News: 1634035512

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Patients must know how their health records are used – and approve any sharing for research

(2021/10/12)


Register debate Welcome to the latest Register Debate in which writers and experts go head to head on technology topics, and you – the reader – choose the winning argument. The format is simple: we propose a motion, the arguments for the motion will run this Monday and Wednesday, and the arguments against on Tuesday and Thursday.

During the week you can cast your vote on which side you support using the poll embedded below, choosing whether you're in favour or against the motion. The final score will be announced on Friday, revealing whether the for or against argument was most popular. It's up to our writers to convince you to vote for their side.

This week’s motion is: [1]Assumed consent is the right approach for sharing healthcare patients’ data, beyond their direct care . Or to put it another way: patient records should be shared with medical researchers on an opt-out basis.

[2]

The debate around the benefits of sharing medical data for the greater good versus individual’s expectations of confidentiality and consent, has become heated to say the least over the last year and a half. But if consent is not just assumed, but informed, do we all stand to benefit? Our contributors serve up their own prescriptions, but you get to decide.

[3]

[4]

Our first contributor AGAINST THE MOTION is privacy campaigner Phil Booth, the coordinator of medConfidential, which campaigns for every data flow in and across the NHS to be consensual, safe, and transparent.

If someone took something from you, and simply “assumed” you were OK with it – without asking or checking, without even telling you or giving you a choice – what would you think?

[5]

How would you feel about them; would you believe they were trustworthy, or more like a thief?

Assuming consent for non-care uses of your medical information is not like implied consent for your own care. When you agree to a medical referral or a particular treatment, you expect that the doctor receiving the referral or the facility providing the treatment will be told why you’re coming.

Implied consent for care doesn’t include also handing your most sensitive health details to marketers who sell products to anywhere in the NHS (not just you). It certainly doesn't automatically include you in experiments without your knowledge or permission, whether on the type of treatment you or others get, how well or badly it goes – or, as is increasingly the case, to train AIs or develop mutant algorithms.

[6]

Implied consent also doesn’t include using your individual-level data to decide who does and who doesn’t receive which type of care, or whether your local hospital or clinic ends up being closed. For such planning and policy decisions, statistical – ie, genuinely anonymous, not just “anonymised” – data are (more than) sufficient.

Assumed consent for purposes beyond people’s direct care would include all of the above, as well as everything else the Government and NHS used to call ‘secondary uses’ and now more benignly, but somewhat misleadingly, term ‘research and planning’.

Why does consent even need to be assumed?

Those seeking shortcuts or to 'streamline access' via assumed consent are seeking to cut through the fundamental principle that patients and doctors should always know what’s going on

We’ve heard a lot about the success of the Recovery trial over the past two years; a trial in which doctors could easily enrol their patients. It involved no assumed consent – nor implied consent either – as every step was appropriately consented, even during the initial stages of a novel pandemic when uncertainty was at a maximum and when both time and facts were in shortest supply.

As medics and ethical researchers well know, trustworthy use of patients’ data means doing it right.

Claims that prior informed consent is just “too difficult” or “too burdensome” self-interestedly disregard people’s lawful rights to dissent or opt out. And as millions have just shown, it’s unwise to assume that a “Don’t ask, don’t tell” approach will work when, say, attempting to grab patients’ GP data.

Those seeking shortcuts or to “streamline access” via assumed consent are seeking to cut through the fundamental principle that patients and doctors should always know what’s going on. Despite promised safeguards (which have yet to be substantially delivered) and years of “selling the benefits”, it is still the case that not all secondary uses of data are in the best interests of patients, or doctors – though many are clearly highly profitable for someone else.

Which is why every use of patients’ data must be consensual, safe and transparent; everyone must know how their data is used, and have their choices respected. ®

Cast your vote below. We'll close the poll on Thursday night and publish the final result on Friday. You can track the [7]debate's progress here .

JavaScript Disabled Please Enable JavaScript to use this feature.

Get our [8]Tech Resources



[1] https://www.theregister.com/Debates/2021/10/11/assumed_consent/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/science&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YWWxNmJ@Jg0MFVrGqH8HiQAAAE4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/science&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YWWxNmJ@Jg0MFVrGqH8HiQAAAE4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/science&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YWWxNmJ@Jg0MFVrGqH8HiQAAAE4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/science&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YWWxNmJ@Jg0MFVrGqH8HiQAAAE4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/science&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YWWxNmJ@Jg0MFVrGqH8HiQAAAE4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/Debates/2021/10/11/assumed_consent/

[8] https://whitepapers.theregister.com/



The writer is spot on

Sorry, you cannot reuse an old handle

"Why does consent even need to be assumed?"

Because the government knows full well that express consent would rarely be given, so it uses the oxymoron of "assumed consent".

Newsflash: if it's assumed, it isn't consent.

Re: The writer is spot on

Evil Scot

If you want access to my medical data, pay my practice manager to ASK my permission to join your medical experiment. Then pay me to participate.

Icon as a reward to you and as a metaphor for why you can not assume consent.

genuinely anonymous, not just “anonymised”

jmch

Absolutely this.

Anyone working with datasets knows that anonymised data can easily be de-anonymised. The higher the level of detail in a dataset, the easier it is to find unique points that can trace back to individuals.

I can accept that certain treatments will vary and have different effects depending on the approximate age, sex* and race of the patient, together with other existing health conditions. I simply do not believe that there are such large differences between people that treatments need to be targeted more individually than that.

*I advisedly use 'sex', of which there are only 2 as opposed to 'gender', since I highly doubt that gender has any relevance to different outcomes of treatments / medications etc

Re: genuinely anonymous, not just “anonymised”

Citizen of Nowhere

>Anyone working with datasets knows that anonymised data can easily be de-anonymised. The higher the level of detail in a dataset, the easier it is to find unique points that can trace back to individuals.

This. And the fact that datasets can be combined and once they are, what appeared "securely" anonymous in only one of them may not remain so after the data is combined.

The problem

Anonymous Coward

Assumed consent is only achievable if you have trust. Governments and society rarely have those at a sufficient level for this to work.

The bigger point here though, I think, is that assumed consent is a short term measure anyway.

The way data is handled is going to change radically over the next 5-10yrs.

I found this article fascinating: https://www.theregister.com/2021/10/04/column_data_privacy/

It points the way to the future of consent.

Re: The problem

Hubert Cumberdale

I trust the current government in only one specific area: I trust them to act purely in their own interest with flagrant disregard for the needs of wider society beyond doing just enough to get themselves re-elected.

Re: The problem

SCP

Trust is a major issue here and many governments of differing hues and nationalities have repeatedly abused the trust of their people. The juxtaposition of the opening of this debate with the reporting of the warning from England's Data Guardian on wider police access to NHS data was incredible [almost smacks of editorial mischief].

The repeated violations of peoples data privacy is compounded by a lack of meaningful "holding to account" of offenders. Too often it seems that it is a case of publishing a "privacy is our highest priority" statement before returning to business as usual.

The medical business does have a long-established ethics infra-structure but it is not perfect and cannot ensure absolute integrity - individuals/companies can violate ethical rules as easily as they violate other laws. What sanctions there are can punish those found guilty - but cannot make good all the harm that has been done.

That should mean we should carefully consider the harm that could be done by sharing data vs the benefits that can be gained, and who is going to suffer that harm vs who is going to benefit. It will be a trade-off between individual rights and societal benefits - but it needs to be an equitable trade-off. It would be interesting to hear from various ethics bodies on the subject of ethical sharing of medical data.

Information and Data Technology are rapidly changing the privacy landscape, some consider that personal privacy will be totally lost. Many [the majority?] seem either ignorant or blasé about it.

I don't think medical privacy should be spear-heading this change, but it seems perverse to deny potential benefits to society by holding onto a concept of privacy that might no longer exist. How many, on receiving bad news from their GP would be Googling for information - so who now has what information.

I don't welcome it, but I am not sure the medical profession, researchers or even pharmaceutical companies are the worst here [individual cases excepted].

Greed

elsergiovolador

Insatiated big pharma industry will corrupt any government to get access to data.

The problem is that big pharma wants patients to be dependent on their drugs, in their interest is to have people take as much expensive meds as they possibly fit in their mouth every few hours.

They don't have any incentives to create a cure.

It's not just big pharma - many industries shift to subscription models where you have to pay for the product every month in order to use it.

Big pharma wants you to take their pills in order to live.

They need this data to see what demographics they can exploit and which illnesses could yield the most profit.

I have a big problem with the way this debate is run

Martin Gregorie

Please DO NOT change the headline used for each part of the debate because that just adds confusion, the more so as the original subject is not visible in this post until after you've voted For or Against.

Ideally the first three lines on each of the four propositions would be:

PROPOSITION BEING DEBATED - This exact same wording appears in all four parts

Headline for the next debater's argument

Debater's name

and the main proposition should be repeated at the top of the 'vote now' box.

Mike 137

" Claims that prior informed consent is just “too difficult” or “too burdensome” self-interestedly disregard people’s lawful rights to dissent or opt out. "

Entirely correct. This is another example of a clearly prevalent mind set that advocates abandoning data subject rights in general in order to support (in the words of a recent DCMS request for comments) ' driving growth and unlocking innovation '. It sits very well alongside the current government proposal to repeal Article 22 of the GDPR, which provides for a data subject to require explanation and review of entirely automated decisions that have a material effect on their rights or freedoms. The result would be "computer says no" enshrined in law, with no route for redress.

It's become perfectly clear that 'digital progress' is more important than the people it's supposed to serve, quite possibly because it's a big bucks business that promises to make a few very rich people even richer. So it's being rushed ahead regardless of possible consequences. However, as I said in my submission to the RFC referred to above " Where lives and livelihoods are at stake, even in the name of progress the public can not legitimately be considered an involuntary test bed for systems development ".

'mutant algorithm'

ibmalone

While I largely agree with the arguments put here, I take issue with the phrase "mutant algorithm". It's meaningless rhetoric to use the word mutant there, and it originated from an attempt last year by the UK government to put the blame for their decisions on some "algorithm" as if it was beyond their control or that of the programmers who wrote it. The algorithm in question was not some uninterrogable machine learning model, but quite simply a choice to take teachers of small classes (private schools) at their word for predicted grades while thresholding results for large classes (state schools) at those of previous years. Talking about a mutant algorithm suggested some unforeseeable and incomprehensible consequence of computer programming beyond the government's control, when these were actually the entirely predictable consequences of fairly simple rules.

The phrases we unquestioningly adopt shape our thinking, and this is one to be rejected. Whatever the algorithm in question, it hasn't crawled out of the sea in some 50's B movie.

A problem? Nope, its a series of individual problems, each of which has privacy implications

Anonymous Coward

Health-related personal data is some of the most sensitive personal data there is and, in the majority of cases, unlike a leaked phone number or bank account details, it is data that cannot be changed.

Some of the risks to personal data include:

- anonymisation of data is hard to perform correctly, especially in a health context where for example certain medical conditions might be 'rare' enough to defeat any anonymisation attempts. Also some (much?) medical research cannot work with anonymous data and rather requires pseudonymised data. So you are relying on the competence and willingness of organisations to anonymise or pseudonymise personal data correctly, especially in the case of pseudonymisation where the org in question may not understand the 'trackability' of particular items of personal data and so leave them present/unaltered in any 'pseudonymised' data they create.

- even if organisations implement proper data security (which is in of itself questionable) there still remains the risk of data breaches

- once personal data is shared there is a loss of control over that data (at least by the data subject themselves, if not by other orgs) from that point onwards. If the recipient org(s) later decide to change what they do with the personal data then its realistically too late (for the individual) to do anything about it. The same applies in the case of anonymised data (which is *not* personal data) - if, for sake of argument, I don't agree with animal testing and an org who receives my anonymised data stated at the time they do not test on animals I may be happy for my data to be used to create their anonymous dataset but if that org later decides to start animal testing there is nothing I can do. Any Privacy Notices or other policy documents reflect a particular point in time and do not reflect on any future intentions.

- inadequate enforcement of data protection law which means that many organisations do not take the laws seriously (or even consider them at all) as the risk of being "caught" is low, the risk of enforcement action is lower, and the risk of a substantial fine or action taken against individuals is even lower.

So as someone who has worked in 'enterprise'/largescale IT for his whole career "I've seen things you people wouldn't believe" (https://en.wikipedia.org/wiki/Tears_in_rain_monologue) and so I am reluctant for my most sensitive personal data to be at risk of either accidential or purposeful misuse, a risk that increases greatly as more organisations have access to it.

With this mind I do not agree with opt-out scenarios for health data - I have already suffered from unlawful processing of my health data in the past due to this: healthcare systems were launched where allegedly letters where sent out notifying of a cut-off date for opting out and I never received the letters and so was unable to opt-out in time to prevent my health data being shared against my wishes (and also in breach of data protection law).

the AA battery in the wallclock sends magnetic interference