Live data from Hacker News

England’s NHS plans to share patient records with third parties

ft.com

21–26 of 26 posts

Re: England’s NHS plans to share patient records with third parties

#21
post #18

People should note that this data cannot really be anonymised. This is because you only need a post code, date of birth and sex to determine who the majority of people are. "A 2000 study found that 87 percent of the U.S. population can be identified using a combination of their gender, birthdate and zip code." https://en.wikipedia.org/wiki/Data_re-identification UK postcodes are more specific I believe.

For example, to book the NHS vaccine you only need a person postcode, first and last name, and date of birth. All this information is easily available, for example from companies house.

[deleted]

Re: England’s NHS plans to share patient records with third parties

#22

In Europe Google is offering large sums for clinical data that is stored within the records of their Electronic Medical Records. If you start selling data, capital will lead to a consolidation of data. Creating Information asymmetries in healthcare might be the stupidest thing the NHS can do, our future generations will be fighting the monopolies that could have been voided if we treat data and its derivates as a com…

Do you have a reliable citation showing Google is doing this?

Re: England’s NHS plans to share patient records with third parties

#23

People should note that this data cannot really be anonymised. This is because you only need a post code, date of birth and sex to determine who the majority of people are. "A 2000 study found that 87 percent of the U.S. population can be identified using a combination of their gender, birthdate and zip code." https://en.wikipedia.org/wiki/Data_re-identification UK postcodes are more specific I believe.

It seems the NHS will still be able to identify patients. FTA: "Data that directly identifies patients will be replaced with unique codes in the new data set, but the NHS will hold the keys to unlock the codes “in certain circumstances, and where there is a valid legal reason”, according to its website. "

What they don't seem to cover is what they think directly identifying data means.

Does anyone actually know what that means? I wouldn't know from a medical record how much data would need to be removed to make it anonymous. It likely depends on the record. And there are different answers that can both be right (so which are they using?).

Re: England’s NHS plans to share patient records with third parties

#24
post #20

Earlier quoted context omitted.

This data will not be anonymized enough IMO. FTA: "Data that directly identifies patients will be replaced with unique codes in the new data set, but the NHS will hold the keys to unlock the codes “in certain circumstances, and where there is a valid legal reason”, according to its website."

This makes sense though from a care optimization perspective though, yeah? Say an ML model is developed to predict a rare disease, and person 12345 scores highly by that model but has not been tested. Without IDs, the NHS would need to replicate the model on secure infrastructure to identify and potentially save the life of the person. With IDs, researchers most familiar with the methodology who already have the infr…

"Without IDs, the NHS would need to replicate the model on secure infrastructure to identify and potentially save the life of the person" why is this an issue?

Re: England’s NHS plans to share patient records with third parties

#25

People should note that this data cannot really be anonymised. This is because you only need a post code, date of birth and sex to determine who the majority of people are. "A 2000 study found that 87 percent of the U.S. population can be identified using a combination of their gender, birthdate and zip code." https://en.wikipedia.org/wiki/Data_re-identification UK postcodes are more specific I believe.

Why not remove postcodes?

Re: England’s NHS plans to share patient records with third parties

#26

People should note that this data cannot really be anonymised. This is because you only need a post code, date of birth and sex to determine who the majority of people are. "A 2000 study found that 87 percent of the U.S. population can be identified using a combination of their gender, birthdate and zip code." https://en.wikipedia.org/wiki/Data_re-identification UK postcodes are more specific I believe.

Why not remove postcodes?

Because you can do something very similar with combos of other fields in the data. That's the problem here: no one knows what combination of details deannonimise a record. So what do you remove, all of them? So the claim it is anonymous is BS. And once the records are out there, there is no way to get them back...

Edit: as an example, I was in a car accident as a 17 year old and broke my jaw. If you Google my name and the location you'll see the news article. I was the only person treated at the local hospital for a broken jaw that day. You just deannonimised me.

Or go again: I'm the only person from my town who went to my university in the year I went. Just look for someone treated in term time and term time 2002-2008.

Post reply on HN