetener use).

The answer isn’t simple.

Comply with Privacy Requirements (4/7)

This is the fourth of seven vendor suggestions I made in my Biometric Update guest post.

“Comply with all privacy laws and regulations. This should be a given, but sometimes vendors are lax in this area. If your firm violates the law, and you are caught, you will literally pay the price.”

Ask companies doing business in the GDPR region, Illinois, Texas, and elsewhere how hefty those fines could be. Meta alone has received billions of dollars of fines in Ireland (EU) and over a billion dollars in Texas.

(Imagen 3)

Video Analytics is Nothing New or Special

There is nothing new under the sun, despite the MIT Technology Review’s trumpeting of the “new way” to track people. 

The underlying article is gated, but here is what the public summary says:

“Police and federal agencies have found a controversial new way to skirt the growing patchwork of laws that curb how they use facial recognition: an AI model that can track people based on attributes like body size, gender, hair color and style, clothing, and accessories.

“The tool, called Track and built by the video analytics company Veritone, is used by 400 customers….”

Video analytics is nothing new. Viewing a picture of a particular backpack was a critical investigative lead after the Boston Marathon bombing. Two years later, I was adapting Morpho’s video analytics tool (now IDEMIA’s Augmented Vision) to U.S. use.

And it’s important to note that this is not strictly an IDENTIFICATION tool. Just because a tool finds someone with a particular body size, gender, hair color and style, clothing, and accessories means nothing. Hundreds of people may share those same attributes.

But when you combine them with an INDIVIDUALIZATION tool such as facial recognition…only then can you uniquely identify someone. (Augmented Vision can do this.)

And if facial recognition itself is only useful as an investigative lead…then video analytics without facial recognition is also only useful as an investigative lead.

Yawn.

(Imagen 3)

How to Isolate Your Unfocused Company

(StealthCo picture from Imagen 3)

So what are you doing, Jane?

“I’m a Scrum Master. Very busy.”

Who are you working for?

“I can’t tell you. We’re in stealth mode.”

When will you emerge?

“When we are ready to blow the world away.”

Um, how do you know that you will blow the world away?

“Our leader says so. And she knows what she’s talking about. She attended Stanford.”

But is anyone checking your assumptions?

“Of course. All 23 employees…forget I said that number.”

But what about your prospects? What are they saying?

“We know they will love it!”

Did they say they will love it?

“We know they will!”

What if the prospects learn about your stealth product and decide it sucks? And all the years you’ve spent developing in isolation are in vain because of a lack of true customer focus?

“That won’t happen. Our leader knows what she’s talking about. She founded one successful company, and uses that experience to guide us remotely from Texas.”

Who is this leader?

“Elizabeth Holmes. Have you heard of her?”

Elizabeth Holmes picture public domain.

Ending the Isolation

There are potentially valid reasons for entering stealth mode, including protecting trade secrets and keeping the competition away. 

But…there is a risk if you also keep the prospects away from your stealth mode operations and fail to engage with them. Who knows—maybe your prospects might have some ideas of what they need, and that information might be good to know. Your unicorn rockstar fearless dear leader may not know EVERYTHING.

If you want to work out a strategy for getting prospects engaged, let me ask you a few questions. Book a free meeting at https://bredemarket.com/cpa/

Store the Minimum (3/7)

This is the third of seven vendor suggestions I made in my Biometric Update guest post.

“Store only the minimum necessary personal information. If you don’t need to keep certain data, don’t store it. I’m sure our decentralized identity friends will agree with this.”

Take one such company, Anonybit.  Did you ever wonder how Anonybit got its name? Here’s what Anonybit does with biometric data after capture:

“Convert biometric into sharded, anonymized bits (“anonybits”)

“Distribute the “anonybits” throughout the multi-party cloud environment for storage, where they are kept and never retrieved or reassembled, even for matching”

(Imagen 3)

Collect the Minimum (2/7)

This is the second of seven vendor suggestions I made in my Biometric Update guest post.

“Collect only the minimum necessary personal information. If you don’t need certain data, don’t collect it. If it’s never collected, fraudster hackers can never steal it.”

Let’s pick on Workday. Job applicants know why. Workday’s default configuration (which many companies don’t change) is to require job applicants to set up an account with login and password.

But what happens to that data when—not if—Workday is hacked?  

(Imagen 3)

TSA PreCheck at Staples Via CLEAR (and IDEMIA)

I was wandering around my local (Upland, California) Staples on a Saturday afternoon. If I had arrived on a weekday, I could have applied for TSA PreCheck.

Only weekday hours, at least at the Staples on Mountain in Upland.

(No, I didn’t apply for TSA PreCheck in 2017 when MorphoTrak became part of MorphoTrust  (when IDEMIA was formed) and I became eligible for a corporate discount. I didn’t predict a pandemic. Oops.)

Now that IDEMIA is not the only game in town for TSA PreCheck, the competitors are trying to grab market share. Thus the alliance between CLEAR (and IDEMIA) and Staples.

Start at the kiosk.

It appears that you start enrollment at the kiosk, and then complete the process with a “Staples Travel Specialist.”

Incidentally, this Staples is in the same shopping center as an IDEMIA IdentoGO location.

Exercise Transparency (1/7)

Get ready for repurposing gone wild. This is the first of seven vendor suggestions I made in my Biometric Update guest post.

“Exercise transparency. Remember that some people are convinced that every piece of data collected by every biometric vendor is fed into a super-secret worldwide surveillance supercomputer maintained by shadowy forces. If you don’t educate your customers and their users on the truth—how data is shared, and how data is not shared—they will believe the lies.”

For example, many companies love to make money by selling your data. ID.me makes it very clear that it does not do this.

“ID.me will not sell, rent, or trade your Biometric Information, and after verification you may request we delete your Biometric Information.”

(Imagen 3)