Live data from Hacker News

Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

theverge.com

21–30 of 72 posts

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#21
post #15
post #7

Frankly these post-docs are engaging in outright witchhunt against DeepMind driven by nothing but pure political agenda. The amount of data obtained is frankly tiny compared to that available regularly to researchers in USA. E.g. as part of my PhD research I have access to de-indentifed data on 40 Million patients spanning 5 years from several states. Not to forget programs like CMS Qualified Entity which provide acc…

1) UK is not the US, and the EU has much stricter privacy laws 2) There is not such thing as "anonymized data" that is gathered by companies. There are several studies out there that show that with only 4 data points you can pinpoint someone in an "anonymized database" with 90% accuracy. Even Apple's differential privacy can probably be reverse engineered to find people. Just because you don't care to do that, doesn'…

1. UK is not in EU. The argument is that such arrangements are commonplace and I am sure one can find other such examples of data sharing in UK.

2. LOL yeah you are so damn clueless that I wont even bother replying. Lets just say there is reading some popular press article about privacy and annonymity. And then there is knowing intricate details of how business/research is conducted.

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#22
post #7

Frankly these post-docs are engaging in outright witchhunt against DeepMind driven by nothing but pure political agenda. The amount of data obtained is frankly tiny compared to that available regularly to researchers in USA. E.g. as part of my PhD research I have access to de-indentifed data on 40 Million patients spanning 5 years from several states. Not to forget programs like CMS Qualified Entity which provide acc…

> driven by nothing but pure political agenda Do you mean personal or political? Because you insinuate personal motive with no evidence ("...and fear of AI sells very well in these types of academic circles..."). However, I don't see anything particularly wrong with researchers being motivated by politics. Personal privacy is political. Climate change is political. Human rights are political. Researchers should not f…

Again take a look at CMS Qualified Entity program which provides identifiable data. In fact most State government health agencies have a special board which routinely meets to discuss identifiable data requests.

Finally their is nothing wrong in writing a paper about a politically charged topic, but completely dismissing existing standards to paint a picture of doom and gloom is ridiculous. E.g. just look at the references cited by that paper.

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#23

Earlier quoted context omitted.

> Just because you don't care to do that, doesn't mean others wouldn't do that either. More to the point, author almost certainly operated under a heavily and independently vetted IRB protocol that would have made such a purposeful re-identification a criminal or at least very serious civil offense.

True in fact the very disks that are used to distribute this data have printed warning that its misuse is a felony offense.

So, do you believe that the sticker was appropriate? Or would a PR statement from your university's press office have been more appropriate?

Ultimately, the lack of a legally binding contractual obligation with sufficient audit-ability is primarily what Julia Powles & Hal Hodson are criticizing.

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#24

Earlier quoted context omitted.

> driven by nothing but pure political agenda Do you mean personal or political? Because you insinuate personal motive with no evidence ("...and fear of AI sells very well in these types of academic circles..."). However, I don't see anything particularly wrong with researchers being motivated by politics. Personal privacy is political. Climate change is political. Human rights are political. Researchers should not f…

Again take a look at CMS Qualified Entity program which provides identifiable data. In fact most State government health agencies have a special board which routinely meets to discuss identifiable data requests. Finally their is nothing wrong in writing a paper about a politically charged topic, but completely dismissing existing standards to paint a picture of doom and gloom is ridiculous. E.g. just look at the refe…

> Again take a look at CMS Qualified Entity program which provides identifiable data

From what I understand, this program has exactly the sort of contractual legal limits on use that the authors are asking for:

"Qualified entities may use the information obtained under section 1874(e) of the Act for the sole purpose of evaluating the performance of providers of services and suppliers, and to generate specified public reports".

> but completely dismissing existing standards to paint a picture of doom and gloom is ridiculous

The authors don't dismiss existing standards, but rather explain how the DeepMind agreement was particularly troubling in light of standard data sharing agreements.

And in any case, two wrongs don't make a right. If NHS hands health data over to private companies, there should be very strong legal protections governing the use of that data. PR statements and unenforceable promises are not enough.

To the extent that it is common for private companies to get access to identifiable health information without agreeing to strong legal protections, the authors of this paper are completely validated re: their doom and gloom tone.

And to the extent that this is not the case, the DeepMind agreement was exceptional and particularly troubling.

In either case, you're just strengthening the paper's thesis.

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#25
post #15

Earlier quoted context omitted.

1) UK is not the US, and the EU has much stricter privacy laws 2) There is not such thing as "anonymized data" that is gathered by companies. There are several studies out there that show that with only 4 data points you can pinpoint someone in an "anonymized database" with 90% accuracy. Even Apple's differential privacy can probably be reverse engineered to find people. Just because you don't care to do that, doesn'…

1. UK is not in EU. The argument is that such arrangements are commonplace and I am sure one can find other such examples of data sharing in UK. 2. LOL yeah you are so damn clueless that I wont even bother replying. Lets just say there is reading some popular press article about privacy and annonymity. And then there is knowing intricate details of how business/research is conducted.

UK is in the EU until 2 years after Article 50 gets invoked, and EU data protection rules fully apply. This is a fact. The rude insult to another user, I won't even address.

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#26
post #12

Earlier quoted context omitted.

This sort of thing is important in a context where more and more NHS services are getting sold off to private entities. Arrangements that have been in the place for decades in the US are not necessarily relevant to the UK.

"What sort of thing?" The report essentially says Google owns Deep Mind and Google has advertising business, ipso facto, some magical standrard dreamt up by the authors were not met. The reason for mentioning US agreements is that several nations, researchers and comapnies have developed procedures around sharing this data. And such sharing is not entirely unprecedented.

You're downplaying valid concerns. The ability to de-anonymise large data sets that we have today is unprecedented. The degree to which systems with access to that data are accessible remotely and potentially vulnerable to security problems is unprecedented. The degree to which powerful organisations like employers and insurers are attempting to profile potential employees and customers is unprecedented. However, neither major breaches involving huge amounts of potentially sensitive personal data nor scope creep in how data is used by large organisations once acquired are unprecedented.

None of this is good for the individuals whose data is potentially at risk, and it's perfectly fair and reasonable to ask whether some of the most sensitive data there is about individuals is being properly handled by those entrusted with it given the implications of modern technology. There might be a lot of potential good in big data analysis for improving healthcare outcomes, but there is also a lot of potential harm if people stop, say, being confident in discussing potentially limiting conditions with their doctors, or reaching out for help with mental health issues because they're worried about confidentiality.

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#27

Earlier quoted context omitted.

True in fact the very disks that are used to distribute this data have printed warning that its misuse is a felony offense.

So, do you believe that the sticker was appropriate? Or would a PR statement from your university's press office have been more appropriate? Ultimately, the lack of a legally binding contractual obligation with sufficient audit-ability is primarily what Julia Powles & Hal Hodson are criticizing.

>> lack of legally binding

From the verge article:

"The data-sharing agreement — which was signed in 2015"

There was a legally binding contractual agreement between the two parties Deep Mind & Royal Free.

Here is the one that I and thousands (I am NOT exaggerating) of other researchers regularly sign to get access to data.

https://www.hcup-us.ahrq.gov/team/NationwideDUA.jsp

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#28
post #18

You can skip reading the article, as it does not list any "errors" that have happened. It merely questions whether the agreement under which the data is shared has adequate protections.

Indeed. The paper itself details seven "transgressions:"

> 1) We do not know––and have no power to find out––what Google and DeepMind are really doing with NHS patient data, nor the extent of Royal Free’s meaningful control over what Google and DeepMind are doing;

> 2) Any assurances about use of the dataset come from public relations statements, rather than independent oversight or legally binding documents;

> 3) The amount of data transferred is far in excess of the requirements of those publicly stated needs, but not in excess of the information sharing agreement and broader memorandum of understanding governing the deal, both of which were kept private for many months;

> 4) The data transfer was done without consulting relevant regulatory bodies, with only one superficial assessment of server security, combined with a post-hoc and inadequate privacy impact assessment;

> 5) None of the millions of identified individuals in the dataset were either informed of the impending transfer to DeepMind, nor asked for their consent;

> 6) The transfer relies on an argument that DeepMind is in a “direct care” relationship with each patient that has been admitted to Royal Free constituent hospitals, even though DeepMind is developing an app that will only conceivably be used in the treatment of one sixth of those individuals; and

> 7) More than 12 months into the deal being made, no regulator had issued any comment or pushback.

Quite a few of these strike me as rather absurd, but I don't know the regulatory environment in the UK.

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#29
post #25

Earlier quoted context omitted.

1. UK is not in EU. The argument is that such arrangements are commonplace and I am sure one can find other such examples of data sharing in UK. 2. LOL yeah you are so damn clueless that I wont even bother replying. Lets just say there is reading some popular press article about privacy and annonymity. And then there is knowing intricate details of how business/research is conducted.

UK is in the EU until 2 years after Article 50 gets invoked, and EU data protection rules fully apply. This is a fact. The rude insult to another user, I won't even address.

If EU data protection rules apply then why aren't the authors marching to doors of EU Privacy Commisioner demnding to prosecute Google? The reality is that what is Deep Mind did is routine and commonplave, and that's why no one other than clickbait driven press is interested in it.

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#30
post #15

Earlier quoted context omitted.

1) UK is not the US, and the EU has much stricter privacy laws 2) There is not such thing as "anonymized data" that is gathered by companies. There are several studies out there that show that with only 4 data points you can pinpoint someone in an "anonymized database" with 90% accuracy. Even Apple's differential privacy can probably be reverse engineered to find people. Just because you don't care to do that, doesn'…

1. UK is not in EU. The argument is that such arrangements are commonplace and I am sure one can find other such examples of data sharing in UK. 2. LOL yeah you are so damn clueless that I wont even bother replying. Lets just say there is reading some popular press article about privacy and annonymity. And then there is knowing intricate details of how business/research is conducted.

From your comments here, it appears that you're doing PhD research dealing with large sets of healthcare data.

It also appears that you are casually dismissive of concerns about the risks of that data being de-anonymised. Your best rebuttal seems to be some vague allusion that the parent poster, who was essentially correct, didn't know what they were talking about. (This is something of a digression anyway, because in the actual case we're talking about, as the report notes, the data supplied was already identifiable anyway.)

You have accused the authors of the report of going on a witch-hunt, but again you have offered little real argument except that such things are going on in other places, as if that makes those practices above criticism or automatically acceptable.

Do you realise that you are providing a near perfect, real-time example of the need for stricter controls on medical data and who is allowed to access it?

Post reply on HN