BMA warns NHS Digital's own confidentiality guardian could halt English GP data grab unless communication with public improves
- Reference: 1624617921
- News link: https://www.theregister.co.uk/2021/06/25/bma_says_nhs_digitals_own/
- Source link:
Speaking to The Register , Dr Farah Jameel, BMA GP committee executive team IT lead, said UK data protection law’s requirement for transparency in uses – and change in use – of people’s data calls into question whether the General Practice Data for Planning and Research (GPDPR) should go ahead, given the current state of public interaction.
NHS Digital announced [1]GPDPR in May, saying it planned to place historic data from the nation's general practitioners (GPs) on 55 million people in England into a central repository from 1 July, for the purpose of NHS planning and medical research. The public was told to opt out of the programme by 23 June.
[2]
Although patients had the right to opt out of the programme, only by doing so before the initial extraction could they prevent historical medical data, including conditions, drugs taken, sexual diseases, child and relationship abuse, from being uploaded to the central store and shared with third parties, including private companies outside the NHS.
[3]UK health secretary Matt Hancock follows delay to GP data grab with campaign called 'Data saves lives'
[4]UK set for 'adequacy' status on data sharing with EU, but it all depends on how much post-Brexit law diverges
[5]British Medical Association calls for clarity on patient deadline for opting out of NHS Digital's GP data grab
[6]Of all the analytics firms in the world, why is Palantir getting its claws into UK health data?
The plan was met by an outcry from personal privacy campaigners, while the BMA and the Royal College of GPs successfully campaigned for the extraction date to be put back (it is now 1 September) to allow more time to explain to patients about their rights to opt out. However, although it has given the 1 September date for when it will inhale the data set, NHS Digital has not said until which date patients may opt out.
Communication is key
UK data regulator the ICO says [7]that fairness and transparency are fundamental to the UK’s interpretation of the General Data Protection Regulation, implemented in the Data Protection Act 2018.
Communication of what has been dubbed the biggest data grab in NHS history has amounted to social media posts, an NHS Digital website and a downloadable poster for GP surgeries, potentially leaving huge swathes of the population unaware that use of their data held by GPs was going to change.
[8]
[9]
Dr Jameel told The Reg that the current level of communication might not meet the requirement for transparency under UK law.
“We have put to NHS Digital that they need to ensure that transparency has been met, and I think at this juncture the social media and the press coverage suggest that transparency has not been met.
[10]
"[NHS Digital] will have their own internal test for compliance, which to me suggests that is a problem for NHS Digital to go away and look at before they progress with the programme. So it might come to a juncture where, if transparency continues not to be met, that could mean their Caldicott Guardian says, ‘Sorry but I cannot allow the rest of this programme’," she said.
A [11]Caldicott Guardian is a senior individual in a health organisation who is responsible for ensuring the confidentiality of medical and health data, under a system dating back to the 1990s named after Dame Fiona Caldicott.
Pressed on whether the BMA, which provides legal advice to doctors, could suggest GPs should prevent the upload of patient data to the central store, Dr Jamel said the union would watch how NHS Digital responded to its calls for better communication and “provide the right advice when the time comes.”
[12]
She said that GPs were under [13]legal direction from the Secretary of State, and “it's a contractual responsibility, we must comply with: that's how this whole programme has been designed.”
First do no harm
But she added that GPs had a [14]professional obligation to “do no harm” to patients.
“My job is to safeguard and be the advocate of my patients, that trumps anything and everything and all clinicians will remember that, and hence the anxiety and concern that's been expressed publicly in the media by numerous doctors,” she said.
Once data is uploaded into the system there is planned oversight of how it might be shared with third parties including other NHS organisations, universities and private companies.
Opting out of NHS Digital data grab
Despite the delay, 55 million citizens of England will need to opt out of the involuntary General Practice Data for Planning and Research scheme before it is introduced to prevent the entire history of their GP visits being slurped, according to campaigners.
The official announcement is [15]here . Opt-out forms are [16]here [.docx]. We understand you will need to give this form to your GP practice to prevent data held by your GP from joining the central repository, which will now happen on 1 September.
There is also a secondary opt-out process that stops non-GP data, such as hospital or clinic treatments, being used or sold for purposes other than your direct care. Healthcare data privacy campaigner medConfidential explains both Type 1 and Type 2 opt-outs [17]here .
This is governed by NHS Digital’s Data Access Request Service, an Independent Group Advising on the Release of Data (IGARD), which sits within NHS Digital but is made up of researchers and medical practitioners. A Professional Advisory Group from the BMA and the RCGP also have oversight of the release of data. That group would scrutinise individual request for data when re-identification of individuals was required, she said.
The Professional Advisory Group already approves the release of hospital data, and Dr Jameel said the BMA was happy with the way that this operated at the moment, but was concerned the process could change at some point after the GP data had been handed over.
“The landscape that we're in at the moment and the era that we're entering is unknown. I don't know what the future will hold… if the government will determine that [health secretary] Matt Hancock will be given powers to command data around the system. Once the data leaves our practice, and it arrives at NHS Digital, we’re fairly confident that what will happen within NHS Digital will be fairly safe. The anxieties are about how future programs might interact,” she said.
NHS Digital has been given the opportunity to comment.
In a statement issued earlier this month, the ICO said: “We recognise the concerns people have with the GP Data for Planning and Research programme and, while we have already engaged with NHS Digital regarding their data protection obligations, we continue to work with them and others about next steps.”
The UK's data regulator declined to offer further comment at this stage. ®
Updated to add at 14:41 UTC on 25/06/21:
An NHS Digital spokesperson told The Register : "Data saves lives and has huge potential to rapidly improve care and outcomes, as the response to the COVID-19 pandemic has shown. The vaccine rollout could not have been delivered without effective use of data to ensure it reached the whole population.
"We are absolutely determined to take people with us on this mission. We take our responsibility to safeguard the data we hold incredibly seriously.
"We intend to use the next two months to speak with patients, doctors, health charities and others to strengthen the plan even further."
Get our [18]Tech Resources
[1] https://digital.nhs.uk/data-and-information/data-collections-and-data-sets/data-collections/general-practice-data-for-planning-and-research
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/databases&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YNX9nY@CXEjLGcz4iXKNYAAAAEM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.theregister.com/2021/06/22/uk_health_secretary_data_saves_lives/
[4] https://www.theregister.com/2021/06/22/uk_eu_data_sharing_adequacy/
[5] https://www.theregister.com/2021/06/16/nhs_digital_gpdpr_deadline/
[6] https://www.theregister.com/2021/06/15/palantir_uk_sci_tech_committee/
[7] https://ico.org.uk/for-organisations/data-sharing-a-code-of-practice/fairness-and-transparency-in-data-sharing/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/databases&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YNX9nY@CXEjLGcz4iXKNYAAAAEM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/databases&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YNX9nY@CXEjLGcz4iXKNYAAAAEM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/databases&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YNX9nY@CXEjLGcz4iXKNYAAAAEM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://www.gov.uk/government/groups/uk-caldicott-guardian-council
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/databases&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YNX9nY@CXEjLGcz4iXKNYAAAAEM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[13] https://digital.nhs.uk/about-nhs-digital/corporate-information-and-documents/directions-and-data-provision-notices/secretary-of-state-directions/general-practice-data-for-planning-and-research-directions-2021
[14] https://www.medicinenet.com/hippocratic_oath/definition.htm
[15] https://digital.nhs.uk/data-and-information/data-collections-and-data-sets/data-collections/general-practice-data-for-planning-and-research
[16] https://nhs-prod.global.ssl.fastly.net/binaries/content/assets/website-assets/data-and-information/data-collections/general-practice-data-for-planning-and-research/type-1-opt-out-form.docx
[17] https://medconfidential.org/how-to-opt-out/
[18] https://whitepapers.theregister.com/
Honestly
I was an IT / Information security consultant for several decades (I retired a few years ago). Frankly I have real trouble summoning up the energy to read all the articles, and details of agreements, what cookies companies want to put on my computer and all the tracking details that I am asked to agree to or reject. The best websites are the ones where there is a "Reject All" option, which saves time. But honestly if I with my expertise and experience have trouble what do the 'general public' do?
The information I've gleaned about 'the Great NHS Data Grab' does not explain to me what the data can or cannot be used for, who will have access, how effective any pseudonimisation may be, or what benefits the NHS will obtain from allowing access to commercial organisations or other country's health organisations.
This is frankly too vague to agree to, but then I want the data used to provide better healthcare (I might need it sometime soon) without exposing individuals to unreasonable side effects. The worry is not that the NHS will sell data for money, but more that it will give it away for peanuts and then be charged vast amounts for treatments created by companies based on the data.
Please send any clear explanations, on a postcard, addressed to 'Confused of Reading'.
Re: Honestly
I find Firefox Temporary Containers addon helps a lot (particularly when combined with Multi Account Containers). Not perfect, but it allows me to not bother with the cookie settings for sites I am using once to look something up or print some tickets or something. Reduces risk of having that visit correlated with something else.
Re: Honestly
"The information I've gleaned about 'the Great NHS Data Grab' does not explain to me what the data can or cannot be used for"
Anything at all.
"who will have access"
Anyone who pays for it. Shortly thereafter, anyone with access to the internet.
"how effective any pseudonimisation may be"
Not at all.
"or what benefits the NHS will obtain from allowing access to commercial organisations or other country's health organisations."
None whatsoever.
Flawed design
There is no need to share any data with anyone. By all means put all the data onto a single air-gapped system and allow third parties to submit statistical queries for review. If the results are sufficiently course grained that no-one can be identified then the can have the statistics but they never get to see the data.
Re: Flawed design
There is no need to share any data with anyone
No need [1]for whom ?
[1] https://www.theguardian.com/politics/2021/jun/22/shareholders-of-firm-backed-by-matt-hancock-have-donated-to-the-tories
The health secretary has his hands full with more important things it seems
Looks like our data is not the only thing he's keen to grab hold of.
Tell your doctor the full details
Be honest, tell the doctor every symptom and what you did, honestly and openly, so he can make the correct diagnosis for you health.
"took some illicit drugs?" tell them so the police can prosecute you
"suspected HIV from some sleezy sex?" tell him, so he can share it with the health insurance company.
"dizzy spells", be sure you tell your doctor, so he can share it with your employer.
Ahh you say, they would never use it like that, Hancock promised! See the City of London "Ring of Steel"? They promised it was to counter terrorism, now its used for parking enforcement, local driver taxation, taxi license enforcement, even littering.
More than that, it will post-hoc be used for that. In other words, even if it isn't used today for that, the data you told your doctor NOW will in be handed over LATER and used for that purpose.
Recognize the pattern NOW, and watch what you say to your doctor NOW. Can this be used against me at some future date in any employment, insurance, or other context? If the answer is yes, then STFU and don't tell your local snitch, erm local medical practitioner.
This is a no win situation, BMA is weak as hell here, that data will be slurped and probably already is being slurped. It is not a "communications" issue. Recognize it, and protect your own data from your doctor.
Slurp Central Here!
My name is Peter Thiel. I've just made (another) $5Billion from this sort of slurping in the USA.
I'm REALLY looking forward to making more billions from the NHS.
Already plugged in to UK contracts.....you know....brown paper envelopes full of cash to the appropriate folk!
Thanks....for paying no attention to what IS REALLY GOING ON in Westmister!!!
*
Link: https://www.bloomberg.com/features/2018-palantir-peter-thiel/
Why two systems?
Why two different processes to opt out? one on-line and one manual (fill in a paper form?)
Is this the dark ages or are the NHS just trying to stop as many people as possible from opting out of the GP data grab (that probably holds more information)
At least the forms are online to download, not stored in a locked filing cabinet, in a disused lavatory ... oh you all know the rest.
I would love to know how NHS digital square off a permanent data grab with a right to be forgotten under GDPR. Now it is a qualified right - but "its too hard/we're too lazy" is not a sufficient excuse.