Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report
51–60 of 72 posts
Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report
#52Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report
#53Earlier quoted context omitted.
Concerns about de-anonymization are NOT AT ALL relevant in cases where patient level data is shared. Since its common knowledge that this data is ripe for misuse and abuse. As a result government agencies have developed a set of legal requirements and contracts to be used when sharing such data. Talking about differential-privacy and de-identification-is-not-de-anonymization is meaningless in this context since all p…
> But unlike the authors I want real debate Substantively improving patient privacy protections in a concrete case by forcing a large corporation to agree to strong privacy protections and auditing regimes seems like a "real" contribution spurring a "real" debate. For 1.6 million people, the results stemming from this paper much more "real" than any number of git commits to a software system.
hahhahah.
Chill dude, chill.
Software changes the world.
Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report
#54You can skip reading the article, as it does not list any "errors" that have happened. It merely questions whether the agreement under which the data is shared has adequate protections.
Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report
#55Under Spain protection of personal data law, any file with personal information must be accessible for the person, and the person has the right to know, modify and delete that file, and to deny the access to that information for any purpose.
Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report
#56Earlier quoted context omitted.
> There was a legally binding contractual agreement between the two parties Deep Mind & Royal Free. Which was, allegedly, far too lax. The claim that DeepMind was providing "direct care" is particularly questionable IMO, and that has significant implications in the context of this agreement. It means anyone who slaps together an iPhone app (and has the right clout/deep pockets) can get access to full and fully identi…
>>> It means anyone who slaps together an iPhone app can get access to full medical records. Ummm thats how the world works, frankly its like saying water is wet. Whenever a hospital works with any third party provider, it signs a BAA agreement which governs the sharing of data. All risks of disclosure, etc. are priced into the contract. Any large hospital will have dedicated group of lawyers for sole purpose of draw…
Most BAA agreements are for things that are actually and unambiguously direct care, and for the actual patient being treated, and only obviously relevant data used for a particular business processes.
Like lab results or billing, for example.
Most of the data Google received was for people who it's unambiguously NOT providing direct care to. And even for the people who might be helped with their app, IMO "direct care" is still a stretch.
So, this agreement was not standard or normal in terms of scope or quantity. That's almost tautologically true, since what DeepMind is doing is presently abnormal.
Now, you may argue that it should be allowed without additional data protections. But don't mis-characterize. Most BAA's are significantly different in scope and purpose from from this agreement in any number of ways.
> No they don't. For starters Deep Mind has not even returned any collected data.
They've agreed to independent auditing, which is a huge improvement. Source: https://deepmind.com/blog/working-nhs-build-lifesaving-techn...
Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report
#57Earlier quoted context omitted.
You're downplaying valid concerns. The ability to de-anonymise large data sets that we have today is unprecedented. The degree to which systems with access to that data are accessible remotely and potentially vulnerable to security problems is unprecedented. The degree to which powerful organisations like employers and insurers are attempting to profile potential employees and customers is unprecedented. However, nei…
De-anonymization has NOTHING to do with the current scenario. When legal contracts are in place, they dictate the rquirements & restriction on using the data. Today you can go and purchase de-identified but NOT de-anonymized data from US government as long as you sign and abide by contract to use it for purpose of aggregate statistical reporting and research. Regarding your second point, yes all these issues have bee…
Nope; contracts create enforceable expectations between parties but do not, except in exceptional cases where the law allows for this, override the requirements that exist in law.
Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report
#58> The data-sharing agreement — which was signed in 2015 and has since been superseded by a new contract — allows DeepMind access to medical records from 1.6 million patients attending London hospitals run by the NHS Royal Free Trust. Although at the time Google presented the deal as primarily about finding patients at risk from a condition known as acute kidney injury or AKI, the actual terms of the agreement, reveal…
We don't really have that in the UK.
This is one particular NHS Trust that runs 3 (I think) hospitals (and some other services) in London.
So if I go to them to have my knee replaced, and I go to a different trust to have a lump-ectomy, the data Deepmind gets doesn't include (I think) the lumpectomy.
As for your question about whether this kind of thing is popular: a while ago the NHS wanted to run something called Care.Data (care dot data) which was a big data project. A bunch of people complained about not being allowed to opt out, and so an opt out was added, and a bunch of people then opted out. Personally, I would have opted in if they'd given that option.
Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report
#59Frankly these post-docs are engaging in outright witchhunt against DeepMind driven by nothing but pure political agenda. The amount of data obtained is frankly tiny compared to that available regularly to researchers in USA. E.g. as part of my PhD research I have access to de-indentifed data on 40 Million patients spanning 5 years from several states. Not to forget programs like CMS Qualified Entity which provide acc…
> de-indentifed data on 40 Million patients This is not how this works. You can't really ensure anonymity with data like this.
Here is more information about the dataset, they themselves are aware of it. https://www.hcup-us.ahrq.gov/tech_assist/tutorials.jsp
In fact one of the major goals of my research is building an online plaform that ensures such large datasets no longer have to be distributed, as they are today.
Re: Google’s DeepMind made ‘inexcusable’ errors handling UK health data, says report
#60Earlier quoted context omitted.
> But unlike the authors I want real debate Substantively improving patient privacy protections in a concrete case by forcing a large corporation to agree to strong privacy protections and auditing regimes seems like a "real" contribution spurring a "real" debate. For 1.6 million people, the results stemming from this paper much more "real" than any number of git commits to a software system.
Number of git commits!!! hahhahah. Chill dude, chill. Software changes the world.
Well, it's true. Differential privacy is a nice idea, but in this particular case, you're disparaging a style of research that -- to date -- has had a much greater impact on improving actual, real world privacy than all the fanciest query engines in the world.
> Software changes the world.
The most important thing to know about differential privacy is that when in comes to privacy, software always plays second fiddle to policy and politics.
Differential privacy algorithms are literally nothing other than the implementation of a legal spec. Without the law, the algorithms are pointless.
Mind you, I don't intend to disparage differential privacy work in any way! But disparaging policy research while holding up differential privacy systems as the answer massively misses the point...