3 ms·
You're right, of course, and that is why the situation is how it is. NHS Digital also seem reluctant to become custodians of the data and only administer servic
by dkarp 5y ago
You're right, of course, and that is why the situation is how it is. NHS Digital also seem reluctant to become custodians of the data and only administer services that have to be done centrally, such as HSCN and NHSMail, and those services tend to involve a lot of external contractors - so the in-house talent may well be missing. But by siloing the data, we're just trusting doctors and hospitals to know what is best and that can't be a good idea either. The WannaCry attack a few years ago was good evidence of that.
On a side note, I can't imagine how hard it must be for the NHS to do anything when essentially an internal transfer of data within the organisation is labeled as "Your medical records are about to be given away" by the media. They seem almost to be victims of how open they are about these data transfers and I sense an exasperation between the lines when reading their response [https://digital.nhs.uk/data-and-information/data-collections-and-data-sets/data-collections/general-practice-data-for-planning-and-research/advice-for-the-public https://digital.nhs.uk/data-and-information/data-collections...].
- Silhouette 5y agoI agree that there are serious problems with non-experts administering these systems at local levels as well. There's no good answer right now, IMHO, only less bad ones. But there is a huge difference between the two main policies here in the scale of damage that could be caused by a catastrophic failure. For the same reason, I have limited sympathy for the idea that this is just another internal data transfer and people are getting worked up without cause. The NHS isn't really a single organisation, the people pushing for this aren't really clinical staff, and there has been a long and undignified history of screw-ups when it comes to patient confidentiality and larger data sharing schemes. Caution does seem to be in order here.
- fragileone 5y agoEspecially with the fact that very recently 10% of vaccinated individuals were secretly location tracked to see if it changed their behaviour it would be difficult to put trust in a central authority that they wouldn't abuse this data.
- motohagiography 5y agoNot sure if NHS has this concept, but in other health systems, the NHS equivalent (an economy that operates a health system o.b.o a government) is a set of service providers, with data custodians at the edges. Custodians hold accountability for health information privacy, where service providers are accountable to a custodian. It all rolls up into these entities. Health admins tend to forget that the relationship they are scaling is between physicians and patients, and it is not the government managing the vetrinary system for a person farm. This health system as proxy for public policy issue is dangerous. If you see my previous comment on this thread about objections to data collection, an opposing view of another health tech and policy expert would be really valuable to the discussion.
- dkarp 5y agoThat's more or less how it ends up working in the NHS, and I guess it's Conway's Law playing out again rather than being intentional. Health is particularly difficult because it's both data that needs to be accessible by a large number of different people/organisations and also about as sensitive as you can get. Any attempt to make the data more secure necessarily slows access, but making the data more accessible also makes it less secure. Having seen the quality of some of the systems holding this data on the edges, I would rather see a central database and a lot of funding go into the technology of that system. Why? Because I agree with your other post, that technical controls are the only solution. Controls that could make it impossible for the data to be misused or leaked, or at least make access auditable. That's where the research and funds should be spent. Ideally, that could be done by every data custodian at the edge, but I just don't think that will happen. It's easier to solve the problem in one place than in 10s or 100s or 1000s of places. In the UK, there are lots of central data repositories holding pretty sensitive information. I think it's fair to say that the government wouldn't have much problem finding your health data, along with detailed census/tax/internet/phone/travel data, if they decided they wanted to.