Chapter 4
The Secretive Giant Behind the Data Trade
IMS Health, a secretive giant in the health data industry with $2.9 billion in revenue in 2015, gathers anonymized medical dossiers on hundreds of millions of patients who know nothing about the company. Despite its massive influence, IMS has historically shunned public attention, with executives routinely declining interview requests.
The company's origins trace back to Ludwig Wolfgang Frohlich, who emigrated from Nazi Germany to the United States in 1935, establishing a Madison Avenue medical advertising agency by 1943. He soon befriended Arthur Sackler, and despite being born worlds apart-Frohlich in Germany and Sackler in Brooklyn to immigrant Jewish parents-they shared much in common, including birth dates just weeks apart in 1913 and commitments to self-reliance and hard work.
These "med men" revolutionized pharmaceutical advertising during the post-war "miracle drugs" era. Despite the cutthroat competition typical of Madison Avenue, Frohlich and Sackler maintained a secret alliance. Rather than competing for accounts, they met behind closed doors to divide business and share client information. This arrangement allowed them to represent competing drug companies without conflicts of interest.
To win new business and prove their advertising effectiveness, Frohlich created Intercontinental Marketing Services (IMS) as a market research company. Ad clients paid for research to see how their products performed against competitors, which the agency would leverage to recommend more advertising-either to protect market leadership or boost lagging products.
Frohlich replicated successful market research models by establishing Intercontinental Marketing Services in Germany, sending executive David Dubow to set up the Institut fur Medizinische Statistik, which published its first national market estimates in 1957 using wholesale pharmacy purchase data. This commercial success quickly expanded to other Western European countries.
Despite speculation among his staff about his background-with some suspecting Nazi ties while others thought he might be Jewish-Frohlich maintained strict privacy about his past. Research revealed he was born in Giessen before WWI, briefly joined the Nazi youth work brigade after Hitler's rise, and studied briefly at Goethe University before emigrating to New York in 1935. Contrary to what even his closest associates believed, documents confirmed Frohlich was indeed Jewish, a heritage he concealed throughout his life alongside his homosexuality amid persistent American anti-Semitism.
IMS moved closer to patient data by soliciting prescription details from doctors, initially offering token gifts like records as compensation. The company eventually increased compensation to about $50 monthly for doctors and paid pharmacies roughly a penny per prescription to share or allow microfilming of dispensing records.
By the 1970s, Frohlich's advertising empire had expanded internationally with offices across major cities and annual billings exceeding $43 million. His career ended abruptly when he collapsed during a staff meeting after returning from vacation. Diagnosed with a brain tumor, he died in September 1971 at age 58.
Chapter 5
The Doctor's Prescription: A Valuable Commodity
After graduating college in 1969, Shel Silverberg joined Lea Associates, which gathered medical data by having doctors complete questionnaires about diagnoses and prescriptions. When IMS acquired Lea in 1972, Silverberg rose to become vice president for international marketing. In 1978, McKesson Corporation hired him away to run Pharmaceutical Data Services (PDS), challenging IMS's monopoly in medical data.
By the early 1980s, PDS began ranking individual doctors into tiers based on their prescribing habits, information gathered through surveys that paid doctors $2-10 to report their prescription volumes and medication preferences. This data allowed pharmaceutical companies to strategically target high-prescribing physicians and compensate sales representatives accordingly.
Drug companies have used "detailers" since the 1850s to convince doctors to prescribe their medications. Before computers, reps would sweet-talk pharmacists to learn doctors' prescribing habits. By 1988, PDS was gathering prescriptions from 8,000 pharmacies (about 35% of all prescriptions) by paying about a penny per script.
IMS Health was initially slow to follow in compiling doctor-specific prescription data, partly to protect sales of its profitable Drug Distribution Data service. After Dun & Bradstreet acquired IMS for nearly $1.7 billion in 1988, IMS finally launched its Xponent service in 1993, marketing it as a precision targeting tool that could dramatically boost pharmaceutical sales. IMS claimed that "winning just one more prescription per week from each prescriber yields an annual gain of $52 million in sales."
Doctor-identified data gave pharmaceutical reps a secret weapon as powerful as X-ray vision. Shahram Ahari, who joined Eli Lilly straight out of college in 1998, discovered these reports were "super-top-classified"-reps were forbidden from mentioning them to doctors or bringing laptops containing this data into physicians' offices.
During his training, Ahari learned that personality, attractiveness and enthusiasm mattered more than scientific knowledge. His job involved categorizing doctors by personality types and tailoring approaches accordingly. Ahari meticulously recorded personal details about physicians-their families, hobbies, interests-to build seemingly genuine friendships. Using IMS data, he and his partner focused on the top 200 prescribers in their territory of 450 doctors, lavishing the 50 biggest prescribers with expensive dinners at Manhattan's finest restaurants.
Though company guidelines officially limited spending to $100 per doctor per meal, managers allowed creative accounting to circumvent these limits for top prescribers. Ahari spent $60,000-$80,000 annually on catering and dining. If doctors didn't increase prescriptions of Eli Lilly drugs after receiving such generosity, the perks would gradually disappear-from gourmet lox to donuts, creating pressure not just from the rep but from office staff accustomed to the freebies.
Chapter 6
When Physicians Fight Back
Dr. Peter Klementowicz initially welcomed pharmaceutical representatives to his New Hampshire cardiology practice, rationalizing that their visits provided free samples for his poorest patients. His perspective changed dramatically when two reps brought lunch and showed him a thick printout detailing regional doctors' prescribing habits, pressuring him to change his prescribing patterns. Outraged, he ordered them to leave.
Klementowicz was stunned by how thoroughly pharmaceutical companies tracked his prescribing, feeling they had stolen his "intellectual property." While his reaction was particularly strong, most doctors remained unaware for years that sales representatives possessed detailed information about their prescribing patterns.
Cindy Rosenwald, Klementowicz's wife and a freshman Democratic representative in New Hampshire, learned about prescription data mining through articles provided by an AARP lobbyist. A 2003 Boston Globe expose revealed the hidden trade in physician-identified data, which shocked and angered Rosenwald, who viewed it as an invasion of privacy likely to increase drug costs.
In 2006, Rosenwald proposed legislation to ban commercial use of prescription data. New Hampshire passed the Prescription Information Confidentiality Act in June 2006, prohibiting the use of prescription records for marketing while allowing public health applications. Despite New Hampshire's small size, the legislation sparked similar bills in Vermont and Maine.
Data miners fought against the new state laws restricting prescription data use, suing in federal court. Throughout the litigation, data miners argued their First Amendment right to gather prescribing information. Their lawyer Tom Julin positioned them as "publishing companies... similar to newspapers" that simply report on doctors' prescribing decisions.
When the Vermont case reached the Supreme Court in April 2011, Justice Kennedy delivered a 6-3 decision favoring IMS and other data miners, ruling that "speech in aid of pharmaceutical marketing" deserved First Amendment protection. The Court found Vermont's law problematic because it selectively restricted pharmaceutical companies while allowing researchers to access the same data.
Despite this defeat for privacy advocates, physicians have increasingly restricted pharmaceutical representatives, with one study showing that by 2014, 49% of doctors placed moderate to severe restrictions on sales visits, more than double the 2008 figure. Meanwhile, data miners shifted focus to an even more intimate frontier: comprehensive patient medical histories assembled from doctors, hospitals, pharmacies, insurers, and labs-all without patients' knowledge that their anonymized information has become a commercial product.
Chapter 7
The Comprehensive Patient Profile
Unlike early atomic bomb survivor studies or the famous Framingham Heart Study where participants gave informed consent, most people unknowingly contribute to commercial longitudinal data files. Data miners compile anonymized dossiers on hundreds of millions of people from insurance claims, pharmacy prescriptions, electronic health records, and lab tests. Each source provides different perspectives on the same patient's treatment, creating comprehensive profiles that help researchers develop new insights while simultaneously creating privacy risks as more data elements become linked together.
Commercial analysis of longitudinal patient files gained momentum in the 1970s when American companies sought ways to reduce soaring healthcare costs. Companies like General Motors began sending insurance claims data to Boston University for analysis, where Professor Richard Egdahl and Dr. Paul Gertman developed techniques to mine this information.
The creation of Medicare and Medicaid in 1965 accelerated the computerization of claims data, creating vast information repositories and opportunities for processing firms. Insurance claims data proved valuable because of its uniformity compared to varied physicians' notes or lab reports.
While some pioneers like Gertman refused to sell patient information to data miners or pharmaceutical companies, concerned about re-identification risks, other entrepreneurs embraced this opportunity. Ernie Ludy founded MedStat Systems in 1981, aggregating claims data from major corporations like Ford and General Electric. His business model offered companies free analysis in exchange for permission to sell their anonymized data to drugmakers and researchers. This approach proved lucrative-Ludy sold MedStat to Thomson Corporation for $339 million in 1994.
By 1997, IMS expanded into longitudinal patient data collection, initially assembling nearly one million anonymized electronic medical records and insurance claims from over 1.5 million US patients. This represented a dramatic evolution from their earlier focus on aggregate sales data and prescription tracking.
As competition intensified, IMS secured more patient data sources, including a $10 million investment in Allscripts in 2000. Originally a medication repackaging service, Allscripts pivoted to electronic prescribing and later electronic medical records, giving it access to valuable patient data. According to former IMS executive Bob Merold, "Most of where IMS is getting their clinical data from is Allscripts."
Over the past two decades, major health insurers have established data analysis companies that monetize their claims information. UnitedHealth created Optum, Anthem operates HealthCore, and Blue Cross Blue Shield's Blue Health Intelligence maintains data on 125 million people dating back to 2005. Companies not traditionally associated with healthcare have joined this lucrative market. IBM acquired Explorys, Phytel, and Truven, gaining access to data on over 300 million patients, while LexisNexis has built what it calls the largest medical claims warehouse with 1.2 billion claims covering 250 million patients.
Chapter 8
The Myth of Anonymity
Despite industry assurances about anonymization, many experts warn that advanced computing makes re-identification increasingly possible. Surprisingly, even MSA's technical director Jani Syed admits: "No matter how much data obfuscation you do, if you have enough data, it's always possible to identify a particular person. It's not that hard."
Computer scientist Latanya Sweeney has built her career exposing these vulnerabilities. The first Black woman to earn a computer science PhD from MIT, Sweeney made headlines in 1997 by identifying Governor William Weld in supposedly anonymized insurance records using just birth date, ZIP code, and gender. She calculated these three data points could identify 87.1% of Americans.
Even without traditional identifiers, unique patterns in our data can reveal our identities. Two New York Times reporters re-identified a woman among 657,000 anonymized AOL users by analyzing her search patterns. Princeton researchers identified Netflix users by comparing rental histories with public IMDB reviews. Anthony Tockar re-identified celebrities in NYC taxi data, even tracking passengers from sex clubs to their homes.
Medical data is particularly vulnerable-a 46-year-old patient seeing doctors in two specific locations, with certain height, weight, and allergies, becomes increasingly identifiable. With people generating constant digital traces through phones, health apps, internet searches, and purchases, re-identification becomes increasingly feasible.
Beyond re-identification risks, data breaches expose millions of medical records directly. Between 2009 and 2016, the US Department of Health and Human Services recorded over 1,300 breaches involving at least 500 people each, exposing more than 170 million patient files. The scale is staggering: Premera Blue Cross reported attackers accessed 11 million records containing names, birth dates, Social Security numbers, bank information, and clinical data. Anthem suffered an even larger breach affecting 78.8 million people.
Companies trading in medical data are reluctant to discuss security and anonymization flaws. When approached, IMS Health's officials declined detailed discussions, with spokesman Tor Constantino providing only a brief statement emphasizing the company's commitment to privacy and security. In a revealing 2002 filing to the European Commission, IMS argued against excessive anonymization requirements, claiming it would be "highly impractical" to ensure no conceivable method could re-identify individuals.
Chapter 9
The Patient's Right to Control Their Data
Deborah Peel evolved into a privacy activist through her psychiatry work. After becoming chief of psychiatry at Austin's Brackenridge Hospital in 1979, she began advocating on mental health issues, eventually testifying before federal panels about privacy concerns. In 2004, she founded Patient Privacy Rights, running it on a shoestring budget funded largely by family and friends.
Peel regularly features patients sharing privacy violation stories at her annual conferences. In 2015, Deanna Fei spoke about being one of two AOL employees whose premature babies had prompted CEO Tim Armstrong to announce benefit cuts. Another speaker was Alina, a bipolar lawyer whose intimate psychiatric records-including details of childhood sexual abuse and family problems-became accessible to all doctors in her health system. When she complained, officials claimed their practices complied with HIPAA regulations, leaving her to choose between privacy and quality care: "You shouldn't have to choose between privacy and the best possible care."
After many hours with Deborah Peel, Tanner asked what she really wants. Her answer was passionate and direct: pharmacies, doctors, hospitals, and middlemen should obtain permission before sharing medical data, even anonymized. "The point is just ask us," she insisted. "They don't want to ask, because they want to steal it!"
Those opposed to patient opt-outs argue science needs complete data sets. Tom Brogan warns that excluding patients with serious conditions creates "massive holes." Others cite administrative complexity-Jonathan Wald notes that blocking one pathway doesn't stop "thirty other pathways" for data distribution.
Controlling one's medical data privacy remains difficult, yet some promising models are emerging. Rhode Island became the first state to allow residents to opt out of anonymized insurance claims sharing, with only 1.5% (about 15,000 people) choosing to do so by mid-2015. Since 2001, the pioneering Framingham study has given participants control over whether their data is shared with commercial entities, with less than 5% opting out. Many former data industry executives now support giving patients more control, with some even suggesting financial compensation ($1-15 per patient) for commercial use of their data.
Chapter 10
A System That Fails Patients
The unfettered commercial trade in anonymized medical data has created a troubling paradox: HIPAA has enabled a vast market for intimate information that undermines patient trust while creating privacy vulnerabilities, yet patients still struggle to access their own complete records.
Despite Obama's 2008 promise to computerize health records and $31 billion in subsidies through HITECH, hundreds of different electronic medical systems still can't communicate effectively. Even tech leaders like Craig Barrett (Intel), Denny Briley (pharmacy records pioneer), and Neal Patterson (Cerner CEO) can't access their complete medical histories, with Patterson's cancer-stricken wife carrying "shopping bags" of records to appointments.
The problem persists because health systems want to retain patients within their networks and vendors create "switching barriers" to lock in customers. Epic, founded by Judy Faulkner in 1979 and now worth billions, has been criticized for lack of interoperability despite exchanging 21 million records monthly. Government failed by not requiring compatibility before distributing billions in subsidies. As David Blumenthal, Obama's health information czar, admitted: "There was no business case for interoperability."
Even tech giants have failed to solve the medical records problem. Google abandoned its Google Health service in 2011, admitting it couldn't achieve "widespread adoption in the daily health routines of millions of people." Microsoft's HealthVault outlasted Google's effort but still struggled, with only two million people signed up by 2014, far below their ten-million goal.
In Vermont's remote Underhill region lives Larry Weed, a doctor in his nineties who pioneered computerized medical records half a century ago. In 1969, Weed moved to Vermont to develop PROMIS (Problem-Oriented Medical Information System), allowing doctors to record patient histories consistently and access medical information decades before the Internet. But Weed's disruptive approach alienated many doctors who resisted having their notes visible to others. The hospital administration prioritized billing systems over patient-centered records. At his Vermont home, Weed remains energetic and passionate in his nineties, demonstrating his knowledge couplers and expressing disgust with the business world's profit focus. After hours of rapid-fire explanation, he admits to being depressed that medicine hasn't embraced his innovations: "The disaster in medicine is far bigger than most people realize."
Chapter 11
Reclaiming Our Medical Identity
Medicine remains a business that caters to the real customer-the patient-far less than other economic sectors. As marketing evolved, patients' needs weren't prioritized. Doctors, insurers, and drugmakers had little incentive to share medical data with patients, instead lessening privacy while denying individuals control of their own information. We now stand at a precipice where medical data can either be treated securely on behalf of individuals or left to market forces.
If the market takes charge-and big pharma wields enormous political and financial leverage-outside businesses will know increasingly more about us, potentially leading to discrimination, exclusion, and humiliation. In a more benign alternative, patients gain greater control over their medical destinies while doctors and pharmaceutical companies still prosper but must cede some control. Patients would have authority over their records and determine how their intimate data contribute to medical science.
Companies buying and selling patient information have obscured their activities from the public, treating us with condescension. This approach is both wrong and counterproductive-many people would gladly share health information if they understood the purpose and had reason to cooperate. The US medical system must transform to put patients in control of their records, requiring clear consent before data sharing, even when anonymized.
Despite the big data revolution, randomized, double-blind, controlled clinical trials remain medicine's gold standard. The for-profit trade in longitudinal patient data has delivered neither the revolutionary breakthroughs promised by data miners nor the catastrophic privacy violations feared by advocates. When pressed for examples of significant insights, industry executives struggle to provide specific cases beyond vague "cost efficiencies."
Many data miners are honorable professionals genuinely seeking to improve patient health while making money. "I don't think there are any evil characters in all of this," says Kris Joshi of health-data company Emdeon. "IMS is not evil, pharmaceutical companies are not evil, and patients are definitely not evil, and neither are insurance companies evil." Yet as former IMS official Bob Merold cautions about longitudinal medical data: "There is a lot of goodness about it. There are huge amounts of potential evil about it."
The question becomes how to harness big data in medicine while protecting individual interests. Corporations trading patient data claim to help science, but may not offer the best societal approach. Health issues represent our most intimate secrets, with greater downside risks than other personal data. What's needed is simple: more transparency, consent, and control. HIPAA protections should extend to all health information, not just "individually identifiable" data, and these protections should apply broadly beyond current "covered entities" to include health device makers, fitness trackers, smartphone apps, and DNA services. After all, it's our data.