Live data from Hacker News

Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

theverge.com

11–20 of 72 posts

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#11
post #3

> The data-sharing agreement — which was signed in 2015 and has since been superseded by a new contract — allows DeepMind access to medical records from 1.6 million patients attending London hospitals run by the NHS Royal Free Trust. Although at the time Google presented the deal as primarily about finding patients at risk from a condition known as acute kidney injury or AKI, the actual terms of the agreement, reveal…

[deleted]

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#12
post #7

Frankly these post-docs are engaging in outright witchhunt against DeepMind driven by nothing but pure political agenda. The amount of data obtained is frankly tiny compared to that available regularly to researchers in USA. E.g. as part of my PhD research I have access to de-indentifed data on 40 Million patients spanning 5 years from several states. Not to forget programs like CMS Qualified Entity which provide acc…

This sort of thing is important in a context where more and more NHS services are getting sold off to private entities.

Arrangements that have been in the place for decades in the US are not necessarily relevant to the UK.

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#13
post #12
post #7

Frankly these post-docs are engaging in outright witchhunt against DeepMind driven by nothing but pure political agenda. The amount of data obtained is frankly tiny compared to that available regularly to researchers in USA. E.g. as part of my PhD research I have access to de-indentifed data on 40 Million patients spanning 5 years from several states. Not to forget programs like CMS Qualified Entity which provide acc…

This sort of thing is important in a context where more and more NHS services are getting sold off to private entities. Arrangements that have been in the place for decades in the US are not necessarily relevant to the UK.

"What sort of thing?"

The report essentially says Google owns Deep Mind and Google has advertising business, ipso facto, some magical standrard dreamt up by the authors were not met.

The reason for mentioning US agreements is that several nations, researchers and comapnies have developed procedures around sharing this data. And such sharing is not entirely unprecedented.

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#14
post #11
post #3

> The data-sharing agreement — which was signed in 2015 and has since been superseded by a new contract — allows DeepMind access to medical records from 1.6 million patients attending London hospitals run by the NHS Royal Free Trust. Although at the time Google presented the deal as primarily about finding patients at risk from a condition known as acute kidney injury or AKI, the actual terms of the agreement, reveal…

[deleted]

[deleted]

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#15
post #7

Frankly these post-docs are engaging in outright witchhunt against DeepMind driven by nothing but pure political agenda. The amount of data obtained is frankly tiny compared to that available regularly to researchers in USA. E.g. as part of my PhD research I have access to de-indentifed data on 40 Million patients spanning 5 years from several states. Not to forget programs like CMS Qualified Entity which provide acc…

1) UK is not the US, and the EU has much stricter privacy laws

2) There is not such thing as "anonymized data" that is gathered by companies. There are several studies out there that show that with only 4 data points you can pinpoint someone in an "anonymized database" with 90% accuracy. Even Apple's differential privacy can probably be reverse engineered to find people. Just because you don't care to do that, doesn't mean others wouldn't do that either.

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#16
post #7

Frankly these post-docs are engaging in outright witchhunt against DeepMind driven by nothing but pure political agenda. The amount of data obtained is frankly tiny compared to that available regularly to researchers in USA. E.g. as part of my PhD research I have access to de-indentifed data on 40 Million patients spanning 5 years from several states. Not to forget programs like CMS Qualified Entity which provide acc…

> driven by nothing but pure political agenda

Do you mean personal or political? Because you insinuate personal motive with no evidence ("...and fear of AI sells very well in these types of academic circles...").

However, I don't see anything particularly wrong with researchers being motivated by politics.

Personal privacy is political.

Climate change is political.

Human rights are political.

Researchers should not feel an obligation to shy away from politically charged topics. At least, not if we want science to be anything except a tool for moneyed interests to batter the rest of us into submission.

Shaming researchers for publishing politically relevant findings is its own form of witch-hunt.

> E.g. as part of my PhD research I have access to de-indentifed data on 40 Million patients spanning 5 years from several states.

De-identified is a rather extraordinary caveat! It's the difference between "aub3bhat has cancer/AIDs/depression" and "entry 143048 has cancer/AIDs/depression". Or, for that matter, "aub3bhat says..." and " says..."

In short, the situations are nothing alike.

> The report does not lists any specific cases where violations occured but rather makes broad hand waving claims about cabining or advertising.

If companies are willing to open-source their analysis tools and provide a mechanism for me to audit how my data is used, then I'm happy to not assume malice.+

Otherwise, I'll assume that they do everything that's legally permissible.

Absence of sufficient contractual protections is enough justification for deep concern, IMO.

IANAL, but I imagine you'd be hard-pressed to find a competent lawyer giving a corporate client literally any other piece of advice. For example.

> The only reason Deep Mind is being persecuted is since they are a juicy target

You say this as if it's unreasonable. Google's very explicit raison d'etre is to collect and organize the world's information for profit. Explain to me again why I should trust them with my health records.

--

+ To DeepMind's credit, the article indicates that they're planning on doing something like this, and an improved contract has already been signed. And I don't fault Google or DeepMind in any of this. The fault is entirely with NHS.

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#17
post #15
post #7

Frankly these post-docs are engaging in outright witchhunt against DeepMind driven by nothing but pure political agenda. The amount of data obtained is frankly tiny compared to that available regularly to researchers in USA. E.g. as part of my PhD research I have access to de-indentifed data on 40 Million patients spanning 5 years from several states. Not to forget programs like CMS Qualified Entity which provide acc…

1) UK is not the US, and the EU has much stricter privacy laws 2) There is not such thing as "anonymized data" that is gathered by companies. There are several studies out there that show that with only 4 data points you can pinpoint someone in an "anonymized database" with 90% accuracy. Even Apple's differential privacy can probably be reverse engineered to find people. Just because you don't care to do that, doesn'…

> Just because you don't care to do that, doesn't mean others wouldn't do that either.

More to the point, author almost certainly operated under a heavily and independently vetted IRB protocol that would have made such a purposeful re-identification a criminal or at least very serious civil offense.

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#19
post #15

Earlier quoted context omitted.

1) UK is not the US, and the EU has much stricter privacy laws 2) There is not such thing as "anonymized data" that is gathered by companies. There are several studies out there that show that with only 4 data points you can pinpoint someone in an "anonymized database" with 90% accuracy. Even Apple's differential privacy can probably be reverse engineered to find people. Just because you don't care to do that, doesn'…

> Just because you don't care to do that, doesn't mean others wouldn't do that either. More to the point, author almost certainly operated under a heavily and independently vetted IRB protocol that would have made such a purposeful re-identification a criminal or at least very serious civil offense.

True in fact the very disks that are used to distribute this data have printed warning that its misuse is a felony offense.

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#20
Interestingly, Deepmind's Ben Laurie has been working on certificate transparency-like tech to permit a verifiable audit log of access to data like this, precisely for this purpose: https://qz.com/929833/googles-goog-deepmind-is-using-blockch...

If you want to take a look at the underlying technology, take a look at https://github.com/google/trillian

Post reply on HN