At Carbn, we're working to give developers a way to solve GDPR with code vs. a legal paper exercise. Basically, privacy-by-design for your existing infrastructure and automated privacy office. Would love to hear feedback!
HN user
filman82
Healthcare startup co-founder, crypto investor, software product designer and evangelist, passionate about contributing
@filsoutherland
Verifying my Blockstack ID is secured with the address 112mTQCvh7BU8g4bgpdqsiJvPk2cAqth2s https://explorer.blockstack.org/address/112mTQCvh7BU8g4bgpdqsiJvPk2cAqth2s
Great illustration of the pervasiveness in personal data collection that IoT will bring to our future. Check out ProjectVRM from Harvard https://cyber.harvard.edu/projectvrm/Main_Page. Vendor Relationship Management is a concept focused on empowering users in their relationship with service providers. The basic idea being that services (supply side) are in control of the relationship in Web and IoT services today, but historically, control shifts over time to users (demand side).
"You agreed to let us do this. We gave you notice of our privacy practices, and you consented."
The EU regards privacy as a right and the recently passed General Data Protection Rule (GDPR) enforces this right for EU citizens worldwide. US companies are slow to realize this and there will be a flood of litigation from Europe against US companies that service EU citizens when this law takes effect in 2018. GDPR implements many of the concepts of VRM and has the stated objective of putting users in charge of their widely-defined personal information. Consent has to be explicit and opt-in prior to collection, so IoT companies would have to make sure that they either differentiated EU citizens and required consent prior to capture or implement standardized policies that respect GDPR across the board.
My thinking is that the disruptive companies of tomorrow will have user trust and personal data collection transparency as a key differentiator. The problem is that the technology to enable this easily isn't there yet. Privacy and personal data management are complex and remain the domain of health companies subject to HIPAA and European privacy wonks. My team is working on a platform to bring easy and transparent personal data management (including consent) to all services that collect personal information. Check it out - www.carbn.io
I'm the CTO at ALMSA Health - we have a SaaS EHR used nationally in Assisted Living and Skilled Nursing communities. Do you plan to stream your station online? Would love to look at linking to it - get in touch if you'd like some perspective on the development of EHR platforms tailored toward the long-term care industry - fils@almsahealth.com