News: 1655201584

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK health privacy watchdog still in talks over who is accessing country's COVID data store

(2022/06/14)


More than two years after England launched a COVID data store, keeping details of National Health Service (NHS) patients, the country's National Data Guardian (NDG) remains unsatisfied with who is accessing the data.

The COVID-19 data store was launched in March 2020, and would pull together medical and operational data about the spread of the virus across the country.

England's NHS treats almost everyone in the country, even those with private insurance, for at least some of their health needs. It estimated it serviced a total of 564 million patient contacts with doctors, mental health practitioners, hospitals, and emergency health services in 2018/19.

"This is [1]equivalent to every person in England being assessed, treated and cared for by the NHS 10 times a year, or 1.5 million interactions with patients every day."

Campaigners had to force the UK government to publish details of the contract supporting the project awarded to AWS, Microsoft, Google, Brexit-linked analytics business Faculty, and Palantir, whose technology has been employed by the CIA and controversial US immigration agency ICE. Palantir's data platform uses data from the COVID data store.

Only in August 2021 did NHS England and NHS Improvement publish a " [2]data dissemination register " to show who had accessed medical information on the data store. At the time, critics and the National Data Guardian – the privacy watchdog for health data – were not satisfied with the response.

[3]Concerns that £360m data platform for NHS England is being set up to fail

[4]NHS England seeks £240m data platform to tackle COVID recovery

[5]Fresh concerns about 'indefinite' UK government access to doctors' patient data

[6]NHS Digital's demise bad for 55 million patients' privacy – ex-chairman

Nearly a year later, despite a further release of data access details, that remains the case.

In a statement to The Register , Dr Nicola Byrne – the National Data Guardian for health and adult social care in England – said it was continuing dialog with NHS England over the release of details.

"It is essential that there is transparency around who gets access to health and care data and for what purposes. The merger of NHS Digital into NHS England and the shift towards data access in secure data environments provides a timely opportunity for NHS England to reflect on how best to achieve this.

[7]

"By acknowledging past criticisms and learning from current best practice, NHS England can implement a clear, coherent approach that meets the needs of the public. I am currently pursuing conversations around achieving better transparency for all NHS data sharing."

[8]

[9]

In August last year, the NDG declined to endorse [10]NHS England's first effort to be transparent about access to the COVID data store . "My panel and I will continue our ongoing dialogue with NHS England and NHS Improvement," Byrne said.

A few weeks earlier, she [11]expressed frustration that it had taken more than a year to release any details all.

[12]

At the time the register was released, critics argued the disclosure did not reflect the reported use of the data during the height of the pandemic. The data store had been accessed just 18 times – more recently updated to 20 – according to the spreadsheet.

NHS England's efforts at transparency will come under the spotlight as it seeks to buy a [13]£360 million (c $438 million) data platform to support an overhaul of how it manages clinical services . As US spy-tech firm Palantir sits at the heart of the current data platform, it is seen as first in line for the contract. NHS England maintains it is an open and fair competition.

The Peter Thiel-founded analytics company recently won a $90 million, five-year contract with the [14]US Department of Health and Human Services for a "holistic" enterprise data project. ®

Get our [15]Tech Resources



[1] https://www.kingsfund.org.uk/projects/nhs-in-a-nutshell/NHS-activity

[2] https://www.england.nhs.uk/publication/data-dissemination-register/

[3] https://www.theregister.com/2022/06/13/nhs_england_palantir/

[4] https://www.theregister.com/2022/04/14/nhs_england_seeks_240m_data/

[5] https://www.theregister.com/2022/03/23/uk_government_gp_data/

[6] https://www.theregister.com/2022/03/04/nhs_digital_privacy_bmj_article/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YqiwoLz5Qg-jHGC7qZ1-dAAAANQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YqiwoLz5Qg-jHGC7qZ1-dAAAANQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YqiwoLz5Qg-jHGC7qZ1-dAAAANQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2021/08/31/nhs_england_palantir_covid_19_dataset/

[11] https://www.theregister.com/2021/08/18/nhs_england_palantir_register/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YqiwoLz5Qg-jHGC7qZ1-dAAAANQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://www.theregister.com/2022/06/13/nhs_england_palantir/

[14] https://www.theregister.com/2022/05/05/palantir_leaps_from_covid_role/

[15] https://whitepapers.theregister.com/



Caldicott Guardians

Eclectic Man

If a medical professional with whom I do not have a clinical relationship (i.e., not working at my registered Family Practitioners, not my dentist, or someone to whom I have been referred by them) access my NHS data, this should be alerted to a 'Caldecott Guardian' who will assess whether the access was justified. So, if I've been involved in a car accident and the A&E team access my data, all well and good. If a medical professional accesses my data to find out if I'm on medication for anything because they know me socially, this is not good.

I do wonder whether the safeguarding rules for NHS Covid Data should have been clearly defined and implemented BEFORE all this data was collected. Not that I mind too much if it is used to save lives, improve public health etc., but if it is for more nefarious or mostly commercial purposes, I'd object strongly.

Re: Caldicott Guardians

John Robson

"I do wonder "

No wondering needed - Of course it should have been... it's not like a pandemic wasn't highlighted as the most significant threat to the country.

Things like how to track it, data monitoring etc should have been preprepared.

Re: Caldicott Guardians

elsergiovolador

whether the access was justified

If they found it was not justified, I wonder how their wrists are going to survive from all that slapping?

Reframe

elsergiovolador

So if it takes so long to get who is accessing it, maybe, just maybe it will be quicker to list who is not?

Obfuscation is because...

heyrick

...they don't know who accessed it, how much they accessed, or what they did with the data retrieved. This is entirely according to design (the design brief being the subtle transfer of banknotes). How dare those woke privacy lefties interfere with a good scam much needed modernisation, blah blah, think of all the children this could save.......

Poorochrondria:
Hypochrondria derived from not having medical insurance.
-- Douglas Coupland, "Generation X: Tales for an Accelerated
Culture"