4 ms·
The issue is that the PID is all encrypted, I wouldn't know if we have a John Doe on our system, we can't see anything to verify that user exists or that they'r
by dawson 14y ago
The issue is that the PID is all encrypted, I wouldn't know if we have a John Doe on our system, we can't see anything to verify that user exists or that they're the appropriate owner of said data. We do have an email (which is also encrypted at a system level, which in theory we could access), but verifying an access request based on an email address? I don't know. The way we solve the problem is by making all the data available to the user once they have authenticated, as long as you can login to our website, all your data is available to you, but if you made a direct data access request to us, like a FOI to our office by letter (the typical way it's done), not much I think we could do.
- thisone 14y agoYour IG team will know. From my understanding, from the yearly IG briefings I used to have, you would be able to provide that requester with information on how to obtain their personal access, and point out to them where they can find the information they have requested. Information needs to be made accessible, you don't necessarily need to actually provide printouts. For example, FOI requests from news agencies often cover the same topics. This information can and often is posted publicly on the organisation's website and the FOI responses refer the requester to those links.
- alexkus 14y agoFOI requests are often made because people don't trust that the "all your information is displayed here on the website" is actually all of the information that is being held on them. What if the FOI request was supplemented with the users password (changed by them to a temporary one)? Other possibilities would be encrypting a second copy of the patients data (each time it is stored by the user) using a public key with the corresponding private key held in escrow somewhere on a machine with no network connection. It would then be someone's job, upon receiving an FOI request, to take the patients master-encrypted record(s), put them on the non-connected computer that contains the private key, decrypt, and print out in order to reply to the FOI and then clean up.
- thisone 14y agoIf this ability to decrypt data exists, you have yet another layer for the FOI request. You must track each and every time a patient's data was decrypted and by whom, and that information must be available as well. Information that you'll probably also need to encrypt, but still be able to search by patient, date, and decrypter. (requests come through to find all records a particular employee has seen within a certain date range as well) I can see the start of a rabbit hole, which is why organisations dealing in PID have IG teams or consultants who know the laws and know how much needs to be done. If a patient thinks an organisation is holding out on them, that patient has a way to complain, and the complaints aren't taken lightly from what I've seen.
- davidw 14y agoInteresting... I'm dealing with similar issues. What would be ideal is to have some kind of "password/data escrow" service that is separate from companies like yours, or the one I'm working with, so that there is a way to recover the data if a password is lost, but a formal/legal separation of the means to access it is maintained.
- rmc 14y agoif you made a direct data access request to us, like a FOI to our office by letter (the typical way it's done), not much I think we could do. Minor pedantic peeve of mine: Many countries have Freedom of Information (FOI) laws, and Data Protection. Often FOI only refers to government bodies and covers lots of stuff (e.g. "How much per year does my local council spend cleaning the local park?"), however data protection mostly applies to personal data that anyone (government or private enterprise) holds on you. Data Protection laws sometimes make it illegal for the company to tell third parties the personal data about you.