Live data from Hacker News

NHS England patient data 'uploaded to Google servers', Tory MP says

theguardian.com

81–90 of 184 posts

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#81
post #28
post #5

Surely PA Consulting should immediately be sued out of existence. This kind of behaviour must be considered beyond negligent, practically criminal. I would strongly support throwing anyone involved in this into jail for a long time as a deterrent against future criminals. This is just unbelievable.

According to them, they got approval for doing that: > The alternative was to upload it to the cloud using tools such as Google Storage and use BigQuery to extract data from it. As PA has an existing relationship with Google, we pursued this route (with appropriate approval). This showed that it is possible to get even sensitive data in the cloud and apply proper safeguards.

And what "appropriate approval" was that, exactly?

In general, exporting personal data outside of the EEA requires the explicit notification of the data subject under UK data protection law (among other consequences of the first Principle[1]). Moreover, the rules for even processing sensitive personal information, which includes health-related information, are significantly stronger than the general case.

They should never had been given that data in the first place, of course, and giving it to them should clearly be illegal on the part of whoever disclosed it. If it turns out not to have been, that will be a compelling case for dramatically strengthening the legal data protection and privacy framework in the UK. But I don't see how either the original source or PA Consulting can get around the basic conditions for processing sensitive personal data[2]. In particular, the most likely condition they might appeal to here in the absence of explicit consent reads:

"The processing is necessary for medical purposes, and is undertaken by a health professional or by someone who is subject to an equivalent duty of confidentiality." [Emphasis added]

Even once they had it, that still doesn't give them a free pass on exporting the data outside the EEA without notification (see [3]), or actually processing the data themselves for that matter.

[1] http://ico.org.uk/for_organisations/data_protection/the_guid...

[2] http://ico.org.uk/for_organisations/data_protection/the_guid...

[3] http://ico.org.uk/for_organisations/data_protection/the_guid...

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#83
post #48

Why does the government repeatedly hire incompetent people?? They pay crazy amounts of money for it too. I hope there is a very public investigation into this. We are losing privacy every day now and this is one area of our lives that needs to remain private at all costs. There is very little I can see to gain and lots to lose from losing privacy in health. Especially in a public system like the NHS.

Because they're all part of the old boys network. No other reason.

Sad but seems to be true.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#84
post #39

Earlier quoted context omitted.

I have begin collaborating in a rare diseases project. So imagine you have one or two people in the country with certain symptoms. How anonymous is that?

Do you still work in that field? If so, you're probably one of the few people that IMO actually should have some access to that data. Maybe you'll get lucky and the data will become a researcher free-for-all, like the Enron emails did. (Not likely, though.)

No we are discussing all the security implications before we even get close to collecting the data.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#85

I don't understand why the data being on "Google servers" is generating such outrage. Google almost certainly has superior security to this "PA Consulting" or even the government itself.

The same government that had completely penetrated Google's network for years without them realising?

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#86
post #5

Surely PA Consulting should immediately be sued out of existence. This kind of behaviour must be considered beyond negligent, practically criminal. I would strongly support throwing anyone involved in this into jail for a long time as a deterrent against future criminals. This is just unbelievable.

If they have permission of government officials then what? We can hold companies accountable but how do you hold government accountable? In a meaningful way? Certainly we can find a myriad of excuses not to fire an government worker for a mistake I am fine with doing the same for this as well. The key is to learn from it and put into place processes that stop it from reoccurring. We need to weigh the penalties to the…

Frankly, if no one lost their life or livelihood I don't think seeking the outcome you suggest is warranted.

I could not disagree more strongly. A betrayal of public trust on this scale, abusing privileged access to the most sensitive and private of personal data, should be met by severe penalties.

At a minimum the people who actually disclosed the data and the responsible executives at both the original NHS-related source and at PA Consulting should be facing jail time, and the executives barred from holding public office or directing companies for a very long time.

That the company in question should be legally obliterated and that Google should be formally notified and required to completely delete the personal data they are illegally holding should go without saying. If Google refuse to comply then any Google executive who sets foot on European soil should be jailed as well.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#87
post #26

Good. Imo, the fearmongering here is actually quite irrational. Google have more credibility (and money) to lose from a high publicity hack than government contractors who already act with impunity . If they'd invested in their own own map-reduce deployment we'd only be hearing another story about government contractors wasted millions of £ in taxpayers money on Big Brother data analysis. > The extracted information…

My postcode and date of birth if sufficient to uniquely identify me. What you seem to miss is that this then acts as a key into the medical information held in this data set. If it was just the NHS number, date of birth, postcode, ethnicity and gender that was available, nobody would have cared much.

That the electoral roll data is available is a further reason why this is bad: It means that by cross-indexing this data with the electoral roll or similar data, one can take the poorly semi-anonymised NHS data and undo a large percentage of the anonymisation, either completely or with a high degree of probability.

> What specifically are people actually afraid of with regard to this data set sitting on Googles servers? I just don't get the regular public outcry about NHS data.

The issue is not Google per se, but that this loose and fast handling with data that is in no way anonymous indicates that the government and consultancies involved does not in any way understand or respect the concerns people have about privacy and the protection of personal information.

We don't want, e.g., a future where employers can look up our health issues and decide to get rid of someone they see as a potential liability, or use it to help manufacture justifications to get rid of someone who is troublesome. Or one where relatives of someone with a cancer diagnosis receives ads about hospice care, possibly before they've even been told. Or any number of other gross invasions of privacy that this data becoming easily available could enable.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#88

I don't understand why the data being on "Google servers" is generating such outrage. Google almost certainly has superior security to this "PA Consulting" or even the government itself.

I've worked with anonymized patient data in a litigation consulting context (in the U.S.). I worked at a small consulting firm nobody's ever heard of.

We worked exclusively on air-gapped servers behind several layers of physical security. Even encrypted data was never, ever sent over the public wire.

You don't connect sensitive data to the internet if a single breach is catastrophic. We talk about things like the Target hack as catastrophic breaches, but they aren't. You can change your password or cancel your credit card. You can't change your medical history - once public, it is always public.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#89
post #28

Earlier quoted context omitted.

According to them, they got approval for doing that: > The alternative was to upload it to the cloud using tools such as Google Storage and use BigQuery to extract data from it. As PA has an existing relationship with Google, we pursued this route (with appropriate approval). This showed that it is possible to get even sensitive data in the cloud and apply proper safeguards.

And what "appropriate approval" was that, exactly? In general, exporting personal data outside of the EEA requires the explicit notification of the data subject under UK data protection law (among other consequences of the first Principle[1]). Moreover, the rules for even processing sensitive personal information, which includes health-related information, are significantly stronger than the general case. They should…

Doesn't the "safe harbor" clause apply to US companies ?

You know, that joke of a clause which says that US companies fit the needs of our data protection law as long as they claim to fit it (and they only have to claim it) ? Part of the new data protection law that was supposed to be voted in the EU following/during the PRISM scandal was revoking that stupid clause but I'm not sure what happened to that reform.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#90

I don't understand why the data being on "Google servers" is generating such outrage. Google almost certainly has superior security to this "PA Consulting" or even the government itself.

The same government that had completely penetrated Google's network for years without them realising?

I'm pretty sure "the government" in GP's context referred to the UK government, not the US.
Post reply on HN