The irony. It's illegal in the US where EU countries cannot send data because of the weak data protection laws and the UK with 'strong' laws is the one selling off all your private medical records (including identification details) for a paltry sum.
The price list looks so cheap that Russian or Nigerian scammers can afford these extracts and it would save them a hell of a lot of time setting up ID scams and instantly make them much more profitable.
No longer any need to mass mail in the hope of finding someone likely to buy V!agr4, the NHS will give you a list of likely marks to direct market to and save all the useless pitches to women !
There was an interesting Businessweek article[1] on the sale of pseudoanonymised data to private companies in the US. One Harvard researcher acquired one such database and was able to identify some individuals:
Latanya Sweeney, the director of Harvard University’s Data Privacy Lab, identified 35 patients from a Washington database by buying state medical data and creating a simple software program to cross-reference that information with news reports and other public records. “All I have to know is a little bit about a person and when they went to a hospital, and I can find their medical record in this kind of data,” Sweeney says. She says data in 25 other states are just as vulnerable.
The whole article is an interesting read. Apparently the data is sold pseudoanonymised in some states, leaving it up to the purchaser to truly anonymise the data.
Police and researchers have provisions to request access to the database under HIPAA
The Harvard researcher probably fell under research for public health. I'd hope private researchers can access public health data. The goal for "ICD" global standardized diagnoses codes is to help research.
There are rules for distribution and compliance that should carry over to each handler of the data sets.
Given all that, I still have anxiety of bad actors handling the private information.
It's not as cut and dry as that, apparently. From that BusinessWeek article:
Washington State’s health agency sold its database 95 times that year, collecting a mere $15,950. Donn Moyer, a spokesman for the state’s health department, says it chose to release extra identifying information such as patients’ Zip Codes to make its data more useful.
The Harvard researcher's point is that it's possible to identify individuals in the datasets being sold in some scenarios.
"Your NHS number Your date of birth Your postcode Your gender and ethnicity Your medical diagnoses (including cancer and mental health) and any complications Your referrals to specialists Your prescriptions Your family history Your vaccinations and screening tests Your blood test results Your body mass index (height/weight) Your smoking/alcohol habits"
That sort of data can be included in de-identified health data in the U.S. if it can be shown statistically that the individual cannot be re-identified.
if it can be shown statistically that the individual cannot be re-identified.
A full UK postcode is very specific - not just which street, but which side and end of the street. "date of birth plus postcode" will in almost all cases identify one and only one person. This data is not actually anonymous at all.
The data available won't include that those personal identifiers. At time of extraction, the patient record in the database is assigned a new unique identifier which has nothing to do with the NHS number.
My New Zealand address is meaningless in the US unless you want to find my house. I see patient numbers on things displayed from time to time and wince - interesting case studies etc. I most certainly could find out who the person is. A distinct pathology is probably enough to identify someone in New Zealand if you tried hard enough.
The data we supply is normally pseudonymised. We only provide identifiable data when there is a lawful basis to do so i.e. with patient consent, approval under section 251 of the NHS Act 2006 which enables The Health Service (Control of Patient Information) Regulations 2002, or where appropriate statutory regulation is in place.
Section 251 came about because it was recognised that there were essential activities of the NHS, and important medical research, that required use of identifiable patient information but because patient consent had not been obtained to use people's personal and confidential information for these other purposes, there was no secure basis in law for these uses. [NB. There are a few exceptions where there is a legal basis for disclosure e.g. reporting of notifiable diseases]. Section 251 was established to provide a secure legal basis for disclosure of confidential patient information for medical purposes, where it was not possible to use anonymised information and where seeking consent was not practicable, having regard to the cost and technology available.
"and where seeking consent was not practicable," //
As they have your contact details and next of kin details then seeking consent must be quite practicable.
I expect them mean "commercially financially viable". Those people the NHS can't simply look up a phone number for (from doctor's surgery records) and ask (or ask their guardian/parent) must be in the few hundreds [of those they have sufficient medical information for to be used in a scientific study].
I guess that's what it says, practicable with regard to cost.
To look at one random example, the first study on the list of approvals in 2013 was the "ETPOS: European Transfusion Practice and Outcome Survey". Apparently they took data from 10,000 patients who had blood transfusions and tried to see if there was any correlations between practices such as "ratio of red blood cells to other blood component therapy, such as plasma and platelets" and health outcomes. I guess it was deemed that phoning each of the patients was impractical.
Robot Dialer: The NHS wish to sell your medical data for use in a study of people who had blood transfusions. Press 1 to accept, 2 to refuse, 3 to speak to an agent.
Robot Dialer: You pressed 1 to accept; can we use your data for future studies? Press 1 to accept, 2 to refuse, 3 to speak to an agent.
Robot Dialer: You pressed 2, can we contact you to ask about using your data in specific studies in the future? Press 1 to accept, 2 to refuse, 3 to speak to an agent.
Umpteen marketing companies appear to be able to afford to do this sort of calling (yes even though it's against the law for them to contact me as I'm on the no-call database [which wouldn't apply to the NHS]).
If it's too costly then the studies can hardly be worthwhile? Remember the NHS wasted £10 Billion on a single IT project over the last 10 years. What would this auto-dialer have cost? £10k in "management", couple of thousand in IT staff and set-up (join study NHS numbers with main database ID table and contact info tables, select phone numbers; set-up dialer script, test, initiate) maybe £500 in direct call costs. They most likely already have systems in place to do auto-dialed calls for disease outbreaks [UK Environment Agency use one for flood warnings].
"... or where appropriate statutory regulation is in place"
You do know that means civil servants have written a statutory order, it has been signed by the minister (might have to be Secretary of State) and it has been placed in Parliament for a week (no vote required). [Exact details may be wrong but that is the overall concept of statutory orders].
My comment is based on a general understanding of statutory orders/secondary legislation and there may be specific reasons why it doesn't apply in this case but it appears to me to be a significant hole in the text you quote that you may not have noticed.
I think "statutory regulation" just means there has to be a law allowing it ("statute" meaning law). From reading their website the other day, I got the impression that the case they had in mind was certain laws about containing contagious diseases, which could override privacy laws.
Reading on Wikipedia, "Statutary orders" and "statuatory instruments" seems to be particular ways of delegating law-making power from parliament. I don't think they are directly relevant here (since there has to be some enabling legislation)? But the section 251 thing already allows the Secretary of State for Health to disclose data, so if you are worried about ministers operating without parliamentary oversight, that is indeed possible....
"This would be straight up illegal in the US due to HIPAA, which guarantees a patient's right to privacy."
That is a blanket statement which is false. Some of what NHS is providing would be illegal in the U.S. Some of it is actually legal. I am mostly responding to the blanket statement.
You're assuming that NHS is selling it without the consent of patients. More likely this is for things like patients on drug trials etc. who sign a waiver to allow sharing of their health information. The UK takes confidentiality of public records pretty seriously and has done for years - I seriously doubt you can just just pull any given person's health records without their agreement.
Clearly we have differing interpretations of that document. I don't think everyone can get the sec. 251 exemption, just for a start. It is certainly possible to de-anonymize individuals if you know enough details to get a correlation, but how many people do you know sufficiently well to work backwards through that process? If your goal is to sell more shampoo by working out who has dandruff, for example, the marginal cost of de-anonymizing your potential customers is likely to drastically exceed the marginal benefit of each additional sale. Fishing expeditions by Fleet street or private detectives targeted on a particular individual are likely to either raise red flags if too obvious or be wildly expensive if sufficiently stealthy (multiple pull requests followed by client-side correlation) - cheaper to go the traditional route of bribing the nanny or suchlike.
On the other hand, the increased risks of malicious de-anonymization (risk, not certainty) have to be weighed against the obvious benefit of having a portable health record and reducing duplication and administrative overhead if you are taken ill and have to visit a hospital or a doctor who's not your GP.
On the other hand, the increased risks of malicious de-anonymization (risk, not certainty) have to be weighed against the obvious benefit of having a portable health record and reducing duplication and administrative overhead if you are taken ill and have to visit a hospital or a doctor who's not your GP.
That's not the system that's being discussed, though.
All other systems are pendant to that. If this data wasn't available in any way we'd have a story saying 'NHS won't release data, obstructing drug development which could save lives.'
Comments
This would be straight up illegal in the US due to HIPAA, which guarantees a patient's right to privacy.
HIPAA = http://en.wikipedia.org/wiki/Health_Insurance_Portability_an...
The irony. It's illegal in the US where EU countries cannot send data because of the weak data protection laws and the UK with 'strong' laws is the one selling off all your private medical records (including identification details) for a paltry sum.
The price list looks so cheap that Russian or Nigerian scammers can afford these extracts and it would save them a hell of a lot of time setting up ID scams and instantly make them much more profitable.
No longer any need to mass mail in the hope of finding someone likely to buy V!agr4, the NHS will give you a list of likely marks to direct market to and save all the useless pitches to women !
There was an interesting Businessweek article[1] on the sale of pseudoanonymised data to private companies in the US. One Harvard researcher acquired one such database and was able to identify some individuals:
The whole article is an interesting read. Apparently the data is sold pseudoanonymised in some states, leaving it up to the purchaser to truly anonymise the data.
[1]http://mobile.businessweek.com/articles/2013-08-08/your-medi...
Police and researchers have provisions to request access to the database under HIPAA
The Harvard researcher probably fell under research for public health. I'd hope private researchers can access public health data. The goal for "ICD" global standardized diagnoses codes is to help research.
There are rules for distribution and compliance that should carry over to each handler of the data sets.
Given all that, I still have anxiety of bad actors handling the private information.
It's not as cut and dry as that, apparently. From that BusinessWeek article:
The Harvard researcher's point is that it's possible to identify individuals in the datasets being sold in some scenarios.
No it isn't. U.S. health data can be sold if it is de-identified or with a patient's permission.
Does
"Your NHS number Your date of birth Your postcode Your gender and ethnicity Your medical diagnoses (including cancer and mental health) and any complications Your referrals to specialists Your prescriptions Your family history Your vaccinations and screening tests Your blood test results Your body mass index (height/weight) Your smoking/alcohol habits"
seem 'de-identified'?
That sort of data can be included in de-identified health data in the U.S. if it can be shown statistically that the individual cannot be re-identified.
A full UK postcode is very specific - not just which street, but which side and end of the street. "date of birth plus postcode" will in almost all cases identify one and only one person. This data is not actually anonymous at all.
How exactly would you 'de-identify' a NHS number?
The data available won't include that those personal identifiers. At time of extraction, the patient record in the database is assigned a new unique identifier which has nothing to do with the NHS number.
Since that number is meaningless in the U.S., I guess you wouldn't care.
My New Zealand address is meaningless in the US unless you want to find my house. I see patient numbers on things displayed from time to time and wince - interesting case studies etc. I most certainly could find out who the person is. A distinct pathology is probably enough to identify someone in New Zealand if you tried hard enough.
But this data is not de-identified. They explicitly list prices for data with confidential, patient-identifying information.
The main page, http://www.hscic.gov.uk/dles , states
This "About Section 251" page, http://webarchive.nationalarchives.gov.uk/20130513181011/htt... , states
As they have your contact details and next of kin details then seeking consent must be quite practicable.
I expect them mean "commercially financially viable". Those people the NHS can't simply look up a phone number for (from doctor's surgery records) and ask (or ask their guardian/parent) must be in the few hundreds [of those they have sufficient medical information for to be used in a scientific study].
I guess that's what it says, practicable with regard to cost.
To look at one random example, the first study on the list of approvals in 2013 was the "ETPOS: European Transfusion Practice and Outcome Survey". Apparently they took data from 10,000 patients who had blood transfusions and tried to see if there was any correlations between practices such as "ratio of red blood cells to other blood component therapy, such as plasma and platelets" and health outcomes. I guess it was deemed that phoning each of the patients was impractical.
Robot Dialer: The NHS wish to sell your medical data for use in a study of people who had blood transfusions. Press 1 to accept, 2 to refuse, 3 to speak to an agent.
Robot Dialer: You pressed 1 to accept; can we use your data for future studies? Press 1 to accept, 2 to refuse, 3 to speak to an agent.
Robot Dialer: You pressed 2, can we contact you to ask about using your data in specific studies in the future? Press 1 to accept, 2 to refuse, 3 to speak to an agent.
Umpteen marketing companies appear to be able to afford to do this sort of calling (yes even though it's against the law for them to contact me as I'm on the no-call database [which wouldn't apply to the NHS]).
If it's too costly then the studies can hardly be worthwhile? Remember the NHS wasted £10 Billion on a single IT project over the last 10 years. What would this auto-dialer have cost? £10k in "management", couple of thousand in IT staff and set-up (join study NHS numbers with main database ID table and contact info tables, select phone numbers; set-up dialer script, test, initiate) maybe £500 in direct call costs. They most likely already have systems in place to do auto-dialed calls for disease outbreaks [UK Environment Agency use one for flood warnings].
"... or where appropriate statutory regulation is in place"
You do know that means civil servants have written a statutory order, it has been signed by the minister (might have to be Secretary of State) and it has been placed in Parliament for a week (no vote required). [Exact details may be wrong but that is the overall concept of statutory orders].
My comment is based on a general understanding of statutory orders/secondary legislation and there may be specific reasons why it doesn't apply in this case but it appears to me to be a significant hole in the text you quote that you may not have noticed.
I think "statutory regulation" just means there has to be a law allowing it ("statute" meaning law). From reading their website the other day, I got the impression that the case they had in mind was certain laws about containing contagious diseases, which could override privacy laws.
Reading on Wikipedia, "Statutary orders" and "statuatory instruments" seems to be particular ways of delegating law-making power from parliament. I don't think they are directly relevant here (since there has to be some enabling legislation)? But the section 251 thing already allows the Secretary of State for Health to disclose data, so if you are worried about ministers operating without parliamentary oversight, that is indeed possible....
"This would be straight up illegal in the US due to HIPAA, which guarantees a patient's right to privacy."
That is a blanket statement which is false. Some of what NHS is providing would be illegal in the U.S. Some of it is actually legal. I am mostly responding to the blanket statement.
You're assuming that NHS is selling it without the consent of patients. More likely this is for things like patients on drug trials etc. who sign a waiver to allow sharing of their health information. The UK takes confidentiality of public records pretty seriously and has done for years - I seriously doubt you can just just pull any given person's health records without their agreement.
No, it's everyone.
http://medconfidential.org/whats-the-story/
Clearly we have differing interpretations of that document. I don't think everyone can get the sec. 251 exemption, just for a start. It is certainly possible to de-anonymize individuals if you know enough details to get a correlation, but how many people do you know sufficiently well to work backwards through that process? If your goal is to sell more shampoo by working out who has dandruff, for example, the marginal cost of de-anonymizing your potential customers is likely to drastically exceed the marginal benefit of each additional sale. Fishing expeditions by Fleet street or private detectives targeted on a particular individual are likely to either raise red flags if too obvious or be wildly expensive if sufficiently stealthy (multiple pull requests followed by client-side correlation) - cheaper to go the traditional route of bribing the nanny or suchlike.
On the other hand, the increased risks of malicious de-anonymization (risk, not certainty) have to be weighed against the obvious benefit of having a portable health record and reducing duplication and administrative overhead if you are taken ill and have to visit a hospital or a doctor who's not your GP.
That's not the system that's being discussed, though.
All other systems are pendant to that. If this data wasn't available in any way we'd have a story saying 'NHS won't release data, obstructing drug development which could save lives.'