Google Stumbles into Healthcare

Google’s researchers apparently didn’t obtain HIPAA releases from patients.

Recently, Google has made some stunning stumbles as it moves into the realm of handling healthcare data. 

First, this is surprising, considering the growing distrust among the public and regulators of platforms like Google and Facebook. Second, and more surprisingly, it seems Google failed to make sure it brought people to the projects who understood HIPAA.

On Nov. 11, Ascension announced on its website:

“Ascension, one of the nation’s leading non-profit health systems, is working with Google to optimize the health and wellness of individuals and communities, and deliver a comprehensive portfolio of digital capabilities that enhance the experience of Ascension consumers, patients, and clinical providers across the continuum of care.”

“The Ascension-Google collaboration will include:    

  • Modernizing Ascension’s infrastructure by transitioning to the secure, reliable, and intelligent Google Cloud Platform. Key elements of this work will focus on network and system connectivity, data integration, privacy and security, and compliance.
  • Transitioning to Google’s G Suite productivity and collaboration tools. Using G Suite will enhance Ascension associates’ ability to communicate and collaborate securely in real-time, supporting interdisciplinary care and operations teams across Ascension sites of care.
  • Exploring artificial intelligence/machine learning applications that will have the potential to support improvements in clinical quality and effectiveness, patient safety, and advocacy on behalf of vulnerable populations, as well as increase consumer and provider satisfaction.”

Just days later, Google was apparently caught off-guard by what would have been one of the largest HIPAA violations in the history of HIPAA (the Health Insurance Portability and Accountability Act).

On Nov. 15, two days before Google was set to publicly post more than 100,000 images of human chest X-rays, they got a call from the National Institutes of Health (NIH), which had provided the images: and NIH noted that some of them contained details that could be used to identify the patients.

Google canceled the project. This is based on emails reviewed by The Washington Post and an interview with a person familiar with the matter, who spoke on the condition of anonymity to Washington Post reporters.

Stunningly, it appears that Google’s researchers didn’t obtain HIPAA releases from patients. They had rushed ahead without any thought of compliance issues. These assertions were apparently documented in emails the Washington Post obtained from a Freedom of Information Act request.

Considering our current political environment, in this election cycle, it would be very surprising to see regulators taking up privacy concerns like this one with Google. My question is, would you trust your medical records to the same people who don’t care if their subscribers running for elected office post fake political ads?

Facebook
Twitter
LinkedIn

Timothy Powell, CPA, CHCP

Timothy Powell is a nationally recognized expert on regulatory matters, including the False Claims Act, Zone Program Integrity Contractor (ZPIC) audits, and U.S. Department of Health and Human Services (HHS) Office of Inspector General (OIG) compliance. He is a member of the RACmonitor editorial board and a national correspondent for Monitor Mondays.

Related Stories

Leave a Reply

Please log in to your account to comment on this article.

Featured Webcasts

AI, Audits, and the Future of the Revenue Cycle

Artificial intelligence is rapidly transforming healthcare revenue cycle operations, from coding and auditing to compliance and denials. Join industry leaders Pam Warren (MaineHealth) and Raemarie Jimenez (AAPC) for a live fireside chat exploring how AI is changing workflows, workforce roles, payer-provider dynamics, and compliance risk—and what organizations should be doing now to prepare.

June 17, 2026

Trending News

Featured Webcasts

Ask Dr. Hirsch: Clarifying Medicare’s Most Misunderstood Rules – Part 2

Medicare regulations are complex and even seasoned professionals struggle to apply them consistently. Due to overwhelming demand, Dr. Hirsch returns for Part 2 of Ask Dr. Hirsch: Clarifying Medicare’s Most Misunderstood Rules to answer even more of Medicare’s most misunderstood questions, covering inpatient status, observation, SNF access, Medicare Advantage denials, and more. Join Dr. Hirsch as he provides clear, referenced answers to real-world questions submitted by your peers, helping you navigate Medicare compliance with confidence and clarity.

June 18, 2026

Reengineering Utilization Management: Building an Adaptive Model for the New Payer Era

Traditional utilization management models can no longer keep pace with regulatory shifts, payer scrutiny, and operational pressures. In this webcast, Tiffany Ferguson, LMSW, CMAC, ACM, ACPA-C, introduces an Adaptive Model strategy that modernizes UM through role specialization, technology-driven workflows, and proactive, team-based processes. Attendees will learn how to restructure programs to improve efficiency, strengthen clinical collaboration, and enhance financial performance in a rapidly changing healthcare environment.

May 20, 2026

Compliance for the Inpatient Psychiatric Facility (IPF-PPS): Minimizing Federal Audit Findings by Strengthening Best Practices

Federal auditors are intensifying their focus on inpatient psychiatric facilities, using advanced data analytics to spotlight outliers and pursue high‑dollar repayments. In this high‑impact webcast, Michael Calahan, PA, MBA, Compliance Officer and V.P., Hospital & Physician Compliance, breaks down what regulators are really targeting in IPF-PPS admissions, documentation, treatment and discharge planning. Attendees will learn practical steps to tighten processes, avoid common audit triggers and protect reimbursement and reduce the risk of multimillion-dollar repayment demands.

April 9, 2026

Mastering MDM for Accurate Professional Fee Coding

In this timely session, Stacey Shillito, CDIP, CPMA, CCS, CCS-P, CPEDC, COPC, breaks down the complexities of Medical Decision Making (MDM) documentation so providers can confidently capture the true complexity of their care. Attendees will learn practical, efficient strategies to ensure documentation aligns with current E/M guidelines, supports accurate coding, and reduces audit risk, all without adding to charting time.

March 31, 2026

Trending News

Celebrate Lab Week with MedLearn! Sign up to win one year of our Laboratory All Access Pass! Click here to learn more →

Have a Medicare regulation question you’d love Dr. Hirsch to answer? Now is your chance! CLICK HERE to learn more→

Happy National Doctor’s Day! Learn how to get a complimentary webcast on ‘Decoding Social Admissions’ as a token of our heartfelt appreciation! Click here to learn more →

This Memorial Day, we honor those who gave all for our freedom. Take 20% off sitewide through May 29 with code MEMORIAL26 at checkout

CYBER WEEK IS HERE! Don’t miss your chance to get 20% off now until Dec. 1 with code CYBER25

CYBER WEEK IS HERE! Don’t miss your chance to get 20% off now until Dec. 2 with code CYBER24