Live data from Hacker News

NHS England patient data 'uploaded to Google servers', Tory MP says

theguardian.com

91–100 of 184 posts

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#91

I don't understand why the data being on "Google servers" is generating such outrage. Google almost certainly has superior security to this "PA Consulting" or even the government itself.

Because it's illegal to put MY data on a server in the US.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#92
post #76

Earlier quoted context omitted.

I'd also assume the worst, even if there are no patient names out. There are too many examples of de-anonymization of purposefully anonymized data out there to warrant any belief that missing real world names alone should constitute much of a privacy blanket.

The dataset in question supposedly contains date of birth, gender and post code. For my family, that uniquely identifies every member, given the size of UK post codes.

If that means full postcodes, then that information will easily be sufficient to identify every member of the UK population, aside from outliers like twins or the occasional statistical fluke.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#93
post #2

It's worse than that: Ben Goldacre is reporting ( https://twitter.com/bengoldacre/status/440475049880195073 ) that the data was made publicly available. This is beyond parody.

recent (20m): "I’m sorry to say I’m also now aware of more @HSCIC stories breaking shortly. What a mess. They need to come clean asap, clean stables."

"Wait for details on story i’ve been tweeting today: twitter is first draft. Story is: small number rule breach, I believe, which is bad."

https://twitter.com/bengoldacre

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#94
post #89

Earlier quoted context omitted.

And what "appropriate approval" was that, exactly? In general, exporting personal data outside of the EEA requires the explicit notification of the data subject under UK data protection law (among other consequences of the first Principle[1]). Moreover, the rules for even processing sensitive personal information, which includes health-related information, are significantly stronger than the general case. They should…

Doesn't the "safe harbor" clause apply to US companies ? You know, that joke of a clause which says that US companies fit the needs of our data protection law as long as they claim to fit it (and they only have to claim it) ? Part of the new data protection law that was supposed to be voted in the EU following/during the PRISM scandal was revoking that stupid clause but I'm not sure what happened to that reform.

Safe Harbor avoids some of the issues with exporting data from the EEA at all.

It doesn't cover exporting the data without notifying the subjects appropriately.

It isn't even close to covering exporting sensitive personal data (which is a technical term explicitly including health-related information), for which much stronger rules apply under UK data protection legislation.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#95
post #71

Earlier quoted context omitted.

They didn't say they had approval from Google. That wouldn't make much sense, you don't really need approval from Google to use BigQuery, you just need to open a Google account and create a new BigQuery project on their Developers Console

Given that the scale of the data, it is likely that they need to contact Google to get rid of the default quotas: https://developers.google.com/bigquery/quota-policy

Why? I don't see any limit being hit by loading 27 DVDs worth of data.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#96
post #5

Surely PA Consulting should immediately be sued out of existence. This kind of behaviour must be considered beyond negligent, practically criminal. I would strongly support throwing anyone involved in this into jail for a long time as a deterrent against future criminals. This is just unbelievable.

PA Consulting are idiots and everybody who gave them this contract should be fired.

Saying "I didn't know" is no excuse as this is not the first time PA Consulting have lost data!

"The Home Secretary announced on 10 September that the government has terminated its contract with PA Consulting, following the recent high profile data loss

On 19 August PA Consulting formally notified the Home Office of the loss of a data stick containing sensitive information relating to the JTrack system which PA manage under contract to the Home Office

The data on JTrack relates to prisoners and other offenders in England and Wales."

http://www.scl.org/site.aspx?i=ne9297

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#97

I don't understand why the data being on "Google servers" is generating such outrage. Google almost certainly has superior security to this "PA Consulting" or even the government itself.

I don't understand why the data being on "Google servers" is generating such outrage.

Because Google's systems demonstrably aren't secure (see numerous recent discussions about NSA etc.) and therefore aren't an appropriate choice to transmit or store sensitive personal data under UK data protection rules.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#98
post #37

Earlier quoted context omitted.

So apparently they don't have money to spend on building a secure, state-owned cloud storage service for patient records right? I wonder, does the GCHQ use private cloud storage contractors or for spying material the government found money to create an appropriate database? :-)

This is just crazy. According to the article, this "big data" fits in 27 DVDs, which is roughly 1-2 TB of data. Do you really need Big Query or whatever for this?

According to Wikipedia, DVDs of the largest capacity can hold 17.08 GB of data, but those are rare. If the article is correct about these details, the data could be ~460 GB at most, but is likely less than half of that if the DVDs in question were of normal capacity.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#99

I don't understand why the data being on "Google servers" is generating such outrage. Google almost certainly has superior security to this "PA Consulting" or even the government itself.

Data must only leave HSCIC under carefully controlled circumstances. It's pseudo-anon within HSCIC and anon outside HSCIC, but still with careful controls on who has access and what they can do with it.

I can't tell from the article what data PA Consulting had; nor why they had it; nor why they felt the need to upload it to Google. Even though it's been anonymised it should still be treated as sensitive confidential data.

There's a possibility that someone at PA Consulting has committed a criminal offence even though they "got permission" to upload it to Google.

The otrage about Google is around keepin data within the EU And this protected by EU data protection laws.

Re: NHS England patient data 'uploaded to Google servers', Tory MP says

#100

Earlier quoted context omitted.

The same government that had completely penetrated Google's network for years without them realising?

I'm pretty sure "the government" in GP's context referred to the UK government, not the US.

It was the UK Government (GCHQ) that was breaking into Google's networks.
Post reply on HN