Release time:2023-10-18 03:00:49
Where is the information generated in the course of receiving medical consultation, laboratory tests, medical examinations and diagnosis at hospitals stored? How long shall such information be retained? Will such information be used by others without our knowledge? Is there any risk of information leakage? In several cases involving personal information leakage of medical institutions, we have noted that these issues indeed cannot be ignored. This article cites typical domestic and foreign cases, analyzes the weak links in the information security of medical institutions, and proposes corresponding countermeasures.
I. The high sensitivity of medical information results in the gravity of consequences arising from its leakage.
U.S. LabMD Medical Information Breach Case
The defendant in this case is a medical testing institution located in the State of Georgia, the United States, which provides laboratory testing services to hospitals across the United States. The information collected by the defendant not only includes common basic personal information, social security account numbers, bank card numbers and other information, but also covers a large volume of highly sensitive medical information, such as laboratory test information, test codes, test results, diagnostic information, medical history, etc. According to statistics, the defendant has obtained and stored the aforesaid information of approximately 750,000 natural persons in the course of its business operations.
In 2008, a monthly financial statement belonging to the defendant was found on a P2P (peer-to-peer) website. The 1,718-page statement contains information including the names, dates of birth, 9-digit social security numbers, and CPT identification codes for laboratory testing of approximately 9,500 natural persons. In October 2012, when the police of Sacramento, the United States, searched the residence of a criminal suspect involved in the crime of theft of citizens' personal information, they discovered 40 "daily statement" documents and 9 check copies, involving approximately 682 individuals. The police suspected that these documents were leaked from the defendant LabMD, and notified the U.S. Federal Trade Commission (FTC) of the relevant situation. The FTC launched an investigation into LabMD, and issued a regulatory penalty order against the defendant LabMD in July 2016.
This case has triggered considerable social impact in the United States. The medical information of American citizens was made public online without their full knowledge. According to official statistics, victims are spread across multiple states throughout the United States. A major focus of controversy in this case is whether the act of disclosing medical information constitutes substantial injury, which is a key element for determining the illegality of the defendant's conduct. The Administrative Law Judge (ALJ) held a negative position on this issue at the initial adjudication stage of the case, finding that the disclosure of such information did not cause objective substantial injury to the victims, but only certain subjective harm and mental damage. At the final adjudication stage, the Federal Trade Commission (FTC) revoked the ALJ's ruling, and determined that the information disclosure act constitutes "substantial injury or a high likelihood of substantial injury". The Commission held that the 1,718-page document contained patients' laboratory test codes, involving highly sensitive personal information such as HIV, herpes, prostate cancer, and testosterone levels. The aforesaid information was shared on the P2P network by LabMD employees for as long as 11 months, during which period anyone could download it via P2P software. The disclosure of such information may lead to patients' identity theft, medical record theft, subsequent misdiagnosis, and endangerment of patients' health and safety. Regardless of whether such risk actually materializes, the damage once incurred will be extremely severe, thus it has constituted a "highly likely risk of substantial injury". Furthermore, medical information involves a large volume of personal privacy, and its disclosure will cause enormous psychological harm to patients, which in itself constitutes a serious tort.
This case fully exemplifies the high sensitivity of medical information and its significance in information security efforts. Pursuant to the *Personal Information Protection Law of China*, biometric information and medical and health information of natural persons fall into the category of "sensitive personal information". As stipulated by law, the aforesaid information refers to personal information that is likely to infringe upon the personal dignity of natural persons or endanger their personal and property security once leaked or illegally used. The processing of sensitive personal information shall obtain the separate consent of the individual. Due to its high sensitivity, medical information is also included in the key protection scope of judicial authorities. The *Interpretation on Several Issues Concerning the Application of Law in Handling Criminal Cases Involving Infringement of Citizens' Personal Information* sets the lowest criminal conviction threshold for sensitive personal information including medical information, where 50 pieces of such information are sufficient to constitute a crime, while the criminal conviction thresholds for ordinary sensitive information and other types of information are set at 500 pieces and 5,000 pieces respectively. At the press conference for the release of the Interpretation, responsible persons of relevant competent authorities stated that the crime of infringing on citizens' personal information has become the predicate offense for all other types of crimes. Most offenses, including extortion, telecom fraud and other various crimes, are premised on illegal acquisition of personal information. Sensitive personal information of citizens such as location tracking information, communication content, credit information, property information, accommodation information and transaction information concerns personal and property security. After being illegally obtained, sold or provided, such information is highly likely to trigger related crimes including kidnapping, fraud and extortion, and entails greater social harmfulness. From the perspective of public security organs, cracking down on crimes of infringing on citizens' personal information is one of the most important measures for cybercrime governance.
II. "Malfeasance by 'Insider Moles'": "Targeted" Information Leakage Involving Collusion between Internal and External Parties
Case 1 of Maternity Information Leakage in Nanning, Guangxi
The defendant Nong Mou was a physician assistant at a community health service center in Qingxiu District, Nanning City. He had worked at the center as a women's health care guidance physician since March 2016, responsible for health guidance and examination work for postpartum women. Defendant Yang Mou operated a postpartum recovery institution in Nanning City, Guangxi Zhuang Autonomous Region. To obtain business resources, he contacted five defendants including Nong Mou to acquire personal information of puerperae and paid them remuneration. Starting from December 2017, Nong Mou logged into the center's internal "Gui Fu'er System" (Guangxi Maternal and Child Health Information System) with his personal username and password, searched for puerperae's personal files, took photos of the files and sent them to Defendant Yang Mou via WeChat. The information involved included puerperae's names, phone numbers, addresses, prenatal examination records, delivery methods and delivery institutions, as well as the gender and date of birth of newborns, with an average of 200 pieces of information sent per month. As ascertained by the court, Nong Mou illegally provided 1,304 pieces of relevant personal information of citizens and obtained illegal gains of RMB 24,000. His act falls under the circumstance of "providing other persons with citizens' health and physiological information obtained in the course of performing duties, with serious circumstances", which constitutes the crime of infringing upon citizens' personal information. He was sentenced to fixed-term imprisonment of one year and six months, and a fine of RMB 30,000.
Case No. 2 of Information Leakage of Pregnant and Lying-in Women in Nanning, Guangxi
Wu Jia and Wu Yi operated a health massage center in Jiangnan District, Nanning City, Guangxi Zhuang Autonomous Region, which mainly provided services for postpartum women. To expand their customer base, Wu Jia proposed to Wei Mou, a supervisor nurse in the obstetrics department of a hospital in Nanning, that Wei provide personal information of postpartum women, and promised to pay Wei RMB 50 or RMB 60 as remuneration for each referred client, plus an extra 10% commission if the client made subsequent consumption after purchasing a membership card. From 2018 to June 2020, under the pretext of requiring data for thesis writing, Wei Mou either deceived colleagues with access privileges to log into the hospital's "Nurse Station" system to query postpartum women's personal information, take photos and send the photos to Wei, or independently queried postpartum women's personal information stored in the hospital's "Guifu'er" System via the department's office computer and took photos of the information. Wei irregularly sent the aforesaid photos of postpartum women's personal information to Wu Jia via WeChat. Wu Jia and Wu Yi then used the above-mentioned information to arrange for their employees to contact postpartum women via telephone to solicit clients.
Upon investigation, Wei sold more than 500 pieces of puerperas' health and physiological information, including their names, home addresses, telephone numbers, delivery dates, delivery methods and other relevant details, to Wu A and Wu B. The people's procuratorate held that Wei sold the information obtained in the course of performing his duties to others, and shall be given a heavier punishment in accordance with the law. On December 16, 2020, the People's Court of Jiangnan District convicted Wei, Wu A and Wu B of the crime of infringing upon citizens' personal information, and respectively sentenced them to fixed-term imprisonment ranging from six months to ten months (the ten-month term of imprisonment was attached with a two-year suspended sentence) and concurrent fines.
"Malfeasance by internal moles" has become the primary cause of current personal information-related crimes. At the joint press conference on the *Interpretation on Several Issues Concerning the Application of Law in Handling Criminal Cases Involving Infringement of Citizens' Personal Information* held by the Supreme People's Court, the Supreme People's Procuratorate and the Ministry of Public Security, responsible persons of relevant authorities stated that a considerable number of citizens' personal information leakage cases are committed by internal personnel, and traces of participation by internal moles can also be found in numerous citizens' personal information trading cases. Internal-caused information leakage is identified in many citizens' personal information trading cases solved by public security organs. At present, the most harmful offences are mainly committed by personnel from industries including banking, education, industry and commerce, telecommunications, express delivery, securities and e-commerce. In terms of crime governance, cracking down on the source of crimes has become the top priority of public security organs. To effectively intensify the punishment of such acts, the aforesaid judicial interpretation imposes heavier penalties on information leakage committed by internal personnel. For acts falling under the circumstance of "selling or providing to others citizens' personal information obtained in the course of performing duties or providing services", the quantity and amount thresholds for determining "serious circumstances" shall be halved. In accordance with the Interpretation, where medical institution staff provide medical information by taking advantage of their functional convenience, the dual criteria of "sensitive information + special subject" shall apply to the criminalization threshold, and provision of 25 pieces of such information shall constitute a criminal offence. After the medical information leakage case in Nanning occurred, the People's Procuratorate of Jiangnan District, Nanning City, in response to problems of the involved hospitals such as inadequate management of citizens' personal information, weak disciplinary restraint on employees and insufficient rule of law education, issued procuratorial suggestions to urge the involved hospitals to carry out retroactive inspection of their information security management status, improve patient information security management measures and systems, and prevent leakage of citizens' personal information from the source.
Author of this Article: Li Chao