Live data from Hacker News

NHS England patient data 'uploaded to Google servers', Tory MP says

theguardian.com

121–130 of 184 posts

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#121
post #5

Surely PA Consulting should immediately be sued out of existence. This kind of behaviour must be considered beyond negligent, practically criminal. I would strongly support throwing anyone involved in this into jail for a long time as a deterrent against future criminals. This is just unbelievable.

If they have permission of government officials then what? We can hold companies accountable but how do you hold government accountable? In a meaningful way? Certainly we can find a myriad of excuses not to fire an government worker for a mistake I am fine with doing the same for this as well. The key is to learn from it and put into place processes that stop it from reoccurring. We need to weigh the penalties to the…

>If they have permission of government officials then what? //

They wouldn't - without wilful negligence - accept such "permission" from anyone other than a senior official who had in depth knowledge of the necessary requirements of privacy laws. A person in that permission is unlikely to be acting lawfully and is likely to be aware of that - there's no way they should retain a post with responsibility over anything greater than a stapler after that.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#122

Earlier quoted context omitted.

Taking a sentient human being and throwing them in a cage is a profoundly violent act. I find it troubling that you guys so casually reach for it as a punitive tool, particularly when the subject has neither committed physical violence nor poses such a threat to others. Surely you clever people can think of forms of punishment/deterrence less destructive to both the individual and society as a whole.

Taking a sentient human being and throwing them in a cage is a profoundly violent act. I find it troubling that you guys so casually reach for it as a punitive tool We aren't reaching for it casually. Some of us consider privacy a fundamental value that must be defended, and regard an attack on our privacy with the same seriousness that we would regard an attack on our physical person. Which is more of a danger to me…

>Some of us consider privacy a fundamental value that must be defended

The severity of a punishment can be tuned separately from the form of punishment. Imprisonment is not appropriate merely by dint of your emotional reaction to the crime itself.

>Which is more of a danger to me...

Sufficient to warrant throwing them in a cage, being brutalized by actually violent criminals, imposing a direct cost burden on society, and also indirectly by depriving society of that individual's productivity?

Probably neither.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#123

I trust Google more than I do "PA Consulting". Which begs the question, how did we get here? Who in their right mind sends out 27 DVDs with probably unencrypted, highly sensitive medical data? Even if the recipient is trustworthy, the transport isn't. This data needs to be on a locked away government server that answers queries by 3rd party by throwing away half of the data and randomizing the remainder.

Basically. An alternative headline for this story could be "Contractor moves sensitive data from insecure, non-audited medium to secure, audited medium."

That would be "Contractor moves sensitive data from insecure, non-audited medium to secure, audited medium monitored by a foreign spy agency"

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#126
> The data set was so large it took up 27 DVDs and took a couple of weeks to upload.

Really? 27 DVDs worth of data is only about 127GB of data and it tooks weeks to upload? I'm on a standard Comcast cable line and I could probably upload that in a few days at most.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#127
post #5

Surely PA Consulting should immediately be sued out of existence. This kind of behaviour must be considered beyond negligent, practically criminal. I would strongly support throwing anyone involved in this into jail for a long time as a deterrent against future criminals. This is just unbelievable.

PA Consulting's statement:

PA purchased the commercially available Hospital Episode Statistics data set from the NHS Information Centre (now the Health and Social Care Information Centre). The data set does not contain information linked to specific individuals. The information is held securely in the cloud in accordance with conditions specified and approved by HSCIC.

This new approach to analytics can help the NHS improve patient care. We have been able to identify where services are needed most and to understand previously unseen side effects of drugs and treatments. Our approach protects patient confidentiality and allows insights to be derived at significantly lower cost, and a hundred times faster, than any traditional approach.

HSCIC's statement:

The NHS Information Centre (NHS IC) signed an agreement to share pseudonymised Hospital Episodes Statistics data with PA Consulting in November 2011.

This included Hospital Episode Statistics on Admitted Patient Care (1999/00 to Provisional 2011/12), Outpatient (2003/4 to Provisional 2011/12) and A&E (2007/8 to Provisional 2011/12). This agreement lasted to November 2012 and was amended in December 2012 to extend to November 2015.

The agreement obliged PA Consulting to abide by conditions to protect the confidentiality of the data, including restricting the data to a named list of individuals, a prohibition on sharing any information with risk of identifying individuals and a requirement to destroy the data after the agreement end date.

PA Consulting used a product called Google BigQuery to manipulate the datasets provided and the NHS IC was aware of this. The NHS IC had written confirmation from PA Consulting prior to the agreement being signed that no Google staff would be able to access the data; access continued to be restricted to the individuals named in the data sharing agreement.

http://www.paconsulting.com/introducing-pas-media-site/relea...

http://www.hscic.gov.uk/article/3948/Statement-Use-of-data-b...

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#129
post #5

Surely PA Consulting should immediately be sued out of existence. This kind of behaviour must be considered beyond negligent, practically criminal. I would strongly support throwing anyone involved in this into jail for a long time as a deterrent against future criminals. This is just unbelievable.

And Obama seriously considers letting 3rd parties keeping everyone's private data?

No Mr. Obama, neither NSA keeping the data nor 3rd parties is the solution. The solution is to stop spying on everyone.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#130
post #28

Earlier quoted context omitted.

According to them, they got approval for doing that: > The alternative was to upload it to the cloud using tools such as Google Storage and use BigQuery to extract data from it. As PA has an existing relationship with Google, we pursued this route (with appropriate approval). This showed that it is possible to get even sensitive data in the cloud and apply proper safeguards.

And what "appropriate approval" was that, exactly? In general, exporting personal data outside of the EEA requires the explicit notification of the data subject under UK data protection law (among other consequences of the first Principle[1]). Moreover, the rules for even processing sensitive personal information, which includes health-related information, are significantly stronger than the general case. They should…

The statement from the offending party is that there was no individual identifying data. So what law?
Post reply on HN