Live data from Hacker News

NHS England patient data 'uploaded to Google servers', Tory MP says

theguardian.com

61–70 of 184 posts

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#61
post #41

Earlier quoted context omitted.

> Google have more credibility (and money) to lose from a high publicity hack than government contractors No, Google's (along with other major USA based firms) credibility flew out the window the minute E. Snowden released the NSA documents. I don't think that any corporation who has to manage sensitive information is going to trust Google or any other USA based company in the post-Snowden Era. The risks outweigh the…

Except that we're now in the post-Snowden era, and companies like Google have taken measures to harden their networks against (among other things) GCHQ-esque intrusion. In contrast, the other party in this story---the NHS---apparently hands out sensitive medical data on physical DVDs. I suppose on the plus side one doesn't need to worry about GCHQ being interested in illicitly acquiring that data, as if they have a r…

The best any US company can say is that they will only turn your information when they obtain a legally binding gag order.

Until our culture changes, US companies can't get that faith back.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#62

Earlier quoted context omitted.

Medical data is a great tool but the problem is that these stories are poisoning public good will. There is no point telling people to calm down when they have just learned that records of every meeting they ever had with their doctor were available on the public internet and identifiable to anybody who knows their address and DOB. That is something that people rightly get upset about. Additionally, it's not like the…

Not underplaying at all - your point is spot on - but this data only relates to hospital attendances and not GP interactions. Currently GP interactions are not available in the database, and that's the point of care.data.

Sorry. Yes you are quite right.

When I said public internet I was actually referring to the things Ben Goldacre has been tweeting ( https://twitter.com/bengoldacre/status/440475049880195073 ) and I'm not sure which data set he is talking about.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#63
post #40

Earlier quoted context omitted.

This sounds all too like the project I am collaborating on. It will be moderately big data (a few terabytes at most). The guys developing it just now are on their third NoSQL database - Elasticsearch. Them: "Look at how fast it is" Me: "You only have 3GB of data in it" Them: "Its so fast to develop, just connect Angular straight to Elasticsearch" Me: "Absolutely no concern given to security" Them: "The previous proje…

Ahh, hipsters.

Actually I didn't make the comment about the database being properly designed. I was at a loss as to what to say when that was the complaint.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#64

I trust Google more than I do "PA Consulting". Which begs the question, how did we get here? Who in their right mind sends out 27 DVDs with probably unencrypted, highly sensitive medical data? Even if the recipient is trustworthy, the transport isn't. This data needs to be on a locked away government server that answers queries by 3rd party by throwing away half of the data and randomizing the remainder.

Sending things in the post may be the acceptable method of sending sensitive data. I'm guessing that the UK prosecutes people who mess with the post the same way that the US prosecutes people who mess with the mail.

EDIT I'm not sure what I'm talking about. Was the complaint about "27 DVDs" just the amount of data or the method?

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#65
post #40
post #3

The report in question (linked in the article) provides "exceptional" evidence for the performance of Cloud technology by comparing a Google BigQuery search against an on-premises SQL Server query. So, cloud is good because map-reduce performs better than relational databases...

This sounds all too like the project I am collaborating on. It will be moderately big data (a few terabytes at most). The guys developing it just now are on their third NoSQL database - Elasticsearch. Them: "Look at how fast it is" Me: "You only have 3GB of data in it" Them: "Its so fast to develop, just connect Angular straight to Elasticsearch" Me: "Absolutely no concern given to security" Them: "The previous proje…

I've seen this theme way too much recently- developers giving preference to their own convenience over the security of their application, or, even worse, their confidential data. Every time, however, it was due to incompetance; they didn't know what they were doing wrong.

Frameworks like Meteor.js encourage bad habits like this. Quoting straight from their homepage[1], "All the same APIs are available on the client and the server — including database APIs! — so the same code can easily run in either environment."

Running arbitrary database queries from the client cannot possibly be a good idea.

[1] https://www.meteor.com/

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#66

Government privacy breaches are one of the things I despise most about current Western society. I am - day in, day out - one of those guys calling for ministerial blood. However I have long thought that proper open access to health data could be as revolutionary as, say, antibiotics. The government can do whatever the hell they like with my data - on the condition that anyone else can too. Can you imagine what insigh…

> The government can do whatever the hell they like with my data - on the condition that anyone else can too.

Wonderful.

Now consider how a potential employer might use your data:

Have you ever seen a GP for stress or mental health issues? Oh, maybe we are dis-inclined to hire you.

Suffer from back pain? Well that's one of the most given reasons for needing time off from work, which means you are a liability and we won't hire you.

Or even a business looking for partners:

Of these two evenly matched companies, this one over here has a CEO that has seen his Dr for stress and has had heart attacks in the past... he can't take the pressure and will be taking it easy when we need aggressive, let's go with the other one.

That's before you even touch what insurance companies will do, or whether schools will look into the mental health of little Timothy's family before determining whether to let the child into the school, or what retirement facilities might be available to you at what cost when you're 75+.

Once out in the open, this data is free for everyone to use. And it's going to be hard to then restrict how it is used by trying to bolt one gate after another.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#67

I trust Google more than I do "PA Consulting". Which begs the question, how did we get here? Who in their right mind sends out 27 DVDs with probably unencrypted, highly sensitive medical data? Even if the recipient is trustworthy, the transport isn't. This data needs to be on a locked away government server that answers queries by 3rd party by throwing away half of the data and randomizing the remainder.

Actually, I wouldn't be surprised if there was a law stating that those DVDs be encrypted... I mean, the key might be in a text file on the DVD, but there are plenty of regs surrounding the transportation of patient data.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#68
Don't the British have something like HIPAA in the US? If so PA Consulting would have had to follow those rules when using Google's infrastructure. Google's infrastructure passes many security levels and has just about every security certification (up to but _not_ including ITAR). There's nothing inherently insecure about doing this as long as they follow the rules. What are the rules about this over there?

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#69
post #22
post #2

It's worse than that: Ben Goldacre is reporting ( https://twitter.com/bengoldacre/status/440475049880195073 ) that the data was made publicly available. This is beyond parody.

another update: "No individuals directly named records online. But a massive breach of the most basic information security policies to prevent jigsaw." https://twitter.com/bengoldacre/status/440488463008550912

We're going to need something longer than a tweet to explain what he's actually talking about.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#70
post #5

Surely PA Consulting should immediately be sued out of existence. This kind of behaviour must be considered beyond negligent, practically criminal. I would strongly support throwing anyone involved in this into jail for a long time as a deterrent against future criminals. This is just unbelievable.

If they have permission of government officials then what? We can hold companies accountable but how do you hold government accountable? In a meaningful way? Certainly we can find a myriad of excuses not to fire an government worker for a mistake I am fine with doing the same for this as well. The key is to learn from it and put into place processes that stop it from reoccurring. We need to weigh the penalties to the…

It all depends on the value we assign to privacy. My personal opinion is that the handling of patient data should legally be protected somewhere on a scale between banking data and state secrets.

If those kinds of data are mishandled, there _is_ punishment, no matter where you work.

But then I'm culturally biased (we here in Germany seem to be collectively more paranoid about privacy than most other populations).

Post reply on HN