Skip to content

Comment on The NHS is selling your private data – here's the price list [pdf]

Comments

I would just like to point out that even if they "anonymize" the records it's generally not that hard to de-anonymize data.

During the Netflix prize, randomly generated IDs were eventually matched to people based simply on movie ratings and matching public information in other public sources:

http://www.wired.com/politics/security/commentary/securityma...

With medical data, it will probably be trivial (maybe easier or more appealing to insurance companies?).

We're a lot more unique than we think. Reminds me of this EFF project:

https://panopticlick.eff.org/

Some companies will probably resell this information to potential employers, banks (there goes your loan), etc.

Well, that's going to suck for people in the UK.

Companies are TERRIBLE at this. We used a company to do an employee feedback survey. They promised us that the data would be delivered in a 100%, completely anonymized format. We sit down to go over the results and slide number one is "Men were a 100% approval while women were 73%". I'm the only male on my team. How in the world is this anonymous?

I know in my C.S. courses most of us guys/girls wont put down our gender on surveys so the 4 or 5 females in the room can maintain anonymity.

No company is going to resell medical data. We have laws to protect personal information and they are very strict for medical information.

http://www.connectingforhealth.nhs.uk/systemsandservices/inf...

Have a look at some UK medical information and see if you can de-anonymise it.

http://www.ons.gov.uk/ons/rel/subnational-health4/suicides-i...

Here's some data for suicide.

There are problems with confidentiality in the NHS - people leave patient records on monitors or send letters to the wrong address. But this kind of project is very different.

And .. suppose a company does sell it. Or an attacker breaks into their system and steals it. Or someone abroad takes it and is out of the UK's jurisdiction.

Medical data can't be got back.

There are criminal offences covering selling of that data, or storing it in such a way that it is released, or moving the data out of the UK.

There are problems with confidentiality of data in the NHS, but this isn't one of those examples. Have a look at any of the very many examples of anonymised information released by the NHS and see if it's possible to deanonymise it.

It's important to note that this story is only about the new development of information held by GPs. A similar scheme has been running for a while now covering information held by hospitals.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.