Live data from Hacker News

Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

theverge.com

41–50 of 72 posts

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#41
post #28
post #18

You can skip reading the article, as it does not list any "errors" that have happened. It merely questions whether the agreement under which the data is shared has adequate protections.

Indeed. The paper itself details seven "transgressions:" > 1) We do not know––and have no power to find out––what Google and DeepMind are really doing with NHS patient data, nor the extent of Royal Free’s meaningful control over what Google and DeepMind are doing; > 2) Any assurances about use of the dataset come from public relations statements, rather than independent oversight or legally binding documents; > 3) Th…

> Quite a few of these strike me as rather absurd

In a "that can't possibly be true" sense? Well, yeah, that's kind of the point...

1-3 seem like the sorts of things that even the least privacy-sensitive person can agree are troublesome.

If Google is willing to give anyone who signs a set of modest legal agreements carte blanc unaudited access to data stored on their servers, I'll begin to even remotely consider entertaining the claim that 1-3 aren't important.

5 in particular is blatantly illegal in the UK unless DeepMind is providing direct care. They claim apps == care (IMO absurd).

6 should just straight up be illegal.

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#42
post #25

Earlier quoted context omitted.

UK is in the EU until 2 years after Article 50 gets invoked, and EU data protection rules fully apply. This is a fact. The rude insult to another user, I won't even address.

If EU data protection rules apply then why aren't the authors marching to doors of EU Privacy Commisioner demnding to prosecute Google? The reality is that what is Deep Mind did is routine and commonplave, and that's why no one other than clickbait driven press is interested in it.

> is routine and commonplave

Then go ahead and try to get access to a similar data set. Unaudited access to fully identified and full medical records going back a half decade for 1.6 million people, without obtaining individual permission or providing any individual notice. For nothing other than the promise of some diagnostic assistance software. As a for-profit company.

Good luck greasing those wheels ;-)

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#43
post #7

Frankly these post-docs are engaging in outright witchhunt against DeepMind driven by nothing but pure political agenda. The amount of data obtained is frankly tiny compared to that available regularly to researchers in USA. E.g. as part of my PhD research I have access to de-indentifed data on 40 Million patients spanning 5 years from several states. Not to forget programs like CMS Qualified Entity which provide acc…

> de-indentifed data on 40 Million patients

This is not how this works. You can't really ensure anonymity with data like this.

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#44

Earlier quoted context omitted.

There was a legally binding contractual agreement between the two parties Deep Mind & Royal Free. Personally identifiable health-related information is classified as sensitive personal data under the DPA, and as such there are particularly strict conditions on processing it. What two organisations write in a contract does not change this.

Again you are unaware of extremely common business practices such as a BAA agreement. E.g. when a hospital contracts an outsourced lab all it needs is just another BAA agreement that governs sharing and use of the data. http://searchhealthit.techtarget.com/definition/HIPAA-busine...

You keep linking to US stuff, and people keep reminding you that this case is in the UK, subject to UK and EU data protection law.

The laws are very different, and there are much stronger protections in the UK.

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#45

Earlier quoted context omitted.

From your comments here, it appears that you're doing PhD research dealing with large sets of healthcare data. It also appears that you are casually dismissive of concerns about the risks of that data being de-anonymised. Your best rebuttal seems to be some vague allusion that the parent poster, who was essentially correct, didn't know what they were talking about. (This is something of a digression anyway, because i…

Concerns about de-anonymization are NOT AT ALL relevant in cases where patient level data is shared. Since its common knowledge that this data is ripe for misuse and abuse. As a result government agencies have developed a set of legal requirements and contracts to be used when sharing such data. Talking about differential-privacy and de-identification-is-not-de-anonymization is meaningless in this context since all p…

As a result government agencies have developed a set of legal requirements and contracts to be used when sharing such data.

That still doesn't matter. If Royal Free shared personal health data with Deep Mind without the data subjects' explicit consent, and if the arrangement doesn't fall under other permitted conditions for processing sensitive personal data under the DPA, then someone is breaking the law. If there were not at least some legitimate grounds for concern about whether that is the case, it is unlikely that the ICO would have opened a formal investigation into the deal. Again, nothing written in any contract between the organisations involved supersedes our primary data protection legislation. As for standard processes for handling such situations developed by government agencies, another substantial part of the report was about how the various regulatory bodies do not seem to have been consulted in ways that would normally have been expected before starting a project of this nature.

There is nothing routine, in the UK environment, about transferring complete, multi-year medical records for large numbers of identifiable individuals to external organisations not run by medical professionals for such open-ended purposes as those described in the agreement here. This is not a small thing.

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#46

Earlier quoted context omitted.

There was a legally binding contractual agreement between the two parties Deep Mind & Royal Free. Personally identifiable health-related information is classified as sensitive personal data under the DPA, and as such there are particularly strict conditions on processing it. What two organisations write in a contract does not change this.

Again you are unaware of extremely common business practices such as a BAA agreement. E.g. when a hospital contracts an outsourced lab all it needs is just another BAA agreement that governs sharing and use of the data. http://searchhealthit.techtarget.com/definition/HIPAA-busine...

We're talking about the UK. HIPAA is irrelevant.

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#47

Earlier quoted context omitted.

From your comments here, it appears that you're doing PhD research dealing with large sets of healthcare data. It also appears that you are casually dismissive of concerns about the risks of that data being de-anonymised. Your best rebuttal seems to be some vague allusion that the parent poster, who was essentially correct, didn't know what they were talking about. (This is something of a digression anyway, because i…

Concerns about de-anonymization are NOT AT ALL relevant in cases where patient level data is shared. Since its common knowledge that this data is ripe for misuse and abuse. As a result government agencies have developed a set of legal requirements and contracts to be used when sharing such data. Talking about differential-privacy and de-identification-is-not-de-anonymization is meaningless in this context since all p…

> But unlike the authors I want real debate

Substantively improving patient privacy protections in a concrete case by forcing a large corporation to agree to strong privacy protections and auditing regimes seems like a "real" contribution spurring a "real" debate.

For 1.6 million people, the results stemming from this paper much more "real" than any number of git commits to a software system.

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#48

Earlier quoted context omitted.

> driven by nothing but pure political agenda Do you mean personal or political? Because you insinuate personal motive with no evidence ("...and fear of AI sells very well in these types of academic circles..."). However, I don't see anything particularly wrong with researchers being motivated by politics. Personal privacy is political. Climate change is political. Human rights are political. Researchers should not f…

Again take a look at CMS Qualified Entity program which provides identifiable data. In fact most State government health agencies have a special board which routinely meets to discuss identifiable data requests. Finally their is nothing wrong in writing a paper about a politically charged topic, but completely dismissing existing standards to paint a picture of doom and gloom is ridiculous. E.g. just look at the refe…

[deleted]

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#49

Earlier quoted context omitted.

>> lack of legally binding From the verge article: "The data-sharing agreement — which was signed in 2015" There was a legally binding contractual agreement between the two parties Deep Mind & Royal Free. Here is the one that I and thousands (I am NOT exaggerating) of other researchers regularly sign to get access to data. https://www.hcup-us.ahrq.gov/team/NationwideDUA.jsp

> There was a legally binding contractual agreement between the two parties Deep Mind & Royal Free. Which was, allegedly, far too lax. The claim that DeepMind was providing "direct care" is particularly questionable IMO, and that has significant implications in the context of this agreement. It means anyone who slaps together an iPhone app (and has the right clout/deep pockets) can get access to full and fully identi…

>>> It means anyone who slaps together an iPhone app can get access to full medical records.

Ummm thats how the world works, frankly its like saying water is wet. Whenever a hospital works with any third party provider, it signs a BAA agreement which governs the sharing of data. All risks of disclosure, etc. are priced into the contract. Any large hospital will have dedicated group of lawyers for sole purpose of drawing up these agreements.

>> NHS patients have stronger legal protections today than they did a year ago.

No they don't. For starters Deep Mind has not even returned any collected data.

Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report

#50

Earlier quoted context omitted.

There was a legally binding contractual agreement between the two parties Deep Mind & Royal Free. Personally identifiable health-related information is classified as sensitive personal data under the DPA, and as such there are particularly strict conditions on processing it. What two organisations write in a contract does not change this.

Again you are unaware of extremely common business practices such as a BAA agreement. E.g. when a hospital contracts an outsourced lab all it needs is just another BAA agreement that governs sharing and use of the data. http://searchhealthit.techtarget.com/definition/HIPAA-busine...

HIPAA rules aren't relevant to the United Kingdom; and, even under HIPAA, a BAA is required for certain sharing of data with contracted parties, but isn't on its own sufficient for unlimited sharing of PHI without restriction on use. Heck, even the entity doing direct service has limits on permitted internal uses.

The items raised with DeepMind would raise serious concerns under HIPAA of the entities involved were covered by it.

Post reply on HN