| Cite as: 6 Nw. J. Tech. & Intell. Prop. 244, http://www.law.northwestern.edu/journals/njtip/v6/n3/1 | NJTIP Home > Volume 6 > Issue 3 (Summer 2008) |
A.Information CollectionIII.The Extant Legal Environment
B.Information Processing
C.Information Dissemination
D.Invasion
E.Self-Exposure
A.Statutory LawIV.Cyber-Patient's Bill of Rights and Responsibilities
B.Common Law
A.Rights of Cyber-PatientsV.Conclusion
B.Responsibilities of Cyber-Patients
¶ 1 Illness has long been the subject of denial, dread, and secrecy. Baring it reveals us at our most human and vulnerable. In a letter to a friend discussing his tuberculosis and hospitalization, Franz Kafka vented angst about his isolation and state of ignorance regarding his then-taboo condition. Although withdrawn by nature,1 he seemed to find comfort in sharing his treatment and experiences with a friend. Kafka wrote:
Dear Robert: Only medical matters—everything else is too involved, but my treatment—its only merit—delightfully simple. Against fever, liquid Pyramidon three times a day. . . . Against coughing, Demopon (unfortunately doesn't help). . . . Verbally I don't learn anything definite, since in discussing tuberculosis of the larynx everybody drops into a shy, evasive, glassy-eyed manner of speech. . . . Otherwise: A good room . . . [t]he place seems to be a great gossipers' nest from balcony to balcony; for the time being it doesn't bother me.2
Imagine Kafka today. Instead of a social outcast imprisoned in a sanitarium, Kafka would likely be online sharing his experiences with other cyber-patients on MyHealthSpace.com.3 On this hypothetical website, he might create a digital health profile, replete with pictures, details of his prognosis, medication lists, lab results, family medical history, and daily journals chronicling his emotions. Our imagined cyber-Kafka would certainly find information, solace, and support in his ability to socialize with healthcare providers and other patients around the world. However, like the captive Kafka above, cyber-Kafka would have to contend with the privacy implications of interacting in a virtual "great gossipers' nest." Unlike gossip from "balcony to balcony," gossip from bits to bits introduces a modern set of privacy gambles.
¶ 2 In recent years, online social networking websites like MySpace, Facebook, and Second Life have changed the way many people communicate, socialize, and memorialize their daily lives. "Online social networking" refers to websites whose main purpose is to act as a connector between users via self-generated web profiles or avatars that represent the user's identity in cyberspace.4 Online profiles are part diary, part autobiography, and part museum of the self.5 Often displaying personal information and photographs, online profiles interact with other profiles to create a rich web of social connections.
¶ 3 Some have proposed that social media is ideal for health care.6 Online health networking has been defined as "the use of social software and its ability to promote collaboration between patients, their caregivers, medical professionals, and other stakeholders in health."7 Like social network profiles, online health profiles operate as a vehicle for healthcare recordkeeping and communication. The perceived benefits of online health networking have caused a rapid growth in websites devoted to health. Websites like Revolution Health, Organized Wisdom, Patients Like Me, and Google Health are revolutionizing the way patients share their health information and personal experiences, learn about health conditions, add to the body of scientific data, and socialize with other patients.8
¶ 4 As idyllic as this all may sound, this new technology may not be as healthy as it seems. On online social forums, the reward is also the risk: socialization through disclosure. While online fora might offer patients the comfort of a like-minded cohort, patients early to adopt the technology may be bartering their privacy with no legal or normative infrastructure to protect them. What if an employee of the website divulges a user's diagnosis to a newspaper, which publishes it to the world? What if another MyHealthSpace user tells the cyber-patient's employer of his condition? What if the cyber-patient's family members disapprove of online disclosure? What if the website goes out of business or expels the cyber-patient, and all of his health information is lost? What if the website sells the cyber-patient's medical identity to marketers or commercial data brokers?
¶ 5 Much ink is currently being devoted to analyzing the introduction of electronic or patient-controlled personal health records ("PHR") in the provision of health care.9 PHRs have been defined as "applications that enable individuals to collect, view, manage, or share their health information and conduct health-related transactions electronically."10 Tech behemoths Google and Microsoft have recently introduced PHR platforms.11 Governments around the world have begun hosting the online exchange of health information.12 Following this trend, the U.S. government has commenced design of a nationwide, interoperable platform for electronic health information, which is slated for completion in 2014.13
¶ 6 Although related, privacy concerns stemming from online health networking websites are distinct from those identified in the existing PHR privacy debate, which to date has focused squarely on the unregulated relationship between the website operator or Internet service provider ("ISP") and the patient-consumer.14 The many privacy risks posed by online health networking involve a complex web of real-life and cyber-relationships, questionable duties to the cyber-patient, and the technological capabilities to widely and permanently publish another's private information. Consequently, health networking privacy breaches can have several perpetrators: a malevolent blabbermouth, a mercenary web operator, a medical identity thief, or even an impulsive cyber-patient with a false sense of security.
¶ 7 By identifying the privacy challenges posed by online health networking and the areas of weakness in the law, this Article aims to evolve the legal and normative rubric governing privacy on this new techno-social medium. Section I begins by describing the phenomenon of online health networking and Section II posits its foreseeable challenges to personal privacy. Section III goes on to examine the extant legal infrastructure governing health privacy and queries whether this rubric properly protects privacy when translated to the online social arena. In light of the fact that the law is currently ill-equipped and norms are not yet established, it becomes necessary to formulate a stopgap solution. To that end, Section IV proposes a Cyber-Patient's Bill of Rights and Responsibilities. This "bill of rights" serves as a non-legal behavioral prescription for cyber-patients, website operators, and others. It begins to enumerate the multiple parties' duties to each other both on and offline. To date, no one has proposed a document governing relationships among cyber-patients interacting online and between these socializers and website operators. The Cyber-Patient's Bill of Rights and Responsibilities can therefore serve as a privacy imprimatur for cyber-patients, indicating a space where norms are defined and privacy is respected by all participating parties.
¶ 8 Throughout history and across cultures, social networks have played a powerful role in influencing healthcare decisions, behavior, and even outcomes. Patient networks have provided advice, support, and counsel to the afflicted, due in large part to the accessibility, empathy, and willingness of participants to listen.15 Health support networks have been instrumental in the promotion of health practices and specific interventions (such as breast cancer screening16 and substance abuse referrals17). Social networks can also influence health-related behavior and mortality rates. Studies have shown individuals are much more likely to successfully quit smoking18 or become obese19 if their networks propagate these behaviors. A wide body of research also indicates that a supportive social network improves health outcomes for patients with a range of conditions, including postpartum depression20 and heart failure.21
¶ 9 Today, the Internet has broadened the definition of community and social networks. Patients can now communicate with each other without regard for geography or proximity. Social media devoted to health has multiplied to include wikis, blogs, video-sharing, online forums, podcasts, and, of course, online social networks. Online social networks, such as MySpace and Facebook, invite users to participate in "groups," or public fora for people with similar interests to meet and interact.22 As of August 2008, MySpace alone hosted 31,684 health-related groups.23 The popularity of the social networking platform has also given rise to dedicated online health networks. PatientsLikeMe.com, for example, focuses on sharing health information for both emotional and research support.24 Statistical data detailing such things as common symptoms, side effects, and drug dosages are generated from user-posted information. Users can then access the statistics, share advice, and receive feedback from other patients facing similar afflictions.25 Other websites are dedicated to communities with specific conditions26 or function as online support groups.27
¶ 10 Online health networks are capable of magnifying the proven benefits of physical-world networks for both patients and society in general. Cyber-patients can log in to read patient reviews on a medication or healthcare provider, glean information from others' experiences, and receive valuable decisional and emotional support.28 Social media technology also offers the ability to easily update friends and family regarding recovery, prognosis, or post-operative status while limiting invasive queries.29 Strong emotional support systems have been shown to have positive effects on recovery.30 Health networking can also record, contextualize, and enrich personal medical histories. By interfacing with family members and linking health profiles, a rich, clinically-useful medical history can emerge.
¶ 11 Online health networking facilitates public health interventions, education, and conversations in novel environments and to new audiences. With the lure of a familiar communication medium, social media is being used to engage groups previously unengaged in their health care, such as teenagers.31 The promise of anonymity on computer-based interfaces can promote open discussions about health status, behavioral risks, and fears while avoiding embarrassment.32 One online health website acts as an authentication of the sexual health of potential sexual partners.33 Users authorize their healthcare providers to upload the negative results of tests for common sexually transmitted diseases and then grant access to partners wanting proof of a clean bill of health. Ongoing health conversations, such as those fostered by social media, have proven to improve overall health. A 2005 study concluded that publicity of a celebrity's breast cancer diagnosis increased the bookings for diagnostic mammograms and checkups in an "unprecedented" manner.34 As a result of more information and continued healthcare conversations provided by social networks, the public is better equipped to make healthcare decisions and consider their implications.
¶ 12 However enticing its benefits, online health networking can also pose significant challenges to personal privacy.35 Health information reveals the most sensitive and intimate details of a person's life, such as psychological and sexual histories and private habits. Consequently, health privacy breaches have the potential to cause great harm with far-reaching effects ranging from loss of employment or insurance coverage to shame and stress that can further affect health. In fear of the possible repercussions of disclosures to unwanted audiences, privacy-wary patients may abstain from communicating via online health networks, thereby foregoing the many emotional and psychosocial benefits the medium may offer.
¶ 13 It is important to classify networking privacy breaches to grasp the technology, the reach of current privacy law, and whether legal redress is available or appropriate for each. Daniel Solove, noted privacy scholar, aptly defined and classified modern privacy violations in a coherent framework, which this Article borrows to understand the privacy concerns posed by online health networking. Professor Solove describes four general categories: (1) Information Collection; (2) Information Processing; (3) Information Dissemination; and (4) Invasion.36 To these we add a fifth category indigenous to online networking: Self-exposure.
¶ 14 Information collection refers to the process of data gathering and can include surveillance, interrogation, or recording of an individual's activities.37 It can be open or covert. It can occur in a private place or in public. On the Internet today, data gathering is the rule of the road. Internet users leave a trail of breadcrumbs with every mouse-click that forms part of their digital dossier. Many companies have volumes of personal information based on a recording of an individual's search patterns, personal preferences, and other online activity like emails.38 For example, targeted advertising logs an individual's searches, clicks, and transactions to deliver ads of interest to the individual. When the practice is clear and consented to, targeted advertising may provide convenience and a comforting sense of familiarity to consumers. However, internet users currently have limited bargaining power to stop it, and little understanding or sense of its magnitude.39
¶ 15 Health information collection aggravates the potential for ensuing harm. Compare the consequences of capturing an individual's interest in spy novels versus his Viagra prescription or other medication from which a health condition can (correctly or incorrectly) be inferred. One report chronicled a woman's shock when she was barraged with ads for healthcare products after discussing her grandmother's recent death in a private email to her mother.40 An advertising industry initiative has proposed guidelines for health-related behavioral targeting ads. In an awkward move to define topics properly designated as private, the proposal identifies certain health conditions and personal information deemed off-limits to ad targeting systems. These include cancer and psychiatric, sexual, and abortion-related conditions. Age, addictions, disability, marital status, pregnancy, beliefs, and affiliations are secondary topics the collection of which is left up to the discretion of the individual advertisers.41
¶ 16 Information processing describes the use, storage, and manipulation of collected data.42 The category includes aggregation of information originally disclosed in multiple places, identifying an individual, secondary use, and exclusion. All of these identified harms are relevant in the health networking context.
¶ 17 First, aggregation is the bringing together of random pixels of personal information from multiple sources to paint what is often interpreted as a complete portrait of an individual. This necessarily involves removing each bit of previously-disclosed information from its original context, thus distorting the resulting image of the person. An overly simplistic caricature of an individual can result in dignitary and other harms and create a chilling effect. The controversy surrounding Robert Bork's video rentals is an early example of aggregation.43 During his Supreme Court nomination hearings in 1988, Judge Bork's video rental log was obtained by a newspaper with the purpose of extrapolating conclusions on his personal views, tastes, and morals. The resultant public outcry prompted Congress to pass the Video Privacy Protection Act,44 which prohibits video rental companies from disclosing their clients' viewing preferences.
¶ 18 Today, anyone online can be Robert Bork, leaving clues to personal intellectual activity, interests, and beliefs scattered throughout cyberspace for any two-bit detective to unearth. As the reach of search engines expands and the data banks collected by separate websites coalesce, millions of people will gain access and draw inferences about an individual from the digital breadcrumbs disclosed on online networks. The potential risks for health-related information are obvious. As a Web pioneer recently quipped, "I want to know if I look up a whole lot of books about some form of cancer that that's not going to get to my insurance company and I'm going to find my insurance premium is going to go up by 5% because they've figured I'm looking at those books."45
¶ 19 A privacy violation can also occur by identification, connecting an individual's identity to information about him. Social networking websites allow users to use a pseudonym when interacting online. Some privacy-conscious internet companies are vowing only to sell or disclose de-identified user data, or non-personally identifiable information.46 True anonymity, however, is an illusion and identification is not especially difficult, whether through use of the legal system or enterprising investigation. Website operators hold the key that connects the user to the information posted, either by tracking an Internet Protocol (IP) address or via login information. In a well-publicized civil copyright infringement case against YouTube, a court recently ordered the defendant to turn over its users' activity records, including their usernames and IP addresses, along with a detailed log of every video viewed.47 This precedent opens the floodgates of the disclosure of networking user information. Under the court's reasoning, social networking websites such as YouTube may be compelled to disclose their users' screen names, computer locations, and public online activities, such as participation on public forums.
¶ 20 Even without a court order, fellow users and others can fairly easily reverse engineer online identities to disclose real-world personae.48 In 2006, AOL released de-identified records of inquiries conducted through its search engine for academic research. Somehow, the records were released to the media and a reporter was able to figure out the identity of some of the users from the search records. The reporter contacted one user, who verified the information was hers and expressed concern that others might draw inferences from her searches for information on "bi-polar disorder."49
¶ 21 A secondary use breach occurs when information disclosed is used for purposes other than those originally intended by the user. For example, personal information and online viewing habits a user "makes public" to strengthen friendship ties may be sold to marketers or commercial data brokers by the ISP or website operator.
¶ 22 Personal health information disclosed on online health networking websites is at great risk for illicit transfer or sale, especially in light of its relative inaccessibility and its value to marketers. In response to market wariness, some online PHR providers have committed to not use patient information for commercial purposes50 and to prohibit advertising banners on health profiles.51 With most websites offering health networking services at no cost, it is unsettlingly unclear how these commercial ventures stand to make a profit in the absence of such commercialization. It remains to be seen how such commercial endeavors will thrive, if these promises are sustainable and legally enforceable, and whether cyber-patients will place their trust in these host corporations.
¶ 23 Exclusion is the failure to grant an individual's right to access his record and ensure its accuracy.52 Many privacy laws, including the Privacy Act53 and the Fair Credit Reporting Act,54 protect individuals from exclusion by mandating transparency and granting access to records.
¶ 24 Online health networking, however, is free from any such regulation. Online networking websites grant users limited rights and little control over their individual profiles. While website operators usually claim no ownership or intellectual property rights over the information contained in a user's profile,55 the websites' ability to delete user profiles and restrict their transferability to a competing networking website is tantamount to exercising proprietary and monopolistic control.
¶ 25 Many terms of use expressly grant the website operators authority to disable user accounts for any or no reason, and to delete all user information from the website without prior notice.56 Participants in interactive websites who invest a substantial amount of time and money creating content on their profiles in reliance on a website's indefinite service are understandably flabbergasted when expelled from a website without reason, explanation, or recourse.57 This is especially true since most enforcement of terms of use seems arbitrary to website users, monitoring for violations of terms of use is rare, and examples of flagrant violations abundant.
¶ 26 Disabling an individual's profile often occurs without notice or an opportunity to appeal. Generally, operators can delete a person's account upon mere suspicion of wrongdoing and with little evidence. The websites are not required to disclose the reasons for deletion and do not have to grant a meaningful right of appeal.58 In fact, most online networking websites have no procedures for reinstatement.59 One recent case illustrates this tension. A music group's MySpace page, its main outlet for promotion and fan interaction, was taken down without notice, in effect erasing the band from existence.60
¶ 27 Unchecked member terminations may have serious repercussions when translated to the online health networking context. Losing access to one's online health profile can lead to erroneous diagnoses, loss of irreplaceable time in combating illness, and other more serious treatment issues. A breaching cyber-patient stands to lose his health record and support group, a devastating and disorienting proposition. PatientsLikeMe, for example, explicitly disclaims responsibility for the loss of information contained in a deleted health profile while establishing that a patient's membership may be terminated "with or without cause" and without prior notice.61
¶ 28 On the flip side, users wishing to permanently delete their networking profiles find it almost impossible to remove information linked to their profile such as tagged pictures, public comments on other profiles, and, of course, anything that has been sent to others.62
¶ 29 Another modern privacy violation is information dissemination. Professor Solove lists two information dissemination sub-categories highly relevant to the online health networking context: disclosure and breach of confidentiality.
¶ 30 Disclosure harms occur when others (who are not necessarily in a confidential relationship with the aggrieved) disclose truthful but private information generally deemed offensive and not of legitimate public concern. In common parlance, this is "TMI": too much information. The problem intensifies and the consequences multiply in the online context, due to the larger, uncontrollable scope of the audience and the permanence and searchability of digital information. Networking websites pose interesting disclosure risks of their own. In online social forums, personal information is the currency of choice. Its unfettered exchange exposes it to the high risk of reaching unintended audiences.
¶ 31 Indisputably, the unwarranted disclosure of health information can lead to embarrassment and shame. More concretely, the revelation of health information can lead to discrimination, the loss of insurance or employment, the denial of a mortgage, or the use of information as evidence in child custody disputes or personal injury lawsuits.63 News media stories abound regarding improper disclosures of personal health information to an incalculable number of other people. Eli Lilly released the names of all subscribers to its Prozac information website.64 Individuals in Florida taking Prozac daily received a free sample of Prozac Weekly in the mail, courtesy of the drug company and a local drug store, alerting everyone from family members to the mail carrier about their medical treatment.65
¶ 32 Online revelations are particularly troubling when they affect a third party who has not assumed the risk of interacting or disclosing online. An individual's health record reveals private information regarding family members' health or medical conditions. Last year, Nobel laureate James D. Watson became the first individual to publish his sequenced personal genome on a website.66 The genome reveals risks for genetically-linked diseases such as cancer and Alzheimer's disease and other serious conditions. This has obvious implications for family members who may not have consented to the public disclosure of their genetic propensities.67
¶ 33 Publishing health information without the consent of all affected parties poses serious medical and ethical concerns, and may also be a breach of confidentiality. When parties have a special relationship of trust or make an explicit promise, the law recognizes an obligation of confidentiality.68 In addition to the disclosure's inherent harm, a breach of confidentiality violates trust, causes damage to the relationship, and reduces the likelihood its victim will share again.
¶ 34 The online social networking environment has brought about a sweeping change in its users' notions of intimacy, friendship, and confidentiality.69 It eases the costs of communication and transforms friendship into a collecting hobby.70 The very definition of friendship and its ensuing obligations are increasingly unclear on online social media. Consequently, the level of confidentiality users expect is almost impossible to assess without explicit requests or privacy settings.
¶ 35 The existing privacy settings implemented by popular social networking websites are insufficient in the health networking context. These allow users to select one setting for their entire profile—public or private.71 Health information sensitivity is much more nuanced. A cyber-patient may feel comfortable with his urologist knowing he takes Viagra, but prefer to keep that information from his dermatologist and online cancer support group.
¶ 36 Invasion is an intrusion into a private sphere, be it spatial (a hotel room or a bedroom) or intangible (one's private affairs or checking account). The mere existence of networked health information poses an increased risk of this type of privacy harm. In the online networking context, an intruder might spy or hack into another's private networking profile or otherwise access information not meant for his eyes. The digital environment lends itself to additional intrusions by corporate interests, employers, or other unwanted audiences. Sockpuppeting, for example, is the "act of creating a fake online identity to praise, defend, or create the illusion of support for one's self, allies, or company."72 In addition to intrusion, this practice involves deceit, often by omission ("did I fail to mention I'm the CEO of the company I'm touting?"). Generally, online networks do not offer mechanisms to verify a member's identity or sub-rosa agenda.73 Uncovering sockpuppets requires a delicate balancing between the poster's right to anonymity and the other members' right to be free from invasion or deceit.
¶ 37 Similarly, nosy employers or insurance companies might discover information that influences important decisions based on a person's genetic predisposition family medical history, or behavior. Other uninvited audiences such as pranksters could wreak havoc on a health networking website by posting erroneous or misleading content, leading fellow users to experience unnecessary anxiety or even death.
¶ 38 A new category of privacy-related harm in the social networking context is caused by the over-disclosing user.74 In other words, people violate their own privacy via facilitating technologies. More than 90% of teenagers are online.75 Of those, over half participate in online social networking.76 Media reports detailing the privacy-noxious behavior of teens with technology abound.77 However, less than half of teens who post regularly on networking websites restrict access to their photographs and videos.78
¶ 39 Under a comforting illusion of safety, an over-disclosing user might upload or share information without regard for the digital information's transferability, malleability, and permanence. These users, most often minors, share more than they would in the physical world—posting information and pictures that eventually embarrass or haunt them and others.79 The sensitive information can then be accessed by unanticipated audiences, including employers, neighbors, and others who deal in real world consequences. Such seemingly self-inflicted harms can have dire implications with respect to personal safety and reputation.
¶ 40 Fault for these privacy harms has been uniformly attributed to the users themselves.80 After all, the argument goes: online, a fool and his privacy are soon parted. Yet the problem of self-exposure may not be so unilateral. It is well documented that the pre-frontal cortex area of the brain, the area controlling reasoning, logic, impulse control, and judgment, is less developed in adolescents and may only mature around age 25.81 The underdevelopment of the brain's risk assessment in teenagers may account for the fact that they simultaneously want privacy but fail to take affirmative steps to safeguard it.
¶ 41 The implications in health networking are unmistakable. A teenager disclosing her health information online may not be concerned by its dissemination, or even expect it to be private. She may not be able to envision the future consequences the information may have on her employment opportunities, medical insurance, and reputation. If some users are divulging under mistaken expectations of privacy (biological or otherwise), whose responsibility is it to educate them?
¶ 42 Despite numerous national and international warnings about online social networking websites,82 the websites have not been active in protecting the privacy of their users and others. While the websites' terms of use generally prohibit invasions of privacy and other tortious conduct, users are not likely to read or understand these policies.83 Further, there are virtually no mechanisms by which to solve user disputes and inadequate monitoring of website terms.
¶ 43 Health networking technologies have the potential to upend healthcare relationships between patients and physicians, hospitals, health plans, and pharmaceutical companies and be a transformative vehicle for health care. Yet questions about privacy on these networks loom. A patchwork of federal and state statutes, common law, and private contracts protect privacy interests in the United States.
¶ 44 The Electronic Computer Privacy Act of 1986, the Children's Online Privacy Protection Act of 1998, and the Health Insurance Portability and Accountability Act of 1996 are three federal statutes that may address burgeoning issues in the area of online health networking. The year associated with each betrays a tenuous applicability to social media. Congress could not have foreseen the reach of social networking and the panoply of modern privacy challenges that would ensue. Any applicability of these laws in the health networking context is incidental to their ambit and original purpose.
¶ 45 The Electronic Communications Privacy Act of 1986 84 ("ECPA"), an extension of the 1968 Wiretap Act,85 prohibits the interception and knowing or intentional disclosure of information transmitted or stored by a wire, radio, electromagnetic, photoelectric, or photooptical system.86 It applies to actions by law enforcement and other governmental agencies, as well as public and private employers.87 The statute covers any communication by a person who exhibits a reasonable expectation that the communication is not subject to interception.88 The ECPA imposes criminal liability and creates a civil remedy, permitting the aggrieved to sue for declaratory relief, injunctive relief, damages, plus reasonable attorneys' fees.89
¶ 46 Accordingly, the ECPA seems to prohibit entities such as social networking websites from knowingly divulging the contents of any private electronic communication or posting. The exact confines of the prohibition, however, are dictated by the extent to which the user's behavior evinces a reasonable expectation of privacy. ECPA prohibitions do not apply to conduct authorized by the service provider or user. [90] Moreover, the statute's legislative history states that "a subscriber who places a communication on a computer 'electronic bulletin board,' with a reasonable basis for knowing that such communications are freely made available to the public, should be considered to have given consent to the disclosure or use of the communication."91
¶ 47 The ECPA only bars disclosure of the content of private communications. In other words, non-content information is fair game. For example, a transcript of a cyber-patient's posting on a private online support group may be protected, but not the fact the cyber-patient participated in an HIV support group. Given the abilities discussed above to aggregate and reverse engineer identity, the ECPA provides very little solace or redress for an aggrieved cyber-patient. Whether content or non-content information is disclosed, a health networker's privacy would be similarly compromised.
¶ 48 The Children's Online Privacy Protection Act of 199892 ("COPPA") requires commercial websites to meet heightened privacy requirements when hosting children. The statute mandates prior parental consent before information can be collected from children under the age of thirteen. It also requires that websites interacting with minors have a privacy policy disclosing information-collection practices (including types of personal information collected, how it will be used, etc.) and provide a contact at the website.93 Subject to certain exceptions, a website must obtain parental consent before collecting, using, or disclosing personal information about a child under thirteen.94
¶ 49 While COPPA is the strongest consumer privacy law, its effectiveness in the social networking arena is limited. The statute only protects minors under thirteen, leaving the great majority of social networking teens to fend for themselves. Moreover, COPPA protects the child-user from predatory practices originating with the ISP or website operator, not from any other privacy violators.
¶ 50 The Health Insurance Portability and Accountability Act of 1996 ("HIPAA") is fundamental to any discussion of health privacy.95 Crafted in anticipation of electronic medical record technology, HIPAA acknowledges the need to protect patients from privacy violations at the hands of their health care providers. In the event of a healthcare-related privacy breach, patients might revert to privacy-protective behavior, such as giving inaccurate information in their medical history, or not seeking healthcare in the first place, thus affecting the quality of care and even personal wellbeing.96 HIPAA addresses the potential fallout of health privacy harms by establishing a framework of duties among healthcare providers.
¶ 51 HIPAA is the most comprehensive piece of federal legislation governing privacy.97 Adopted in 2002, HIPAA's Privacy Rule was designed to protect personally identifiable health information ("PHI") in an increasingly electronic medical record environment. Essentially, HIPAA addresses the retention, storage, transmission and exchange of PHI, defined as anything related to the "past, present, or future physical or mental health condition" in "any form or medium."98 Medical records (both paper and electronic), personal communications, and electronic communications (email and faxes) are all subject to HIPAA's requirements.99
¶ 52 HIPAA's Privacy Rule requires certain entities to obtain patient authorization before sharing PHI. These covered entities include: (1) healthcare providers (doctors, nurses, pharmacists); (2) healthcare facilities (hospitals, clinics, stand-alone healthcare facilities); (3) health plans (HMOs, insurers, Medicare/Medicaid); and (4) health information clearinghouses (billing services, community health information systems).100 As repositories of health information, these entities must take the necessary steps to ensure that access, use, and disclosure of PHI are handled appropriately.101 Although only these particular entities are subject to HIPAA standards, each covered entity must assure that its business associates—from transcribing to cleaning services—protect patient information. Patients also have the right to request that covered agencies reveal all parties who have seen the record for any reason other than treatment, payment, or healthcare operations.102
¶ 53 HIPAA's privacy protections are not particularly stringent. Violations of HIPAA may result in anemic civil fines of up to $100 per violation.103 Criminal indictments under HIPAA, for which the Department of Justice has exhibited a recent interest, still number fewer than ten.104 All covered entities may see a patient's health information if the purpose is connected to treatment, payment, and healthcare operations; there is no explicit restriction of a "need to know" or other reasonable limit.105 Others may obtain access under expansive interpretations of the regulations. For example, certain institutions have interpreted the regulations to allow patient information such as names, addresses, and dates of treatment to be disclosed without authorization to business associates for fundraising purposes.106 Further, covered entities are authorized, and sometimes obligated, to disclose certain health information without the patient's permission; these exceptions arise in the context of promoting certain "public health activities" including research and reporting disease, "public health surveillance [and] public health investigations."107
¶ 54 HIPAA's privacy protections also present procedural problems. HIPAA does not preempt more stringent state laws governing the privacy of health information.108 This often leads to confusion and compliance problems for business.109 Some speculate that the lack of a private right of action for aggrieved patients leads to a degree of insouciance by covered entities.110 Further, covered entities and patients themselves are confused about the exact parameters of the privacy requirements.111
¶ 55 As weak as HIPAA's privacy protection may be, the statute has heightened institutional awareness of patient rights and generated a degree of respect where little existed.112 While no private right of enforcement exists, healthcare providers and institutions are mindful that a legal duty of care exists, one that theoretically could be privately enforced on a negligence theory.113 While initial attempts have not been particularly successful114, the heightened concern for privacy of health information may herald a new judicial sensibility in this regard.115
¶ 56 Questions regarding the reach of HIPAA to networking websites remain largely unexplored.116 As with most privacy laws, HIPAA duties are premised on relationships. As such, it is necessary to analyze each health networking party's role and relationship with the cyber-patient to determine its ensuing HIPAA duties, if any.
¶ 57 The most common health networking host is commercial: a for-profit entity provides a platform and applications for user-generated content. These entities promise to hold patient information and provide a forum for patient-authorized exchange. Commercial health networking providers are most likely not subject to HIPAA.117 HIPAA could only apply if a network host were to be acting as a "clearinghouse." An online health network may be functioning as a health information clearinghouse if any of the sources or destinations of networked information is a covered entity, such as a physician or a pharmacy.118 Despite these creative arguments, health network ISPs seem to be the square peg to HIPAA's round hole. As such, scholars agree: health records maintained on an online health network can be more easily leaked, sold, subpoenaed, or otherwise misused.119
¶ 58 Healthcare providers and insurance companies are also incorporating social media into the provision and management of health care. One prominent insurer has launched a healthcare community in Second Life, a virtual world where users interface with self-styled avatars.120 At least one hospital has launched a fully interactive social network, allowing for patient-controlled information exchange with clinical care providers, researchers, public health authorities, and other patients.121 Such health networking websites controlled by doctors, insurers, or other health care providers would come under HIPAA's purview, as one would assume the patient has authorized the use and retention of the information as part of an established health care relationship.
¶ 59 Many privacy breaches on social media occur at the mouse-clicks of fellow cyber-patients or are facilitated by the patients themselves. Individuals, however, are not covered entities under HIPAA. Health information under a patient's control falls outside of HIPAA's ambit. For example, health information stored by a patient on an online health profile—or even a personal filing cabinet — has no claim to privacy.122 Similarly, health information shared with friends or family members is not protected.
¶ 60 As a practical matter, the common law legal system is ill-suited to provide redress to the online networker. As with any lawsuit, bringing a case to court is costly and time consuming.123 Suing for a privacy breach is often counter-productive, as it would definitely bring more unwanted attention to the damaging information and incorporate it into the public record.124 One British case aptly illustrates this point. Max Mosley, a well-known figure in international auto racing, sued British tabloids for intrusion after they unearthed his penchant for Nazi-themed sadomasochism.125 At public trial, Mr. Mosley was forced to recount the particulars and details of his fetish, as well as its effect on his health and family life.
¶ 61 In a privacy tort case, monetary damages are hard to prove, as they commonly involve unquantifiable injury to reputation and dignity. Remedies in equity such as injunction are unavailable. Further, jurisdictional issues may stymie a suit.
¶ 62 Even if a victim wanted to pursue a legal claim, there may be no one to sue. Often, the identity of the perpetrator is difficult to determine, since many online networkers operate with pseudonyms that can only be deciphered by the website operator via subpoena.126 Victims of online privacy torts such as defamation or disclosure of private facts cannot obtain legal redress from the websites themselves. Section 230 of the Communications Decency Act of 1996 shields ISPs and other service providers from torts, including defamation or other injurious publication, committed by their users, unless the provider fails to take action after actual notice or has itself played an active role in developing the harmful content.127 Courts have reinforced the applicability of Section 230 in the social networking context.128
¶ 63 Few legal rules protect the privacy of voluntarily disclosed health information. In the event privacy breaches were to occur, the aggrieved would likely be forced to rely on the state common law of privacy, whose applicability in the health networking context is questionable.
¶ 64 Substantively, tort law is no more comforting to the unwittingly exposed. Traditional privacy torts address traditional harms. The American Law Institute's Restatement (Second) of Torts129 forms the well-accepted foundation of state privacy law in virtually every jurisdiction in the U.S. The Restatement only addresses those harms occurring in four ways—by intruding on the victim's private space ("Intrusion"), using his likeness in a commercial context ("Appropriation"), placing him in a false light in the public eye ("False Light"), or disclosing his secrets ("Public Disclosure").130 Intrusion applies when information is uncovered in a furtive way from a place within which the victim has a reasonable expectation of privacy, such as a home or a hotel room.131 The tort also clearly encompasses the activities of high tech Peeping Toms, as it covers unwarranted sensory intrusions like eavesdropping, wiretapping, and visual or photographic spying.132 Appropriation focuses on the unpermitted commercial use of a person's identity.133 The tort of False Light addresses the publication of information that casts a person in a false light.134 Finally, Public Disclosure applies when the plaintiff's private facts are publicly disclosed by the defendant in an unsanctioned manner. The tort requires the plaintiff to show that the defendant gave publicity to a private fact that is not of legitimate concern to the public, where such disclosure is highly offensive to a reasonable person.135 It has traditionally been relied upon by patients who suffered from the unwarranted disclosure of their sensitive health information by third parties, such as newspapers or other media outlets.
¶ 65 The most common privacy harms in the online health networking context are those addressed by the torts of Intrusion and Public Disclosure, although neither tort has been successfully applied to activities occurring on online social networks. As such, in the world of online social media, privacy torts have become an anachronism. As evidenced by the lack of online privacy tort jurisprudence, the privacy panorama has changed and the harms enumerated above no longer fit the Restatement's stale rubric. Even when available to a plaintiff, these rights of action are severely debilitated by the nature of the online forum and the information breached.
¶ 66 The weakness of privacy torts online is due to a blurring of what is private, public, shameful, and newsworthy in an exposed online social world. The success of a privacy tort claim hinges on an assessment of the reasonableness of the victim's expectation of privacy in the space invaded or information disclosed. This determination is highly dependent on the nature of the space, the circumstances surrounding the information and its intrusion, the relationship between the parties, the technology, and the prevailing social norms.136 In general, the law does not protect privacy in public or publicly-accessible places, even when the information whose protection is sought is sensitive in nature.137 For example, one court examined whether patients who were videotaped while receiving emergency medical treatment had a legitimate expectation of privacy.138 Their images were broadcast without their consent on a television show called "Trauma: Life in the ER."139 The court dismissed the patients' privacy claim because the medical treatment was "open to public observation."140 As such, the common law does not recognize an individual's per se right to privacy in his medical information.
¶ 67 As a general rule, if information has been voluntarily disclosed by a patient to anyone in a non-fiduciary capacity or is publicly available somewhere, it is no longer deemed "private" and therefore privacy torts do not apply.141 This is fatal to any online privacy claim. For example, if a person has a skin disease that is immediately visible to anyone that sees him, tort law may not protect a subsequent disclosure of the particulars of the condition. Similarly, health information voluntarily disclosed by a cyber-patient to an online support group is not likely to be protected from subsequent dissemination to his employer or any other unwanted audience.
¶ 68 For a Public Disclosure claim to succeed, the information disclosed must also be shameful. Courts have widely acknowledged that Public Disclosure only protects health information when it consists of "unpleasant or disgraceful or humiliating illnesses"142 or "hidden physical or psychiatric problems."143 This significantly limits the privacy protection granted to health information. Courts have sustained Public Disclosure suits for the publication of such health information such as an unusual disease,144 a sexually-transmitted disease,145 a mastectomy,146 fertility treatments,147 and plastic surgery.148
¶ 69 Finally, to succeed on a privacy tort claim, the disclosed information must not be of public concern. If the health information disclosed is newsworthy or of public concern, the aggrieved is precluded from recovery in tort, as such recovery is preempted by the formidable First Amendment.149 Courts have held a wide range of information to be newsworthy. In Shulman v. Group W Productions, Inc.,150 for example, plaintiffs were non-public figures who were involved in a near-fatal car accident. A camera crew filmed plaintiffs' extrication from the car and their transport to the hospital in the helicopter and recorded the flight nurse's conversations with one of the injured plaintiffs. This videotape and sound track were then broadcast on a documentary television show without the plaintiffs' consent. Weighing whether the filming and subsequent disclosure was an infringement on their privacy rights, the California Supreme Court concluded the broadcast was of legitimate public concern and their appearance in it bore a "logical relationship to the newsworthy subject of the broadcast."151 Other examples of health information held to be newsworthy include a non-public figure's HIV-positive status as it related to a publicized malpractice lawsuit,152 a woman's rape,153 and an individual's unwanted sterilization.154
¶ 70 It has been established that health information is not protected by privacy torts if it is not inherently shameful, has been previously disclosed, or is newsworthy. Given the narrow interpretation of privacy torts and the nature of the Internet, the probability of a successful lawsuit in tort is remote.
¶ 71 In the wake of tort law's frailty, some have advocated turning to contract law to better shape the expectations and behavior of parties to confidential information.155 While a suit in tort may reward the plaintiff for the foreseeable damages, emotional or otherwise, contract law may offer parties the ability of quieting the purported busybody. Unlike tort law, contract law offers injunctive relief to avoid ongoing harm.156
¶ 72 The terms of use of most online networking websites create a legal relationship between the service provider and its members and define the website's rules.157 Privacy policies act as a warranty on the website's use and disclosure of user information. The enforceability of these agreements is dependent on whether their terms meet the classic requirements of a binding contract or are unconscionable or a violation of public policy. To date, these contracts are largely unregulated.
¶ 73 Using such contractual vehicles as privacy protectors raises several issues. The first is the difficulty of informed consent online.158 Of course, consent validates a privacy breach; but, what of informed consent? The general lack of comprehensibility and user-friendliness of the terms of use makes informed consent burdensome and exasperating for the average website visitor.159 As evidenced by numerous surveys, the majority of website users does not understand, access, or know the significance of privacy policies and terms of use.160 Many user contracts are written abstrusely or in a legalistic style, dissuading even the most punctilious consumer from taking time out of her online pursuit to carefully read and understand them. This issue is exacerbated when the user is a minor. Further, terms of use and privacy policies vary from website to website, making true understanding of each contract more difficult and impracticable, especially since most users visit several websites a day.
¶ 74 Website contracts are built on shifting sands. The professed ability of many operators to change terms of use at any moment and without prior notice leaves users in a constant state of uncertainty about their rights and privacy expectations. According to a Federal Trade Commission report, "[w]ebsites rarely provide information about when the current policies were created or updated and, if updated, exactly what changes were made. . . . They tell consumers that the policies will likely change and instruct them to check back frequently."161 Such tactics put the privacy burden on users, who would need to closely compare previous (and now unavailable) versions of the agreement with the new one to assess the changes made and their probable impact.162 Most health networking websites adopt this widespread practice.163
¶ 75 Confusing and misleading terms of use and privacy policies are beginning to catch the attention of the FTC, the states' attorneys general, and other government enforcers. The New York attorney general accused Facebook of fraud for failing to live up to the representation of a "trusted environment for people to interact safely."164 The attorney general of New Jersey is investigating another online social network because its terms of use state it may remove offensive content that is abusive, obscene, or an invasion of privacy, but the website lacks the tools to report or dispute this material.165
¶ 76 Spotty enforcement and a lack of mechanisms for dispute resolution further weaken the power of contract law online. A contract is only as good as its observation and enforcement. Social websites generally have no system of dispute resolution processes for disputes between users and no mechanism for appeal or defense from social network banishment. Defamation and privacy breaches are common occurrences in social media, surely exacerbated by users' perceived lack of accountability. Similarly, there are scant appropriate forums for airing disputes against the website itself. Case law seeking to enforce terms of use is practically nonexistent. The only likely recourse for a cyber-patient seeking redress against a misbehaving website is to seek action by the FTC or the states' attorneys general166 or under a private right of action under state unfair competition laws.
¶ 77 In the absence of trust and enforcement mechanisms, confidentiality agreements are the most reliable vehicles to protect the unwarranted disclosure of private health information.167 American courts have consistently upheld the principle of "freedom of contract," generally allowing contracting parties to strike any bargain they wish, including confidentiality agreements.168 These agreements have also been upheld against First Amendment challenges.169
¶ 78 Some scholars have argued that implied contracts of confidentiality can arise from romantic relationships or friendships.170 Members of online health social networking websites form relationships based on trust and intimacy. They divulge private information pertaining to their health and emotional state assuming it will not be disseminated outside their perceived confined network.
¶ 79 Online, express confidentiality agreements are a more tenable solution. Facilitated through available technology, confidentiality agreements between users could assure a higher level of protection for those sharing private and personal information. In some instances, confidentiality agreements have been offered through online health ISPs as a prerequisite to membership. PatientsLikeMe.com includes such a clause as part of its terms of use. It states:
You agree not to disclose to any person or entity personally identifiable information about other members that you learn using this Site (whether posted in the Member Area by a member or emailed to you by a member) without the express consent of such member. You may disclose information of a general nature (that could not identify the member who provided such information or whom such information is about) to third parties outside this Site, subject to the above restriction on non-commercial use.171
Confidentiality clauses could be both preventive and prescriptive. Clearly establishing the "rules of the road" between participating parties may deter disclosures before they occur as well as provide some redress after the damaging information is disseminated.
¶ 80 Start with what is right rather than what is acceptable.172
¶ 81 Given the awkwardness of the law in the social media context, one might conclude the only way of protecting privacy is to refrain from sharing personal information online. Rejecting such extreme measures, this Article sets out a framework of principles intended to provide a foundation for much-needed legislation or a meaningful self-regulatory system. Acknowledging the glacially slow pace of the legislative process vis-a-vis the dramatically nimble nature of the techno-social environment, it is necessary to articulate clear principles and recommendations to inform law, industry standards, and behavioral norms. To date, despite FTC recommendations for the enactment of stringent online privacy laws,173 legislators have been slow to respond to privacy concerns posed by health networking.174 Industry efforts to implement an effective self-regulatory system have failed.175 Certification systems granted by overseeing third parties have proven to be the most successful at increasing privacy compliance on the part of the service providers.176 But service providers are only one piece of the puzzle: cyber-patients must be held accountable for their actions regarding their personal information as well as that of others.
¶ 82 To that end, this Article proposes a Cyber-Patient's Bill of Rights and Responsibilities to systematically anticipate, address, and organize a set of norms and rules for the online health networking environment. This Bill of Rights and Responsibilities is predicated on a set of overarching principles supporting its legitimacy and credibility: (1) the balancing of paternalism and autonomy; (2) education and engagement of cyber-patients; (3) trust in the system, in technology, and in the community of users; and (4) a duty to respect other users.
¶ 83 Healthcare ethics has long understood the need to balance paternalism with patient autonomy. Education of health network users is necessary to achieve this balance, ergo the medical community's emphasis on information and consent. Trust in the social-media system—the websites, the underlying technology, and the community of users—is paramount to the spirit of the rights and responsibilities proposed below.
¶ 84 Finally, and perhaps most importantly, a duty to respect fellow users is fundamental in the world of online health networking. Cyber-patients often visit health networking websites in vulnerable states because of a medical condition. The responsibility of users to respect all fellow cyber-patients allows everyone to benefit from the use of the network without the additional burden of privacy concerns.
¶ 85 Building upon these basic principles, our Cyber-Patient's Bill of Rights and Responsibilities proposes to address the absence of law or "clear, consensus-based policies and practices"177 to protect user privacy. Currently, service providers and cyber-patients act within a "moral free space"178 regarding online health information. As described above, the online exchange of health information involves an unusual intersection of business, health, and private actors and results in a web of complex relationships and responsibilities. It thus becomes necessary to enumerate expectations, rights, and responsibilities.
¶ 86 Cyber-patients must have the right to the latest "systems for health information exchange [that] protect the integrity, security, and confidentiality of [their] information."179 Health networking providers must offer the latest technological resources to protect user information from being used, accessed, or divulged in an unwarranted manner. This includes a vow on the part of the websites to continuously update privacy-protection technology and applications in a commercially-reasonable fashion.
¶ 87 In the current landscape, the following are only some options to enhance the architecture of online health privacy:
Ensuring ISPs put forth best efforts to update and maintain a level of privacy protection enables cyber-patients to better control their information, thereby preventing aggregation, identification, and dissemination to unwanted parties.
¶ 88 Cyber-patients have the right to be educated before disclosing personal information online. They must have access to information regarding the technological medium and its capabilities, the website's privacy policies, and who has access to cyber-patient records, postings, and online activities.
¶ 89 Websites and cyber-patients can ensure informed consent while minimizing irrational privacy-protective behavior in the following ways:
Education raises cyber-patients' awareness to the potential harms associated with use of the network and empowers them to make sound, informed decisions regarding their privacy. Research indicates that the mere mention of privacy concerns predisposes individuals to be more cautious.180 This heightened level of awareness will minimize over-exposure, confidentiality breaches, and unwanted dissemination of information.
¶ 90 Once informed, individuals are in the best position to decide what information to disclose and to whom. Cyber-patients must have the right to control their information. This includes the ability to grant or deny access to their information. Moreover, cyber-patients must have a right to determine what information is private on a context-by-context basis.
¶ 91 Websites and cyber-patients can better control the disclosure of digital information to unwanted audiences in the following ways:
Providing cyber-patients the ability to disclose selective information to different audiences enables them to enjoy all the benefits of networking while reducing the risk of harms such as identification, aggregation, dissemination, and breach of confidentiality. It allows cyber-patients to be truthful without fearing self-exposure will have adverse consequences.
¶ 92 Cyber-patients must have the right to know exactly how their personal information is used, collected, and accessed. Further, they must know who else has access to it. This right encompasses the ability of the individual to inspect and modify their information and to obtain records of disclosures and authorizations.
¶ 93 Website operators and ISPs can strengthen the right to transparency in the following ways:
Transparency ensures that users are notified of any access, use, or breach of their health information by the website or third parties. This knowledge empowers cyber-patients to act promptly by altering privacy settings or abandoning the website, thereby limiting harms such as information collection, aggregation, and invasion.
¶ 94 Cyber-patients must have the right to access, alter, and delete any information pertaining to them. They must also have the right to easily transfer their profiles to another online health network.
¶ 95 The multiple parties involved can enable consumer choice and portability in the following ways:
Accessibility and portability minimize the risk of loss of health information stored on an online health profile. This right ensures control and retention of records for banished website users, former users of no longer existing websites, and users wishing to switch websites. This grants cyber-patients the liberty to leave a website that forces them to sacrifice certain privacy protections and increases their chances of becoming a victim of information collection, aggregation, identification, and dissemination.
¶ 96 Cyber-patients must have the right to be notified of, defend, and appeal any allegation or charge of conduct that could result in their removal from the website or loss of information contained therein. Cyber-patients must also have access to a trusted forum for dispute resolution.
¶ 97 Due process and dispute resolution can be established in the following ways:
Due process presents cyber-patients with an extra level of protection from exclusion. Allowing users to address accusations of wrongdoing and contest network expulsions is imperative. A proper dispute resolution system could limit harms resulting from the unwanted disclosure of information, identification, breach of confidentiality, and invasion. The mere existence of a dispute resolution system would certainly act as a deterrent to privacy-offending behavior.
¶ 98 Cyber-patients who are minors have a right to a heightened level of privacy protection on each of the foregoing enumerated rights. This right provides an additional shield of protection to a population especially vulnerable to the privacy harms of health networks. Minors are more likely to be the victims of online privacy harms due to their lacking full comprehension of the consequences of over-exposure online and overly-optimistic nature regarding risk. Both ISPs and caretakers should be charged with the duty to safeguard minors.
¶ 99 The following recommendations could begin to ensure a proper level of protection for minors on health networking websites:
These safeguards shield minors from over-exposure, identification, dissemination, and information collection.185
¶ 100 Cyber-patients must have the right to communicate anonymously, subject to certain limitations. By masking identity, cyber-patients can interact freely and confidently without fearing stigmatization.
¶ 101 The following tools should be implemented by ISPs to allow cyber-patients to post freely while respecting others:
The ability to maintain anonymity or pseudonymity are critical to a cyber-patient's free expression, but must be balanced against the rights of other cyber-patients to be free from harassment and fallacy. Anonymity minimizes the damages caused by identification, insecurity, and dissemination of information.
¶ 102 It is axiomatic that with every right comes a duty. Cyber-patients must be charged with responsibilities over their online privacy as follows.
¶ 103 Cyber-patients have a duty to understand the nature of the online setting and adjust expectations of privacy accordingly. Disclosure always involves risk. Armed with the rights of ISP transparency and informed consent, users must assume the following responsibilities:
Informed cyber-patients are more apt to act appropriately and avoid breaching other users' privacy, or even their own.
¶ 104 Cyber-patients have the duty of confidentiality to fellow patients. All information disclosed on health networking websites is privy and not to be divulged or otherwise disseminated. Users should not disclose any information obtained through the website unless specifically authorized. Similarly, disclosing cyber-patients should be as clear as possible regarding the level of confidentiality they expect. Cyber-patients have the duty to obtain the consent of family members and others whose health information they disclose. Relevant information regarding the health of family members is a vital part of a complete medical record. However, cyber-patients must understand these individuals also have rights to privacy in their health information. Cyber-patients must, therefore, obtain the informed consent of their family members before posting such information on the website.
¶ 105 Cyber-patients' responsibility to maintain the confidentiality of other users prevents various information dissemination harms.
¶ 106 Cyber-patients have the duty to refrain from using the health network illicitly. Commercial, political, and other hidden agendas can compromise the benefits of online health networks. Cyber-patients must restrict use of health networks to their intended and stated functions, and abstain from any activity deviating from the website's purpose.
¶ 107 Cyber-patients have the related duty to ensure good information on the network to the best of their abilities. Inaccurate health information can result in invasive physical, emotional, or financial harm to fellow cyber-patients.186 Cyber-patients should flag or question any posted information that they believe to be erroneous or misleading.
¶ 108 Primum, non nocere, or "first, do no harm,"187 is a governing precept for physicians, reminding them to weigh the possible harms of a medical intervention against the probability of benefit to the patient. This ancient norm embodies the constitutional duty of the doctor to the patient. Similarly, modern healthcare laws such as HIPAA have created duties and rights among healthcare providers and consumers fundamentally based on their relationships and roles.
¶ 109 Online health networking has transformed the foundational relationships in health care by changing how, why, and to whom cyber-patients disseminate personal healthcare information. While social media applied to health care has many possible benefits relating to patient care, it currently exists in a legal and normative vacuum. This vacuum has serious implications for the privacy interests of cyber-patients and others whose information may be disclosed online, as they can neither rely on the ex ante protection of statutory law nor the redress of privacy tort law.
¶ 110 In the absence of law, actors in this new healthcare environment must embrace ethical norms designed to meet the challenges posed by the technologies in use. This Article proposes the Cyber-Patient's Bill of Rights and Responsibilities, a normative protocol for immediate consideration and application. It is only through the definition of expectations, rights, and duties that new health media technologies can aim to do no harm.
Microsoft may access and/or disclose your personal information if we believe such action is necessary to: (a) comply with the law or legal process served on Microsoft; (b) protect and defend the rights or property of Microsoft (including the enforcement of our agreements); or (c) act in urgent circumstances to protect the personal safety and welfare of users of Microsoft services or members of the public (emphasis added).
See HealthVault Privacy Policy, supra note 50.
| © Copyright 2008 by Northwestern University School of Law, Northwestern Journal of Technology and Intellectual Property | Volume 6 Issue 3 (Summer 2008) |