Your medical data isn’t as private as you might think. Your healthcare providers—from your pharmacy to your health insurer—sell your medical data to data brokers, who compile and sell hundreds of millions of patient records for marketing and industry analysis purposes. In Our Bodies, Our Data (2017), Adam Tanner surveys the medical data industry and its worrisome capabilities.
Tanner is a journalist and lecturer who has worked at Harvard as an associate and fellow. He spent over a decade as a Reuters correspondent, has appeared on networks like CNN, NPR, and the BBC, has written for publications like Scientific American, Fortune, and MIT Technology Review, and is the author of What Stays in Vegas.
In our guide, we’ll explore the medical data industry, including its history. We’ll look at the sources data miners draw from, how the data is used, and who uses it. Finally, we’ll look at the different forces that propel the medical data industry, as well as the forces that oppose it.
According to Tanner, medical data mining and selling has become a profitable industry. What we think are private medical records are actually being compiled and sold for marketing and commercial purposes. For example, leading data broker IQVIA (valued at $20 billion as of the book’s publication) boasts having 530 million non-identified patient records, 85% of pharma sales tracked, 400,000 sources of social media, and 15 million healthcare professionals.
It's no exaggeration to assume that all your health providers are reselling your medical data to brokers like IQVIA. Nearly all information is sold—your disease diagnoses, what drugs you take for which conditions, what your most recent lab tests say, who your doctors are, and when you saw them. Every vendor you interact with to get medical service—including pharmacies, medical providers, and insurers—is able to sell medical data. Reselling data is a high-margin business, and thus tantalizing for managers to add to their bottom line.
The only restriction companies have under HIPAA law is to remove identifying information like your name, address, and Social Security Number, instead creating a unique personal code for you. However, removing your name from your record is little barrier. With so much data and this unique code, the data broker compiles data streams into a new patient record. Any new data the broker receives is associated with your personal record, making it more and more identifiable. Your entire medical record is virtually owned by multiple third parties, just with your name and SSN replaced by a unique ID.
The broker resells your health record, along with those of hundreds of millions of other patients, for marketing, industry analysis, and research purposes. Note that in large part, the data buyers (for example, pharma companies) are interested not in you as an individual but in how you fit into general trends—what drugs you're taking or switching to, what drugs your doctors are prescribing, and how disease prevalence varies by location.
But there’s always a risk of a data leak. And given how much information your patient record has, it can likely quickly be matched back to you, especially if you have a rare condition, see a unique combination of doctors, or have any other public health-related information (for example, public exercise data from health devices).
In some sense, it’s already too late to opt out or take back your data. Data brokers say your records can’t be traced back to you, so even if you wanted to opt out, they claim to have no way to tell which data to delete. But at a minimum, you should be aware of the extent to which your data is shared and be more mindful of future opportunities to opt out.
Tanner provides a history of how resold medical data became increasingly personal and detailed. The overall trend over the past decades has been toward 1) more granular data consisting of more detail about a patient’s history, 2) data linked to distinct providers and patients, and 3) piecing together large datasets longitudinally across time. For example, wholesalers and pharmacies started by selling bulk sales data. This allowed the study of pharmaceutical company market share, overall and by territory.
Later, prescription data with doctor identification allowed data companies to create profiles on the prescribing habits of individual doctors. And eventually, anonymized patient data from wide sources were linked together to get patient dossiers.
In the 1930s, Arthur Charles Nielsen, founder of the A.C. Nielsen Company, paid pharmacies to share wholesale invoices. Staffers also counted products on shelves to monitor and estimate sales by region and season. Pharma research firm Davee, Koehnlein and Keating used receipts from US pharmacies and manufacturers to estimate pharma market sizes by category.
In 1947, graduate student Ray Gosselin asked drugstores for permission to copy their prescription records for his research. He started a company in 1952 to send bimonthly surveys to pharmacies nationwide and to collect prescription data from physicians, which allowed pharma companies to track sales and compare their market presence against the competition. (Note that drug sales are distinct from drug prescriptions.)
Market research company IMS Health, founded in the mid-1950s, acquired purchase data from wholesale pharmacies to estimate market sizes in Germany and began began asking doctors to share what they prescribed for different diagnoses. Generally, IMS tried to get data for free, arguing the data would help science. Otherwise, they gave $50 a month for this data. IMS later started the...
Unlock the full book summary of Our Bodies, Our Data by signing up for Shortform.
Shortform summaries help you learn 10x better by:
Here's a preview of the rest of Shortform's Our Bodies, Our Data summary:
Our Bodies, Our Data contains a useful history of how resold medical data became increasingly personal and detailed.
The overall trend over the past decades is toward 1) more granular data consisting of more detail about a patient’s history, 2) data linked to distinct providers and patients, and 3) piecing together large datasets longitudinally across time. A few examples:
1930s: Nielsen pays pharmacies to share wholesale invoices every 2 months to project overall US sales. Staffers also count products on shelves to monitor sales rates....
Every vendor you interact with to get medical service is able to sell medical data. Reselling data is a high-margin business, and thus tantalizing for managers to add to their bottom line. Our Bodies, Our Data describes the following data sources:
This is the best summary of How to Win Friends and Influence People I've ever read. The way you explained the ideas and connected them to other books was amazing.
What is enabled by having hundreds of millions of patient records?
Many pharma business decisions can be empowered by granular data on which patients take which drugs in which locations. Research studies are also empowered by large datasets.
The risk is that more unsavory, discriminatory uses can arise.
Here’s an array of how different types of firms can use medical data for their own purposes.
The book describes the following major players in the medical data industry.
IMS Health (now known as IQVIA)
"I LOVE Shortform as these are the BEST summaries I’ve ever seen...and I’ve looked at lots of similar sites. The 1-page summary and then the longer, complete version are so useful. I read Shortform nearly every day."
Jerry McPheeHere are forces that have propelled patient data selling over the past decades:
Here is a collection of notes about the healthcare industry that frame strategy.
This is the best summary of How to Win Friends and Influence People I've ever read. The way you explained the ideas and connected them to other books was amazing.