Google Health Opens To the Public
Several readers noted that the limited pilot test of Google Health has ended, and Google is now offering the service to the public at large. Google Health allows patients to enter health information, such as conditions and prescriptions, find related medical information, and share information with their health care providers (at the patient's request). Information may be entered manually or imported from partnered health care providers. The service is offered free of charge, and Google won't be including advertising. The WSJ and the NYTimes provide details about Google's numerous health partners.
Yes, Google Health supports advertising. Spamming, even. Read the developer guidelines. Google just doesn't run the ads themselves. That's outsourced to "affiliates".
There are some rules for affiliates, like "one spam per week per user" and "no popups or popunders". Other than that, consumers are fair game. In particular, affiliates are not prohibited from using Google health data to target ads, as long as they "disclose" that somewhere in their "privacy policy". The policy says "Only use Google Health user data for the purposes disclosed in your privacy policy, and obtain users' opt-in consent if personally identifiable health data will be used for ad targeting." So a bit of fine print, and the affiliate 0wns your health history.
It's a typical slimeball tactic - pretend to be the good guy, encourage "affiliates" to do the bad stuff.
Your medical provider is covered by HIPPA and CANNOT release your records to a third party without your consent. When you go to a new doctor they generally make you sign something saying they can share it with your insurance company, who also cannot share it with Google without your consent.
The way Google Health works is you give them your data and they store it.
Okay, here is the government telling you that HIPAA doesn't apply to Google. Google isn't a health care provider, nor is it a health care insurance plan, nor is it a health care clearinghouse, by the legal definitions of those terms (check the law if you like), so, no, HIPAA most certainly does not apply to Google or any other company or entity providing a similar service.
My blog