SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Government >> Program

Opinion: RFID technology in health care - it's not the end of privacy, it's the beginning

Opinion: RFID technology in health care - it's not the end of privacy, it's the beginning

By:  Ann Cavoukian  On: 24 Jan 2008 For: ComputerWorld Canada Creator

Health-care providers around the world are undergoing a digital transformation, harnessing information communication technologies such as Radio Frequency Identification (RFID) and applying it in innovative ways to increase operational efficiencies, improve services and save lives.


Health-care providers around the world are undergoing a digital transformation, harnessing information communication technologies such as Radio Frequency Identification (RFID) and applying it in innovative ways to increase operational efficiencies, improve services and save lives.

In the U.S., health-care providers are already using RFID chips to track surgical instruments and sponges to ensure that nothing is left behind inside a patient. If anyone doubts the value of this service, take note of an Australian woman who continued to suffer intense pain for months after her surgery. Doctors eventually discovered a 6.7-inch pair of surgical scissors that were left behind in her abdomen.

Other health-care providers are using RFID chips to trace pharmaceutical products to ensure that the correct medication and dosage is being administered to patients. A 1999 study of 1,116 hospitals by the United States Institute of Medicine suggests that more than 44,000 deaths occur each year in the United States as a result of in-hospital medication errors. Yet, while there are many benefits in using RFID technology in the health-care sector, concerns arise regarding the protection of personal information and the tracking of individuals.

Yesterday, in collaboration with Hewlett Packard (HP) Canada, I released a joint publication entitled, RFID and Privacy: Guidance for Health-Care Providers, at a special RFID health-care conference in the U.S.

This research paper reviews a wide range of RFID-enabled health-care uses - from tagging hospital supplies to embedding a chip into a person - noting not just the potential benefits, but also the privacy risks. This is because RFID tags contain a microchip and radio antennas that transmit a unique identifying number to an electronic reader, which in turn links to a computer database where information about the item is stored. And, while RFID tags are primarily designed to be attached to products, they nevertheless still pose potential risks to privacy if attached to objects than can be linked to people, if not directly attached to people.

The paper further organizes RFID health-care applications into three broad categories. The first category, tagging things, raises few privacy concerns as it refers to keeping track of objects such as inventory, supplies, mobile hospital devices, bulk pharmaceuticals, dossiers and files.

The second category is tagging people. Here, benefits and privacy concerns need to be balanced. For instance, despite being a Privacy Commissioner and a privacy professional, I nonetheless support the use of RFID tags for tracking newborns. In a complex hospital environment, strong patient identification is a desirable benefit, as long as the privacy questions have been addressed and the benefits are demonstrable.

The third category, tagging things linked to people, has to be addressed very carefully. As I already have pointed out, while objects can be tagged and tracked, the question remains whether those objects, such as hospital access cards or blood samples, can be used to identify individuals, who may not even know they are being tracked.

So, what can those in the health-care sector do to ensure that privacy is protected when employing potentially life-saving RFID technology? First, get a copy of our paper. Then, think about something I call "privacy by design," which essentially means that privacy needs to be built in early, at the design stage, before a system is in place where there is the potential for a privacy breach.

Everyone, from health-care providers, to patients, to privacy advocates, want the best technology possible in the health sector, without needless invasion of privacy. While I, as a patient, would welcome RFID technology improving my health care, as a Privacy Commissioner, I firmly believe that we must also ensure that the deployment of this technology does not infringe upon our privacy. RFIDs can improve key segments of health-care services while protecting patient privacy. It's all a matter of changing the paradigm from a zero-sum game to a positive-sum model.

Ann Cavoukian is the Information and Privacy Commissioner of Ontario. The paper cited in this column, RFID and Privacy: Guidance for Health-Care Providers, is available at www.ipc.on.ca

Related content:

Big Brother on a tiny chip

No excuses for SickKids, says Ontario privacy chief

Privacy complaints reach record highs, says Ontario czar


Sign up for our Newsletters












Print |  Views: 682   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Ann Cavoukian Ann Cavoukian is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Early adopters seek return on investment for RFID
Early adopters seek return on investment for RFIDIt may start with adding a wireless tracking tag, but according to experts at a Canadian conference this week, it doesn't end there. Kimberly-Clark and others share their success stories
New Ontario RFID guidelines emphasize 'consumer consent'
New Ontario RFID guidelines emphasize 'consumer consent'Consumer consent must be obtained before personal information linked to a radio frequency identification (RFID) tag is collected, used and disclosed, according to a new set of guidelines issued by Ontario's Information and Privacy Commission (IPC).
IT vendors, privacy groups release RFID standards
IT vendors, privacy groups release RFID standardsA set of best practices designed to help assuage consumers’ concerns about RFID (radio frequency identification) tags was released this month by a group of technology vendors, RFID users and consumer groups. Companies using RFID tags on products should notify customers; should tell customers whether they can deactivate the tags; and should build security into the technology as a primary design requirement, the group said.
The semantics of privacy
bell and the canadian association of internet providers made submissions to the crtc in answer to questions the regulator had over their respective cases in the traffic-throttling controversy. (long story short, if you missed it: bell is choking off p2p traffic on the lines it l
blog comments powered by Disqus