One person being everyone's data controller
Hi James! I think you'll find you'll become a phishing target like never before...
Health secretary James Murray has said that he will become a data controller of all National Health Service records in England shared through the government’s planned single patient record (SPR). Murray, who is formally the secretary of state for health, told the House of Commons on 1 June that GP surgeries, NHS trusts and other …
Can you give any actual examples of individuals being prosecuted except where they personally have been severely negligent and have not followed their organisation's processes, and this has directly led to a data breach?
I don't think I've ever seen any - where records have leaked due to general corporate crapness the company might get a slap on the wrist, but individuals aren't normally prosecuted.
The 'data controller' is normally a corporate body, not an individual. In this case, I suspect that the 'Department of Health' would be the data controller.
He won't though, will he? It's just the usual politician bullshit - the data controller will be the Department of Health, not the serving Health Secretary personally. Therefore any prosecutions will just mean that one part of the Government uses cash from taxes to pay a fine to another part of the Government.
As with a lot of modern interactions these days (e.g.parking) without an appropriate phone, email address et al, you will be deemed a non person and ignored.
Count yourself lucky in so far HMRC have not (yet) demanded that you purchase a computer and pay a monthly subscription to a third party software provider to facilitate your tax returns.
FWIW, I can do my self-assessment just fine using HMRC webforms; although my situation is pretty uncomplicated. Although once, some years back now, I /did/ have some more exotic form to add and that did indeed require a commercial service (so naturally I reverted to paper the next year).
I presumed at the time that - since it was just typing numbers into boxes and the like - that they simply hadn't got around to doing their own. But it wouldn't surprise me at all if that sort of thing still persisted...
All of it currently CAN be done via simple web forms, I've done my tax returns that way for over 15 years. Takes less time than it takes to make a cup of tea - but that's because I've spent ten minutes each month getting the appropriate data ready in my spreadsheet.
quote: HMRC have not (yet)...
I think they have with the MTD thing.
The two least trusted entities in the UK are the government and VAR, and VAR only operate during the football season, so it had to be the government.
It does beg the question of who is responsible in between secretary of states for health, when one has stepped down to oust their boss and the next one hasn't been drawn out of the hat.
Just accept that all the data will eventually be hacked, and move on. To give it a positive spin, transparency is a good thing. And hackers might be able to get you treated faster.
The NHS App is utterly shite anyway - I didn't have access to most of my records on it (something the GP hadn't done, possibly?), and the main purpose of the app seemed to be for the GP practice to send messages about their bank holiday opening times and warning people not to miss appointments.
I removed the app and deleted the associated online account (I was surprised that this was even possible, but it is). If they need to communicate with me they can use the phone or send a letter!
It's not just between countries! Healthcare provision across NHS ICB (Integrated Commissioning Board) boundaries is messy too, and if you happen to live near a boundary it can be awkward. The boundaries don't necessarily correspond to county boundaries either so unless you are clued up on the NHS structure you may not even be aware of them.
when you need care in different countries NHS’s.
Not having this national is dumb.
To quote a senior person I used to know at the DHSC: "Remember, the NHS is neither national nor a health system"..
(The point she was making was that every organisation did things Their Way (and damn all the others) and that, for most organisations, the most important thing is their budget, not the patients.)
Yeah, good luck with that. I've had them change an appointment and the letter arrived a week after the amended date. Fortunately they were also sending texts, which meant I actually turned up. The "you cost the NHS £XXX billion when you don't turn up" messages get a bit galling when they change the arrangements more often than you do. (You don't need an app for texts, my phone doesn't do "apps"...)
Yes, but also no. The access log will be worthless because you will just see the hourly 'palantir_svc' account poll with the reason as 'data integrity check'. Nobody will be accessing these records personally; it will all be done through supplier data browsers and sufficiently generalised as to be meaningless.
"....the health secretary said that the SPR “will be governed by the highest levels of security” including an audit trail of access and “the strongest available” cyber-security....."
I am very pleased to hear that.
However, that is tempered rather by the distinct feeling that I have that he doesn't actually know precisely what he means by it, and in all probability, neither do most of the other people who will be involved in the decision making during the procurement and award of the final contract.
All part of the outcome of 'politics' being a career which people go into from university.
In a sensible world, politicians would be required to have actually done a real job first, and Secretaries of State would need to have relevant experience - e.g. a doctor or nurse as Health Secretary, a Forces veteran as Defence Secretary, etc. And there would be an expectation that they stay in the role for a decent length of time, rather than having a tantrum and resigning, or getting 'promoted' to a more juicy role which they also know nothing about.
Not going to happen, of course.
Well, yes. That used to be the case. And then the usual suspects (media, self-interested lobby groups, etc) screamed "conflict of interest!" because Jim Bugglesworth the businessman would obviously, once installed as Minister for Business, give juicy favouritism treatment to all his industry mates.
And so now we have bland identikit drones who've ridden the conveyor belt from student union protest-organiser, to PPE graduate, to local government, to quango membership, to union convenor, to SpAd, to MP, to Minister, all achieved by mouthing the currently fashionable platitudes and nostrums and never daring to show an iota of independent thought. And we're supposed to believe that they will be completely free of the taint of corruption or incompetence.
Which is equally obviously A Good Thing and a vast improvement, no?
Be careful what you wish for.
And we're supposed to believe that they will be completely free of the taint of corruption or incompetence
It probably helps that none of them have actually ever done anything of consequence..
(except Reform types of course that have had to purge their financial history and social media of embarrassing events..)
That's why I laughed when I heard the latest missive from a Mr T Blair: AI is the future (along with fossil fuels).
This from the man that never had a computer on his desk (and no smartphone in his pocket coz there were none then), and who is well paid for lobbying for the fossil fuel industry.
Is that also true for a Mr Rage, sorry, Farage?
Is that also true for a Mr Rage, sorry, Farage?
I'm sure he's an equal opportunities grifter, and will support any belief or company so long as it comes bearing multi-million pound gifts. I daresay he's no different to most parliamentarians in that respect.
Greenpeace UK spend about £37m a year, maybe they could sack a few of their invariably American, Canadian, Australian spokespeople, and find a £5-10m "services payment" to Farage?
ITYM "civil service hubris". Notice how every government, of whatever colour, suddenly starts prattling on about causes dear to the hearts of the civil service - ID cards, PFI, etc - using whatever justification will appeal to the Daily Mail readers that week. "It's FOR THE CHILDREN", "it's TO STOP TERRORISTS", "it's TO REDUCE CARBON EMISSIONS", etc etc.
Why can individual GPs not remain the data controller for their patients?
Government could provide the mechanism (ie, buy the software) without being the ones that use it. As long as an agreed set of protocols are used, you could even have several providers. (Ho ho!) But no. Apparently we need a big fucking database, managed by a foreign company, with clueless Arts graduates providing the only legal assurance that it is secure.
Edit: I say "ho ho", but specifying interfaces and having multiple interoperable implementations is how you create quality software. Sadly, the current generation of vibe coders don't even understand how wrong they are on this point.
Why can individual GPs not remain the data controller for their patients?
Because it's not really the GP's fault if their network gets pwnt because someone in management clicked on a dodgy link. Plus if a practice did have a data breach, all GP staff in the building would immediately become liable. Suddenly, nobody wants to be a GP anymore. Everyone dies of measles. The end.
"Why can individual GPs not remain the data controller for their patients?"
because the data controller has to have the final say as to what is done with the data, and there's no way the government would allow individual GP practices to stop it from whatever slurping and analysis it decided it wants to do!
>he government is likely to lessen risks by offering a series of contracts for the SPR, rather than award a single deal<
How does involving more external companies lessen risks? Why is it a good idea to split implementation but necessary to have a single data controller?
Is any logic or intelligence involved when politicians produce a statement?
How does involving more external companies lessen risks?
It doesn't (if anything it increases it). But, importantly for the political types, it transfers the risk *elsewhere*.
So, when it all goes belly-up and 30m peoples medical records get sold on the Dark Web, they can point to Capita/Palantir/Cap Gemini/etc etc (whichever of the usual suspects has floated to the top of the Government bidding cesspool) and say "it was them."
We used to call it "pre-emptive CYA".
So the Department of Health is sitting on our health data. Hmm. I vaguely recall reading that government data was more or less freely exchanged between departments. Now that would have been a long time ago, and I may be remembering wrongly, but I'd be intrigued - and likely alarmed - to know who else gets access to this data with substantially less effort than they do now. Officially, that is - we all know what government employees are like for leaving documents on a train etc.
"I vaguely recall reading that government data was more or less freely exchanged between departments."
As a civil servant I'm forever surprised at the amount of hoops one department has to jump through to get access to data another department is sitting on, even when it's not PII.
These days its nigh on impossible to find out even the most basic stuff like another department's organisation structure and the name and contact details of relevant officials; this has created a small but significant cadre of people in each department (and even each group or directorate) whose sole job is to try and build and keep relationships between different departments.
".. said that the government was promising safeguards ... It added that the Department of Health already makes it difficult for people to opt out ..."
Medical records, protected health information, whatever you want to call it is probably the most personal of personal information. If society has learned nothing from all the supposed "safeguards" on electronic data, it's that it takes a special type of arrogance for someone to say, "don't worry, we will keep your personal information safe." How many have eaten their words in an articles here, alone. 23andMe, Baymark, Kettering anyone?
Whether and how your medical information is captured and stored needs to be a patient choice made after informed consent, just like any medical treatment that carries risk. Unfortunately, the very last people competent to safeguard information are medical folks (sorry Docs, the truth hurts, most of you don't even know where the data goes... "it's like magic...") Government held data is no more secure than privately held data and vice versa.
The problem is most people don't give it a second thought until they receive a breach disclosure letter in the mail, and reality sets in. It's up to those who know enough to know, to make sure these concerns are elevated and reflected in legislative discussions and that "opt-out" isn't something made difficult for people to do. This is far more an acute problem in private payer countries where any breach and leak of data can be used to deny future coverage and care, but a leak anywhere of this type of data usually contains all the personal identifiers needed to do serious financial harm -- even by a blind identity-thief.
I don't have the answers, but I can sure identify the problem. Ensuring people have a choice about whether and what of their medical information is digitally captured seems like it should be of primary concern, not an afterthought, and not a choice made intentionally difficult for people to exercise.
As others have said: NOOOOOOOoooooo.......!!!!! Single point of failure.
Plus, we already have distributed remotely accessible electronic patient records, privately supplied to GP practices by such as EMIS, SystmOne, Focus, MediTech, others I can't remember. The only failure point is the NHS - ie, hospitals - haven't had to boot put in hard enough to force them to sign up to something. Remember, GPs are *NOT* part of the NHS, they are *FUNDED* by the NHS, and so for decades they have been on the ball with this stuff through individual decision making, instead of The Government imposing some One Record System To Bind Them All. EMIS is Egton Medical Information System written by a couple of doctors at Egton GP Practice, originally on BBC Computers. In the 40+ years since the NHS has failed to do anything even as basic.