I Introduction
The connected at-home health care device industry is booming.Footnote 1 Wearable health trackers alone constituted a $21 billion market in 2020, anticipated to grow to $195 billion by 2027.Footnote 2 At-home devices now purportedly make it possible to diagnose and monitor health conditions, such as sleep apnea, diabetes, and fertility, automatically, immediately, and discreetly. By design, these devices produce a wealth of data that can inform patients of their health status and potentially even recommend life-saving actions.Footnote 3
But patients and their health care providers often lack access to this data.Footnote 4 Manufacturers typically design connected at-home devices to store data in cloud services run by the manufacturers themselves, requiring device owners to register accounts and accept the terms of use and limitations that the manufacturers impose. A recent survey of 222 mobile “app families” associated with wellness devices found that 64.4 percent “did not report sharing any data” with other apps or services.Footnote 5 A parent testified in Congress as to how a lack of data access impaired his daughter’s ability to manage Type I diabetes,Footnote 6 and patients with sleep apnea have had to circumvent technological device locks to extract data on their own sleep.Footnote 7 Many medical and wellness devices that patients use for in-home diagnosis and monitoring – which we simply call “health devices” – lock patients into manufacturers’ ecosystems. This limits patients’, and society’s, ability to tap into the full value of the data, despite the extensive individual and social benefits that access could provide.
The problem here is not solely technical; it is also legal. Existing law in the United States provides patients with no guarantee of access to their data when it is generated and stored outside the traditional health care system. The Health Insurance Portability and Accountability Act (HIPAA) provides patients a legally enforceable right of access to copies of their electronic health records (EHRs), and, in recent years, the Department of Health and Human Services (HHS) has moved to make this right enforceable and meaningful.Footnote 8 But as HHS itself has observed about health devices and other “mHealth” technologies used outside the EHR ecosystem, manufacturers “are not obligated by a statute or regulation to provide individuals with access to data about themselves,” so patients with data on such devices “may not have the ability to later obtain a copy.”Footnote 9
This chapter begins by identifying the individual and societal benefits of patient access to health device data. It then addresses the arguments for restricting such access, especially those based on intellectual property laws and policies. We conclude that such arguments are ultimately doctrinally and normatively unconvincing, such that they should not dissuade legislatures and federal agencies from legislating or regulating rights of access. We then consider what can and should be done to create a robust, administrable right of patients to access health device data that protects all stakeholders’ interests, and we offer a nascent framework that draws from other regimes for patient and consumer access to personal information. We hope the framework will guide legislatures and regulators as they begin to address this important issue.
II Benefits of Patient Access
There are important individual and societal benefits when patients can access their own health data. Foremost for individuals is the fulfillment of patient autonomy and dignity. Health device data informs decisions about treatment, so a patient without access can neither make fully informed decisions about a course of care nor evaluate a provider’s recommendations.Footnote 10 Patients may also need access to health device data to “transport” their data to new health care providers for safekeeping,Footnote 11 or to repair their devices.Footnote 12 From a research perspective, patients can and do exploit health device data to useful ends, since their own health stands to benefit from insights and discoveries drawn from that data.Footnote 13 Many patients use health device data for “quantified self” or “n=1” research to discover how best to manage their own health.Footnote 14
Turning to broader societal benefits, a key starting point is the research that is enabled when patient data is aggregated.Footnote 15 For example, the National Institutes of Health (NIH)-run ClinVar database receives genetic variant data authorized for inclusion by individual patients and now contains over two million records representing 36,000 different genes, which public and private enterprises have used to advance research and create consumer products and services.Footnote 16 The ClinVar model of government-supported collaborative dataset-building is one starting point for the idealistic vision of “medical information commons” – the collective, shared governance of medical knowledge (rather than proprietary or authoritarian governance of the same)Footnote 17 – that researchers and regulators alike believe would be a tremendous boon to science.Footnote 18
Research on aggregated health data also allows patient groups and civil society watchdogs to verify manufacturers’ claims and ensure that health devices function as advertised – especially important given that those devices are only lightly regulated.Footnote 19 Aggregated health device data also promises to become a variety of the “real-world evidence” increasingly used to conduct public health research and validate the safety and efficacy of other products the same patients are using.Footnote 20 But these potential benefits depend on patient data aggregated at a sufficient scale.Footnote 21
Societal spillover effects explain, at least in part, why market forces do not prompt manufacturers to satisfy patient demand for data access. Patient self-researchers tend to be consumer-innovators who share their insights and discoveries altruistically, at low or no cost, which may undercut the manufacturers.Footnote 22 And the value of aggregated patient data cannot easily be captured by a single entity. As a result, there is no straightforward way for patients and health device manufacturers to transact for data access.
Another economic disconnect arises from competition among device manufacturers. When patients can easily extract their data from one device and port it to a competing device, they avoid “lock-in,” which promotes patient choice and fosters competition.Footnote 23 In an effort to avoid such competition, however, device manufacturers have incentives to limit patient data access. Indeed, some have implemented technical measures to keep even savvy patients from extracting data and asserted laws against the circumvention of those technological measures to further keep patients from their data.Footnote 24
III Legality of Patient Access
To be sure, there are real concerns with giving patients access to health device data.Footnote 25 Device manufacturers have pointed to these as reasons to limit such access. The main concerns fall into three categories.
First, there are costs associated with authenticating users, formatting data, and otherwise providing access to records. This problem can be solved by permitting reasonable, small charges for data access.Footnote 26
Second, device manufacturers may be better stewards of sensitive health data than patients, in terms of privacy and cybersecurity.Footnote 27 In theory, manufacturers enjoy economies of scale that enable them to protect health records from data breaches and other compromising disclosures, while individual patients may fail to secure their data or fall victim to privacy-invading scams. Yet, there are countervailing considerations: Manufacturers’ vast databases are themselves an attractive and recurring target for data malfeasance,Footnote 28 and some manufacturers’ shady deals with privacy-intrusive data brokers suggest that companies holding volumes of lightly regulated personal data may not be better positioned than patients to protect data security and privacy.Footnote 29
The third concern often raised as a reason to limit patient access is that the data is somehow proprietary to the device manufacturers. This intellectual property concern requires a bit of conceptual unpacking, as it operates on two different levels. First, it is a legal or doctrinal argument, in which the manufacturers assert specific intellectual property rights over the data. Second, it is a normative, policy-oriented argument that exclusive control over patient data is desirable to protect incentives to develop health devices and data ecosystems.
Evaluating these arguments requires distinguishing the types of health device data. First, there is the software code that the device manufacturer writes. Second, the device takes the raw measurements of the patient and stores them. Third, the device (or external software) may perform computations on the raw data to produce values intended to approximate a natural phenomenon, such as a pulse. Fourth, the device may compute data outputs of the manufacturer’s own invention. For example, a device might use pulse measurements across a night to produce a “sleep score,” indicating how well, in the manufacturer’s opinion, the patient slept, and offer recommendations on how to sleep better.Footnote 30
Our focus is the second and third types of information – raw measurements and computed estimates of physiological properties – because they are likely to be of the most interest to patients. We therefore refer hereinafter to these two types of data together simply as “patient data.” With access to this patient data, patients likely will not need to view source code on the device to put the data to use. Manufacturer-specific computations and scores are likely not useful for cross-device interoperability, and the black-box nature of the algorithms often used to compute such scores limits their usefulness for care and research alike.Footnote 31
Two intellectual property regimes are most frequently raised to justify withholding patient data from patients: Copyright law and trade secret protection.Footnote 32 Yet neither provides a genuine doctrinal basis for “ownership” of patient data or barriers to patient access.
Copyright law, which protects creative works of authorship from unauthorized copying, almost certainly cannot justify withholding patient data. Raw physiological measurements and estimates of natural phenomena are facts, ineligible for protection under copyright.Footnote 33 Furthermore, given the immense health benefits that patients can enjoy from their own data, data access likely qualifies as fair use, exempt from copyright infringement.Footnote 34 Indeed, the US Copyright Office has consistently agreed since 2015 that patient access to medical device data is not copyright infringement, thus, permitting patients to circumvent the technological locks that interfere with their access to data on medical devices.Footnote 35
Nor is patient data a trade secret. First, every legal definition of a trade secret requires the information in question be secret to qualify for protection.Footnote 36 Patient data of all sorts is shared with patients, health care providers, and others and, thus, is not actually secret. Second, even if subsets of patient data are kept secret, they are not the sort of information that trade secrecy law protects. To qualify as a trade secret, information must derive “independent economic value” from its secrecy.Footnote 37 As Hrdy has explained, “secret information whose value does not stem from secrecy cannot be a trade secret.”Footnote 38 Unlike traditionally protectable information – manufacturing processes, precise recipes, and so on – patient data derives economic value from aggregation and sharing, not secrecy.Footnote 39
To be sure, some (nonpatient data) aspects of devices’ software and mechanical designs may be deemed trade secrets.Footnote 40 The European Medicines Agency (EMA) offers helpful guidance here, in its official view of the limits of trade secrecy protection of clinical trial data.Footnote 41 (Like the patient data that is the focus of this chapter, clinical trial data describes patients’ health and is enormously valuable to researchers and patients themselves.) EMA announced that a large majority of clinical trial data “should not be considered” proprietary.Footnote 42 In EMA’s view, only “innovative features” of the methods through which data is collected can constitute trade secrets.Footnote 43 EMA expressly defines narrow categories of information it deems innovative and protectable.Footnote 44 These focus on methods for gathering data more quickly or cheaply, such as immunogenicity assays.Footnote 45 Notably, EMA’s categories do not permit proprietary claims to the outcome data that describes patients’ health (analogous to health devices’ patient data); EMA instead mandates that all outcome data be publicized.Footnote 46
What remains of health device manufacturers’ intellectual property claims is a normative argument that data inaccessibility gives manufacturers incentives to innovate.Footnote 47 Yet, there are serious defects to this normative argument. First, patients themselves have a countervailing incentive to innovate – their own health depends on it. Second, the “innovation” manufacturers wish to protect may not be beneficial at all: Secrecy can conceal safety problems, false claims of efficacy, racially biased outcomes, and other defects. Normatively and doctrinally, trade secrecy should not and does not protect this kind of secrecy.Footnote 48 As the Supreme Court has stated, if the disclosure of secret information reveals “harmful side effects of the [trade secret holder’s] product and causes the [holder] to suffer a decline in the potential profits from sales of the product, that decline in profits stems from a decrease in the value of the [product] to consumers, rather than from the destruction of an edge the [holder] had over its competitors, and cannot constitute the taking of a trade secret.”Footnote 49
IV Toward a Regulatory Framework
Although we have argued patients should have access to health device data as a legal and policy matter, the practical fact remains that manufacturers are currently free to build devices that deny such access at a technological level. There is, thus, a need for a legal framework to secure such access. No such framework currently exists: The existing regulations are generally limited to narrow classes of medical records or apply only to traditional health care providers and some of their business associates.
To develop an effective framework, it is useful to survey existing consumer data-access regimes both within the health care system and otherwise. We arrange them into three categories, roughly ranked by the strength of their mandates.
The most powerful regimes mandate patients’ right to data access. The HIPAA Privacy Rule provides patients with “a right of access to inspect and obtain a copy of protected health information” from health care providers.Footnote 50 Similarly, European law and the laws of some states provide consumers with rights to retrieve data about themselves.Footnote 51 These laws employ a range of enforcement mechanisms, including civil actions by consumers, state attorney general investigations, and administrative monetary penalties. For example, the HHS’s Office for Civil Rights recently began penalizing HIPAA-covered health care providers that fail to supply patients’ protected health information upon request or charge excessive fees for them,Footnote 52 prompting improvement after years of subpar compliance.Footnote 53
A second approach is softer financial incentives and disincentives – “carrots” and “sticks” – to encourage data holders to offer access. This was the primary approach used for the adoption of EHRs: The HITECH Act of 2004 both offered providers incentive payments for adopting certified EHR systems in their practices, and imposed a modest penalty on Medicare reimbursements for providers who did not.Footnote 54 Today, after billions of dollars of investment by HHS, the vast majority of providers have adopted EHRs,Footnote 55 and those systems largely comply with HHS’s voluntary certification standards because the financial benefits created sufficient demand.Footnote 56 HHS’s ongoing ability to set certification standards has enabled the agency to require EHR systems to export data in standardized interoperability formats, to expose application programming interfaces for data access, and to stop companies’ “information blocking” practices that hamper patients’ ability to access their own health records.Footnote 57
A third possibility is to build public infrastructure or subsidize private infrastructure that coordinates patient data access. With ClinVar, for example, genetic testing laboratories voluntarily submit annotated reports of genetic variants to an NIH-run database, with patient consent. They make these voluntary submissions because, among other reasons, foundations and publishers often require them as a condition of grants or publication.Footnote 58 The presence of established, stable, government-supported infrastructure for data sharing makes such data submission requirements more common and more effective. In this way, legislatures and regulators can incentivize data sharing even without direct regulation.
We integrate aspects from these regimes into a nascent framework for patient access to at-home health care device data. Our framework-in-progress has three elements: A legal hook to induce device manufacturers to make patient data accessible to patients, a technical standard for data storage and access, and infrastructure for patients to deposit and use their data.
As to the first element, legislation or regulation to compel access, akin to HIPAA, would be most forceful and effective. For example, in 2019, Senators Klobuchar and Murkowski proposed creating a HIPAA-like statutory right of patients “to access, amend, and delete a copy of the personal health data that companies collect or use,”Footnote 59 including data from all “cloud-based or mobile technologies that are designed to collect individuals’ personal health data.”Footnote 60
US states also have substantial authority to legislate around HIPAA and could themselves create statutory patient-data access rights. Texas, for example, subjects some HIPAA-exempt entities, such as schools and public health researchers, to some of the obligations that HIPAA imposes.Footnote 61 The California Consumer Privacy Act (CCPA) arguably creates a right of access to health device data not covered by HIPAA, though this theory is so far untested.Footnote 62
Federal regulators could also explore their existing legal authority to require device manufacturers to share data. For example, the Federal Trade Commission could apply its authority to police unfair and deceptive practices to health device makers that market patient access to data as a feature of their products and require that these companies meet their claims.Footnote 63
Alternatively, following the example of the HITECH Act, Congress could provide financial incentives for health devices that meet data access standards, for example, making such devices reimbursable under Flexible Spending Account (FSA) plans or Medicare. A different, intriguing possibility could leverage the status quo of minimal regulation to create new financial incentives and disincentives. Current Food and Drug Administration (FDA) guidance exempts health devices from clearance and approval requirements only if they “present a low risk to the safety of users and other persons.”Footnote 64 As noted above, patients’ data access can enable researchers to study the safety risks of devices, so it could be reasonable for the FDA to change its policies and extend a presumption of safety (and thus of exemption from regulation) only to those devices that make data accessible to patients – and perhaps to qualified researchers, too. Manufacturers that choose to withhold data would not be, per se, prohibited from marketing their products, but would be subject to stricter FDA oversight, which would come with new costs.
The second element of the framework is a technical standard to govern how data is to be stored and accessed. Since health devices typically store data in manufacturers’ cloud servers, there is little sense in requiring less than electronic access via a network-connected application programming interface, akin to the requirements for EHR systems. Furthermore, both research and interoperability would benefit from greater standardization of data formats, in light of the profusion of health devices and manufacturers.Footnote 65 HHS and its Office of the National Coordinator for Health Information Technology could play an important role here, as it did in the standardization of EHRs.
The third element is an institutional infrastructure for aggregating and sharing data. We propose a public, ClinVar-like repository of patient-authorized submissions of appropriately anonymized device data. Without such a repository, patient access and data interoperability will likely still enable new research and other benefits for patients, but they also could augment the power of firms that amass data and broker access. A government-run repository of patient data arguably has several benefits. As a focal point for data aggregation, it empowers all researchers, not just the largest firms. Also, firms that contribute to this central repository share a relationship with the government that could be leveraged to ensure data privacy and security. And a public repository enables the government and outside experts to think through and develop privacy practices that best protect patients, rather than leaving these questions, in the first instance, to profit-driven firms.
V Conclusion
In this chapter, we have argued for a legal right of patients to access their own health device data. We have begun to trace a legal framework for access, one that includes three key elements: A legal “hook” to coax or compel device manufacturers to share data with patients, a technical standard to govern how data is stored and accessed, and an institutional infrastructure for aggregating and sharing data. We intend to expand on this framework in future work.