The Register Home Page

back to article Listen up, England. The Health Secretary is going to be data controller for everyone's Single Patient Record

Health secretary James Murray has said that he will become a data controller of all National Health Service records in England shared through the government’s planned single patient record (SPR). Murray, who is formally the secretary of state for health, told the House of Commons on 1 June that GP surgeries, NHS trusts and other …

  1. Dev_Fit

    One person being everyone's data controller

    Hi James! I think you'll find you'll become a phishing target like never before...

    1. Anonymous Coward
      Anonymous Coward

      Re: One person being everyone's data controller

      One data controller to rule them all... and in the darkness bind them

    2. UCAP Silver badge

      Re: One person being everyone's data controller

      I think what James has forgotten is that, as the designated Data Controller, he will be personally liable for criminal prosecution if anyone's medical records are leaked So speakth the data protection legislation!

      1. Anonymous Coward
        Anonymous Coward

        Re: One person being everyone's data controller

        Can you give any actual examples of individuals being prosecuted except where they personally have been severely negligent and have not followed their organisation's processes, and this has directly led to a data breach?

        I don't think I've ever seen any - where records have leaked due to general corporate crapness the company might get a slap on the wrist, but individuals aren't normally prosecuted.

        The 'data controller' is normally a corporate body, not an individual. In this case, I suspect that the 'Department of Health' would be the data controller.

      2. Anonymous Coward
        Anonymous Coward

        Re: One person being everyone's data controller

        Maybe he skipped his Caldecott Guardian and Oliver McGowan eLfH mando training for Data Protection.

  2. teebie

    Someone short-sighted enough to say "I will be making myself legally responsible for a whole criminal behaviour when carries out by any of my 2-million-ish employees" isn't someone that I want to be making these sorts of decisions.

    1. Anonymous Coward
      Anonymous Coward

      He won't though, will he? It's just the usual politician bullshit - the data controller will be the Department of Health, not the serving Health Secretary personally. Therefore any prosecutions will just mean that one part of the Government uses cash from taxes to pay a fine to another part of the Government.

      1. Anonymous Coward
        Anonymous Coward

        It can be an entity… and I’m sure like other govt … they will pulling ‘Crown Exemption’ as required.

  3. Anonymous Coward
    Anonymous Coward

    NHS App

    I use my phone for making phone calls and whatsapp calls. I don't use it for important things like finance and medical things. So how am I supposed to access my medical data?

    1. Recluse

      Re: NHS App

      As with a lot of modern interactions these days (e.g.parking) without an appropriate phone, email address et al, you will be deemed a non person and ignored.

      Count yourself lucky in so far HMRC have not (yet) demanded that you purchase a computer and pay a monthly subscription to a third party software provider to facilitate your tax returns.

      1. midgepad Bronze badge

        HMRC and Companies House

        Rather have for people letting a flat or owners management companies. Well, a few flats this year, one flat soon.

        And none of the software, which AFAICS sends them one overcomplicated XML document, seems to run on Linux.

        1. Anonymous Coward
          Anonymous Coward

          Re: HMRC and Companies House

          And no doubt all of it could be done using a simple web form?

          But they can't do that, of course. They need to make things unnecessarily difficult by using an 'app' or some badly-designed piece of Windows software.

          1. Anonymous Coward
            Anonymous Coward

            And no doubt all of it could be done using a simple web form?

            FWIW, I can do my self-assessment just fine using HMRC webforms; although my situation is pretty uncomplicated. Although once, some years back now, I /did/ have some more exotic form to add and that did indeed require a commercial service (so naturally I reverted to paper the next year).

            I presumed at the time that - since it was just typing numbers into boxes and the like - that they simply hadn't got around to doing their own. But it wouldn't surprise me at all if that sort of thing still persisted...

          2. J.G.Harston Silver badge

            Re: HMRC and Companies House

            All of it currently CAN be done via simple web forms, I've done my tax returns that way for over 15 years. Takes less time than it takes to make a cup of tea - but that's because I've spent ten minutes each month getting the appropriate data ready in my spreadsheet.

      2. Tron Silver badge

        Re: NHS App

        quote: HMRC have not (yet)...

        I think they have with the MTD thing.

        The two least trusted entities in the UK are the government and VAR, and VAR only operate during the football season, so it had to be the government.

        It does beg the question of who is responsible in between secretary of states for health, when one has stepped down to oust their boss and the next one hasn't been drawn out of the hat.

        Just accept that all the data will eventually be hacked, and move on. To give it a positive spin, transparency is a good thing. And hackers might be able to get you treated faster.

      3. ChoHag Silver badge

        Re: NHS App

        > Count yourself lucky in so far HMRC have not (yet) demanded that you purchase a computer and pay a monthly subscription to a third party software provider to facilitate your tax returns.

        Lucky? I can't wait until they do that and I don't have to pay them any more!

      4. phuzz Silver badge

        Re: NHS App

        pay a monthly subscription to a third party software provider to facilitate your tax returns

        but it works so well in the US!

        /s

    2. Anonymous Coward
      Anonymous Coward

      Re: NHS App

      The NHS App is utterly shite anyway - I didn't have access to most of my records on it (something the GP hadn't done, possibly?), and the main purpose of the app seemed to be for the GP practice to send messages about their bank holiday opening times and warning people not to miss appointments.

      I removed the app and deleted the associated online account (I was surprised that this was even possible, but it is). If they need to communicate with me they can use the phone or send a letter!

      1. Anonymous Coward
        Anonymous Coward

        Re: NHS App

        With irony not used in Scotland and neither are NHS Numbers….you get a Community Health Index (CHI) number instead. Though both health services kinda use each others when you need care in different countries NHS’s.

        Not having this national is dumb.

        1. Anonymous Coward
          Anonymous Coward

          Re: NHS App

          NHS Healthcare provision ‘across the Scottish/English border’ is quite messy because of this. Esp. As people living 100m apart can enable or block your access to free prescriptions for example.

          A hard soft border.

          1. Anonymous Coward
            Anonymous Coward

            Re: NHS App

            It's not just between countries! Healthcare provision across NHS ICB (Integrated Commissioning Board) boundaries is messy too, and if you happen to live near a boundary it can be awkward. The boundaries don't necessarily correspond to county boundaries either so unless you are clued up on the NHS structure you may not even be aware of them.

        2. CrazyOldCatMan Silver badge

          Re: NHS App

          when you need care in different countries NHS’s.

          Not having this national is dumb.

          To quote a senior person I used to know at the DHSC: "Remember, the NHS is neither national nor a health system"..

          (The point she was making was that every organisation did things Their Way (and damn all the others) and that, for most organisations, the most important thing is their budget, not the patients.)

      2. Maurice Mynah

        Re: Phone or letter

        Yeah, good luck with that. I've had them change an appointment and the letter arrived a week after the amended date. Fortunately they were also sending texts, which meant I actually turned up. The "you cost the NHS £XXX billion when you don't turn up" messages get a bit galling when they change the arrangements more often than you do. (You don't need an app for texts, my phone doesn't do "apps"...)

        1. andy the pessimist Bronze badge

          Re: Phone or letter

          How do i know i have an appointment? I get two emails through mychart, two text messages. Occasionaly i get a letter and another mychart email.

          Are they in the spamming business?

  4. Ste Van De Mull

    So nothing to go wrong here

    Incoming BAFU.

    How do I opt out?

    1. Anonymous Coward
      Anonymous Coward

      Re: So nothing to go wrong here

      What's a BAFU?

      "BAFU most commonly refers to the Federal Office for the Environment (BAFU), which is Switzerland's central environmental agency responsible for environmental protection, natural hazard prevention, and the management of natural resources."

    2. Anonymous Coward
      Anonymous Coward

      Re: So nothing to go wrong here

      British A.... Fuck Up. What does the A stand for?

      1. nobody who matters Silver badge

        Re: So nothing to go wrong here

        Actual?

        Behaving in much the same way as the word 'actual' behaves in the exclamation WTAF.

      2. lvd
        Mushroom

        Re: So nothing to go wrong here

        "British A.... Fuck Up. What does the A stand for?"

        It's Big Almighty Fuck Up.

        Haven't heard that expression for years!

  5. midgepad Bronze badge

    decades ago I wrote a rule for this

    That each access to a patient's record must produce an entry in an account which is eventually conveyed to them.

    Giving who accessed it, why they say they did, why they claim they are entitled to, what they looked at.

    It seems rather a good idea.

    1. Aaiieeee
      Unhappy

      Re: decades ago I wrote a rule for this

      Yes, but also no. The access log will be worthless because you will just see the hourly 'palantir_svc' account poll with the reason as 'data integrity check'. Nobody will be accessing these records personally; it will all be done through supplier data browsers and sufficiently generalised as to be meaningless.

  6. nobody who matters Silver badge

    "....the health secretary said that the SPR “will be governed by the highest levels of security” including an audit trail of access and “the strongest available” cyber-security....."

    I am very pleased to hear that.

    However, that is tempered rather by the distinct feeling that I have that he doesn't actually know precisely what he means by it, and in all probability, neither do most of the other people who will be involved in the decision making during the procurement and award of the final contract.

    1. Like a badger Silver badge

      Murray is another Oxford PPE w*nker, and I surmise he knows nothing about IT, nothing about data security, and nothing about healthcare. Which is par for the course amongst our wretchedly talentless political classes.

      1. Anonymous Coward
        Anonymous Coward

        All part of the outcome of 'politics' being a career which people go into from university.

        In a sensible world, politicians would be required to have actually done a real job first, and Secretaries of State would need to have relevant experience - e.g. a doctor or nurse as Health Secretary, a Forces veteran as Defence Secretary, etc. And there would be an expectation that they stay in the role for a decent length of time, rather than having a tantrum and resigning, or getting 'promoted' to a more juicy role which they also know nothing about.

        Not going to happen, of course.

        1. David 132 Silver badge

          Well, yes. That used to be the case. And then the usual suspects (media, self-interested lobby groups, etc) screamed "conflict of interest!" because Jim Bugglesworth the businessman would obviously, once installed as Minister for Business, give juicy favouritism treatment to all his industry mates.

          And so now we have bland identikit drones who've ridden the conveyor belt from student union protest-organiser, to PPE graduate, to local government, to quango membership, to union convenor, to SpAd, to MP, to Minister, all achieved by mouthing the currently fashionable platitudes and nostrums and never daring to show an iota of independent thought. And we're supposed to believe that they will be completely free of the taint of corruption or incompetence.

          Which is equally obviously A Good Thing and a vast improvement, no?

          Be careful what you wish for.

          1. CrazyOldCatMan Silver badge

            And we're supposed to believe that they will be completely free of the taint of corruption or incompetence

            It probably helps that none of them have actually ever done anything of consequence..

            (except Reform types of course that have had to purge their financial history and social media of embarrassing events..)

          2. Daniel Pfeffer

            Nothing is new under the sun

            https://genius.com/Gilbert-and-sullivan-when-i-was-a-lad-annotated

      2. Anonymous Coward
        Anonymous Coward

        Murray is another Oxford PPE w*nker

        That's why I laughed when I heard the latest missive from a Mr T Blair: AI is the future (along with fossil fuels).

        This from the man that never had a computer on his desk (and no smartphone in his pocket coz there were none then), and who is well paid for lobbying for the fossil fuel industry.

        Is that also true for a Mr Rage, sorry, Farage?

        1. Like a badger Silver badge

          Re: Murray is another Oxford PPE w*nker

          Is that also true for a Mr Rage, sorry, Farage?

          I'm sure he's an equal opportunities grifter, and will support any belief or company so long as it comes bearing multi-million pound gifts. I daresay he's no different to most parliamentarians in that respect.

          Greenpeace UK spend about £37m a year, maybe they could sack a few of their invariably American, Canadian, Australian spokespeople, and find a £5-10m "services payment" to Farage?

    2. Doctor Syntax Silver badge

      It's just standard UK govt. hubris. It's what they do best so whichever party is in power that's what you get.

      1. David 132 Silver badge

        ITYM "civil service hubris". Notice how every government, of whatever colour, suddenly starts prattling on about causes dear to the hearts of the civil service - ID cards, PFI, etc - using whatever justification will appeal to the Daily Mail readers that week. "It's FOR THE CHILDREN", "it's TO STOP TERRORISTS", "it's TO REDUCE CARBON EMISSIONS", etc etc.

  7. Ken Hagan Gold badge
    Facepalm

    why only one?

    Why can individual GPs not remain the data controller for their patients?

    Government could provide the mechanism (ie, buy the software) without being the ones that use it. As long as an agreed set of protocols are used, you could even have several providers. (Ho ho!) But no. Apparently we need a big fucking database, managed by a foreign company, with clueless Arts graduates providing the only legal assurance that it is secure.

    Edit: I say "ho ho", but specifying interfaces and having multiple interoperable implementations is how you create quality software. Sadly, the current generation of vibe coders don't even understand how wrong they are on this point.

    1. MonkeyJuice Silver badge

      Re: why only one?

      Why can individual GPs not remain the data controller for their patients?

      Because it's not really the GP's fault if their network gets pwnt because someone in management clicked on a dodgy link. Plus if a practice did have a data breach, all GP staff in the building would immediately become liable. Suddenly, nobody wants to be a GP anymore. Everyone dies of measles. The end.

    2. J.G.Harston Silver badge

      Re: why only one?

      GPs are already data controllers for their patients' data through their clinical systems SystemOne, EMIS, MedicTech, thingy wotsit. This is a solved problem. The government is just stomping over with their big boots and creating a problem out of their own incompetance.

  8. Anonymous Coward
    Anonymous Coward

    "Why can individual GPs not remain the data controller for their patients?"

    because the data controller has to have the final say as to what is done with the data, and there's no way the government would allow individual GP practices to stop it from whatever slurping and analysis it decided it wants to do!

    1. Doctor Syntax Silver badge

      That is why the GPs should remain the data controllers.

  9. OhForF'

    >he government is likely to lessen risks by offering a series of contracts for the SPR, rather than award a single deal<

    How does involving more external companies lessen risks? Why is it a good idea to split implementation but necessary to have a single data controller?

    Is any logic or intelligence involved when politicians produce a statement?

    1. CrazyOldCatMan Silver badge

      How does involving more external companies lessen risks?

      It doesn't (if anything it increases it). But, importantly for the political types, it transfers the risk *elsewhere*.

      So, when it all goes belly-up and 30m peoples medical records get sold on the Dark Web, they can point to Capita/Palantir/Cap Gemini/etc etc (whichever of the usual suspects has floated to the top of the Government bidding cesspool) and say "it was them."

      We used to call it "pre-emptive CYA".

  10. TheMaskedMan Silver badge

    So the Department of Health is sitting on our health data. Hmm. I vaguely recall reading that government data was more or less freely exchanged between departments. Now that would have been a long time ago, and I may be remembering wrongly, but I'd be intrigued - and likely alarmed - to know who else gets access to this data with substantially less effort than they do now. Officially, that is - we all know what government employees are like for leaving documents on a train etc.

    1. Anonymous Coward
      Anonymous Coward

      "I vaguely recall reading that government data was more or less freely exchanged between departments."

      As a civil servant I'm forever surprised at the amount of hoops one department has to jump through to get access to data another department is sitting on, even when it's not PII.

      These days its nigh on impossible to find out even the most basic stuff like another department's organisation structure and the name and contact details of relevant officials; this has created a small but significant cadre of people in each department (and even each group or directorate) whose sole job is to try and build and keep relationships between different departments.

  11. Anonymous Coward
    Anonymous Coward

    Leak it all now

    Avoid the rush!

  12. drankinatty Silver badge

    It's not a matter of "If", only "When"

    ".. said that the government was promising safeguards ... It added that the Department of Health already makes it difficult for people to opt out ..."

    Medical records, protected health information, whatever you want to call it is probably the most personal of personal information. If society has learned nothing from all the supposed "safeguards" on electronic data, it's that it takes a special type of arrogance for someone to say, "don't worry, we will keep your personal information safe." How many have eaten their words in an articles here, alone. 23andMe, Baymark, Kettering anyone?

    Whether and how your medical information is captured and stored needs to be a patient choice made after informed consent, just like any medical treatment that carries risk. Unfortunately, the very last people competent to safeguard information are medical folks (sorry Docs, the truth hurts, most of you don't even know where the data goes... "it's like magic...") Government held data is no more secure than privately held data and vice versa.

    The problem is most people don't give it a second thought until they receive a breach disclosure letter in the mail, and reality sets in. It's up to those who know enough to know, to make sure these concerns are elevated and reflected in legislative discussions and that "opt-out" isn't something made difficult for people to do. This is far more an acute problem in private payer countries where any breach and leak of data can be used to deny future coverage and care, but a leak anywhere of this type of data usually contains all the personal identifiers needed to do serious financial harm -- even by a blind identity-thief.

    I don't have the answers, but I can sure identify the problem. Ensuring people have a choice about whether and what of their medical information is digitally captured seems like it should be of primary concern, not an afterthought, and not a choice made intentionally difficult for people to exercise.

  13. You aint sin me, roit Silver badge
    Facepalm

    Will he be getting advice from Dido?

    After a couple of "minor" breaches at TalkTalk she must be the parliamentary expert...

  14. J.G.Harston Silver badge

    As others have said: NOOOOOOOoooooo.......!!!!! Single point of failure.

    Plus, we already have distributed remotely accessible electronic patient records, privately supplied to GP practices by such as EMIS, SystmOne, Focus, MediTech, others I can't remember. The only failure point is the NHS - ie, hospitals - haven't had to boot put in hard enough to force them to sign up to something. Remember, GPs are *NOT* part of the NHS, they are *FUNDED* by the NHS, and so for decades they have been on the ball with this stuff through individual decision making, instead of The Government imposing some One Record System To Bind Them All. EMIS is Egton Medical Information System written by a couple of doctors at Egton GP Practice, originally on BBC Computers. In the 40+ years since the NHS has failed to do anything even as basic.

  15. Anonymous Coward
    Anonymous Coward

    See Bruce Schneier..............

    .....on the subject of "security theatre"...............

    ......oh!.....and then there's Palantir and "digital sovereignty"..............

    Sigh!

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon