{"id":344,"date":"2020-06-01T14:25:34","date_gmt":"2020-06-01T18:25:34","guid":{"rendered":"https:\/\/pbacyber.com\/?p=344"},"modified":"2020-06-23T15:31:54","modified_gmt":"2020-06-23T19:31:54","slug":"emerging-covid-19-exposure-notification-technology-data-privacy-and-cybersecurity-issues","status":"publish","type":"post","link":"https:\/\/pbacyber.com\/index.php\/2020\/06\/01\/emerging-covid-19-exposure-notification-technology-data-privacy-and-cybersecurity-issues\/","title":{"rendered":"Emerging COVID-19 Exposure Notification Technology, Data Privacy, and Cybersecurity Issues"},"content":{"rendered":"<p>By Jennifer K. Wagner, J.D., Ph.D<\/p>\n<p>&nbsp;<\/p>\n<p>The ongoing COVID-19 pandemic has raised its own set of data privacy and cybersecurity issues, as people turn to technological solutions to assist with the daunting task of quickly identifying cases of infection (despite persistent problems with availability of diagnostic and serologic testing) and stopping the spread of the disease (despite the phased relaxation of public health safety measures) through contact tracing. Here we take a quick look at the emerging technologies, two competing pieces of federal legislation that have been introduced specifically to address data privacy and cybersecurity issues that COVID-19 technologies raise, and the situation in Pennsylvania.<\/p>\n<p>&nbsp;<\/p>\n<p>A few introductory definitions might be helpful for those interested in this discussion but who might not be familiar with or regularly interact with public health information. The following table is intended to promote better communication among attorneys, scientists, and the public in connection with the many relevant <a href=\"https:\/\/healthitsecurity.com\/news\/covid-19-contact-tracing-apps-spotlight-privacy-security-rights\">data privacy and cybersecurity issues<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<table>\n<tbody>\n<tr>\n<td width=\"126\"><strong>Term<\/strong><\/td>\n<td width=\"354\"><strong>Definition<\/strong><\/td>\n<td width=\"240\"><strong>Sources<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"126\"><strong>Case Investigation <\/strong><\/td>\n<td width=\"354\">\u201cthe identification and investigation of clients with confirmed and probable diagnoses\u201d<\/td>\n<td width=\"240\">CDC <a href=\"https:\/\/www.cdc.gov\/coronavirus\/2019-ncov\/downloads\/case-investigation-contact-tracing.pdf\">Guidance<\/a> 2020<\/td>\n<\/tr>\n<tr>\n<td width=\"126\"><strong>Contact Tracing<\/strong><\/td>\n<td width=\"354\">\u201cthe subsequent identification, monitoring, and support of their contacts who have been exposed to, and possibly infected with, the virus\u201d<\/td>\n<td width=\"240\">CDC <a href=\"https:\/\/www.cdc.gov\/coronavirus\/2019-ncov\/downloads\/case-investigation-contact-tracing.pdf\">Guidance<\/a> 2020<\/td>\n<\/tr>\n<tr>\n<td width=\"126\"><strong>Epidemiology<\/strong><\/td>\n<td width=\"354\">\u201cthe study of the distribution and determinants of health-related states or events in specified populations and the application of this study to the prevention and control of health problems\u201d<\/td>\n<td width=\"240\">JM Last. A Dictionary of Epidemiology, 3rd Ed. New York: Oxford University Press, 1995.<\/td>\n<\/tr>\n<tr>\n<td width=\"126\"><strong>Digital Epidemiology<\/strong><\/td>\n<td width=\"354\">\u00a0\u201cepidemiology that uses digital methods from data collection to data analysis\u201d or, alternatively, \u201cepidemiology that uses data that was generated outside the public health system, <em>i.e., with data that was not generated with the primary purpose of doing epidemiology<\/em>\u201d<\/td>\n<td width=\"240\">H-E Park et al. 2018, <a href=\"https:\/\/www.ncbi.nlm.nih.gov\/pmc\/articles\/PMC6230537\/\">PMC6230537<\/a>; PA Eckhoff and AJ Tatem 2015, <a href=\"https:\/\/www.ncbi.nlm.nih.gov\/pmc\/articles\/PMC4379987\/pdf\/ihv013.pdf\">PMC4379987<\/a>; M Salath\u00e9 2018, <a href=\"https:\/\/www.ncbi.nlm.nih.gov\/pmc\/articles\/PMC5754279\/\">PMC5754279<\/a>. For discussion of an ethical duty to participate, see B Mittelstadt et al. 2018, <a href=\"https:\/\/www.ncbi.nlm.nih.gov\/pmc\/articles\/PMC5943201\/pdf\/40504_2018_Article_74.pdf\">PMC5943201<\/a><\/td>\n<\/tr>\n<tr>\n<td width=\"126\"><strong>(Human) Genetic Epidemiology<\/strong><\/td>\n<td width=\"354\">\u201cthe branch of epidemiology that studies the role of genetic factors and their interactions with environmental factors in the occurrence of disease in various populations\u201d<\/td>\n<td width=\"240\">MJ Khoury 1997, <a href=\"https:\/\/academic.oup.com\/epirev\/article\/19\/1\/175\/616864\">PMID: 9360914<\/a> (citing MJ Khoury, TH Beaty, and BH Cohen 1993)<\/td>\n<\/tr>\n<tr>\n<td width=\"126\"><strong>Molecular Epidemiology<\/strong><\/td>\n<td width=\"354\">\u201cthe study of the distribution and determinants of diseases and injuries in human and nonhuman animal populations using molecular microbiology methods\u201d<\/td>\n<td width=\"240\">LW Riley and R Blanton 2018, <a href=\"https:\/\/www.ncbi.nlm.nih.gov\/pmc\/articles\/PMC6343655\/\">PMC6343655<\/a><\/td>\n<\/tr>\n<tr>\n<td width=\"126\"><strong>Infectious Disease Surveillance<\/strong><\/td>\n<td width=\"354\">\u201ca continuous and systematic process of collection, analysis interpretation, and dissemination of descriptive information for monitoring health problems.\u201d<\/td>\n<td width=\"240\">LW Riley and R Blanton 2018, <a href=\"https:\/\/www.ncbi.nlm.nih.gov\/pmc\/articles\/PMC6343655\/\">PMC6343655<\/a> (internal citation omitted); For history, see also L Simonsen et al. 2016, <a href=\"https:\/\/www.ncbi.nlm.nih.gov\/pmc\/articles\/PMC5144901\/\">PMC5144901<\/a>;<\/p>\n<p>&nbsp;<\/td>\n<\/tr>\n<tr>\n<td width=\"126\"><strong>Syndromic Surveillance<\/strong><\/td>\n<td width=\"354\">\u201cmethods relying on detection of individual and population health indicators that are discernible before confirmed diagnoses are made.\u201d<\/td>\n<td width=\"240\">KD Mandl et al. 2004, <a href=\"https:\/\/pubmed.ncbi.nlm.nih.gov\/14633933\/?from_single_result=PMC353021&amp;expanded_search_query=PMC353021\">PMC353021<\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p><strong><em>Google and Apple Release Exposure Notification API <\/em><\/strong><\/p>\n<p>On May 20, 2020, Google and Apple made a <a href=\"https:\/\/blog.google\/inside-google\/company-announcements\/apple-google-exposure-notification-api-launches\/\">joint announcement<\/a> of their exposure notification application programming interface (API), the culmination of a <a href=\"https:\/\/blog.google\/inside-google\/company-announcements\/apple-and-google-partner-covid-19-contact-tracing-technology\/\">collaboration<\/a> announced in April 2020 to support public health authorities in their response to the COVID-19 pandemic. The Exposure Notification API is intended to facilitate \u201cprivacy-preserving proximity tracing apps\u201d to avoid some of privacy concerns that involved with use of GPS location data by instead relying on Bluetooth contacts. The technology uses an \u201copt-in\u201d approach and makes it possible for privacy-conscious developers to design their contact tracing apps with adherence to data minimalization principles. It enables data to be generated, stored, and processed locally on the users\u2019 own devices and only collects data from those individuals who self-report their positive COVID-19 status. Notably, however, there is nothing to prevent the contact tracing apps that connect to the Exposure Notification API from requesting user permissions and tapping into sensitive GPS location data or other identifying self-reported information, thereby possibly negating the privacy preserving benefits of the API.<\/p>\n<p>&nbsp;<\/p>\n<p>The technology\u2019s function is fairly <a href=\"https:\/\/9to5mac.com\/2020\/05\/23\/apple-and-google-exposure-notification-api\/\">straightforward<\/a>. Devices with apps connecting to the Exposure Notification API will exchange beacons (including an anonymous identifier or key) via Bluetooth with other smart devices nearby. Those identifiers are recorded locally on the device. If an individual uses the app later to self-report their positive COVID-19 status, the Exposure Notification API will push the individual\u2019s recorded beacon keys from the most recent 14 days to the server. Other individuals\u2019 devices enabled with the same app will periodically download the server\u2019s COVID-19 positive beacon keys and check for matches against those beacon keys recorded on their device. If there\u2019s a match, a notification is pushed indicating that the individual has been exposed to someone who has tested positive for COVID-19. The details\u2014such as how long two devices need to be in close proximity to be considered a sufficient interaction to count as an exposure (a minimum of 5 minutes) and what information is ultimately communicated as part of any exposure notification (what the person exposed should do with that information)\u2014are determined by the app developers for the public health authority.<\/p>\n<p>&nbsp;<\/p>\n<p>It is largely up to the states\u2019 public health authorities to determine if and how to use Google and Apple\u2019s Exposure Notification API, thus raising <a href=\"https:\/\/www.wired.com\/story\/covid-19-contact-tracing-app-fragmentation\/\">potential interoperability, privacy, and cybersecurity issues<\/a> inherent in a state-by-state approach. Three states (Alabama, North Dakota, and South Carolina) were <a href=\"https:\/\/www.forbes.com\/sites\/rachelsandler\/2020\/05\/20\/alabama-north-dakota-and-south-carolina-to-debut-apple-and-googles-covid-19-contact-tracing\/#4943adc91732\">quickly reported<\/a> as having committed to using the Exposure Notification API (as were 22 countries, with Switzerland already launching the <a href=\"https:\/\/www.zdnet.com\/article\/the-worlds-first-contact-tracing-app-using-google-and-apples-api-goes-live\/\">first contact tracing app using the Exposure Notification API<\/a>). Other states might be reluctant to trust Google\u2019s commitment to privacy (e.g., <a href=\"https:\/\/www.washingtonpost.com\/technology\/2020\/05\/27\/google-android-privacy-lawsuit\/\">Arizona Attorney General filed a lawsuit against Google<\/a> alleging it continued to track Android users\u2019 locations via its browser searches, map, and weather app features even after users disabled location tracking settings unless a second, harder-to-locate setting was also disabled). Potential <a href=\"https:\/\/www.wired.com\/story\/apple-google-contact-tracing-strengths-weaknesses\/\">flaws have been reported<\/a> for the contact tracing apps that might rely upon the Exposure Notification API, including the risk of false positives and risks of re-identification by the public health authority if the device IP address or GPS location or other identifiers are collected with the app (notwithstanding the efforts that Google and Apple had taken to ensure the Exposure Notification API itself limits data collection to only those who are infected and even then limits data collection to anonymized data). <a href=\"https:\/\/www.wired.com\/story\/covid-19-contact-tracing-app-fragmentation\/\">One obvious challenge<\/a> is that people are mobile, cross jurisdictional borders, and interact with individuals who might not be residents of the same state: states will need to determine whether to cooperate with one another and share beacon key information about those who have self-reported as COVID-19 positive so that app users in both states can be properly notified of the exposure. Neighboring states who take distinct approaches (one Bluetooth-based and the other GPS location-based) could undermine the utility of a contact tracing app by missing cross-jurisdiction notifications.<\/p>\n<p><strong><em>\u00a0<\/em><\/strong><\/p>\n<p><strong><em>COVID-19 Might Shape U.S. Data Privacy and Cybersecurity Policy More Broadly<\/em><\/strong><\/p>\n<p>Experts have increasingly weighed in on the topic of technology as part of the public health response. For example, <a href=\"https:\/\/www.cigionline.org\/articles\/digital-response-outbreak-covid-19\">Sean McDonald has pointed out<\/a> the need for governance not merely good intentions, recognizing \u201ctechnology can cause an enormous range of harms during disaster, from using ineffective tools to enabling sweeping abuses of power.\u201d Additionally, <a href=\"https:\/\/science.sciencemag.org\/content\/368\/6494\/951.full\">Michelle M. Mello and C. Jason Wang have together outlined ethical issues<\/a> raised by digital epidemiology (distinct from contact tracing), highlighting how privacy-preserving technologies are actually \u201cantithetical to effective epidemiology and noting that \u201charnessing the power and ingenuity of the tech sector\u201d necessitates \u201ccarefully placed constraints\u201d that have not yet been created.<\/p>\n<p>&nbsp;<\/p>\n<p>Two relevant and competing pieces of Federal legislation have been introduced. The COVID-19 Consumer Data Protection Act of 2020 (<a href=\"https:\/\/www.congress.gov\/116\/bills\/s3663\/BILLS-116s3663is.xml\">S.3663<\/a>) was introduced on May 7, 2020 by Senator Wicker (R-MS) with four original cosponsors: Sen. Thune (R-SD), Sen. Moran (R-KS), Sen. Blackburn (R-TN), and Sen. Fischer (R-NE). The bill was referred to the Senate Committee on Commerce, Science, &amp; Transportation, for which Senator Wicker serves as <a href=\"https:\/\/www.commerce.senate.gov\/chairman\">chairman<\/a>. The Public Health Emergency Privacy Act (<a href=\"https:\/\/www.congress.gov\/bill\/116th-congress\/senate-bill\/3749\">S.3749<\/a>\/<a href=\"https:\/\/www.congress.gov\/bill\/116th-congress\/house-bill\/6866\/text?q=%7B%22search%22%3A%5B%22HR.6866%22%5D%7D&amp;r=1&amp;s=1\">HR.6866<\/a>) was introduced shortly thereafter on May 14, 2020 by Senator Blumenthal (D-CT) and Senator Warner (D-VA), where it was referred to the Senate <a href=\"https:\/\/www.help.senate.gov\/\">HELP Committee<\/a> (a committee on which Sen. Bob Casey serves). A version was introduced in the House by Representative Eshoo (D-CA-18) with five original cosponsors\u2014 Rep. Schakowsky (D-IL-9), Rep. DelBene (D-WA-1), Rep. Clarke (D-NY-9), Rep. Butterfield (D-NC-1), and Rep. Cardenas (D-CA-29)\u2014and was referred to the House <a href=\"https:\/\/energycommerce.house.gov\/\">Committee on Energy and Commerce<\/a> (a committee on which Rep. Doyle, D-PA-18, serves). While both bills would require affirmative express consent, would set basic privacy and security requirements (including data minimization), and give the Federal Trade Commission the primary responsibility to enforce the law, the bills are <a href=\"https:\/\/iapp.org\/news\/a\/democrats-propose-public-health-emergency-privacy-act\/\">different<\/a> in key aspects.<\/p>\n<p>&nbsp;<\/p>\n<p>The COVID-19 Consumer Data Protection Act is framed narrowly and requires basic cybersecurity and data privacy protections. Any individual or entity that must comply with the Federal Trade Commission Act as well as any Common Carrier or Non-Profit Organization would be subject to this law. The data covered would include personal health information only when collected for a covered purpose (i.e., tracking the spread, signs, or symptoms of COVID-19; measuring compliance with social distancing and other safety interventions; and conducting contact tracing for COVID-19 cases) as well as geolocation data, proximity data, device data (IP address, serial number, etc.). It would expressly exclude from \u201ccovered data\u201d any aggregated data, business contact information, de-identified data, employee screening data, and publicly available information. Individuals would have a right to \u201creport\u201d inaccuracies in the data but not necessarily insist on corrections. The bill would not require data deletion but instead would give those subjected to the law the option to delete or de-identify covered data when it is no longer being used for purposes related to the COVID-19 public health emergency. Reporting would be required every 60 days to indicate how many individuals are affected by the data collection, processes, or transfers. S.3663 would give the Federal Trade Commission primary enforcement authority and also allow the State\/Territorial Attorneys General to enforce the law; however, it would not allow for individuals to have a private cause of action. Notably, this version would preempt any state laws on point.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/www.washingtonpost.com\/technology\/2020\/05\/27\/google-android-privacy-lawsuit\/\">By contrast,<\/a> the Public Health Emergency Privacy Act is framed more broadly, protecting a broader scope of COVID-19 emergency health data (including not only past, present, or future health status but also any other information in conjunction with it, including geolocation data, proximity data, demographic data, contact information, any other information from a personal device) and also requiring compliance by not only private individuals and entities but also public (governmental) entities with five exclusions (health provider, public health authority, service provider, de minimis collector or processor, and individual acting in personal\/household capacity). The bill also offers stronger data privacy protections and data use restrictions, including important provisions (1) to prohibit the use of emergency health data for advertising; (2) to prohibit discrimination in commerce, public accommodations, employment, financial, housing, insurance, and education contexts; and (3) to prohibit the denial of voting rights based on an individual\u2019s emergency health data, medical conditions, or participation in a program involving emergency health data. It would enable individuals to have not only the ability to report inaccuracies in the data but to \u201ccorrect\u201d them. The bill also would require data to be destroyed within 60 days of the end of the emergency or within 30 days of an individual revoking consent. Public reporting would be required every 90 days for those whose data practices affect at least 100,000 people. S.3749 would be enforced by the Federal Trade Commission, by the State\/Territorial Attorneys General, and by individuals via a private cause of action with tiered relief for negligent violations and reckless, willful, or intentional violations. This version would not preempt state law.<\/p>\n<p>&nbsp;<\/p>\n<p><strong><em>Relevance to Pennsylvania<\/em><\/strong><\/p>\n<p><a href=\"https:\/\/9to5mac.com\/2020\/05\/21\/covid-19-exposure-notification-api-states\/\">Reports<\/a> about which states have committed to using the Google and Apple Exposure Notification API have indicated that Pennsylvania was not yet decided. The Pennsylvania Department of Health (PA DOH) website provides helpful information regarding its <a href=\"https:\/\/www.health.pa.gov\/topics\/disease\/coronavirus\/Pages\/Contact-Tracing.aspx\">plans for contact tracing<\/a>, including its use of the MITRE-Sara Alert contact monitoring app (which is web-based and <a href=\"https:\/\/whyy.org\/articles\/the-technology-and-privacy-tradeoffs-behind-covid-19-contact-tracing-apps\/\">reportedly<\/a> used by at least four states\u2014PA, WA, VT, and AR\u2014and the Northern Mariana Islands). While PA DOH has not expressly indicated (as of May 30, 2020) whether it is building an app that will rely upon Google and Apple\u2019s Exposure Notification API, it indicates, \u201cThe department will also examine Bluetooth proximity exposure notification technology that does not use GPS navigation data,\u201d suggesting this remains a possibility.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/www.statnews.com\/2020\/04\/24\/contact-tracing-public-private-partnerships-covid-19\/\">In Pennsylvania, public-private partnerships have been key<\/a> to COVID-19 contact tracing. Contact tracing is labor intensive, and\u2014if the effort is to be effective in slowing and ultimately stopping the spread of the infectious disease\u2014time is of the essence. The pursuit of technological solutions to help ease the operational burdens of that process must be expected, but it is imperative that data stewardship principles (including data governance as well as cybersecurity, data privacy, nondiscrimination) be identified, implemented, assessed to ensure their fulfillment, and continually improved.<\/p>\n<p>&nbsp;<\/p>\n<p>Unfortunately, contact tracing and exposure notification for COVID-19 has become <a href=\"https:\/\/6abc.com\/-representative-brian-sims-covid-19-house-of-representatives-pennsylvania-coronavirus\/6217016\/\">an unnecessarily partisan topic<\/a> in Pennsylvania\u2019s General Assembly, although no legislation specific to COVID-19 data privacy and cybersecurity appears to have been introduced yet.<\/p>\n<p>&nbsp;<\/p>\n<p><strong><em>Concluding Remarks<\/em><\/strong><\/p>\n<p>Like many things these days, it is uncertain whether federal legislation will come to fruition or whether a commonwealth-coordinated effort for contact tracing and exposure notification in Pennsylvania will be implemented. Nevertheless, the public health challenges of COVID-19 and the question of how to use emerging technologies responsibly will persist, at the very least, until a safe and effective vaccine has been developed and universally administered.<\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<p>Jennifer K. Wagner, J.D., Ph.D., is a solo practicing attorney and also conducts research as an Assistant Professor in the Center for Translational Bioethics &amp; Health Care Policy at Geisinger. She is a former contributing editor of the <em>Genomics Law Report<\/em> and has published scholarly articles in prominent legal and scientific journals, including the <em>Journal of Law &amp; Biosciences<\/em>; <em>Journal of Law, Medicine, &amp; Ethics; Albany Law Journal of Science &amp; Technology<\/em>; <em>Virginia Sports and Entertainment Law Journal<\/em>; <em>North Carolina Journal of Law and Technology<\/em>; <em>Nature Communications<\/em>; <em>Nature Medicine; American Journal of Human Genetics<\/em>; <em>Genetics in Medicine; and PLOS Genetics<\/em>. She served as a AAAS Congressional Fellow in a U.S. Senator\u2019s office in 2014-2015, and her work has been cited by the Supreme Court of the United States. You may follow her on Twitter as <a href=\"https:\/\/twitter.com\/DNAlawyer\" target=\"_blank\" rel=\"noopener noreferrer\">@DNAlawyer<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Jennifer K. Wagner, J.D., Ph.D &nbsp; The ongoing COVID-19 pandemic has raised its own set of data privacy and cybersecurity issues, as people turn to technological solutions to assist with the daunting task of quickly identifying cases of infection (despite persistent problems with availability of diagnostic and serologic testing) and stopping the spread of <br \/><a class=\"read-more-button\" href=\"https:\/\/pbacyber.com\/index.php\/2020\/06\/01\/emerging-covid-19-exposure-notification-technology-data-privacy-and-cybersecurity-issues\/\">Read More &raquo;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[6,4,23],"tags":[],"_links":{"self":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/344"}],"collection":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/comments?post=344"}],"version-history":[{"count":6,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/344\/revisions"}],"predecessor-version":[{"id":359,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/344\/revisions\/359"}],"wp:attachment":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/media?parent=344"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/categories?post=344"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/tags?post=344"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}