ODI Lunchtime Lecture, “Why selling people’s medical/tax/school records isn’t open data” – Friday 6/6/14,13:00-13:50

Open Data Institute Friday lunchtime lecture:

Why selling people’s medical/tax/school records isn’t open data

Friday 6 June 2014, 1:00pm – 1:50pm

Venue: Open Data Institute, 65 Clifton Street, London EC2A 4JE [map]

The care.data programme in the NHS came off the rails, despite – or possibly because – officials tried presenting it as an ‘open data’ initiative. It isn’t. But this conflation of ‘data sharing’ with open data is far from unique; from the National Pupil Database to your tax records and Cabinet Office’s resurrection of plans for mass sharing of citizen data that last surfaced in an obscure clause in the 2009 Coroners and Justice Bill, the government has designs on your data.

More information and to book your place

Public meeting in St Albans, “care.data – transfer of GP medical records” – Wednesday 28/5/14 from 19:00

Public Meeting:

‘care.data – Transfer of GP Medical Records
Understand the Benefits – and the Risks’

Organised by St Albans & Harpenden Patient Group (SAPG)

Wednesday, 28 May 2014

The public meeting will be held at 19:00 at the
Council Chamber, St Albans District Council
Civic Close, St. Peter’s Street, St. Albans AL1 3JE [map]

Speakers:

Dr Ros Taylor MBE speaking in favour
Phil Booth speaking against 

“Can we know who all the end users of our data are?”

A commentable YouTube version of the Health Select Committee’s evidence session on the ‘Handling of NHS patient data‘ from Tuesday 8th April is now available online.

In the official transcript of the session, a quite extraordinary exchange occurred at Question 272:

Q272 Barbara Keeley: So have you got the information because I have asked for it twice, but not been given it? For all those 249 organisations with a commercial reuse licence, can we know who all the end users of our data are?

Kingsley Manning: No, because they are using it and putting it into additional services. So, for example, a company such as McKinsey or KPMG would have used it to support Monitor or the NHS TDA in advising on the transformation of health care services.

And there you have it.

The Chair of the Heath and Social Care Information Centre openly admits it doesn’t know who has your medical data or what they are doing with it. The examples given are clearly a distraction, as they name some (less controversial) end users. What about the ones that HSCIC not only won’t, but can’t name?

Don’t forget, this is the body that we are supposed to trust to look after our medical information; the body which in fact intends to suck up even more – much, much more – from the GP records of every man, woman and child in England.

Now its Chair baldly admits they don’t know who got hold of the data HSCIC has already sold and passed on. And he doesn’t even seem to care!

You can read the written transcript of the entire evidence session from Tuesday, and a copy of the letter HSCIC sent to the Select Committee, following the car crash evidence session by officials and the Minister on care.data on 25th February.

If you missed it, you can still view a YouTube video of that first session, featuring HSCIC’s Max Jones, NHS England’s Tim Kelsey and Under-Secretary of State for Health, Dr Dan Poulter in the second half. Or read the official transcript.

HSCIC opt-out form ‘phrased like a threat’

There were some extraordinary revelations at the Health Select Committee’s second evidence session of its (expanded) inquiry into the handling of NHS patient data on Tuesday 8th April.

This post is to draw attention to just one of them: a third opt-out form that the Health and Social Care Information Centre (HSCIC) has produced, on top of the two care.data opt-out codes you need to instruct your GP to add to your record.

The form that HSCIC has produced is dangerous. We don’t propose to link to it in case people download it, fill it in and accidentally de-register themselves from their GP!

In essence, HSCIC completely unnecessarily added a section to its form relating to a system called NHAIS (National Health Applications and Infrastructure Services) which if someone had completed – as many do when filling in complex forms, by signing wherever the form asks for a signature – would have meant they’d be de-registered by their GP and not be called for essential screening.

This exchange between Select Committee member Barbara Keeley MP and HSCIC Chair, Kingsley Manning gives you a sense of how this was viewed by the Committee:

Barbara Keeley MP: But it’s the way its phrased, it just looks like a threat. If you opt out…
Kingsley Manning: No, I agree, I agree…
Barbara Keeley MP: …your GP will drop you, and you’ll never have any screening.
Kingsley Manning: …I entirely agree.

You can download a safe version of the form, from which we have removed the offending section, via either of these links:

Withdrawal of Consent form (Microsoft Word format)

Withdrawal of Consent form (PDF format)

The Withdrawal of Consent form we provide should enable you to opt-out* of any one or more of the following ‘secondary use’ data sets, i.e. data sets that are not used for your direct medical care:

Hospital Episode Statistics (HES) – holds records on hospital episodes of care including inpatient, outpatient and A&E.

Secondary Uses Service (SUS) – the single source of comprehensive data for a range of reporting and analysis.  NHS hospital trusts submit patient activity to SUS for performance monitoring, reconciliation and payments purposes.

Mental Health Minimum Data Set (MHMDS) – contains patient-level data about NHS services delivered to people with severe and enduring mental health problems.

Diagnostic Imaging Dataset (DIDS) – a central collection of detailed information about diagnostic imaging tests carried out on NHS patients, extracted from local radiology information systems.

*In this instance, ‘opt-out’ does not mean that your data will be deleted. Data held about you will instead be ‘anonymised’, i.e. items or links to anything that identifies you will be removed. For statistical audit purposes, NHS systems still require a de-identified record to exist.

Public meeting in Lancaster, Monday 28/4/14, 18:15 – 20:45

*UPDATE* Read a write-up of the meeting on the Living Data Research Group website.

Many thanks to Richard Tutton, Mairi Levitt and Garrath Williams at the Department of Sociology and Centre for Science Studies for organising the event, and to Maggie Mort for chairing such a lively public discussion.

Care about care.data?

Lancaster_poster

VENUE: Banquesting Room, Lancaster Town Hall, Lancaster, Lancashire LA1 1PJ [Map]

DATE & TIME: Monday, April 28, 2014 from 6:15 PM to 8:45 PM

SPEAKERS: Dr David Wrigley, GP based in Carnforth; Phil Booth, medConfidential, Dr Garrath Williams, Senior Lecturer, Lancaster University, others tbc.

The event is free to attend but the organisers ask you to please register at:

https://www.eventbrite.com/e/care-about-sharing-your-medical-records-tickets-11073722803 (tickets closed)

Addendum to Press Release: HSCIC register “inadequate and patronising”

For context, see our press release, HSCIC’s lack of transparency is not so “innocent” after all, and HSCIC’s follow-up ‘clarification’, Publication of HSCIC register of approved data releases: clarification on points of public interest.

Despite both the Under-Secretary of State for Health, Dr Daniel Poulter, telling Parliament that “a report detailing all data released by the HSCIC from April 2013” would be published and the Chair of HSCIC, Kingsley Manning, saying at the HC2014 conference on 20th March that “we will be publishing the details of all the data releases we have made since we were formed“, HSCIC is trying to limit the scope of its register to just those releases “under agreement” initiated or renewed during the last year.

This is patently ridiculous, as there are organisations and companies to which data has been released during the past year that (a) were not and never will be “under agreement”, e.g. the police, (b) had received data and are still able to use it under an active licence during the past year, e.g. PA Consulting, and (c) continue to receive monthly updates, e.g. of HES data, under licences that may not have been issued or renewed since April 2013 but that are still active.

Without the publication of all active licences and agreements  – which should include any ‘Memoranda of Understanding’ – the public simply won’t know who is receiving their information under circumstances (b) or (c). And any reasonable human being would consider (a) to be a release of data, whether it is “under agreement” or not.

Further analysis of the register suggests a number of ‘approved’ releases recorded in other registers seem to be missing as well.

With reference to HSCIC’s ‘clarification’:

Does HSCIC deny that PA Consulting has an active contract for the use of HES until 2015?

No – in fact it confirms it. Again. We accept that the use of data already released under continuing licence may not be ‘a new release’, but for a register that is supposed to be the model for a new era of transparency it is a pretty poor showing to exclude any organisation or company that HSCIC well knows is holding and can process patient data under an active contract.

We understand that Sir Nick Partridge’s report is to be a retrospective audit. The HSCIC register doesn’t show active contracts / agreements or any start or end dates, so how is the public supposed to know who has their information at any point in time?

Does HSCIC deny that it has provided data to the police in the last year?

No – it confirms that it has done so. That it has previously admitted this “in a Freedom of Information request and in statements to the media” makes it no less a release of data than any other during this period. Will HSCIC exclude other releases of data from the register if someone has asked about them in a Freedom of Information request? We sincerely hope not.

That HSCIC seems to be trying to wriggle out of publishing releases made under other laws, such as the Data Protection Act, or indeed any release not made “under agreement” is extremely worrying indeed. And the vagueness of the legal basis given – often nothing more than “Health and Social Care Act 2012”, with no section or clause – suggests an attitude that really hasn’t shifted all that much from the ‘bad old days’… before April 1st 2013.

If they really want to earn the trust of patients, professionals and the public at large, we suggest that HSCIC officials stop making up lame excuses that only add to the suspicion they have something to hide, and publish every release of data – with full details – so that people can know exactly who has their medical data at any point, why and what for.

And rather than quarterly, the register should be updated monthly – as any number of other government bodies who do a far better job of being transparent seem to manage.

If this register represents HSCIC’s answer to revelations of its past misbehaviour, then it is inadequate and dangerously patronising – especially given the trust that it and NHS England are haemorrhaging right now over the care.data scheme.

[PRESS RELEASE] HSCIC’s lack of transparency is not so “innocent” after all

For immediate release – Wednesday 3 April 2014

The Health and Social Care Information Centre’s register of data releases, published at noon today, is incomplete and fails to reveal some of the most potentially embarrassing and damaging releases of patient data.

The register does list dozens of commercial companies that have received patient information in various forms over the past year, but fails to list companies known to be holding significant amounts of patient data under ongoing commercial licences.

For example, PA Consulting was awarded a licence for HES data in 2011 which was extended in 2012 to last until November 2015 [1]. The Information Commissioner’s Office is currently investigating a complaint by medConfidential, the Foundation for Information Policy Research (FIPR) and Big Brother Watch on PA Consulting’s uploading of this data to Google’s BigQuery cloud servers [2] so it is inconceivable that HSCIC is not aware the licence remains active.

Another significant omission is the lack of any Police Forces in the register. A Freedom of Information request revealed that Police Forces routinely request data about patients from HSCIC, and that data has been released in dozens of instances within the last year [3].

Phil Booth, coordinator of medConfidential, [4] said:

“Despite saying it has turned a new leaf, HSCIC is deliberately concealing releases of data that might cause itself, or ministers or other officials, embarrassment or political damage. The Information Centre’s lack of transparency is clearly not as “innocent” as its Chair has claimed. [5]

“HSCIC continues in its ridiculous assertion that pseudonymised data is not sensitive or identifiable when tools its customers have built show you can track individuals visit by visit through hospital – and with information published in press reports, social media posts or the date your child was born make it possible to pick out a named individual and read off their entire record. [6]

“Billions of patient records continue to be sold for commercial use without patients’ knowledge or consent, using as justification the very law that minsters have said provides additional safeguards. How long does HSCIC think it can get away with ignoring Jeremy Hunt’s promise to stamp out the commercial exploitation of NHS patients’ information?”

Notes for editors

1) See http://www.hscic.gov.uk/article/3948/Statement-Use-of-data-by-PA-consulting

2) See http://medconfidential.org/wp-content/uploads/2014/03/2014-03-13-ICO-PA-FIPR- complaint.pdf for medConfidential, FIPR and Big Brother Watch’s complaint to the ICO and http://www.theregister.co.uk/2014/03/04/tripleheaded_nhs_privacy_scare_after_hospital_data_rea ch_marketers_google/ for a description of what happened.

3) The FOI response states: “The Health & Social Care Information Centre (HSCIC) was formed on the 1 April 2013. Since the HSCIC was formed there have been 472 requests received from British Police Forces for information.” A spreadsheet detailing just 180 of these requests shows that 51 releases were made during the period covered by today’s register, all but 3 of which were made under Section 29(3) of the Data Protection Act – not under warrant or Court Order.

4) medConfidential campaigns for confidentiality and consent in health and social care, seeking to ensure that every flow of data into, across and out of the NHS and care system is consensual, safe and transparent. Founded in January 2013, medConfidential is an independent, non-partisan organisation working with patients and medics, service users and care professionals.

care.data opt out forms and letters available here: www.medconfidential.org/how-to-opt-out/

5) “Quite rightly however, the public are suspicious that these arrangements are in some way unfairly tipped in favour of the profit makers. This suspicion has been fuelled by our innocent lack of transparency.” Full text of Kingsley Manning’s speech at HC2014 conferencefile was (re)moved by HSCIC following this press release. This link is to a copy downloaded by medConfidential on 24/3/14.

6) See http://medconfidential.org/2014/commercial-re-use-licences-for-hes-disappearing-webpages/ for a screen grab and explanation of a tool developed by OmegaSolver – one of the companies listed in the register of releases – for use by pharmaceutical marketers.
For further information or for immediate or future interview, please contact Phil Booth, coordinator of medConfidential, on 07974 230 839 or phil@medconfidential.org

– ends –

 

care.data conference at QMUL, Saturday 5th April 2014

*UPDATE* Read the Conference statement, published 8th April 2014

Many thanks to Richard Horton and Allyson Pollock for organising the conference, and to everyone who made such useful contributions on the day.

Conference co-organised by Richard Horton, Editor of The Lancet and Prof Allyson Pollock, QMUL

Date: Saturday 5th April 2014, 09:30 – 12:45

Venue: Clark-Kennedy Lecture Theater, QMUL Whitechapel Campus, London E1 2AD (Map)

PROGRAMME:

Programme for care.data meeting – Saturday 5th April 2014
ChairpersonRichard Horton, Editor of The Lancet

Time Action
9.30am Coffee
10.00am What are the governance concerns : brief review of HSCIC, CAG and GP data controllers and CSUs – Phil Booth, medConfidential (slides); Ron Singer, GP & MPU
10.10am Concerns about what is happening to public health data: cuts to ONS data collection – Prof Alison McFarlane
10.20am The Faculty of Public Health’s position – Dr John Middleton
10.30am How robust are the current legal protections: DPA and exceptions to patient confidentiality – Peter Roderick
10.40am The Scottish position regarding data sharing – Dr Janet Murray (ISD Scotland)
10.50am                                Discussion and contributions from the floor
11.20am The government’s proposed amendment – Lord David Owen
11.30am Proposals for new legislation – Peter Roderick
11.40 – 12.45pm Proposal for Action: discussion led by Lord David Owen and Peter Roderick
LUNCH PROVIDED

Free text, CPRD and yet another threat to medical confidentiality

Thanks to Professor Julia Hippisley-Cox and Helen Wilkinson for pointing out that the Clinical Practice Research Datalink (CPRD) has extracted highly sensitive ‘free text’ from patients’ GP records without approval or fair processing.

Free text is your GP’s own notes, attached to the codes that are entered onto their computer systems. It can basically contain anything – names, highly sensitive personal details, medical and non-medical information about you or other people. Free text is for your doctor’s own use when providing you care, and to provide context that will help any other doctor you may see in future to provide you care.

See page 15 of CAG meeting minutes 3 October 2013 – 6a. CPRD – processing of free text information [CAG 6-06(a)/2013]

N.B. CAG is the Confidentiality Advisory Group, now based at the Health Research Authority, which advises the Secretary of State on the use of the extraordinary ‘Section 251‘ powers that allow the common law duty of confidence to be set aside so that patient identifiable information may be used without consent.

That free text has been extracted is confirmed by this presentation on Using free text in primary care research, on slide 55, which states:

“We plan to run FMA on free text within +/- 90 days of myocardial infarction [heart attack] for 2000 patients… Software will be run at CPRD without anonymisation”

(N.B. You will need to add .pdf to the filename of the file once downloaded in order to view it in Acrobat Reader.)

And this published study on BioMed Central suggests that GPRD (the General Practice Research Database) the precursor to CPRD, had been collecting free text for years.

Even more worrying is this statement on page 16 of the CAG minutes from 3/10/13:

“It was noted from the discussion that CPRD were seeking to progress solutions and were in discussion with those leading on the care.data mechanism.”

So CPRD had been using an out-of-date leaflet from 2008 to ‘notify’ patients about what it was doing and was in discussion with care.data leaders about using whatever ‘mechanism’ they were going to use to inform the public – which we now know was a junk mail leaflet!

If you even received a junk mail leaflet in January, did you see any mention of CPRD? Or any suggestion that your doctor’s private free text notes about you would be extracted? If you didn’t, why not check the leaflet out now. It says:

“Details that could identify you will be removed before your information is made available to others, such as those planning NHS services and approved researchers.

We sometimes release confidential information to approved researchers, if this is allowed by law and meets the strict rules that are in place to protect your privacy.”

So, you have been lied to on at least two counts; details that could identify you (i.e. free text) clearly are not always removed before information has been made available to researchers, and confidential information has been ‘released’ unlawfully and without meeting these so-called “strict rules”.

Because, as the CAG minutes clearly state:

“The CAG agreed that the minimum criteria under the Regulations did not currently appear to be met, and therefore advised recommending deferral to the SofS and the Health Research Authority, to enable the following actions to take place to bring the application within the framework of the Regulations:

a. Fair processing actions to be progressed in conjunction with the Information Commissioner’s Office; assurance and approved patient information materials to be provided at the relevant time before any final approval could come into effect.

b. Revision of the application form to fully incorporate responses to the issues set out above. This was to include a cover paper to clearly show which sections reflected these responses within the application.

c. A favourable ethical opinion to be provided from a Research Ethics Committee on the revised application to be considered by the CAG.

d. A satisfactory level to be achieved within the IG Toolkit before any final approval could be provided; this could be carried out in parallel to CAG consideration of the application.”

So there you have it. Yet another way that sensitive patient information has been taken from GP records without consent or proper approval. And care.data leaders knew all about it.

The problems aren’t just limited to HSCIC, folks.

We’re not saying research shouldn’t happen – of course it should – but it must be done with proper consent and/or proper authorisation, e.g. Section 251 support, which CPRD clearly didn’t have and doesn’t have yet.

Please note: we are not suggesting that the researchers referred to in this post are necessarily at fault; they may simply have been using a ‘service’ provided by GPRD / CPRD, without knowing that the free text had not been gathered with consent or proper approval.

[PRESS RELEASE] Patient groups slam head of MRC for “offensive” slur against patients

For immediate release – Friday 21 March 2014

Patient advocacy groups today called on the head of the Medical Research Council, Professor Sir John Savill, to publicly apologise for characterising people who have legitimate concerns about NHS England’s controversial care.data scheme as “consent fetishists”.[1]

Research is just one of several proposed ‘uses’ of patient data – which will by default be extracted in identifiable form from the GP records of every man, woman and child in England this autumn – but patients will be given no option to decide how their information will be used, e.g. you wouldn’t be able to choose for your medical data to be used in research, but not be sold to third parties. The only choice patients will be given to protect their and their family’s medical confidentiality is to opt out.

The care.data scheme conflates research with other ‘secondary uses’ such as commissioning, audit or sale to third parties outside the NHS. Despite research being one of the most common benefits claimed for the scheme, research was not a top priority when NHS England first applied to extract data from GP records and in fact care.data has not yet received approval for research use of patients’ medical information.[2]

Phil Booth, coordinator of medConfidential,[3] said:

“Sir John Savill owes an apology to every patient in the country. His arrogant and offensive remark pooh-poohs the legitimate and serious concerns many people have about this toxic scheme.

“care.data is not just about research. In cheerleading for a scheme the breadth of which he seems not to grasp, and with echoes of the GM debacle,[4] Sir John is putting the MRC’s own particular interests over the right of every NHS patient to expect that their doctor will keep their most intimate and sensitive secrets.”

Roger Goss, co-director of Patient Concern, [5] said:

“We support good medical research involving use of identifiable medical records but only with patients’ properly informed explicit consent. This is common sense – not fetishism. Plenty of people have overwhelmingly good reasons for prioritising their privacy.”

Notes for editors

1) See, e.g. http://www.thetimes.co.uk/tto/health/news/article4040095.ece and http://www.hsj.co.uk/news/mrc-head-brands-caredata-naysayers-consent-fetishists/5069163.article#.Uywru4Xvvcg

2) See pp5-8 of GPES Independent Advisory Group minutes for 12/9/13: http://www.hscic.gov.uk/media/12911/GPES-IAG-Minutes-for-12-September-2013/pdf/GPES_IAG_Minutes_12.09.13.pdf – these relate to the ‘care.data Addendum’, in which NHS England proposed that requests for patient data by all organisations, not just researchers, be considered: http://www.hscic.gov.uk/article/3525/Caredata

3) medConfidential campaigns for confidentiality and consent in health and social care, seeking to ensure that every flow of data into, across and out of the NHS and care system is consensual, safe and transparent. Founded in January 2013, medConfidential is an independent, non-partisan organisation working with patients and medics, service users and care professionals.

care.data opt out forms and letters available here: www.medconfidential.org/how-to-opt-out/

4) See last paragraph of Nuffield Council on Bioethics blog, 21/3/14: http://blog.nuffieldbioethics.org/?p=1059

5) Patient Concern has campaigned for patient choice and patient empowerment since 1999.

For further information or for immediate or future interview, please contact Phil Booth, coordinator of medConfidential, on 07974 230 839 or phil@medconfidential.org or Roger Goss, co-director of Patient Concern, on 01903 785 776 or 07946 644 110.

– ends –