News: 1624636811

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Backbench Tory campaigner promises judicial review of data grab of English GP patients unless UK government changes tack

(2021/06/25)


A judicial review will inevitability challenge the UK government's plans to extract millions of sensitive medical records held on GP systems in England, according to a high-profile backbench Conservative MP.

Speaking in Parliament last night, David Davis said that if privacy campaigners' concerns over the government's plans for [1]General Practice Data for Planning and Research (GPDPR) were not addressed, they would seek a formal process to stop it.

"If the government does not take corrective action to address our concerns, there will inevitably be a full judicial review," he told MPs.

[2]

Davis had backed a letter threatening such a review – also supported by technology law campaigners Foxglove, Just Treatment, Doctors' Association UK, the Citizens, openDemocracy, and the National Pensioners Convention – shortly before the data extraction was [3]put back from 1 July to 1 September .

[4]

[5]

But in Parliament yesterday, Davis called an adjournment debate in the Commons to argue that the database risked patient confidentiality, government could share the information with private tech companies, and presented a tempting target for criminals.

"Patient trust is vital to our NHS so foreign tech companies like Palantir, with their history of supporting mass surveillance, assisting in drone strikes, immigration raids and predictive policing, must not be placed at the heart of our NHS," he told MPs.

[6]

"We should not be giving away our most sensitive medical information lightly under the guise of 'research' to huge companies whose focus is profits over people."

Davis lambasted plans to [7]store pseudonymised patient data because it is impossible to fully anonymise medical records, a fact well understood by experts in the field.

"The government has failed to explain exactly how it will use the data, failed to say who will use the data, and failed to say how it will safeguard this treasure trove of information," he said.

[8]

Medical histories including psychiatric conditions, history of drug or alcohol abuse, sexually transmitted infections, and pregnancy terminations would be held on record.

"Revealing this may not be embarrassing for everyone. But it could be life-destroying for someone," Davis said.

[9]BMA warns NHS Digital's own confidentiality guardian could halt English GP data grab unless communication with public improves

[10]UK health secretary Matt Hancock follows delay to GP data grab with campaign called 'Data saves lives'

[11]British Medical Association calls for clarity on patient deadline for opting out of NHS Digital's GP data grab

[12]UK government bows to pressure, agrees to delay NHS Digital grabbing the data of England's GP patients

Meanwhile, holding a central store of medical histories would inevitably attract nefarious actors wanting to illegally break into the system. Davis pointed out that [13]a 2017 ransomware attack brought parts of the NHS to its knees causing trusts to turn away patients and cancel 20,000 operations.

"These highlight significant problems the Government has yet to address," he said.

The backbench MP also said communication with the public over their rights to opt out of the scheme was severely lacking.

"Where are the texts, the emails, the letters to the patients?" he asked. "On the Today programme earlier this week, the Health Secretary indicated he was now willing to contact every patient. This is welcome and he should now be writing to every single patient involved in this proposed database and informing them properly."

The GPDPR is to store historic and ongoing GP records of 55 million people in England. When it was quietly announced in May, NHS Digital told citizens they'd need to opt about by 23 June before the 1 July implementation.

Davis advocated the [14]OpenSafely approach to NHS patient data and analytics, created by Dr Ben Goldacre, science campaigner and director of the DataLab at Nuffield Department of Primary Care Health Sciences, and others.

The approach, sometimes dubbed Trusted Research Environments (TREs), avoids extracting sensitive patient records and instead runs analytics with the data in place within its original data store. Any analysis is carried out by a select group of data scientists and the only data leaving the group is summaries of specific queries.

Davis commended OpenSafely because it is "distributed across a range of databases – not centralised. Their software maintains health data within the secure systems it was already stored on – it is not transported outside the existing servers.

"This is important because the biggest risk with any new data system is losing control of the data dissemination – once it is out there, like Pandora's Box, you can't close the lid."

Replying in Parliament, Health Secretary Matt Hancock also appeared to advocate the OpenSafely/TRE model, but with one crucial difference. NHS Digital, effectively a branch of the government, would extract GP patient data into a central data store, and then apply the TRE model, rather than applying it to data where it already resides in GP systems.

"I have heard the concerns people have about using dissemination of pseudonymised data, we will not use this approach in the new GPDPR: the new system will instead use trusted research environments," Hancock told MPs. "All data in the system will only ever be accessible through a TRE. And this means that the data will always be protected in the secure environment, individual data will never be visible to the researcher and we'll know and will publish who has run what query or use which bit of data."

Critics might point out that trust in this approach would depend on trust in NHS Digital, which will run and control the central data store of patient information after it has been extracted from GP systems.

Hancock did not repeat his promise to write to patients to inform them of their rights to opt out of the data grab. ®

Get our [15]Tech Resources



[1] https://digital.nhs.uk/data-and-information/data-collections-and-data-sets/data-collections/general-practice-data-for-planning-and-research

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/databases&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YNYCr8K9jQIIGUdA1U-O7gAAAEY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2021/06/08/uk_gov_delays_gp_data_grab/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/databases&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YNYCr8K9jQIIGUdA1U-O7gAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/databases&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YNYCr8K9jQIIGUdA1U-O7gAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/databases&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YNYCr8K9jQIIGUdA1U-O7gAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2021/06/07/gpdpr_labour/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/databases&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YNYCr8K9jQIIGUdA1U-O7gAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2021/06/25/bma_says_nhs_digitals_own/

[10] https://www.theregister.com/2021/06/22/uk_health_secretary_data_saves_lives/

[11] https://www.theregister.com/2021/06/16/nhs_digital_gpdpr_deadline/

[12] https://www.theregister.com/2021/06/08/uk_gov_delays_gp_data_grab/

[13] https://digital.nhs.uk/data-and-information/data-collections-and-data-sets/data-collections/general-practice-data-for-planning-and-research

[14] https://www.theregister.com/2020/06/01/uk_store_covid_19_trace_data/

[15] https://whitepapers.theregister.com/

Peter2

Replying in Parliament, Health Secretary Matt Hancock also appeared to advocate the OpenSafely/TRE model, but with one crucial difference. NHS Digital, effectively a branch of the government, would extract GP patient data into a central data store, and then apply the TRE model, rather than applying it to data where it already resides in GP systems.

If your in A&E unconscious then you probably want enough records available to the A&E staff (ie, blood type, allergies to painkillers) to be available to those staff, rather than to your doctor who's off for the evening/weekend.

Yet Another Anonymous coward

And so that the A&E know who you are it will be necessary to tattoo a QR code of your NHS number on your forehead. Or they could just chip you like a pet.

Gordon 10

Stop using whataboutery to justify a data monetisation grab.

Firstly your chance of actually being unconscious in A&E are small, secondly they already have protocols to deal with those scenarios. Thirdly if that was actually what they are doing with it it would probably get broad support.

What they are actually doing is a vast data grab with assumed opt-in and no right to delete at a later date and some questionable pseudo-anonymisation and then letting the fucking Nazgul to name just one grey actor at it. Each one of those is a red flag in its own right. All together it’s riskier than Matt Hancock discharging your granny to a care home in early 2020.

The chances of it ending in disaster are approximately equal to those of Matt Hancock hooking up with one of his Aides.

Is it a real opt-out?

Anonymous Coward

I did, as perhaps many people have also done. I sent along the appropriate form, opting OUT of the data grab, to the surgery of the doctor that I'm registered with. This was some time ago, and I've heard nothing back to indicate that the opt-out has been set in place, or that they received my application, or that they intend to do anything with it. Surely, this requires some sort of formal acknowledgement, to indicate that it perhaps did not go straight into the w.p.b.

Intel CPUs are not defective, they just act that way.
-- Henry Spencer