Live data from Hacker News

NHS England patient data 'uploaded to Google servers', Tory MP says

theguardian.com

131–140 of 184 posts

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#131
post #120

Earlier quoted context omitted.

I would leave the data in the hands of medical professionals who are subject to medical ethics and confidentiality, kept away from anyone who might have any other ambitions for it. And I would keep it within the range of European data protection law, which is in general considerably stronger (rightly so, IMHO) than the rules in places like the US, though in this particular case if HIPAA is relevant that may not actua…

> I would leave the data in the hands of medical professionals Presumably, the medical professionals aren't also IT professionals. If they want their data to be on a hard drive, and accessible via a network, using some apps, then some group of non-medical professionals is going to need to maintain those services. Who do you think that should be, and why do you think their systems would be more secure than Google's? >…

If a malicious incident like the below happened then Google wouldn't even be liable, unlike data that is kept under UK control.

From http://gawker.com/5637234/gcreep-google-engineer-stalked-tee...

In at least four cases, Barksdale spied on minors' Google accounts without their consent, according to a source close to the incidents. In an incident this spring involving a 15-year-old boy who he'd befriended, Barksdale tapped into call logs from Google Voice, Google's Internet phone service, after the boy refused to tell him the name of his new girlfriend, according to our source. After accessing the kid's account to retrieve her name and phone number, Barksdale then taunted the boy and threatened to call her.

In other cases involving teens of both sexes, Barksdale exhibited a similar pattern of aggressively violating others' privacy, according to our source. He accessed contact lists and chat transcripts, and in one case quoted from an IM that he'd looked up behind the person's back. (He later apologized to one for retrieving the information without her knowledge.) In another incident, Barksdale unblocked himself from a Gtalk buddy list even though the teen in question had taken steps to cut communications with the Google engineer.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#132
post #127
post #5

Surely PA Consulting should immediately be sued out of existence. This kind of behaviour must be considered beyond negligent, practically criminal. I would strongly support throwing anyone involved in this into jail for a long time as a deterrent against future criminals. This is just unbelievable.

PA Consulting's statement: PA purchased the commercially available Hospital Episode Statistics data set from the NHS Information Centre (now the Health and Social Care Information Centre). The data set does not contain information linked to specific individuals. The information is held securely in the cloud in accordance with conditions specified and approved by HSCIC. This new approach to analytics can help the NHS…

> no Google staff would be able to access the data

Well that's obviously bullshit... But aside from that, if it's commercially available and pseudonymised, I can't see much wrong with it.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#133
post #66

Government privacy breaches are one of the things I despise most about current Western society. I am - day in, day out - one of those guys calling for ministerial blood. However I have long thought that proper open access to health data could be as revolutionary as, say, antibiotics. The government can do whatever the hell they like with my data - on the condition that anyone else can too. Can you imagine what insigh…

> The government can do whatever the hell they like with my data - on the condition that anyone else can too. Wonderful. Now consider how a potential employer might use your data: Have you ever seen a GP for stress or mental health issues? Oh, maybe we are dis-inclined to hire you. Suffer from back pain? Well that's one of the most given reasons for needing time off from work, which means you are a liability and we w…

Although I didn't say it explicitly in the particular sentence you quoted, I did say (pseudo|a)nonymously just after. I'm not suggesting identifiable health records should be searchable by all!

You raise interesting points. I think you are quite correct in saying these things are likely to happen. But I wonder whether hiding such information is actually the most efficient strategy. I mean if some divine power gave us all the ability to see inside each others minds, and ergo all the bullshit, lies, and politicking that makes up a great deal of human interaction was to evaporate, wouldn't the world be a better, more forgiving place? Obviously this is all a bit esoteric, and the game-theoretical analysis of moving from the status quo to a world of almost creepy honesty would almost certainly show that it could never happen, but I find it a useful thought nonetheless.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#134
post #66

Government privacy breaches are one of the things I despise most about current Western society. I am - day in, day out - one of those guys calling for ministerial blood. However I have long thought that proper open access to health data could be as revolutionary as, say, antibiotics. The government can do whatever the hell they like with my data - on the condition that anyone else can too. Can you imagine what insigh…

> The government can do whatever the hell they like with my data - on the condition that anyone else can too. Wonderful. Now consider how a potential employer might use your data: Have you ever seen a GP for stress or mental health issues? Oh, maybe we are dis-inclined to hire you. Suffer from back pain? Well that's one of the most given reasons for needing time off from work, which means you are a liability and we w…

[deleted]

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#135

Earlier quoted context omitted.

Taking a sentient human being and throwing them in a cage is a profoundly violent act. I find it troubling that you guys so casually reach for it as a punitive tool We aren't reaching for it casually. Some of us consider privacy a fundamental value that must be defended, and regard an attack on our privacy with the same seriousness that we would regard an attack on our physical person. Which is more of a danger to me…

>Some of us consider privacy a fundamental value that must be defended The severity of a punishment can be tuned separately from the form of punishment. Imprisonment is not appropriate merely by dint of your emotional reaction to the crime itself. >Which is more of a danger to me... Sufficient to warrant throwing them in a cage, being brutalized by actually violent criminals, imposing a direct cost burden on society,…

Financial penalties have a long record of poor influence toward desired, legal behaviour. Further, they tend to simply be, sooner or later, passed on to the customers or clients who in many cases are the original wronged. Those individuals actually responsible for the sanctioned behaviour are not or only weakly punished and perhaps influenced against its repetition.

As an individual, one could well go to prison for such misbehaviour. Corporate and government employment should not serve as an impenetrable shield and dilution of responsibility against such eventuality.

Incarceration is often described as having two goals: Punishment for crimes committed, and mitigation against such crimes. For the latter, both by actual restraint and by aversion to the potential results.

It seems that stronger aversion is needed; we have a systemic problem with recurrence -- often by the same parties -- of this behaviour.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#136

I trust Google more than I do "PA Consulting". Which begs the question, how did we get here? Who in their right mind sends out 27 DVDs with probably unencrypted, highly sensitive medical data? Even if the recipient is trustworthy, the transport isn't. This data needs to be on a locked away government server that answers queries by 3rd party by throwing away half of the data and randomizing the remainder.

I've worked with anonymized patient data in the U.S. at a small consulting firm nobody's ever heard of. We received encrypted physical media via USPS and registered mail. It may seem byzantine, but we also worked exclusively on air-gapped servers.

Best practice in data security is pretty straightforward - you don't connect data to the internet if a single breach is catastrophic. We talk about things like the Target hack as catastrophic breaches, but they aren't. You can change your password or cancel your credit card. You can't change your medical history - once public, it is always public.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#137
A second scandal is now emerging out of this, as digital mapping firm Earthware are accused of posting HES data in Google maps form on its website for all to see.

[1] http://www.independent.co.uk/life-style/health-and-families/...

[2] http://www.hscic.gov.uk/article/3947/Statement-Use-of-data-b...

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#138

Earlier quoted context omitted.

Basically. An alternative headline for this story could be "Contractor moves sensitive data from insecure, non-audited medium to secure, audited medium."

That would be "Contractor moves sensitive data from insecure, non-audited medium to secure, audited medium monitored by a foreign spy agency"

Correct. I disregarded the nationality issue in assuming that GCHQ having "NHS, please pass me your data because terrorists" access to the health records is equivalent to the NSA having "[GAG ORDER] Google, a secret court has ordered you..." access to the health records, given how closely those agencies seem to be working together based on the Snowden disclosures.

Others may place differing weights and values on their cloak-and-dagger outfit of choice. ;)

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#139
post #17

This is the data in question: http://www.hscic.gov.uk/hes It is anonymised [1], publicly licensable data. Here are a list of users and uses. [2] [1] "We apply a strict statistical disclosure control in accordance with the HES protocol, to all published HES data. This suppresses small numbers to stop people identifying themselves and others, to ensure that patient confidentiality is maintained." [2] http://www.hscic.g…

> It is anonymised Not meaningfully, no. A UK postcode covers 20 households or less. If you have that plus gender and date of birth (as seems to be the case here), you almost always have a unique individual.

Tiny nitpick[0]: a UK postcode corresponds to a minimum of 1, and maximum of 100 (not 20), delivery points[1] (not households). Typically about 15 delivery points.

I fully agree with your main point, though, that the data are not meaningfully anonymised.

[0] http://www.poweredbypaf.com/wp-content/uploads/2013/11/Progr... (page 19, "Small User Postcode")

[1] https://en.wikipedia.org/wiki/Delivery_point

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#140
post #67

I trust Google more than I do "PA Consulting". Which begs the question, how did we get here? Who in their right mind sends out 27 DVDs with probably unencrypted, highly sensitive medical data? Even if the recipient is trustworthy, the transport isn't. This data needs to be on a locked away government server that answers queries by 3rd party by throwing away half of the data and randomizing the remainder.

Actually, I wouldn't be surprised if there was a law stating that those DVDs be encrypted... I mean, the key might be in a text file on the DVD, but there are plenty of regs surrounding the transportation of patient data.

That's true; they may be secured in that fashion (does anybody know what NHS policy is?)

I was thinking "secure" in the sense of "Physically inside a datacenter with privileged access" as opposed to "Physically on 27 DVDs that are... Hm.... Where are those DVDs... Hey Bob, did you have the DVDs last? Shoot, I know I put those DVDs around here somewhere..."

Post reply on HN