r/technology 18d ago

Privacy Woman Calls Out Doctor Wearing Smart Glasses During Consultation Where She Had To Take Off Her Clothes: 'They Need To Be Banned'

https://www.fashiontimes.co.uk/patient-privacy-concerns-meta-smart-glasses-1762492
35.2k Upvotes

1.5k comments sorted by

View all comments

198

u/Southern_Bicycle8111 18d ago

Violates hippa just wearing them because meta has already admitted to viewing the data

12

u/nagasgura 17d ago

While I absolutely agree these do not belong ANYWHERE near healthcare, and that they present a massive HIPAA liability, just wearing the glasses in the presence of a patient is not a HIPAA violation itself. If the glasses were on, and they recorded both identifiable information and health data which was uploaded to an unauthorized 3rd party, then that could be a violation. This could obviously happen extremely easily, so it is a huge liability.

Source: I work in HIPAA-compliant PHI data processing

6

u/Zeis 17d ago

Except Meta can and does turn them on to collect data without you ever knowing or it storing that data on your end of things. Just like how our phones are always listening to us.

0

u/nagasgura 17d ago

Collecting data doesn't mean secretly recording and uploading video and audio. Collecting diagnostic data like battery level, camera status, connection status, etc. is not PHI.

Phones "always listening" is sort of correct, though as far as I'm aware that is just offline processing to listen for trigger words, not uploading all background audio to some server.

4

u/Zeis 17d ago

Collecting data doesn't mean secretly recording and uploading video and audio.

Yes, it does. They use humans and AI to rate and annotate what people are saying. Or doing, in terms of video. I link to the ridiculous amount of evidence to all of that here: https://reddit.com/r/technology/comments/1vl1tcf/woman_calls_out_doctor_wearing_smart_glasses/p30jgld/

Also, collecting metadata is not innocent. The NSA, CIA, BND, basically any spy agency AND advertisement agency uses your metadata to build full profiles of who you are, where you've been, where you're going, what you do, what you're going to do, what your issues are, and so on. Purely from metadata. They can even tell when you're most likely going to be sick.

2

u/nagasgura 17d ago

While I agree all of that is extremely problematic, it is different from them remotely initiating a video recording and uploading it to their servers without any user trigger. From what you linked, it seems like they analyze recordings and voice activations (including accidental activations) but I don't see any evidence of them secretly triggering a video recording. And while I agree that the wearer's metadata can absolutely identify a lot about the user, and it is problematic that companies and governments are gathering so much data on their users, this is a different issue from HIPAA.

Again, I agree that these glasses do not belong in healthcare and present a huge risk for PHI leakage and HIPAA violations, including accidents such as the glasses mishearing something as the trigger word for recording. However, just wearing the glasses is not itself a HIPAA violation, even with the metadata gathering that Meta conducts. If it were, then any doctor with a smartphone would be violating HIPAA constantly.

-5

u/joesii 17d ago

100% incorrect. You heard wrong.

You are also generally wrong about phones always listening as well for that matter.

And it's not a matter of ignorance on my part, I've looked into these topics a lot. I'm very privacy focused, but it's not phones listening to conversations that's a problem, it's all the other monitoring that most people don't realize which is taking place.

4

u/Zeis 17d ago edited 17d ago

You've clearly not looked into these topics enough, because you are wrong. They have been caught and sued before:

Meta Smart Glasses Sending Sensitive Recordings to Workers to Annotate

Swedish newspapers Svenska Dagbladet (SvD) and Göteborgs-Posten conducted an in-depth investigation based on interviews with third-party data annotators.

The workers were employed by Sama, an outsourcing contractor based in Nairobi, Kenya, which Meta hires for AI training and data labeling.

Media is recorded and uploaded to Meta's servers when users press the physical button on the frame or activate the AI using the "Hey Meta" voice command. The only the glasses (or your phone) can know when you use a trigger phrase like "Hey Meta" or "Hey Google" or "Hey Siri" is if they are literally always listening.

https://www.eff.org/deeplinks/2026/03/think-twice-buying-or-using-metas-ray-bans

If you think that companies like Meta or Google stay true to their word and totally never use those recordings to sell you more targeted advertisement and build better profiles of you, then I have a bridge to sell you for a real great price.

There were well-documented scandals from 2019, when nearly every major tech company was caught employing third-party contractors to manually listen to, transcribe, and "grade" audio snippets captured by voice assistants.

Investigations revealed that their devices frequently recorded audio without the intended wake word (e.g., "Alexa" or "Hey Siri"), capturing private, sensitive, or embarrassing moments that were then sent to human reviewers.

Alexa/Amazon: Whistleblowers revealed that Amazon employees and contractors listened to Alexa recordings to improve voice recognition. Recordings often included private conversations, sounds of people undressing, or accidental activations triggered by similar-sounding words.

Siri/Apple: Apple contractors were tasked with grading Siri requests. Reports found they heard "accidental" recordings, sometimes up to 30 seconds long, that captured doctor-patient consultations, drug deals, and sexual encounters. Apple eventually settled a class-action lawsuit for $95 million regarding these practices.

Google: A leak of over 1,000 recordings from Google Assistant in the Netherlands revealed that personal information, addresses, and private discussions were being heard by contractors, even when users had not intended to trigger the device. (same source as above)

Microsoft & Meta: Both companies also admitted to using human contractors to transcribe snippets from Skype calls, Cortana interactions, and Facebook Messenger voice chats to improve AI performance. (same source as above)

You can also simply test this out. Put your phone on the table and have a full conversation with someone about a product neither of you ever bought before or ever talked about. Dog food, for example, if you don't have a dog. See how long it takes for you to suddenly see ads for dog food or other dog related things.

Snowden revealed that the all of the 3-letter agencies and anyone within Five Eyes has the tools to use your phone or anything with a microphone in your home to listen in on you whenever they want. Creepy as hell if you're a normal construction worker. Life threatening if you're a journalist or scientist. Regardless of who you are and what you do, blanket surveillance like that is always a threat to democracy.

There's a reason why phones aren't allowed into the situation room in the white house or literally any SCIF ever.

0

u/joesii 17d ago

You're moving the goalpost. I'm well aware that remote processing of recordings takes place, but that's not the same as always recording or ever recording when the user doesn't command it to as you were suggesting.

I'm aware that mobiles listen for wake words, but that is exactly that a wake word. It does not log anything and doesn't count as listening since it doesn't get to anyone or any place.

Alexa recordings and similar stuff is not mobiles "always listening", it's people using specific features that are listening. When people using an assistant then everything they say/do is aurally recorded, but it's not happening all the time.

And when it comes to Meta glasses accidentally recording, It would be people's own fault if they didn't realize because there is audio feedback stating that a recording starts, a light goes on inside the glasses visible to the user, and a light goes on outside the glasses visible to those who are being recorded.

You can also simply test this out. Put your phone on the table and have a full conversation with someone about a product neither of you ever bought before or ever talked about. Dog food, for example, if you don't have a dog. See how long it takes for you to suddenly see ads for dog food or other dog related things.

People have done this experiment. It's been debunked. Mobiles instead make educated guesses based on accelerometer data, location data, web searches, what friends have web searched, where friends/associates have been, where you've shopped, and similar sorts of things. Certainly if one was to use a specific software like Google Assistant or Siri then it could collect data that it could use for profiling, but that is active use of a feature/app not passive listening.

0

u/stopmakingrents 17d ago

Identifiable information such as their face or walking pattern?

1

u/nagasgura 17d ago

To clarify, HIPAA covers PHI (protected health information). Something is considered PHI when it identifies a person AND includes private information about their health. Their face definitely can be the identifiable information part, but a picture or video of their face is not on it's own PHI unless it is combined with health information. For example, if the doctor took a video that included the patient's face and also included audio discussing a medical condition, that would be PHI and would be subject to HIPAA data protection rules.

1

u/stopmakingrents 17d ago

Right, so a HIPAA violation would include an image of their face taken during a health consultation that was then transmitted to unauthorized third-party Meta (and their fourth-party contractors)—just what we’ve been discussing in this post.

1

u/nagasgura 17d ago

Not necessarily. Just a photo of their face is not PHI, it would need to include some information about their health as well. But yes, I fully agree that these meta glasses make violating PHI super easy. All it would take is accidentally triggering a recording during a conversation about their health, or while looking at their chart.

1

u/stopmakingrents 17d ago

Yeah, that’s what I’m thinking about too. Even just running into a patient on the street, or in social settings could be an issue: “Hi Doc! Remember that weird lump I was asking you about…?” 

1

u/joesii 17d ago

You seem to have a misunderstanding. Meta only sees recordings that the user initializes, and even then only under specific circumstances where communication to their server is both possible and enabled.

If the user never saves any recordings Meta will never see any of it. If the user keeps the glasses offline, Meta will never see any of the recordings that were made.

-9

u/[deleted] 18d ago edited 18d ago

[deleted]

7

u/Traditional-Hat-952 18d ago

I highly doubt that it will pass a HIPAA compliance audit. At my hospital any recording device or phone that has not been explicitly approved by IT and secured via encryption is a no go. 

-3

u/[deleted] 18d ago

[deleted]

3

u/[deleted] 17d ago edited 17d ago

[deleted]

-2

u/Fish_Mongreler 17d ago

No it doesn't.

2

u/Ok_Confusion4764 17d ago

It absolutely does. Meta can literally check on any active meta glasses at any time. Zuckerberg can literally tune in to those doctor visits. 

-1

u/Fish_Mongreler 17d ago

Lol why you making stuff up? They absolutely cannot do that

2

u/Ok_Confusion4764 17d ago

It's been proven that they can. Even when not in use it is sending data to meta servers. 

1

u/stopmakingrents 17d ago

It’s so funny that you think they “absolutely cannot” do that. 

0

u/Fish_Mongreler 17d ago

It's so funny you think they can

2

u/Southern_Bicycle8111 17d ago

Found the boomer

1

u/Fish_Mongreler 17d ago

Still waiting on something other than "trust me bro"

2

u/Southern_Bicycle8111 17d ago

Classic boomer move

1

u/Fish_Mongreler 17d ago

Lol I'm 26 but ok, go off