News: 1627547412

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Ex-health secretary said 'vast majority' were 'onside' with GP data grab. Consumer champion Which? reckons 20 million don't even know what it is

(2021/07/29)


Around 20 million people in England are in the dark over plans to share their GP medical records with a NHS Digital database, according to a study by not-for-profit consumer watchdog Which?

In a survey of 1,700 adults in England, Which? found 45 per cent were unaware of proposals for their medical records held by their doctor to be sent to the non-departmental government body under the controversial plan dubbed the [1]biggest data grab in the history of the NHS .

The proportion unaware of the plans – and therefore their rights to opt out – is equivalent to 20 million people in England and reveals how ineffective the health department has been in informing patients, as required under data protection law.

[2]

The government has now delayed the General Practice Data for Planning and Research (GPDPR) programme, quietly announced in May this year, [3]for a second time . Last week, NHS Digital said the project, which has attracted a wave of criticism from privacy campaigners and [4]healthcare professionals , would only restart after a "campaign of engagement and communication has increased public awareness of the programme, explaining how data is used and patient choices."

[5]

[6]

It also said the GPDPR would only go ahead in a trusted research environment, whereby third parties analysing the data did not extract it from NHS Digital systems. Meanwhile, patients could opt out at any stage, and have historic data deleted from NHS Digital systems after it had been uploaded, options previously denied. The government unit said it was moving away from a previously fixed date of 1 September, which [7]replaced an earlier deadline of 1 July .

Rocio Concha, Which? director of policy and advocacy, said: "NHS Digital and the government are right to delay implementation of the GPDPR scheme and must now go to greater lengths to engage the public, raise awareness of the scheme, and increase people's understanding of it through better communication and transparency."

[8]

The Which? survey calls into question NHS Digital's earlier claims that it was informing the public about its plans to extract GP-held health data and former [9]health secretary Matt Hancock's claim that "the vast majority of people are strongly onside" with the data grab.

[10]Snail mail would be a fool-proof way to inform patients about plans to slurp GP data, but UK govt won't commit

[11]England's controversial extraction of personal medical histories from GP systems is delayed for a second time

[12]Backbench Tory campaigner promises judicial review of data grab of English GP patients unless UK government changes tack

[13]BMA warns NHS Digital's own confidentiality guardian could halt English GP data grab unless communication with public improves

The survey found half of the respondents who had heard about GPDPR had done so via the [14]news or [15]social media , rather than NHS Digital or GP surgeries. "NHS Digital had not publicised it widely in the news or online," the consumer group said.

Four in 10 of those unaware of the plans said that on hearing about it, they would probably want to opt out while of those who had heard of the scheme, 71 per cent felt the NHS had not publicised it well.

Which? also found that the lack of transparency around the scheme could affect trust in the NHS. At the start of its survey, three-quarters of respondents said they trusted the NHS to handle their GP medical records safely and transparently. Four in 10 (42 per cent) said hearing about the scheme in the survey had made them trust the NHS less.

Meanwhile, communication of the controversial scheme also affects its legal standing. Data regulator the Information Commissioner's Office says that fairness and transparency are fundamental to the UK's interpretation of the General Data Protection Regulation (GDPR), implemented in the Data Protection Act 2018.

[16]

Doctors' union the British Medical Association (BMA) has said the level of communication might not meet the requirement for transparency under UK law. NHS Digital's own patient confidentiality guardian could stop the process unless communication with the public is improved, Dr Farah Jameel, BMA GP committee executive team IT lead, [17]told The Register .

Critics of the GPDPR scheme have pointed out that the data extraction plan for 55 million people living in England involves sensitive patient medical histories, which although "pseudonymised" in the process, can be reidentified with individual patients when combined with other datasets within the sphere of the Department for Health and Social Care.

Campaigners medConfidential and [18]Foxglove also point to a lack of transparency over how [19]private-sector organisations accessing the data might gain. NHS Digital has said it would "not approve requests for data where the purpose is for marketing... including promoting or selling products or services, market research or advertising."

However, in May The Register showed that under current sharing agreements around hospital patient data, [20]companies that offer market intelligence get access to it .

A more recent investigation by the Financial Times showed that at least 40 companies, including management consultancies and pharmaceutical groups, had received years of detailed medical records from English hospitals under current data sharing arrangements. [21]The FT found that insights from the data were often shared or sold on to other commercial entities and providers that use it to price products being sold back to the NHS, or conversely restrict the NHS's access to analysis of its own data, creating conflicts of interest.

Responding to the Which? survey, NHS Digital said: "We know we need to take people with us on this mission which is why we have committed to putting even tougher protections and safeguards in place and stepping up communications through a public information campaign before the new programme begins.

"Data is only shared where there is a clear benefit to healthcare planning and research. This benefits all of us, but it is only as good as the data it is based upon which is why it is absolutely vital that people make an informed decision about whether to share their data."

The UK Government clearly did not learn from its mistakes with the [22]care.data debacle . Transparecy? They've heard of it. ®

Get our [23]Tech Resources



[1] https://www.theregister.com/2021/05/13/nhs_data_grab/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/databases&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YQJ8NTmrCAp64oWaTBZWtQAAABc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2021/07/20/nhs_data_grab_delayed_again/

[4] https://www.theregister.com/2021/06/04/bma_and_royal_college_of/

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/databases&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQJ8NTmrCAp64oWaTBZWtQAAABc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/databases&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YQJ8NTmrCAp64oWaTBZWtQAAABc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2021/06/08/uk_gov_delays_gp_data_grab/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/databases&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQJ8NTmrCAp64oWaTBZWtQAAABc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2021/06/09/matt_hancock_nhs_data_grab/

[10] https://www.theregister.com/2021/07/21/health_committee_gpdpr_engagement/

[11] https://www.theregister.com/2021/07/20/nhs_data_grab_delayed_again/

[12] https://www.theregister.com/2021/06/25/david_davis_gpdpr/

[13] https://www.theregister.com/2021/06/25/bma_says_nhs_digitals_own/

[14] https://www.theregister.com/2021/05/13/nhs_data_grab/

[15] https://twitter.com/TheRegister/status/1392770887779299328?s=20

[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/databases&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YQJ8NTmrCAp64oWaTBZWtQAAABc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[17] https://www.theregister.com/2021/06/25/bma_says_nhs_digitals_own/

[18] https://www.theregister.com/2021/06/04/bma_and_royal_college_of/

[19] https://www.theregister.com/2021/05/17/nhs_data_market_access/

[20] https://www.theregister.com/2021/05/17/nhs_data_market_access/

[21] https://www.ft.com/content/6f9f6f1f-e2d1-4646-b5ec-7d704e45149e

[22] https://www.theregister.com/2016/09/27/scrapped_nhs_care_data_cost_taxpayer_8_1m_pounds/

[23] https://whitepapers.theregister.com/



Robert Grant

> a trusted research environment

Phrases that mean "we bought an expensive firewall and that's it". No environment should be trusted since Google (I think) brought out Zero Trust.

It's always trusted...

Sgt_Oddball

Until it inevitably isn't.

Dentistry?

Eclectic Man

Just had a dental checkup* and wondered whether dental records are included? And I should be having an eye test soon too, will they be gobbled up, or is only NHS GP records that are affected?

*No problems, since you ask.

Re: Dentistry?

macjules

If carried out via your GP or in an NHS hospital, then yes your details are included.

GPDPR

macjules

Using "GPDPR" makes it sound like General Data Protection Regulation, i.e.something designed to help protect the public. Of course Mr Hancock couldn't possibly be looking at joining the boards of Facebook Pharma, Google Patient Assistance or Twitter Medical ...

Re: GPDPR

Joe W

Yes. So much.

(I did think and comment the same, a few months ago, no doubt I was not the first one to remark this, no doubt you won't be the last)

Let's be honest, okay ?

Pascal Monett

" Four in 10 (42 per cent) said hearing about the scheme in the survey had made them trust the NHS less "

Given the UK Government's history of IT project management in general, I would suggest that 10 out of 10 should opt out. NOW.

Simple solution

David M

Make it opt-IN. That way only people who have heard about it and are happy to have their data shared will be affected. It would then be up to NHS Digital to convince everyone that it's a good idea, and that their data will be kept safe and not be misused.

NHS Stealth Secretary

Scott Broukell

Well I'm rather glad he's gone at least. But if NHS Digital want to engage with the public over this, then I would suggest that the best way is to; (1) Opt Out all individuals from the start! (2) Write to all individuals, explaining clearly what is intended and how their personal health data is to be used and by whom. (3) Back that all up with a comprehensive TV / Internet information campaign. (4) Then ask people if they would still like to sign up to it - with the option of reversing that decision at any time in the future.

I think any loss of trust should be directed towards ministers and their cronies, not what is left of the NHS as a whole.

My own awareness, of this and earlier related stories, came about through this worthy web site and it's many contributors!

Opt out?

Anhydrous Cummerbund

I thought ALL data gathering had to be opt-IN by law these days?

The grab

elsergiovolador

We have already seen "the grab".

Inversion of purpose

Mike 137

As a spin off from the European Declaration of Human Rights in the aftermath of WW2, data protection legislation was envisaged primarily as a means of protecting citizens from abuse of their personal data by governments - in fact as an extension of human rights law. Ever since, governments have availed themselves of ways to exempt themselves from its restrictions in the name of providing "services" or "security". It's been quite easy, as governments effectively make the laws. What's hard is finding legal ways to curb the resultant abuses (for the same reason).

Anonymous Coward

They've heard of "Transparecy" well that's impressive!

Flee at once, all is discovered.