8 ms·
The NHS is selling your private data – here's the price list [pdf]
- ghswa 13y agoA good explanation of the scheme, from Dr Neil Bhatia can be found at http://care-data.info/ http://care-data.info/ It includes details of how to opt-out.
- switch007 13y agoIt's a long site so I'd just like to highlight the following: "The data extracted - your Primary Care Dataset - will include the following: Your NHS number Your date of birth Your postcode Your gender and ethnicity Your medical diagnoses (including cancer and mental health) and any complications Your referrals to specialists Your prescriptions Your family history Your vaccinations and screening tests Your blood test results Your body mass index (height/weight) Your smoking/alcohol habits" --- Go to that site. Opt out here http://optout.care-data.info/ http://optout.care-data.info/. It's really simple.
- aaren 13y agoIf you prefer, you can just write a letter to your surgery: - State that you wish to opt-out of care.data - Request that both the 9Nu0 and 9Nu4 codes are added to your GP records - Remember to include full names and DOBs (and your address if you are happy to)
- porker 13y agoThe conundrum I have is knowing this has been done. I wrote a letter with all of this, took it to the GP surgery. The receptionist was bemused. There has been no acknowledgement. Can I tell if I've been opted out, without hassling the already-overworked reception staff?
- ghswa 13y agoTry talking to your practice manager - mine is very helpful and (s)he'll hopefully be much more clued up about this than the reception staff.
- smikhanov 13y agoNot only that, how do you know those codes are meaningful?
- DanBC 13y agoWrite a letter and address it to the practice manager or the caldicott guardian. Ask for a response within 28 days to tell you what is happening.
- gcb0 13y agowow. having that being already identified to the individual is pretty dumb. what is the excuse for this to even be like so in the first place?
- thinkpad20 13y agoCrazy that one has to opt OUT of that, seeing as I'd bet only a minuscule fraction of the population would ever opt in...
- donskif 13y agoIt is fairly simple to print off a form and send it in to your GP but I suspect the vast majority of people will see this as a hassle and never bother. Considering recent government actions, I find it unsurprising that this is the only method - as far as I can find - to opt-out. A simple form or email address would have been great. But we couldn't possibly have that for an online data service, oh no.
- lostlogin 13y agoLove how it is opt out. If it was opt in would they have any takers? If you set up auto-opt in systems where I live you would soon have the commerce commission, privacy commission or the police knocking on your door asking hard questions.
- dewiz 13y agothank you!!
- brownesauce 13y agoI found this blog post from the NHS chief data officer useful to understand how they view patient data http://www.england.nhs.uk/2014/01/15/geraint-lewis/ http://www.england.nhs.uk/2014/01/15/geraint-lewis/
- optimiz3 13y agoThis would be straight up illegal in the US due to HIPAA, which guarantees a patient's right to privacy. HIPAA = http://en.wikipedia.org/wiki/Health_Insurance_Portability_and_Accountability_Act http://en.wikipedia.org/wiki/Health_Insurance_Portability_an...
- mortov 13y agoThe irony. It's illegal in the US where EU countries cannot send data because of the weak data protection laws and the UK with 'strong' laws is the one selling off all your private medical records (including identification details) for a paltry sum. The price list looks so cheap that Russian or Nigerian scammers can afford these extracts and it would save them a hell of a lot of time setting up ID scams and instantly make them much more profitable. No longer any need to mass mail in the hope of finding someone likely to buy V!agr4, the NHS will give you a list of likely marks to direct market to and save all the useless pitches to women !
- rpedela 13y agoNo it isn't. U.S. health data can be sold if it is de-identified or with a patient's permission.
- tansey 13y agoBut this data is not de-identified. They explicitly list prices for data with confidential, patient-identifying information.
- rpedela 13y ago"This would be straight up illegal in the US due to HIPAA, which guarantees a patient's right to privacy." That is a blanket statement which is false. Some of what NHS is providing would be illegal in the U.S. Some of it is actually legal. I am mostly responding to the blanket statement.
- vilhelm_s 13y agoThe main page, http://www.hscic.gov.uk/dles http://www.hscic.gov.uk/dles , states > The data we supply is normally pseudonymised. We only provide identifiable data when there is a lawful basis to do so i.e. with patient consent, approval under section 251 of the NHS Act 2006 which enables The Health Service (Control of Patient Information) Regulations 2002, or where appropriate statutory regulation is in place. This "About Section 251" page, http://webarchive.nationalarchives.gov.uk/20130513181011/http://www.nigb.nhs.uk/s251/abouts251/index_html http://webarchive.nationalarchives.gov.uk/20130513181011/htt... , states > Section 251 came about because it was recognised that there were essential activities of the NHS, and important medical research, that required use of identifiable patient information but because patient consent had not been obtained to use people's personal and confidential information for these other purposes, there was no secure basis in law for these uses. [NB. There are a few exceptions where there is a legal basis for disclosure e.g. reporting of notifiable diseases]. Section 251 was established to provide a secure legal basis for disclosure of confidential patient information for medical purposes, where it was not possible to use anonymised information and where seeking consent was not practicable, having regard to the cost and technology available.
- joshavant 13y agoWould this enable the private industry to create services and analyses based off this cheaply available data? Yes, it seems heinous at first, but are there legitimate, palatable Big Data opportunities here, assuming the data is properly anonymized?
- deleted 13y ago[deleted]
- foxhill 13y agothere isn't even an attempt at anonymizing the data.
- UVB-76 13y agoIt is exceptionally difficult, if not impossible, to properly anonymize this kind of data, and this particular dataset is absolutely not anonymized.
- uxp 13y agoHeh, mostly off topic: I just bought the book "Anonymizing Health Data"[0]. No significance to the article, just amused at the timing. Looks like this is going to be a problem domain moving forward with my career. [0] http://shop.oreilly.com/product/0636920029229.do http://shop.oreilly.com/product/0636920029229.do
- foxhill 13y agoperhaps. the data is not anonymized.
- mortov 13y agoDid you look at the price list ? Standard extract – no personal confidential data £9,565 Alternatively for just under £1,000 more : Standard extract – containing personal confidential data £10,453 They're specifically enticing people to purchase the confidental data version since it is only 10% extra to get all the juicy information. Trouble connecting people to their parents, siblings, children, (ex)partners ? Simple, they'll even do that for you - look at Patient Tracking, Cohort Event Notification (!) etc. The value of this data to marketers (e.g. health insurance, private hospitals - which do exist in the UK, etc. makes the price list charges trivial and insignificant to just slurp up everything they can and start targeting people). Want someone to try and sell you cancer insurance 2 weeks after your mother dies of breast cancer ? Cohort event notification report makes this simple. Remember the toothpaste does not go back into the tube - once the data is sold, it's basically wild and free for all sorts of use and abuse. You have absolutely no guarantee it will only be used by benign 'good actors'. edit:spelling
- pbowyer 13y agoWhoever gets their hands on this data should build a "20 Questions" game, to identify a person's NHS number. Knowing something of my neighbour's recent medical history, I'm pretty sure it'd take 10 questions or less. Are there any restrictions on publishing the data? I can't find licensing terms.
- ghswa 13y agoNot exactly licensing terms but page 3 of the price list states that extracts subject to an annual fee will continue to be charged that fee until it is certified that all hard and soft copies of the data have been destroyed. Other than that I'm guessing they will enforce some pretty draconian restrictions on publishing and sharing the data since doing so would undermine their ability to sell the data.
- gohrt 13y agoSo the UK govt aren't even claiming that this data is public information, and charging a processing fee for it -- the govt is claiming that citizen's personal health information is owned by the goverment with privileges to restrictively license it to commercial customers!
- angersock 13y agoI just threw up in my mouth a little. Then I started thinking about how to make a dating service using this data--find all eligible males with your blood type in a given area!
- Fasebook 13y agoOh don't worry, you can "opt out"
- ed_blackburn 13y agoI await the shit storm when a public figures medical records are mined by the media divulging something controversial.
- pbhjpbhj 13y agoPeople with rare diseases, especially multiples, must be reasonably easy to deanonymise. Also joining the data with newspaper reports of crimes (perhaps only ones that are pertinent are mentioned, eg harassment of hospital staff) or hospitalisations would seem likely to deanonymise quite a few records.
- tomelders 13y agoPost code. Date of Birth. Gender. What more do you need?
- optimiz3 13y agoOpportunity here for the motivated - the prices seem high, so arbitrage the price by reselling the data at lower prices to multiple buyers. Bonus: you could set up a system where a person's data gets cheaper as more people query it! (Not for me thanks.)
- deleted 13y ago[deleted]
- dawson 13y agoWill data be made available outside the NHS?* (PDF) [england.nhs.uk] http://goo.gl/CxqFVa http://goo.gl/CxqFVa * FAQ 39.
- ghswa 13y agoAt first the statement that identifiable data will only be released when there is a legal obligation to do so reassured me. Then I read that section 251 (http://goo.gl/rtuVF8 http://goo.gl/rtuVF8) is one of those obligations - the secretary of health can override common law to allow the data to be used for particular purposes.
- dublinclontarf 13y agoYou can choose to have your information not included, it's an opt out system. Form is here: http://www.connectingforhealth.nhs.uk/systemsandservices/scr/staff/aboutscr/comms/pip/optout.pdf http://www.connectingforhealth.nhs.uk/systemsandservices/scr...
- ghswa 13y agoThat's an opt out for the summary care record which is a different centralised system. We're talking about care.data here.
- nodata 13y agoYou are spreading misinformation, almost definitely not on purpose. Read about the correct opt-out form here: http://optout.care-data.info/ http://optout.care-data.info/
- takeda 13y agoAnd of course you're included automatically, but to opt out it is most painful way to do it. And not to mention that you need to know about it in the first place.
- zmmmmm 13y agoI fully expected to read the details and see that the headline was some sort of hyperbole, as these things nearly always are. I'm still hoping someone will tell me this isn't real. This seems downright evil. Disgusting. There is no justifiable reason for this data to be available in any sort of unanonymized form. Everything that is justifiable that can be achieved with it in anonymous form can be achieved with it anonymized. The terrible part is that there is a good reason for a program like this. There are real reasons to collect and know this kind of data - it can make a huge difference to human health and well being. And that is why this is so bad. It's going to set back participation in any sort of electronic health record all around the world, if people see such a high profile program manifest as a privacy disaster.
- lindavers 13y ago>I fully expected to read the details and see that the headline was some sort of hyperbole It really is, see the source page for more details: http://www.hscic.gov.uk/dlesaac http://www.hscic.gov.uk/dlesaac The misunderstanding going on in the comments seems to be stemming from a failure to distinguish between personal identifiable data and personal confidential data. The former: "This includes patient identifiable data, such as: NHS number Name Address Postcode Date of Birth Date of Death" and the latter: "Personal confidential data also includes sensitive data which may include items such as: Racial or ethnic origin Political opinions Religious or other similar beliefs Physical or mental health condition Sexual life Criminal record" The patient identifiable needs explicit permission from the patient in order to obtain, patient confidential needs a good legal reason + reviewed application.
- aaren 13y agoThe patient identifiable needs explicit permission from the patient in order to obtain - please could you link me to the official document that states this, specifically in the context of care.data?
- Osmium 13y agoDoes anyone know if this is England-only, or if it affects Wales/Scotland/Northern Ireland too? How does the opt out work if you've been in multiple areas/GPs/etc.?
- dawson 13y agoIt's [NHS] England only (currently).
- ghswa 13y agoI live in Bristol. I wonder how quickly I can move to Cardiff?
- pbhjpbhj 13y agoWell in Cardiff you'll be opted in to organ donation automatically of course.
- nyrina 13y agoYou say this is a bad thing?
- chopin 13y agoAt least here in Germany, we had some scandals around organ transplantation. It's big business. And there is a difference between recovery treatment and organ preservation treatment. The emergency team could be under economic pressure when doing a triage.
- pbhjpbhj 13y agoI think government assuming ownership of [parts of] persons is a bad thing, yes. IMO it makes logical sense to either not assume ownership of anything a person had in life, including their body and allow their family/executors to look after the remains of their person , effects and assets [the status quo]. Or you should say that ownership is void on dying and all assets, including one's body should pass to the state. It would make far more difference for the state to assume ownership of the things a person had, houses, bank accounts, than it will make to only assume state ownership of a persons body post mortem. There doesn't appear to be a consistent argument to compel one to take this middle ground.
- pessimizer 13y agoA comment on one of the Guardian articles: J_smudger 24 January 2014 3:00pm I think there is confusion amongst some commenters here. This comes from reading a large amount of literature from the relevant pages on the NHS / Health and Social Care Information Centre (HSCIC). The HSCIC are basically a repository in Leeds, where all this information will be stored. Your GP records are going to the HSCIC as pseudoanonymised information, which as has been said does indeed include your NHS number, date of birth and postcode. The HSCIC will then build up a database of this information. They can indeed pass on certain of this information to certain external interested parties, although when they do this the data becomes truly anonymised as opposed to pseudoanoymised. You can read about this in the NHS published guidelines (although not in the rather patronising leaflet), as well as from the documentation of the HSCIC and the government itself. To quote the HSCIC: we take out details that could identify you before we make any information available At the NHS: there are no personal details such as your date of birth and postcode included... We would never publish this type information because there is a risk that you might be identified. The HSCIC can only release identifiable information when (1) you specifically ask them to, or (2) hypothetically, when there is a national emergency such as a highly virulent pandemic. This would require a legal process. http://www.nhs.uk/NHSEngland/thenhs/records/healthrecords/Pages/care-data.aspx http://www.nhs.uk/NHSEngland/thenhs/records/healthrecords/Pa... http://www.hscic.gov.uk/article/3399/Rules-for-sharing-information http://www.hscic.gov.uk/article/3399/Rules-for-sharing-infor... Or if you have a hour to spend read this: http://www.hscic.gov.uk/media/12931/Privacy-Impact-Assessment/pdf/privacy_impact_assessment_2013.pdf http://www.hscic.gov.uk/media/12931/Privacy-Impact-Assessmen... ... or perhaps just sections 3.3.4. and 3.3.5.
- ghswa 13y agoRegulation 5b allows the Secretary of State for Health to disclose confidential patient information for any medical purpose. No need for a national emergency. http://www.legislation.gov.uk/uksi/2002/1438/regulation/5/made http://www.legislation.gov.uk/uksi/2002/1438/regulation/5/ma... :edit: gohrt pointed out that I'd overlooked the restriction to medical purposes in regulation 5, thanks.
- deleted 13y ago
- vrikis 13y agoSo happy I live in Scotland...
- lostlogin 13y agoOnce you're part of Scandinavia all your problems will be gone. http://m.bbc.co.uk/news/magazine-16050269 http://m.bbc.co.uk/news/magazine-16050269
- tomelders 13y agoI'm not worried, there's absolutely no way anyone could identify you with only your NHS number, your date of birth, your postcode, your gender and ethnicity, your medical diagnoses (including cancer and mental health) and any complications, your referrals to specialists, your prescriptions, your family history, your vaccinations and screening tests, your blood test results, your body mass index (height/weight) and your smoking/alcohol habits.... Oh... wait....
- ajb 13y agoWhat would be interesting would be to write up this 'opt out' procedure, slightly disguised, as part of a research proposal and submit it to the UK ethics committees. I'd be shocked if they don't all reject it. Any UK academics - with enough tenure that it won't bork their career - up for that?
- lrei 13y agoI would just like to point out that even if they "anonymize" the records it's generally not that hard to de-anonymize data. During the Netflix prize, randomly generated IDs were eventually matched to people based simply on movie ratings and matching public information in other public sources: http://www.wired.com/politics/security/commentary/securitymatters/2007/12/securitymatters_1213 http://www.wired.com/politics/security/commentary/securityma... With medical data, it will probably be trivial (maybe easier or more appealing to insurance companies?). We're a lot more unique than we think. Reminds me of this EFF project: https://panopticlick.eff.org/ https://panopticlick.eff.org/ Some companies will probably resell this information to potential employers, banks (there goes your loan), etc. Well, that's going to suck for people in the UK.
- ryguytilidie 13y agoCompanies are TERRIBLE at this. We used a company to do an employee feedback survey. They promised us that the data would be delivered in a 100%, completely anonymized format. We sit down to go over the results and slide number one is "Men were a 100% approval while women were 73%". I'm the only male on my team. How in the world is this anonymous?
- lettergram 13y agoI know in my C.S. courses most of us guys/girls wont put down our gender on surveys so the 4 or 5 females in the room can maintain anonymity.
- DanBC 13y agoNo company is going to resell medical data. We have laws to protect personal information and they are very strict for medical information. http://www.connectingforhealth.nhs.uk/systemsandservices/infogov/codes http://www.connectingforhealth.nhs.uk/systemsandservices/inf... Have a look at some UK medical information and see if you can de-anonymise it. http://www.ons.gov.uk/ons/rel/subnational-health4/suicides-in-the-united-kingdom/2011/index.html http://www.ons.gov.uk/ons/rel/subnational-health4/suicides-i... Here's some data for suicide. There are problems with confidentiality in the NHS - people leave patient records on monitors or send letters to the wrong address. But this kind of project is very different.
- sarreph 13y ago£300 for a DVD copy? ...Huh?
- jon_black 13y agoLet's say I believe that this data truly is anonymised (read: cannot be traced back to an individual in any way). I still have a problem that MY data is being sold by SOMEONE ELSE. The opt-out nature of this process stinks. It feels as though it's someone else's data by default unless I kick up a fuss.
- blueskin_ 13y agohttp://medconfidential.org/how-to-opt-out/ http://medconfidential.org/how-to-opt-out/
- rodh 13y agoHmm. Interesting. I remember when I recently registered with a new doctor, I was asked directly if I wanted to opt out from my medical information collected by my GP being digitally accessible by hospitals, etc. I'll have to admit: I chose not to opt out. Thinking "it's about time they join us in the digital age!" Plus, from the perspective of my health, this seemed like a positive move overall. Of course now that I read a bit more into it, I am less sure. But I do find the above link a little fear-mongery. Incidentally, this document has some interesting insight into the position of the hscic. http://www.hscic.gov.uk/media/12931/Privacy-Impact-Assessment/pdf/privacy_impact_assessment_2013.pdf http://www.hscic.gov.uk/media/12931/Privacy-Impact-Assessmen.... I am a little tickled by this statement about preventing the data falling into the wrong hands: "The Government itself could be considered a pair of 'wrong hands' with questions raised over whether it would have access and therefore would be able to misuse or exploit the data". Not sure how they're mitigating against that risk...
- oskarpearson 13y agoI think the thing that's missing from much of the discussion is that all released information is subject to a very clear contractual agreement and for specific purposes. The agreements limit the ability to link supplied data with anything else. These contracts and use of data are subject to privacy group oversight, managed by the NHS. The intended use is not that insurance companies can link your medical data against you and then charge you more (or any variant on that). Instead, the intended use is that companies with clear information controls can perform useful research more cheaply, and stop guessing at cause and effect. I personally support that intent, and am interested to see what comes out of it. What's to stop the companies just doing whatever seems to get them the most money? In my opinion, it'd be the fact that failing to stick within the agreement would cause existential risk to the company. I think that courts, government, the NHS, and UK society at large would come down VERY heavily on any company contravening their contracts. Companies are going to spend significant effort ensuring their company doesn't disappear overnight in a storm of lawsuits with the directors in jail. Companies wouldn't do this for the same reasons that Seagate doesn't sell the data off RMA'd hard drives on the open market. I trust the relevant public bodies in the UK to protect my interests here. You may not, of course.
- ZenoArrow 13y ago"I think that courts, government, the NHS, and UK society at large would come down VERY heavily on any company contravening their contracts." Supposing a leak happened. What makes you think you'll be able to tie it down to a single company? The data could be leaked anonymously, and the risk of such a leak becomes higher the longer this care.data scheme carries on for.
- cmdkeen 13y agoBecause the same data set isn't being given to loads of different companies, it is a unique process. The whole concept is you apply for specific data for a reason, get vetted and then receive the data. At the scale we are talking about here the differences between both fields and individual records is going to be so great as to identify almost any leak.
- tonylemesmer 13y ago2 words: thumb drive.
- quantumpotato_ 13y agoYou have to email them instead of querying an API?