DMNS refutes allegations of data misuse

NOTMYTRIBE received this response from the Denver Museum of Nature and Science to our post: IS THE MUSEUM OF NATURE AND SCIENCE GATHERING PRIVATE DATA FOR HEALTH INSURERS? In the July 26 article I outlined concerns that medical data specialists could be harvesting checkup results conducted on visitors to the DMNS exhibit “Expedition Health.”

July 29, 2009

Dear Eric,

As the Curator of Human Health at the Denver Museum of Nature & Science, and a member of the team that created the Expedition Health exhibition, I can say unequivocally that visitor information recorded in the exhibition is NEVER shared with insurers, and the “signs of subterfuge” you detail in your blog have no basis in fact.

Privacy issues were a top consideration in the development of Expedition Health because the exhibition was deliberately designed to be highly personalized. Based on research and best practices in informal science education, we know that people learn human biology better when they’re learning about their own bodies, not the human body in general. The data that visitors provide when they sign-in to get their Peak Pass serves no other purpose but to customize Expedition Health for each person with the goal of creating a relevant, empowering, educational and memorable experience.

While visiting Expedition Health, visitors can choose to participate in activities that record their resting heart rate, their target heart rate, their height and arm span, their stride length, speed and energy score. These activities are designed to provide data that is accurate, but this information is not intended to be used for any clinical or diagnostic purpose. The true reason for this data collection: through these measurements, visitors see that their bodies are constantly changing in ways they can see, measure and optimize though healthy lifestyle choices.

Contrary to the claims made in your blog, we do not collect biometric data such as fingerprints,, voice patterns, retinal scan, etc., nor do we gather information about diet preferences, weight, body fat ratio, “stress test” results, vital statistics or present/past tobacco or sunscreen use. Visitors are challenged to build a healthy meal and see hypothetically what they might look like based on lifestyle choices such as wearing sub block.

Information provided by visitors in Expedition Health—information that personalizes the experience and therefore enhances the educational experience—is stored in a secure database. This database does not interface with the Museum’s ticketing systems. A very limited number of staff members in the Museum have access to the visitor information that is gathered at the exhibit components. The data is kept so that visitors can look at their information and extend their learning experience at home by logging on to their own unique and secure web site.

Visitors have two weeks to access their information online. Every two weeks, 98 percent of our visitors have their data purged from the database because they have not accessed it online after their visit to Expedition Health. The remaining two percent of visitors who elected to see their data online and extend their learning experience have their data saved in the database for six months should they wish to access their data again. The Museum never shares this data with any outside entities.

Finally, the Museum maintains as strict policy with donors when it comes to the development of exhibition content and the sharing of information gathered in the exhibition. Kaiser Permanente Colorado is the presenting sponsor of Expedition Health, and the lead donors include Boettcher Foundation, The Colorado Health Foundation, and Gates Family Foundation, a Colorado-based foundation that is not connected with the Bill and Melinda Gates Foundation. While these organizations did provide funding, they did not have any involvement in content development for Expedition Health, nor have they ever received any visitor information recorded on Peak Passes. This distinct separation between content and funding is critical to the Museum’s long-standing credibility.

As the region’s leading resource for informal science education, the Museum is committed to presenting objective scientific content, and retains control of and responsibility for all exhibits and programs. When the Museum developed Expedition Health, we worked to ensure that our new exhibit was firmly grounded in the most current biological science and was relevant to visitors. All content in Expedition Health was created or vetted by Museum staff members—scientists, educators and exhibition designers—with the help of a blue ribbon advisory board. Our overall aim with Expedition Health is to broaden visitors’ knowledge of human biology, disease, and wellness, and inspire the application of these discoveries to their lives.

I respectfully request you post this response online. If you would like to discuss this further, I invite you to contact me directly at the Museum.

Sincerely,

Bridget Coughlin, PhD

Thank you Dr. Coughlin, we are eager to take you up on your offer. Ultimately I would hope to see the museum provide its visitors a written assurance of what you’ve explained.

Ours is a surveillance society where military recruiters are granted access to high school records, where consumer profiles are traded among marketers, and health insurers are pushing to overcome national privacy safeguards by digitizing all medical records. You have explained that the “Expedition Health” exhibit is not collating its data with others. Because current technology makes clandestine data harvesting feasible, perhaps the museum could introduce firewalls to demonstrate how their visitors’ anonymity remains protected. This would offer more comfort than docents who assure patrons that the information is purged every night, or you, who explain it is purged after two weeks.

Is the Museum of Nature and Science gathering health data for insurers?

dmns expedition health
DENVER- At the Denver Museum of Nature and Science the most popular exhibit this summer is called “Expedition Health” and features high-tech diagnostic kiosks where visitors can gauge the general state of their health. Judging by the long lines, you’d think these people haven’t visited a doctor lately. I suspect that unless the medical insurance underwriters of the exhibit can be trusted, many of the DMNS-goers won’t get to see a doctor again.

My hypothesis– that “Expedition Health” is surreptitiously collecting personal medical data on every visitor who comes through their doors, to add actionable factors to insurance customer files. If this is happening or not, it easily could. And the DMNS is not offering any assurance that it is not.

Basically, everybody who goes through the Expedition Health exhibit is surrendering personal health data, which in the hands of insurers could be critical in their decision about whether or not to offer them medical coverage. Museum staff insist that the personal information is purged every night, although with a simple internet link this explanation is disproved. Staff explain that attendee magnetic cards are erased, perhaps innocently ignorant of where the information actually accrues as the public circulate from one kiosk to the next.

expedition health peak passAt pharmacies you can measure your blood pressure without a personalized magnetic card. But at the DMNS health exhibit, sponsored by Met Life, Kaiser Permanente, et al, you have to tell the machines who you are before you can learn your heart rate, your vital statistics, results of a stress test, a measure of your “stride,” digital imagery of your body at rest and in motion, scans of your fingers and palm, and a 3-D imaging of your face.

A telling detail, to my mind, is that the DMNS offers no printed assurance that the health information of its attendees is not being harvested by data merchants. Is it? Do I have any proof? I will offer you the clues, and you can be the judge. I think there are enough signs of subterfuge to suspect that “Expedition Health” is not serving your health.

Here’s how it looks to the average exhibit visitor: the attendee is given a magnetic card to use at the electronic kiosks, at the culmination of which a “Peak Pass” card will be generated to reflect the user’s health results. In the process the attendee learns about positive and negative factors which govern human health. Attendee are free to initiate the card with whatever fictitious ID data they wish, depending on how helpfully relevant they want their results to be.

The impression of anonymity is bolstered by several insincerities. I will illuminate a few.

A. The ruse of an aliased identity

Part one, the ID. Before museum-goers can attend “Expedition Health,” they must obtain an admission ticket marked with the time they can be scheduled to enter. This is done ostensibly to ease congestion through the exhibit hall.

denver museum peak passIn purchasing their museum passes, or submitting their DMNS membership cards, the visitors are of course revealing their verifiable identities. If they are not already members in the museum’s database, their admission purchase via credit card or personal check and driver’s license confirms who they are. Under the pretense of museum security, driver’s IDs can be inspected all of their own. Who would begrudge the museum knowing who is visiting? And if you had the foresight to worry about your anonymity, what would it matter if the museum recorded too, when you would be presenting yourself at the start of the health exhibit?

Part two: the unclean slate. At the exhibit door attendees submit their tickets and are admitted entrance and given a blank magnetic card. The staffer who collects the tickets is not the same person who immediately hands out the magnetic cards, thus reinforcing the sensation of a severed paper trail. But in actuality, there is no discontinuity because the card-holder immediately queues for a kiosk to personalize the card.

Although the user can chose to conjure personal information entirel fictitious, the impression is given that the card’s data goes no further than the exhibit’s exit door. When I asked, a staff member earnestly assured me that all the cards are erased every night. Which could be true, but irrelevant. The cards serve like a patient wristband at the hospital. The wristband confirms the identity of the patient at the various checkup points, as the medial records accumulate in remote files.

Part three, a false sense of anonymity. The museum patients are free to initiate their magnetic cards with whatever manner of fictitious name and birthday. Especially if it does not matter to them that the final printout will bear false facts. My companion felt he had to turn around to explain to me that he always lies about his birthday, by one day, to shake off the data spooks,. He volunteered this in case I thought he didn’t remember his own birth date. My sense is that most people give their true identity, if only so the kiosks will address them by their given names, the exchanges being in full view of friends and relatives waiting in line.

If the attendee hopes to glean some helpful health advice from the “Expedition Health” experience, they are inclined not to falsify the three remaining details: sex, age, and which “buddy,” among a statistical sampling of lifestyle types, they might identify themselves with.

Tell me that the last three profile items are not enough to provide a match to the hard data from the museum entrance receipts or membership database. Remember, the samples to compare are linked by the window of time the museum alloted to your ticket.

The choice of your “buddy” is the clincher. It might appear to be the most innocuous of indiscretions, but your surrogate patient type relays reliable biographical data about you, and doesn’t add anything to the health exhibit narrative except to use as a third person example, when the patient-specific explanation would reveal the alarming degree to which the diagnostics had taken your measure.

Which, to be fair, would create a liability risk for the museum, to complicate matters with pseudo diagnoses, easily misinterpreted by laymen.

The DMNS “Expedition Health” curators thus know quite definitively who you are, as you pass through their kiosks, putting yourself through a fairly extensive check up, the results of which are explained only generally to you, but to a medical administrator say enough to narrow many odds about your health prospects.

B. Diversionary misapplication of magnetic cards

Several of the Kiosks at “Expedition Health” are not interactive, and do not require the magnetic card. Of course, to assure that your “Peak Pass Personal Profile” data card will be filled print out with your EKG, Resting Heart Rate, Target Heart Rate, whether you reached your heart rate; your Arm Span, Height, Energy Score, Stride Length and Speed, a silhouette of your walking profile and another of your outreached Leonardo DaVinci pose; you’d have to have scanned your magnetic card at those machines.

By the way, the data summarized on the personal profile card was far more rudimentary in comparison to the information shown on the screens, and doubtless neither reflect the sophistication of the diagnostic electronics employed. The optics, for example, are capable of far better than inch-high cameos of your body. The lengths of time for which you have to pose for the scans betray the resolution the graphics engines are really processing.

Here’s the information being gathered at the various stops:

Taking your measure
The station which measures your arm span and height requires you to stand, arms outstretched, shoes off, for a full body digital picture, which records an uncommonly revealing photographic record of the subject’s body fat ratio.

Another station measures your stride length and speed, from which an “energy” score is awarded. To do this, a full motion video records you as you take over a half dozen steps, perhaps pushing yourself purposefully to boost your “energy score.” This video must be invaluable in what it reveals about a person’s vitality or physical challenges.

While the cardio-vascular stress tests might appear to offer mere stationary bicycling experiences, a subject’s entire session can be recorded, offering telltale clues to heart condition and lung stamina. Probably we’d all be more comfortable studying these results with the peace of mind that we have health insurance, as opposed to considering that our results might be grounds used to deny us health insurance coverage.

Diet
Several kiosks would seem to have no need for a card. For example, one featured an interactive script about nutrition. Mostly children sit at this station, to pick among menus of food, the mission being to fortify a climber for an ascent of a peak. Their choice of nutrients determines how far the animated climber will get, before tumbling after from hunger. You plug in your card to begin, and as a result the climbing figure features a Tanqueray-head-type of your chosen buddy. If this kiosk is gleaning a sense of your diet preferences, it’s not revealed on the exhibition debriefing printout.

Identification Marks
Another kiosk teaches you about wind chill. You stick your hand into a plexiglass chamber where lasers measure the change in your skin temperature over the course of several minutes. Curiously, you have to insert the magnetic card at this stop. Why? And you cannot proffer your elbow, your fist, or the back of your hand. Is it possible that the lasers reading your hand are actually scanning the prints of your palm and fingers? I know too little about medicine to conjecture what use the medical industry might have for such information, but the data is certainly marketable to security firms.

Confessions
While on this tangent, there’s another kiosk, the most popular in fact, which DOES NOT REQUIRE A CARD. At this station you get to see your face as it’s projected to age over the course of your life. The line is the longest at this station, while subjects pose, their face held immobile, framed in a stainless steel ring, for an interminable several seconds. I witnessed one person complain that the light into which he had to stare hurt his eyes. Eventually the scan yields only an oddly primitive, cellphone-quality facsimile of the subject’s face, projected on an adjacent flat screen. Next, the subject is asked which among three factors might influence how he’s expected to age. Please check which apply: UV damage, Obesity, and/or Smoker.

By law, none of these behaviors would have to be confessed to a doctor, or an insurance agent, in particular if such was a vice already put well behind. But the aging machine draws out the truth. Because the interrogator machina does not ask for your ID, it creates the semblance that you are being asked anonymously. Who doesn’t fully comprehend by now that sun exposure, obesity and smoking are very tragic predictors of our future health problems?

The pseudo age-disfigured face is disappointing. The transformation is just a transparency of age spots, wrinkles and discoloration overlaid on an initial low-rez photograph. If you are not recording the age-progression with your own camera, the ephemeral image passes, with no trace of what the long facial scan had actually recorded. You’d think since the lines of visitors here are always so long, that the aging image is what visitors might like to take with them as a memento. Alas, there’s no slot on this kiosk into which to insert your magnetic card to “record” it. But the sovereignty of this station is illusory.

Biometrics
If a webcam, a PC, and a common internet connection can transmit video in real-time video, why would this DMNS workstation be laboring for so long over your face? Can I hazard a guess? A 3-dimensional study of your face, and something just short perhaps of a retinal scan? If medical administrators are not looking at symptoms deep in your eyes, or in the translucence of your skin, perhaps this kiosk is for the security interests tabulating your biometrics.

If nothing else, the biometric configuration of your face can be matched to a digital image of your whole body from a previous kiosk, thus confirming your identity, BECAUSE AT THIS KIOSK YOU ENJOYED ANONYMITY. But now your smoker/obesity concession can be deftly noted alongside the other red flags being added to your health profile.

C. The Parting Shot
The last kiosk, in my opinion, gives the game away. If you insert your magnetic card, you can record a video message, a propo anything at all. I saw many takers offering calm Youtube soliloquies, as if composing a greeting to send into space. And AHA –instead of pretending that your video would be encoded on your card, instructions beside the screen offered the internet URL at which you can go see it.

First, this directive gives truth to the lie, the DMNS staffers’ incurious conclusion, that individual records are purged everyday. Your profile lives on on the internet, see it for yourself. Give your six-digit pass-code to a friend and they can see it too. And of course, you’re not the only one with the pass-code.

Second, you might well ask yourself, what does a videogram have to do with apprising me about my health? Unless it’s a time-capsule snapshot of you before you lost your insurance coverage. Because the video has everything to do with breached personal privacy. There you are, in your unguarded candor, sitting not upright like you would for a job interview, nor slouched like you might for Social Security, and you’re providing a recording for voice pattern recognition, for further data triangulation.

Third, you’ll have noticed, if you tried the Peak Pass link to the DMNS website, you get no further with your personal code than an invitation to “extend your experience” by installing Microsoft Silverlight. I hadn’t mentioned that the Gates Foundation was another big sponsor of “Expedition Health.” Beside the security vulnerabilities of client-side code, managing what is supposed to be confidential information, what usual back doors is Microsoft leaving in its pseudo-Flash, offering untold windows into our personal medical records?

The DMNS
I do not believe the museum staff have any idea what becomes of the data, nor the extent of the data, logged as museum visitors recreate through “Expedition Health.” The multiple employees, including a manager to whom I spoke, believed all data was erased daily. I’m not sure why they were untroubled by the internet database that obviously refutes their understanding of the process.

However the IT programmers who wired up the displays, and information managers handling the data, would most certainly know the full extent of this nefarious harvest.

Judging from the recent performance of the CEOs of the top medical insurers before Congress, expressing no remorse about their disreputable practice of rescinding coverage for customers upon their being diagnosed with expensive health problems, I do not think it is alarmist in the least to suspect that projects like “Expedition Health” and other similar museum “exhibits” around the country, are being used to further screen the prospectively less-than healthy.

DNA
Readers who’ve already visited “Expedition Health” will note that I ‘ve omitted mention of a significant corner of the experience, the hands-on, let’s play pathologist portion where visitors don lab-coats and, with the assistance of similarly lab-coated docent/lab-technicians, draw and observe their own DNA samples.

Where I inquired, I saw no magnetic-stripped cards changing hands, so I cannot say, on the hot topic of DNA, that the sky is falling. This holds with my inclination to believe that the museum volunteers are not party to the privacy improprieties of the sponsors running the machines. But what hands-on scientific observations are being conducted on digital equipment, as distinguished from analog microscopes, might be kept in the records, and it would only require just one lab-coated coordinator to monitor which sample came from whom. And wouldn’t that be the whole ball of wax?

CRYING WOLF?
If all this seems implausible, consider what is happening at Buckley AFB, by coincidence only a few miles away in Denver. Although US security agencies refuse to comment, respected intelligence experts have determined that at Buckley reside the data storage units upon which are the recordings of every single cellphone conversation that’s been transmitted via satellite. Every last one, for the past several years. Current technology does not afford agents the capability to monitor all those calls, but the processors are quickly catching up. The spooks can project that the eventual capacity to parse the information is inevitable. So why not begin logging the information now? The public has learned about Buckley from former employees, this is not mere idle speculation. Meanwhile the telecom companies who’ve been complicit in the data collection, have been very adamant about receiving immunity from prosecution for what constitute gross violations of American law.

AND NOW?
The information tracking mechanisms are there, the DMNS staff do not presume to vouch for machines, only for the harmless cards. Meanwhile the DMNS has no written pledge that their visitors’ confidentiality is being respected. Harvesting test data is not illegal after all, and with the pretense of anonymity, it’s even laudable, in the name of Science and Nature. I am awaiting a written response from the “Expedition Health” curator, and I intend to solicit an informed and verifiable refutation of these charges. I’ll keep you posted.

The “Expedition Health” installation went up in April, but it’s not coming down. It’s the most recent PERMANENT EXHIBIT to be added to the DMNS offerings. Add the trajectory of time to the information the diagnostics will be able to assemble about you.

And so, what do you think of a museum of Nature and Science, adding a whole wing about FREE HEALTH TESTING? Is that the dominion of museums, usually public repositories of the archives of knowledge? Or can you imagine a more appropriate setting for equipment and staff to perform medical checkups?

Kaiser Permanente Health Care Plan

kaiser permanenteAre you or have you ever considered enrolling in the Kaiser Permanente Health Care Plan? Please read this before you do, because It just underlines how caring the Kaiser Permanente people will be with your health. I know, because I have had both the fortunate experience at working in Kaiser Permanente facilities and have also been covered along with my family by their caring medical coverage. Checkout and see what nice people these folk really are! Distraught Father Kills Wife, 5 Kids, Self

Privacy freak

Social Security clownA couple of years ago I took my son to a local college to register for a class. I filled out the required paperwork and when I handed it back to the clerk she said, “Oh, you forgot to fill in his Social Security number.” I replied that no, indeed, I had not forgotten but that Social Security had nothing to do with studying Plant Biology and therefore I was unwilling to give his SSN to them. “But we need it because it will be his student ID number.” I disagreed and informed her that she could simply assign him a student ID number like 999-99-9999.

I am sure I’ve never seen anyone look quite as perplexed as the clerk did at that moment. It took over an hour and several different administrators “reasoning” with me before my son got his random student ID number and off we went to the bookstore.

First mini-moral of the story. You people are giving out your Social Security numbers way too readily. This is obvious because with thousands of students registering every year I was apparently the only privacy nut in the history of the college unwilling to cooperate. Your SSN should never be given to anyone except a company/individual who is required to report your earnings or wages to the IRS. Period. Period. Period.

Next, remember in the not-too-distant past when brilliant geeks in labs participating the the Human Genome Project discovered that the presence of certain genes could predict possible future diseases or health problems. What an amazing discovery, one that could benefit mankind mightily. Enter bastard medical insurance companies. “Oh, we’d sure like to get our hands on that kind of information so we can deny coverage.” Enter corporate assholes. “Oh, we’d sure like to get our hands on that kind of information so we can deny employment.”

Second mini-moral of the story. Guard your medical information in every way that you can. Start by refusing to give doctor’s offices and insurance companies your SSN which is, as we’ve learned, a number you must only give to an employer, possibly a bank or a broker. If you are insured under a group plan, talk to your employer about keeping those numbers private. There is absolutely no reason that Kaiser Permanente needs your fucking Social Security number. Make some noise about it.

And if you ever need to seek treatment for substance abuse or mental health problems, do not do it with the knowledge or assistance of any insurance company. Pay cash, use a fake name. I know this sounds like paranoia (oops! a mental health problem) but this is a monkey that will hang onto your back forever. Once again, denial of employment, medical coverage. Don’t even think of running for public office or being a teacher or a policeman or a firefighter. Medical care providers pretend that our privacy is protected. It’s not protected. Talk to Bill O’Reilly.

The Patriot Act gives the government the right to mine the entire spectrum of public and private sector information. Any walls of privacy that may have formerly existed, shaky as they were, have come crashing down.

Third mini-moral of the story. Teach your children to protect their privacy. I’m not advocating that we make them hate or fear the government, or insurance companies, or school counselors, or Kaiser Permanente (actually I am). But young people should be made aware that personal information in the wrong hands can make life a nightmare.

I saw my son this morning and he showed me his new cell phone. “Guess what?” he said. “I got it at Wal-Mart. Sixteen cents per minute prepaid, no contract, I gave ’em a fake name. Kubla Khan.”

Mission accomplished.

Kaiser Dumpanente, caught ‘cutting health care costs’

It was just a week or so ago that I was out walking my dog, and ran into a gentleman who thought he had seen me at his heart clinic. We got to talking, and he informed me of his heart condition and how fragile his health was. I showed him my sympathy for his condition, and he responded by telling me not to worry, that he had the best care possible and a fabulous doctor. I then asked where, and he told me Kaiser Permanente! My heart sunk for him. He was as good as dead in my experience.

Goodbye, Pal, I wanted to say. You see, I have both had KP care and have worked for them, too. Squeezing necessary medical care from them is harder than squeezing water out of a rock. So the story making the rounds of the news outlets today (see Gazette page A4), hardly surprises me at all. Los Angeles is bringing charges against Kaiser Permanente for not caring, in essence. KP ‘dumps’ patients every day, and not just indigents into the streets. So if you have their coverage, Be Aware. You will be having your own health care dumped all the time, in one form or the other.