7 ms·
So, do you believe that the sticker was appropriate? Or would a PR statement from your university's press office have been more appropriate? Ultimately, the la
by throwaway729 10y ago
So, do you believe that the sticker was appropriate? Or would a PR statement from your university's press office have been more appropriate?
Ultimately, the lack of a legally binding contractual obligation with sufficient audit-ability is primarily what Julia Powles & Hal Hodson are criticizing.
- aub3bhat 10y ago>> lack of legally binding From the verge article: "The data-sharing agreement — which was signed in 2015" There was a legally binding contractual agreement between the two parties Deep Mind & Royal Free. Here is the one that I and thousands (I am NOT exaggerating) of other researchers regularly sign to get access to data. https://www.hcup-us.ahrq.gov/team/NationwideDUA.jsp https://www.hcup-us.ahrq.gov/team/NationwideDUA.jsp
- throwaway729 10y ago> There was a legally binding contractual agreement between the two parties Deep Mind & Royal Free. Which was, allegedly, far too lax. The claim that DeepMind was providing "direct care" is particularly questionable IMO, and that has significant implications in the context of this agreement. It means anyone who slaps together an iPhone app (and has the right clout/deep pockets) can get access to full and fully identified medical records without patient consent. IMO that's the big story here, and it's troubling. The "don't worry that's covered by existing law" responses were also problematic. Why does this particular contract need to depend upon the enforce-ability of that law? What happens if the law is repealed and DeepMind happened to keep a copy of the data? We want the protection here, in this context, so just put it in this agreement. Which is what they ultimately did in the new agreement AFAICT. Also, the data shared is extremely broad -- I doubt you could get access to a data set of that size and quality without patient consent through standard channels, for example. I've never seen an identifiable data set containing "not only to relevant blood tests and diagnostics, but historical medical records dating back five years, including information on HIV diagnoses, drug overdoses, and abortions" for 1.6 million people. Access to such sensitive data creates a difference in kind that justifies greater care and skepticism, especially WRT audit-ability. The parties appear to agree, since they signed a new agreement recently! Demonize these researchers all you want, but as a direct result of their work, NHS patients have stronger legal protections today than they did a year ago.
- aub3bhat 10y ago>>> It means anyone who slaps together an iPhone app can get access to full medical records. Ummm thats how the world works, frankly its like saying water is wet. Whenever a hospital works with any third party provider, it signs a BAA agreement which governs the sharing of data. All risks of disclosure, etc. are priced into the contract. Any large hospital will have dedicated group of lawyers for sole purpose of drawing up these agreements. >> NHS patients have stronger legal protections today than they did a year ago. No they don't. For starters Deep Mind has not even returned any collected data.
- throwaway729 10y ago> Ummm thats how the world works, frankly its like saying water is wet. Whenever a hospital works with any third party provider, it signs a BAA agreement which governs the sharing of data Most BAA agreements are for things that are actually and unambiguously direct care, and for the actual patient being treated, and only obviously relevant data used for a particular business processes. Like lab results or billing, for example. Most of the data Google received was for people who it's unambiguously NOT providing direct care to. And even for the people who might be helped with their app, IMO "direct care" is still a stretch. So, this agreement was not standard or normal in terms of scope or quantity. That's almost tautologically true, since what DeepMind is doing is presently abnormal. Now, you may argue that it should be allowed without additional data protections. But don't mis-characterize. Most BAA's are significantly different in scope and purpose from from this agreement in any number of ways. > No they don't. For starters Deep Mind has not even returned any collected data. They've agreed to independent auditing, which is a huge improvement. Source: https://deepmind.com/blog/working-nhs-build-lifesaving-technology/ https://deepmind.com/blog/working-nhs-build-lifesaving-techn...
- Silhouette 10y agoThere was a legally binding contractual agreement between the two parties Deep Mind & Royal Free. Personally identifiable health-related information is classified as sensitive personal data under the DPA, and as such there are particularly strict conditions on processing it. What two organisations write in a contract does not change this.
- aub3bhat 10y agoAgain you are unaware of extremely common business practices such as a BAA agreement. E.g. when a hospital contracts an outsourced lab all it needs is just another BAA agreement that governs sharing and use of the data. http://searchhealthit.techtarget.com/definition/HIPAA-business-associate-agreement-BAA http://searchhealthit.techtarget.com/definition/HIPAA-busine...
- DanBC 10y agoYou keep linking to US stuff, and people keep reminding you that this case is in the UK, subject to UK and EU data protection law. The laws are very different, and there are much stronger protections in the UK.
- Silhouette 10y agoWe're talking about the UK. HIPAA is irrelevant.
- dragonwriter 10y agoHIPAA rules aren't relevant to the United Kingdom; and, even under HIPAA, a BAA is required for certain sharing of data with contracted parties, but isn't on its own sufficient for unlimited sharing of PHI without restriction on use. Heck, even the entity doing direct service has limits on permitted internal uses. The items raised with DeepMind would raise serious concerns under HIPAA of the entities involved were covered by it.