I don't want my privacy invaded as much as the next person, but arguing about broadness of medical history in this context is pretty stupid. The data needs to be broad if you are interested in finding out things you don't already know... that's why it's being fed into a machine learning algorithm in the first place - If you get selective then it's not going to be very useful - how do you limit history to what's relev…
Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report
31–40 of 72 posts
Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report
#32Earlier quoted context omitted.
So, do you believe that the sticker was appropriate? Or would a PR statement from your university's press office have been more appropriate? Ultimately, the lack of a legally binding contractual obligation with sufficient audit-ability is primarily what Julia Powles & Hal Hodson are criticizing.
>> lack of legally binding From the verge article: "The data-sharing agreement — which was signed in 2015" There was a legally binding contractual agreement between the two parties Deep Mind & Royal Free. Here is the one that I and thousands (I am NOT exaggerating) of other researchers regularly sign to get access to data. https://www.hcup-us.ahrq.gov/team/NationwideDUA.jsp
Which was, allegedly, far too lax.
The claim that DeepMind was providing "direct care" is particularly questionable IMO, and that has significant implications in the context of this agreement. It means anyone who slaps together an iPhone app (and has the right clout/deep pockets) can get access to full and fully identified medical records without patient consent. IMO that's the big story here, and it's troubling.
The "don't worry that's covered by existing law" responses were also problematic. Why does this particular contract need to depend upon the enforce-ability of that law? What happens if the law is repealed and DeepMind happened to keep a copy of the data? We want the protection here, in this context, so just put it in this agreement. Which is what they ultimately did in the new agreement AFAICT.
Also, the data shared is extremely broad -- I doubt you could get access to a data set of that size and quality without patient consent through standard channels, for example. I've never seen an identifiable data set containing "not only to relevant blood tests and diagnostics, but historical medical records dating back five years, including information on HIV diagnoses, drug overdoses, and abortions" for 1.6 million people. Access to such sensitive data creates a difference in kind that justifies greater care and skepticism, especially WRT audit-ability. The parties appear to agree, since they signed a new agreement recently!
Demonize these researchers all you want, but as a direct result of their work, NHS patients have stronger legal protections today than they did a year ago.
Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report
#33Earlier quoted context omitted.
"What sort of thing?" The report essentially says Google owns Deep Mind and Google has advertising business, ipso facto, some magical standrard dreamt up by the authors were not met. The reason for mentioning US agreements is that several nations, researchers and comapnies have developed procedures around sharing this data. And such sharing is not entirely unprecedented.
You're downplaying valid concerns. The ability to de-anonymise large data sets that we have today is unprecedented. The degree to which systems with access to that data are accessible remotely and potentially vulnerable to security problems is unprecedented. The degree to which powerful organisations like employers and insurers are attempting to profile potential employees and customers is unprecedented. However, nei…
Regarding your second point, yes all these issues have been considered in depth by policymakers in US government and NHS. And current rules/contracts already incorporate legal protections to prevent misuse in form of both civil and criminal penalties.
If DeepMind had done something truly unusual or nefarious they would have been already prosecuted. But having failed to find any evidence of explicit misuse the authors of the original paper have shifted the goalpost into territory of vague arguments.
Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report
#34Earlier quoted context omitted.
So, do you believe that the sticker was appropriate? Or would a PR statement from your university's press office have been more appropriate? Ultimately, the lack of a legally binding contractual obligation with sufficient audit-ability is primarily what Julia Powles & Hal Hodson are criticizing.
>> lack of legally binding From the verge article: "The data-sharing agreement — which was signed in 2015" There was a legally binding contractual agreement between the two parties Deep Mind & Royal Free. Here is the one that I and thousands (I am NOT exaggerating) of other researchers regularly sign to get access to data. https://www.hcup-us.ahrq.gov/team/NationwideDUA.jsp
Personally identifiable health-related information is classified as sensitive personal data under the DPA, and as such there are particularly strict conditions on processing it. What two organisations write in a contract does not change this.
Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report
#35Earlier quoted context omitted.
UK is in the EU until 2 years after Article 50 gets invoked, and EU data protection rules fully apply. This is a fact. The rude insult to another user, I won't even address.
If EU data protection rules apply then why aren't the authors marching to doors of EU Privacy Commisioner demnding to prosecute Google? The reality is that what is Deep Mind did is routine and commonplave, and that's why no one other than clickbait driven press is interested in it.
Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report
#36Earlier quoted context omitted.
1. UK is not in EU. The argument is that such arrangements are commonplace and I am sure one can find other such examples of data sharing in UK. 2. LOL yeah you are so damn clueless that I wont even bother replying. Lets just say there is reading some popular press article about privacy and annonymity. And then there is knowing intricate details of how business/research is conducted.
From your comments here, it appears that you're doing PhD research dealing with large sets of healthcare data. It also appears that you are casually dismissive of concerns about the risks of that data being de-anonymised. Your best rebuttal seems to be some vague allusion that the parent poster, who was essentially correct, didn't know what they were talking about. (This is something of a digression anyway, because i…
And regarding your concern about me, if anything I should be the one engaging in this ridiculous witch hunt against Deep Mind since I have during my PhD developed an Open Source transparent analytics platform for data on millions of patients.
But unlike the authors I want real debate and real systems that can be used, not faux outrage over another click bait article.
Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report
#37You can skip reading the article, as it does not list any "errors" that have happened. It merely questions whether the agreement under which the data is shared has adequate protections.
Indeed. The paper itself details seven "transgressions:" > 1) We do not know––and have no power to find out––what Google and DeepMind are really doing with NHS patient data, nor the extent of Royal Free’s meaningful control over what Google and DeepMind are doing; > 2) Any assurances about use of the dataset come from public relations statements, rather than independent oversight or legally binding documents; > 3) Th…
Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report
#38Earlier quoted context omitted.
>> lack of legally binding From the verge article: "The data-sharing agreement — which was signed in 2015" There was a legally binding contractual agreement between the two parties Deep Mind & Royal Free. Here is the one that I and thousands (I am NOT exaggerating) of other researchers regularly sign to get access to data. https://www.hcup-us.ahrq.gov/team/NationwideDUA.jsp
There was a legally binding contractual agreement between the two parties Deep Mind & Royal Free. Personally identifiable health-related information is classified as sensitive personal data under the DPA, and as such there are particularly strict conditions on processing it. What two organisations write in a contract does not change this.
http://searchhealthit.techtarget.com/definition/HIPAA-busine...
Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report
#39Earlier quoted context omitted.
You're downplaying valid concerns. The ability to de-anonymise large data sets that we have today is unprecedented. The degree to which systems with access to that data are accessible remotely and potentially vulnerable to security problems is unprecedented. The degree to which powerful organisations like employers and insurers are attempting to profile potential employees and customers is unprecedented. However, nei…
De-anonymization has NOTHING to do with the current scenario. When legal contracts are in place, they dictate the rquirements & restriction on using the data. Today you can go and purchase de-identified but NOT de-anonymized data from US government as long as you sign and abide by contract to use it for purpose of aggregate statistical reporting and research. Regarding your second point, yes all these issues have bee…
It does, though. Legal contracts aren't magical spells. Audit-ability is important when data sets are particularly sensitive and extensive. Which is why the new agreement includes provisions for auditing.
edit: NVM, I see down-thread what you mean.
Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report
#40> The data-sharing agreement — which was signed in 2015 and has since been superseded by a new contract — allows DeepMind access to medical records from 1.6 million patients attending London hospitals run by the NHS Royal Free Trust. Although at the time Google presented the deal as primarily about finding patients at risk from a condition known as acute kidney injury or AKI, the actual terms of the agreement, reveal…
The most basic issue is that health records about an identifiable individual are classified as "sensitive personal data" under the Data Protection Act, which is our primary privacy legislation. As such, there are several extra conditions that apply, in addition to all the ones covering all personal data, which constrain how "data controllers" and "data processors" are allowed to use that data. (The technical terms are defined in the Act itself.)
A lot of the details discussed in the original report are relevant because in this case the "data subjects" (the patients) did not give their explicit consent. There are specific conditions required under the Act for processing sensitive personal data without such consent, and it's not clear whether this agreement met them, for reasons such as those discussed in the report we're talking about. If in fact the conditions were not met then a lot of people have probably broken the law, and both the organisations involved and their officers are potentially guilty of offences.