OBJECTIVE: Most individuals would like to maintain the privacy of their medical information on the World Wide Web (WWW). In response, commercial interests and other sites post privacy policies that are designed to inform users of how their information will be used. However, it is not known if these statements are comprehensible to most WWW users. The purpose of this study was to determine the reading level of privacy statements on Internet health Web sites and to determine whether these statements can inform users of their rights.
STUDY DESIGN: This was a descriptive study. Eighty Internet health sites were examined and the readability of their privacy policies was determined. The selected sample included the top 25 Internet health sites as well as other sites that a user might encounter while researching a common problem such as high blood pressure. Sixty percent of the sites were commercial (.com), 17.5% were organizations (.org), 8.8% were from the United Kingdom (.uk), 3.8% were United States governmental (.gov), and 2.5% were educational (.edu).
OUTCOMES MEASURED: The readability level of the privacy policies was calculated using the Flesch, the Fry, and the SMOG readability levels.
RESULTS: Of the 80 Internet health Web sites studied, 30% (including 23% of the commercial Web sites) had no privacy policy posted. The average readability level of the remaining sites required 2 years of college level education to comprehend, and no Web site had a privacy policy that was comprehensible by most English-speaking individuals in the United States.
CONCLUSIONS: The privacy policies of health Web sites are not easily understood by most individuals in the United States and do not serve to inform users of their rights. Possible remedies include rewriting policies to make them comprehensible and protecting online health information by using legal statutes or standardized insignias indicating compliance with a set of privacy standards (eg, “Health on the Net” [HON] http://www.hon.ch).
Approximately 33 million individuals in the United States have used the Internet to access medical information.1,2 Even though most people would like to maintain the privacy of their medical and other information,3-6 few users of the Internet take steps to do so.7 Commercial vendors develop profiles of individual users of the Internet. The information tracked includes Web sites visited; terms entered into search engines (including medical terms); goods or services bought online; and participation in forums, chat rooms, and e-mail lists (eg, listservs). The text of any postings in forums and email lists can also be tracked. This information is sold to anyone willing to pay for it, including advertisers, employers, and insurance companies. Commercial vendors use this information to offer goods and services targeted to a user’s needs, including medical needs. For example, an individual who visits Web sites dedicated to the care of diabetes mellitus will receive advertising about new diabetes medications and glucose monitoring devices. However, the information can and has been used in other ways, leading to job termination and arrest.8 A user who repeatedly visits a breast-cancer-related Web site, for example, could be discriminated against by a potential employer or insurance company because she is suspected of being afflicted with the disease.
Unauthorized access to an individual’s personal information also occurs. Doubleclick.com, a corporation that collects user information, has had several high-profile breaches of computer security, leaving individuals’ information vulnerable to exploitation.9
The importance of the confidentiality of medical information has been underscored by the recent publication of the new “Standards for Privacy of Individually Identifiable Health Information” by the Department of Health and Human Services.10 In part, these guidelines are designed to “protect the privacy of individually identifiable health information.”10 Although Internet use does not generate a formal medical record, online profiling allows the collection of detailed medical information about a user’s diagnoses, medications, etc, which essentially creates “individually identifiable health information” when associated with their names.
One proposed solution to maintaining Internet privacy has been the voluntary posting of privacy statements. These statements serve to inform users of the privacy policies of the Web site, such as what user information is collected and with whom this information will be shared. Three recent studies have shown that the readability level of much of the patient information on the Internet is beyond the comprehension of many individuals in the United States.11-13 For voluntary privacy statements to be useful, they need to be written at a level understood by most individuals using the Internet. The purpose of this study was to determine the readability level of privacy statements on Internet health Web sites.
Methods
A total of 80 Internet health Web sites were examined in May 2001 to see if they included privacy policies. To emulate the way a consumer might find information on the Internet, 55 of the sites were selected by entering search terms for common conditions into a widely used Internet search engine (http://www.google.com). The terms searched for were “high blood pressure,” “fever,” “cough,” and “wellness.” The other 25 Web sites analyzed represent the most commonly visited health information Web sites on the Internet.10 For Web sites identified by Google, the Web pages represented by the top 10 results for each term were viewed, and any links on those pages were followed until 55 health information Web sites were identified. We did not limit the Web sites to only those identified by the search engines because in many cases, users will follow the links on a page identified by the search engine. Links that led to medical school lectures, nonhuman diseases, online journal articles aimed at health care professionals, or the contents of e-mail or listserv summaries were omitted.