Live data from Hacker News

NHS England patient data 'uploaded to Google servers', Tory MP says

theguardian.com

111–120 of 184 posts

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#111
post #28

Earlier quoted context omitted.

According to them, they got approval for doing that: > The alternative was to upload it to the cloud using tools such as Google Storage and use BigQuery to extract data from it. As PA has an existing relationship with Google, we pursued this route (with appropriate approval). This showed that it is possible to get even sensitive data in the cloud and apply proper safeguards.

And what "appropriate approval" was that, exactly? In general, exporting personal data outside of the EEA requires the explicit notification of the data subject under UK data protection law (among other consequences of the first Principle[1]). Moreover, the rules for even processing sensitive personal information, which includes health-related information, are significantly stronger than the general case. They should…

I thought that was why google hosted a lot of stuff in Ireland? So that companies could host EU data there without running afoul of the privacy laws?

I don't think the duty on a company is all that strong - the data has to stay in Europe, on a properly protected computer. Providing you needed a password or equivalent secret to get to the data they are probably okay legally.

Given the NHS is planning to sell poorly anonymized patient records at 10'000 for $10 imminently, I think we are complaining about the wrong problem.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#112
post #111

Earlier quoted context omitted.

And what "appropriate approval" was that, exactly? In general, exporting personal data outside of the EEA requires the explicit notification of the data subject under UK data protection law (among other consequences of the first Principle[1]). Moreover, the rules for even processing sensitive personal information, which includes health-related information, are significantly stronger than the general case. They should…

I thought that was why google hosted a lot of stuff in Ireland? So that companies could host EU data there without running afoul of the privacy laws? I don't think the duty on a company is all that strong - the data has to stay in Europe, on a properly protected computer. Providing you needed a password or equivalent secret to get to the data they are probably okay legally. Given the NHS is planning to sell poorly an…

I don't think the duty on a company is all that strong

You are mistaken. For sensitive personal data, there are much stricter rules on what you can do. Please see the second link I cited before.

Given the NHS is planning to sell poorly anonymized patient records at 10'000 for $10 imminently

Are you referring to care.data? That programme is essentially dead, in the face of massive opposition, and it was even before the current round of disclosures about hospital records already being leaked.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#113
post #103

Earlier quoted context omitted.

Is your concern that the NSA itself is targeting British health records? If so, what makes you think anyone else is better prepared for this adversary? Or, if you're talking about someone other than the NSA (which you allude to with your use of "etc"), then who is it? What are they going to do, and why do you feel it's demonstrably more likely to happen with the data on Google's servers? Where would you put the data…

The NSA specifically isn't the point, though I do believe their blanket surveillance of the Internet (and the similar surveillance by other government spy agencies such as our own GCHQ) should be considered a hostile act and incur a proportionate response. I simply don't accept that there is any ethical legitimacy to such dragnet programmes or that they bring more benefit than the risk they obviously pose to free, pe…

You didn't answer any of my questions.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#114
post #5

Surely PA Consulting should immediately be sued out of existence. This kind of behaviour must be considered beyond negligent, practically criminal. I would strongly support throwing anyone involved in this into jail for a long time as a deterrent against future criminals. This is just unbelievable.

Taking a sentient human being and throwing them in a cage is a profoundly violent act. I find it troubling that you guys so casually reach for it as a punitive tool, particularly when the subject has neither committed physical violence nor poses such a threat to others. Surely you clever people can think of forms of punishment/deterrence less destructive to both the individual and society as a whole.

Taking a sentient human being and throwing them in a cage is a profoundly violent act. I find it troubling that you guys so casually reach for it as a punitive tool

We aren't reaching for it casually. Some of us consider privacy a fundamental value that must be defended, and regard an attack on our privacy with the same seriousness that we would regard an attack on our physical person.

Which is more of a danger to me, someone who punches me in the face on their drunk night out and gives me a bloody lip and a bit of pain for a few hours, or someone who betrays confidences that may have lifelong implications for my employability, insurance premiums and credit levels, ability to travel freely, and for that matter my self-respect and basic human dignity, before you even get to the kinds of more extreme and very physical dangers that could be posed by invasions of privacy if we consider the lessons of history?

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#115

Once the data enters the US, it is subject to HIPAA. PA is criminally liable.

So, that's an interesting question, right?

If it's UK data, from the UK .gov, being stored to a server whose hardware is in the US, to be worked on by a UK consultancy, should it actually be subject to HIPAA?

Jurisdiction in the Internet is tricky business.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#116
post #113

Earlier quoted context omitted.

The NSA specifically isn't the point, though I do believe their blanket surveillance of the Internet (and the similar surveillance by other government spy agencies such as our own GCHQ) should be considered a hostile act and incur a proportionate response. I simply don't accept that there is any ethical legitimacy to such dragnet programmes or that they bring more benefit than the risk they obviously pose to free, pe…

You didn't answer any of my questions.

I would leave the data in the hands of medical professionals who are subject to medical ethics and confidentiality, kept away from anyone who might have any other ambitions for it. And I would keep it within the range of European data protection law, which is in general considerably stronger (rightly so, IMHO) than the rules in places like the US, though in this particular case if HIPAA is relevant that may not actually be the case.

Edit: Incidentally:

presumably, PA was given the contract because the potential benefits of the research were believed to outweigh the privacy risks.

That "belief" would be a huge assumption, for which I see little evidence in this specific case, nor any historical pattern to suggest it is reasonable. In any case, it was clearly a bad assumption with hindsight, because the privacy risks are evidently not merely risks at this point.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#117
post #111

Earlier quoted context omitted.

And what "appropriate approval" was that, exactly? In general, exporting personal data outside of the EEA requires the explicit notification of the data subject under UK data protection law (among other consequences of the first Principle[1]). Moreover, the rules for even processing sensitive personal information, which includes health-related information, are significantly stronger than the general case. They should…

I thought that was why google hosted a lot of stuff in Ireland? So that companies could host EU data there without running afoul of the privacy laws? I don't think the duty on a company is all that strong - the data has to stay in Europe, on a properly protected computer. Providing you needed a password or equivalent secret to get to the data they are probably okay legally. Given the NHS is planning to sell poorly an…

You are wrong about the HES records and about the proposed GP records - there are criminal offences if the data is misused.

> Given the NHS is planning to sell poorly anonymized patient records at 10'000 for $10 imminently,

That's wrong too. It's okay to be against something, but only if you know what that thing actually is. The data would be pseudo anonymous with HSCIC and anonymous outside HSCIC. While there's a possibility of de-anonymisation anyone doing so would be committing a criminal offence.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#118
post #5

Surely PA Consulting should immediately be sued out of existence. This kind of behaviour must be considered beyond negligent, practically criminal. I would strongly support throwing anyone involved in this into jail for a long time as a deterrent against future criminals. This is just unbelievable.

PA Consulting definitely think they were in the right here, they attended a recruitment event at my university and told us about how they did this for the NHS using Google tools. I figured they had permission from the NHS or whatever, and they also seemed to have some relationship with Google. My first thought is that this is just an MP looking for attention, but if the NHS genuinely didn't know then I agree it's surely criminal.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#119
post #26

Good. Imo, the fearmongering here is actually quite irrational. Google have more credibility (and money) to lose from a high publicity hack than government contractors who already act with impunity . If they'd invested in their own own map-reduce deployment we'd only be hearing another story about government contractors wasted millions of £ in taxpayers money on Big Brother data analysis. > The extracted information…

But it was a government contractor who uploaded and queried the data (PA), they just used Google's platform. Frankly, this seems as related to Google as Nokia would be if someone used one of their cellphones to detonate an explosive. They're just the database provider.

Yes, but putting "Google" in the headline is more likely to get clicks.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#120
post #113

Earlier quoted context omitted.

You didn't answer any of my questions.

I would leave the data in the hands of medical professionals who are subject to medical ethics and confidentiality, kept away from anyone who might have any other ambitions for it. And I would keep it within the range of European data protection law, which is in general considerably stronger (rightly so, IMHO) than the rules in places like the US, though in this particular case if HIPAA is relevant that may not actua…

> I would leave the data in the hands of medical professionals

Presumably, the medical professionals aren't also IT professionals. If they want their data to be on a hard drive, and accessible via a network, using some apps, then some group of non-medical professionals is going to need to maintain those services.

Who do you think that should be, and why do you think their systems would be more secure than Google's?

> kept away from anyone who might have any other ambitions for it

What ambitions are you implicitly accusing Google of having? Do you think Google's going to tap into their customers' private files and sell them to a third party?

If not, then what's the actual, non-vague scenario you're worried about?

Post reply on HN