Live data from Hacker News

NHS England patient data 'uploaded to Google servers', Tory MP says

theguardian.com

151–160 of 184 posts

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#151
post #127

Earlier quoted context omitted.

PA Consulting's statement: PA purchased the commercially available Hospital Episode Statistics data set from the NHS Information Centre (now the Health and Social Care Information Centre). The data set does not contain information linked to specific individuals. The information is held securely in the cloud in accordance with conditions specified and approved by HSCIC. This new approach to analytics can help the NHS…

> no Google staff would be able to access the data Well that's obviously bullshit... But aside from that, if it's commercially available and pseudonymised, I can't see much wrong with it.

It can be done !

http://people.csail.mit.edu/nickolai/papers/popa-cryptdb-cac...

That said, I doubt that Google is doing it. More interesting is that this tech appeared two years ago, I thought the world would rush to pick it up and as far as I know no one has!

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#152

I don't understand why the data being on "Google servers" is generating such outrage. Google almost certainly has superior security to this "PA Consulting" or even the government itself.

I agree. I personally trust Google far more than the US or my own (UK) government.

It's the whole monopoly on force thing. I have no fear that Google will grab me out of my bed in the middle of the night.

With the UK government — even though I trust them to be pretty rational and fair, and to my knowledge I've done nothing that would warrant that treatment — there's always the worry that they have the ability to significantly reduce my quality of life (if they ever chose to) and I might not even deserve it.

It's always surprising to me the fear regular people have of companies doesn't extend to governments, who have far more power over their lives.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#153

Earlier quoted context omitted.

I'm pretty sure "the government" in GP's context referred to the UK government, not the US.

It was the UK Government (GCHQ) that was breaking into Google's networks.

GCHQ has done some appalling stuff, but the Google network penetration was done by the NSA.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#154
Interestingly enough, the company behind this cluster#### has previous and proven record of similar behaviour.[1][2] Sure, it takes conscious effort to upload multiple DVD's worth of data, which already rules out accidents - but because this is not an isolated incident, I wouldn't rule out corporate policy of willful neglect either.

"Fined and fired" is not a sufficient deterrent.

1. http://www.theregister.co.uk/2008/09/11/pa_consulting_home_o...

2: http://www.scl.org/site.aspx?i=ne9297

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#155

Earlier quoted context omitted.

> It is anonymised Not meaningfully, no. A UK postcode covers 20 households or less. If you have that plus gender and date of birth (as seems to be the case here), you almost always have a unique individual.

NHS number, date of birth, postcode, ethnicity and gender. Is about as anonymous as wearing a different hat.

NHS England’s Chief Data Officer says that with the pseudonymous dataset (he calls it amber data) patient’s identifiers are removed, including "(their date of birth, postcode, and so on)". Also, I think it might be hospital number rather than NHS number in the data

http://www.england.nhs.uk/2014/01/15/geraint-lewis/

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#156
post #39
post #17

This is the data in question: http://www.hscic.gov.uk/hes It is anonymised [1], publicly licensable data. Here are a list of users and uses. [2] [1] "We apply a strict statistical disclosure control in accordance with the HES protocol, to all published HES data. This suppresses small numbers to stop people identifying themselves and others, to ensure that patient confidentiality is maintained." [2] http://www.hscic.g…

I have begin collaborating in a rare diseases project. So imagine you have one or two people in the country with certain symptoms. How anonymous is that?

Small numbers (cells containing values less than 6) are supposed to be removed from the data or obscured, to prevent breaches of confidentiality.

Word document: http://www.hscic.gov.uk/media/1879/NHSIC-small-numbers-terms...

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#157
post #137

A second scandal is now emerging out of this, as digital mapping firm Earthware are accused of posting HES data in Google maps form on its website for all to see. [1] http://www.independent.co.uk/life-style/health-and-families/... [2] http://www.hscic.gov.uk/article/3947/Statement-Use-of-data-b...

Earthware's statement claims that they used mock data

HES Data Map Statement 3 March 2014 18:55 GMT. Earthware was contacted this morning by the HSCIC regarding a demo online map we had created to demonstrate how HES data might be displayed in a mapping environment.Earthware immediately withdrew this map from our website upon request from the HSCIC. Earthware would like to clarify the following: The map displayed mock data held by a third party who provided this data to Earthware via a web API. We do not hold nor have we ever held HES data on our servers. No patient identifiable data was ever displayed on the map. Earthware are confident that we have not breached any legal or regulatory rules regarding the licencing or publication of HES data. We will continue to co-operate fully with the HSCIC if required. http://www.earthware.co.uk/

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#158
post #120

Earlier quoted context omitted.

I would leave the data in the hands of medical professionals who are subject to medical ethics and confidentiality, kept away from anyone who might have any other ambitions for it. And I would keep it within the range of European data protection law, which is in general considerably stronger (rightly so, IMHO) than the rules in places like the US, though in this particular case if HIPAA is relevant that may not actua…

> I would leave the data in the hands of medical professionals Presumably, the medical professionals aren't also IT professionals. If they want their data to be on a hard drive, and accessible via a network, using some apps, then some group of non-medical professionals is going to need to maintain those services. Who do you think that should be, and why do you think their systems would be more secure than Google's? >…

Who do you think that should be, and why do you think their systems would be more secure than Google's?

The security isn't the only point here. They transferred the data outside of the jurisdiction where our laws apply, and they're not allowed to do that without fulfilling conditions that they appear not to have satisfied.

Note that it is not within the power of PA Consulting to vary these conditions, whatever any contract says, nor are HSCIC above the law in this respect (though some of the relatively recent and dubiously worded get-out-of-jail-free cards like s251 might protect them to some extent).

What ambitions are you implicitly accusing Google of having? Do you think Google's going to tap into their customers' private files and sell them to a third party?

I'm not implicitly accusing them, I'm openly stating that I think they would do tap those files in a heartbeat if (a) it would help them to earn more from their advertising or other profit-generating activities, and (b) they thought they could get away with it.

I regard organisations like Google (and other big data miners like Facebook) as some of the most dangerous entities on the planet today. They respect little other than money, and they have consistently not just pushed the boundaries of what is acceptable behaviour but IMHO (and apparently in numerous other people's opinion and indeed in the law's opinion in many places and on many occasions) stepped far over the line. They can continue to do this because the regulators who should be reining them in are toothless and because they have an army of lawyers and lobbyists who exemplify just about everything that makes those professions unpopular.

I do very little with Google services myself, by deliberate choice, and I sure as hell do not consent to anyone breaching their duty of confidentiality regarding my medical records and giving them to Google either.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#159

Earlier quoted context omitted.

Taking a sentient human being and throwing them in a cage is a profoundly violent act. I find it troubling that you guys so casually reach for it as a punitive tool We aren't reaching for it casually. Some of us consider privacy a fundamental value that must be defended, and regard an attack on our privacy with the same seriousness that we would regard an attack on our physical person. Which is more of a danger to me…

>Some of us consider privacy a fundamental value that must be defended The severity of a punishment can be tuned separately from the form of punishment. Imprisonment is not appropriate merely by dint of your emotional reaction to the crime itself. >Which is more of a danger to me... Sufficient to warrant throwing them in a cage, being brutalized by actually violent criminals, imposing a direct cost burden on society,…

We could debate the relative effectiveness of different forms of penalty, and the relative importance of punishment/deterrent, ongoing protection, and rehabilitation, but I'm not sure this is the forum for it.

However, let me be clear: if the facts in this case really are as I've seen reported, then I have no problem with taking people who did this, throwing them in a cage, and depriving society of their "productivity" for a while. As far as I'm concerned, that kind of productivity is about as welcome as the banking executives who command "competitive compensation packages" for running their organisations into the ground or the politicians who once elected proceed to legislate for the highest bidder.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#160
post #5

Surely PA Consulting should immediately be sued out of existence. This kind of behaviour must be considered beyond negligent, practically criminal. I would strongly support throwing anyone involved in this into jail for a long time as a deterrent against future criminals. This is just unbelievable.

Taking a sentient human being and throwing them in a cage is a profoundly violent act. I find it troubling that you guys so casually reach for it as a punitive tool, particularly when the subject has neither committed physical violence nor poses such a threat to others. Surely you clever people can think of forms of punishment/deterrence less destructive to both the individual and society as a whole.

> Surely you clever people can think of forms of punishment/deterrence less destructive to both the individual and society as a whole.

OK, how about getting all their personal information and putting it on a public website?

Post reply on HN