Refuting NHS England’s response to Guardian story “NHS patient data to be made available for sale”

When medConfidential refutes something, we provide proof or evidence. We don’t use weasel words or mere assertion, we provide you the links to check out for yourself that what we say is correct.

Following the front page story in the Guardian today, NHS patient data to be made available for sale to drug and insurance firms, NHS England have posted a terse but incredibly carefully-worded response on their website.

In it, NHS England’s Chief Data Officer, Dr Geraint Lewis says:

“It is vital, however, that this debate is based on facts, and that the complexities of how we handle different types of data are properly understood. Patients and their carers should know that no data will be made available for the purposes of selling or administering any kind of insurance and that the NHS and the HSCIC never profit from providing data to outside organisations.”

You will note that Dr Lewis has not – because he cannot – refute the fact that insurers will be able to get hold of patient information extracted by the care.data scheme. And there are plenty of ways an insurer could profit from care.data without “selling or administering” insurance – tuning its premiums, for instance.

NHS England’s own ongoing application to the Health and Social Care Information Centre (HSCIC) to massively expand the uses and users of care.data makes it quite clear that “Examples of additional customer organisations may include:

  • Universities and other academic research organisations
  • Commercial companies
  • Think-tanks
  • Medical charities
  • Medical Royal Colleges
  • Information intermediaries

And the Information Governance assessment of this ‘care.data addendum’ quite clearly states, at the bottom of page 5:

“Access to such data can stimulate ground-breaking research, generate employment in the nation’s biotechnology industry, and enable insurance companies to accurately calculate actuarial risk so as to offer fair premiums to its customers.”

(We’ll leave it up to you to decide how “fair” the insurance companies are likely to be.)

And to Dr Lewis’ point about the NHS and HSCIC ‘not profiting’ from providing our data to companies outside the NHS, we can only say… why then do you publish a price list for accessing our medical information?

NHS England and HSCIC can call it ‘cost recovery’ or whatever they like; sophistry seems to be their standard approach. But most normal people’s understanding of the word ‘sell’ involves money changing hands in a transaction, which is clearly what’s happening here.

Whatever the value these extremely powerful bodies are putting on our medical information – and in this case it’s clearly not much – this is not the sort of behaviour that patients expect of the people and institutions that should be guardians of our data. Not by a long way.

PRESS RELEASE: Research organisations promote medical record data grab

Patient privacy campaign medConfidential [1] today strongly criticised the launch of a media campaign by 42 research organisations and medical charities [2] promoting NHS England’s new care.data scheme [3].

The advertising campaign, funded by organisations some of which have lobbied to access information held in patients’ medical records [4], uses blatant appeal to emotion to encourage people not to opt out of having confidential medical details from their GP record uploaded to central servers in identifiable form.

Information provided on the campaign website [5] focuses on research uses but makes only passing mention of other ‘secondary uses’ to which people’s medical information may be put and the non-medical, non-research organisations outside the NHS which will also be given access [6].

Evidence consistently shows that while many may be quite happy for their personal health information to be used for medical research with their permission, around a quarter of people are not [7] – with concerns ranging from disclosure and misuse to fraud, discrimination, breaching rights, commercial use, inaccuracy and private information becoming known to friends, family or acquaintances.

Phil Booth, coordinator of medConfidential, said:

“Promoting a scheme that is based on dodgy ‘presumed’ consent is bad enough, but trying to convince people not to protect their family’s medical confidentiality using such overtly manipulative imagery borders on unethical. The money would have been better spent building ways for people to express a positive choice to participate in research.

“The Wellcome Trust’s and MRC’s own studies show that around a quarter of the population don’t want their sensitive health details being shared, even for medical research. And this is their absolute right. So if opt out rates turn out significantly lower than 25% this Spring, it won’t be an indication of success. It’ll point more to a massive whitewash.”

Notes for editors

1) medConfidential campaigns for patient privacy, confidentiality and consent in health and social care. It was founded in January 2013 in response to the imminent and serious threat posed by radical changes in the way patient health information is to be collected and passed on. medConfidential is an independent, non-partisan organisation working with patients and medics, service users and care professionals to defend and enhance confidentiality across health and social care: www.medconfidential.org

2) The campaign website is at www.patientrecords.org.uk

3) The care.data scheme will begin uploading confidential medical information in identifiable form from the GP record of every man, woman and child in England from Spring 2014. For more information on the scheme, see http://care-data.info – written by Hampshire GP, Dr Neil Bhatia, this site provides a more comprehensive description than is provided by NHS England at www.nhs.uk/caredata

4) From ‘care.data Addendum papers’, September 2013:

“Although the care.data Customer Requirement Summary [March 2013] makes reference to data for research purposes, it was subsequently clarified by NHS England, and confirmed to the GPES Independent Advisory Group, that the research community was not included at that time.

In the meantime, NHS England and the HSCIC have been approached by a number of organisations that use the HSCIC’s Hospital Episode Statistics (HES) managed extract service to express their disappointment that the original submission only requested access to the data for commissioners. These organisations include Diabetes UK, the Nuffield Trust, Cancer Research UK, University Hospitals Birmingham NHS Foundation Trust, Caspe Healthcare Knowledge Systems (CHKS), the National Cancer Registration Service, and Arthritis Research UK.

Therefore, this addendum requests that access now be granted by the HSCIC to a wider audience, including researchers, on a case by case basis.”

5) The campaign website unfortunately repeats the assertion, also made in the junk mail leaflet currently being sent out by NHS England that “you will need to speak to your GP” to opt out. This is potentially misleading. Patients do not have to speak with their GP and they most certainly do not need to book an appointment. If they are concerned in any way for the confidentiality of their and their family’s medical records, people can simply write to their doctor or drop a form such as the one provided here: www.medconfidential.org/how-to-opt-out/ into their GP practice, instructing their doctor to opt them out.

4) From ‘care.data Addendum papers’, September 2013:

“Examples of additional customer organisations may include:
• Universities and other academic research organisations
• Commercial companies
• Think-tanks
• Medical charities
• Medical Royal Colleges
• Information intermediaries”

And NHS England has already, e.g. received Section 251 exemption to pass identifiable patient data around a range of bodies at national and local level, for commissioning and other purposes not to do with patients’ medical care.

5) Studies such as the Wellcome Trust Monitor, 2009 & 2012 – see table on p119 of Wave 1 study: http://www.wellcome.ac.uk/stellent/groups/corporatesite/@msh_grants/documents/web_document/wtp040713.pdf which shows that 28% of people are concerned (and a further 10% may be concerned) about allowing access to their medical records for medical research.

This figure is reflected in MRC’s ‘The Use of Personal Health Information in Medical Research’ report, 2007:

“The most common reason for being unlikely or certain not to allow personal health information to be used for medical research purposes is concern over privacy (28%). Other common concerns focus on potential abuse and loss of control. Around one in ten are anxious about such information ‘falling into the wrong hands’ (13%), and similarly over the perception that individuals can not control who uses their information (13%), or for what purpose (12%).”

– page 8, http://www.mrc.ac.uk/Utilities/Documentrecord/index.htm?d=MRC003810, see also pie chart on page 40 which indicates that 25% are unlikely to allow their personal health information to be used for the purposes of medical research. Table on page 38 lists perceived ‘Disadvantages of Collecting Personal Health Information’.

For further information or for immediate or future interview, please contact Phil Booth, coordinator of medConfidential, on 07974 230 839 or phil@medconfidential.org

– ends –

Better information means better care leaflet

Goodness only knows how NHS England’s new junk mail leaflet, Better information means better care (2MB PDF) got its plain English Crystal Mark. It is one of the most disingenuous pieces of literature in the history of the NHS, full of ambiguity and misdirection – surpassed only perhaps its predecessor leaflet, How information about you helps us to provide better care (343KB PDF).

What these leaflets are talking about is care.data, a new scheme that will extract confidential medical information from the GP-held records of every man woman and child in England.

If you want to know more about care.data right now, you can read Hampshire GP, Dr Neil Bhatia’s comprehensive explanation at www.care-data.info or check out how care.data came about in our section called ‘What’s the story?’

The newer junk mail leaflet, which is being pushed through letterboxes across England throughout January 2014, is designed to make you think nothing extraordinary is going on. It is. The leaflet, which many patients may never actually see, is a study in evasion and omission, failing to mention rather significant pieces of information like the name of the scheme itself – ‘caredata’ appears just once in the leaflet as part of a URL at the bottom of the last page; it doesn’t appear at all in the first leaflet – and, more crucially, the new leaflet doesn’t contain an opt out form.

That’s because this is about consent. Or rather it’s about manufacturing consent.

For if you don’t act and opt out of care.data in the next 8 weeks, confidential information from your and your family’s medical records will be uploaded, and once it leaves their systems your GP will have no say in what is done with it. It will be presumed that you have consented for this to happen, and for your medical records to be passed on to companies and organisations outside the NHS – all on the basis of a leaflet which you may not even have received, noticed, read or understood.

After all, it’s being sent as junk mail, not to you directly as a patient.

But if you did get a leaflet, got the sense you’re not comfortable with the rather vague information you are being given and decide it would probably be safer to opt out – it is – you are instructed to… “speak to your GP practice”. Wrong! You don’t have to speak to your GP, and you certainly don’t have to book an appointment – you can opt out of care.data via letter or send in a form, copies of which we provide.

NHS England’s leaflet campaign is a deliberate and shameful attempt to make it as awkward for you to opt out as it can. And if this is how they are (begrudgingly) going about ‘informing’ the public about care.data, can the scheme really be trusted? If it can, then what have they got to hide?

care.data: the creep begins

If there were ever any doubts that NHS England’s first care.data upload, planned for next March, is anything more than a toe in the door, recent developments should quash them. Speaking at the BCS Primary Health Care Specialist Group’s annual conference a couple of weeks ago, Geraint Lewis (Chief Data Officer at NHS England) said that the current data spec would not yield enough information to be of use to researchers. In other words, it’s going to need some significant expansion.

And now, recently-published minutes of the Information Advisory Group (IAG) show that before the programme has even started, the Health and Social Care Information Centre has already been back for more. In an addendum to the first care.data request, they have sought to expand the range of agencies with access to ‘potentially identifiable’ patient data. Currently this data is available to commissioning bodies. HSCIC now wants to include ‘research bodies, information intermediaries, companies, charities’… oh, and ‘others.

The IGA that accompanies the application provides the following caveat:

This information governance assessment of the addendum is not classified in the summary sheet as either identifying or non-identifying because no assessment is made, or can reliably be made, of all of the possible additional disclosures of data to the wide variety of recipients that could result from this proposal

Ah, so this is all a bit of a shot in the dark then.

The HSCIC’s application, which can be seen here, further suggests that they could avoid troubling the IAG further by in future deciding for themselves on a case-by-case basis who can have access.

The IAG has firmly knocked back the application and sent the HSCIC away to think about it. It’s worth reading the IAG minutes in full because underneath the specific issue of the care.data addendum, the small nuances in the wording reveal a welter of problems and irritations.

Opening Up Patient Records: Pandora’s Box or the Holy Grail? – BCS Primary Health Care Specialist Group conference, 24/25th October

Phil Booth will be speaking on data sharing concerns at the BCS Primary Health Care Specialist Group’s annual conference at the Ettington Park Hotel, Stratford-upon-Avon on 25th October 2013.

The theme of the conference is ‘Opening Up Patient Records – Pandora’s Box or the Holy Grail?’ and confirmed speakers include Kathy Mason (NHS England), Tracey Painter, Geraint Lewis (NHS England), Dr Chris Frith, Maggie Lay (Oxford CSU), Dr Sam Rogers (CCIO Central London), Dr Dai Evans, Dr Luke Twelves, Phil Booth (medConfidential), Prof Iain Buchan (University of Manchester)

Further details and conference programme available from the PHCSG website [PDF].

Don’t take our word for it!

On the pages of this site you’ll find information about the planned extraction of medical records from GP surgeries. In particular we recommend that you read the whole of ‘What’s the Story?’ and follow up the links that we provide. All of these are to reputable sources, and mainly to NHS England’s own documents or those of their new Health and Social Care Information Centre.

Our aim has been to bring together the facts so that the public can understand what’s going on, and journalists can ensure that everything they write is based on the available evidence. We hope to save everyone the research leg-work that would otherwise be necessary in order to understand a dauntingly complex story.

Politicians and NHS England have repeatedly stressed that all patient information will be anonymised. Recently one or two journalists have been quick to pick up on this mantra. But if you read ‘What’s the Story?’ you will see that this is not true. What they really mean is that patient data will be anonymised unless there is a legal exemption that allows the use of identifiable information. NHS England has obtained just such an exemption.

But don’t simply take our word for it. Please take a bit of time to read the detailed information and if you think it isn’t accurate, let us know and send us all relevant links so that we can correct it where necessary.

If you’re new to this whole issue, there is a simplified FAQ sheet here but note that this doesn’t contain any links.

NHS #1: What’s happening in England? The new legislation

You’ve probably gathered that a lot of reorganisation is going on within the NHS. The most obvious changes and difficulties have been well-reported, but others are passing pretty much unremarked. In particular changes to the way that patient information in England is collected, passed around and processed fundamentally alter the concept of doctor-patient confidentiality. That isn’t hyperbole.

It’s been quite difficult to write the blogs that follow because it’s so interwoven. Please read all of the blog posts in sequence and bear with us if the story loops back on itself or if we haven’t explained something clearly enough.

For the time being we have switched comments off. When we’ve finished our outline of the current state of play, we will put them back on so that you can leave your views, ask questions and tell us if you think we’ve got something wrong – for which we apologise in advance. The situation is changing all the time and all we can do is set out our current understanding of it. Once we have set out the basic framework, we will discuss some of the elements in greater detail and with a wider range of links.

And now to get down to business. The first step is to look at the legislative framework that allows your medical records to be used in surprising new ways.

The Health and Social Care Act 2012, which came into force on April 1st 2013, made some fundamental changes to the structure of the NHS. The ones that are of particular interest here are:

1)    The creation of the ‘NHS Commissioning Board’

2)    The creation of ‘Clinical Commissioning Groups’

3)    New powers that change the ‘Regulation of health care and associated professions’ into the ‘Regulation of health professions, social workers, other care workers etc’ – in other words, the creation of a new over-arching Health and Social Care Service

4)    And finally, the whole of Part 9 of the Act.  This creates another new body: ‘The Health and Social Care Information Centre’. It also sets out various powers and duties relating to the establishment of information systems (e.g. databases) and the central collection and dissemination of health and social care information about every individual in England.

Tomorrow we’ll explain how this new structure actually works.

NHS #2 The new structure

At the top of the new pyramid sits the National Health Service Commissioning Board (NHSCB). This is an arms-length body of the Department of Health responsible for spending the £95.6 billion budget of the NHS. Actually, it has now changed its name to ‘NHS England’ – the reasons for this change are set out in this letter from NHSCB to the Secretary of State – so if you see any reference to NHSCB or NHS England, it should be taken as meaning the same thing.

Primary Care Trusts have been abolished and their staff have been moved across to local authorities and 19 regional Commissioning Support Units (CSUs). Or made redundant. In theory, decisions about the provision of services in your area will now be made by Clinical Commissioning Groups (CCGs). These are local groups made up of representatives of every GP practice in the area, a nurse, a hospital doctor and other healthcare practitioners. In practice, many decisions will still be made centrally by NHS England or one of its 27 Local Area Teams (LATs).

The NHS Information Centre – up until now principally a statistical data warehouse – has been renamed the Health and Social Care Information Centre (HSCIC) that is now to act as a ‘hub’ for data flows inside and out of the NHS.

As the legislation shows, the HSCIC:

  • can be directed by NHS England (or the Secretary of State) ‘…to establish and operate a system for the collection or analysis of information of a description specified in the direction.’  (s254)
  • can require health and social care bodies, and any of their sub-contractors, to provide it ‘with any information which the Centre considers it necessary or expedient for the Centre to have…’ (s259)
  • can request information from anyone else
  • must publish statistical information that does not identify individuals and
  • ‘may disseminate (other than by way of publication), to any such persons and in such form and manner and at such times, as it considers appropriate’ any other information – including identifiable patient information – that it receives (s261)

The National Information Governance Board (NIGB) – the independent statutory body responsible for data handling procedures and practices across the NHS – has been abolished, leaving responsibility for how your confidential information is treated spread across a number of different groups: the Confidentiality Advisory Group (CAG), the Data Access Advisory Group (DAAG) and other Independent Advisory Groups, such as GPES IAG*. You will need more information about how the new structure works in order to understand their functions, so we will deal with them later.

For further reading about the changes, you may find this BMA explanation helpful.
An overview of the current trusts and authorities in the English NHS can be found here.

*@Bigjoe498 adds: The Confidentiality Advisory Group and the Health Research Authority are the only ones that can advise the Secretary of State to grant s251 approval for the release of identifiable data. The Data Access Advisory Group only deals with sensitive data items, which for HES (Hospital Episode Statistics) includes things like consultant code, referrer and census area. DAAG also look at consent forms to make sure they are explicit enough to release identifiable data for those who have consented using each form. The GPES Independent Advisory Group only advises the HSCIC about whether they should allow an extraction of GP data using GPES. The IAG has no standing in law to decide whether or not identifiable data can be shared outside the HSCIC.

NHS #3: General Practice Extraction Service – GPES

The next thing you need to know about at this stage is something called the General Practice Extraction Service or GPES. This is a tool for extracting patient data directly from the records held on GP surgery systems and transferring it to central HSCIC systems.

Sending data from a GP practice to an Information Centre is not new. Information about specific groups of patients – e.g. those with mental health problems – has been submitted in anonymised form for some time. The difference now is that, for the first time, information that identifies you will routinely be extracted from your GP-held records – even if that information was gathered elsewhere.

Details of diagnoses and treatments will be collected together with each patient’s NHS number, date of birth, postcode, gender, ethnicity and other information. It may be processed in regional Data Management Integration Centres (DMICs) or be sent directly to the HSCIC, still in identifiable form, to be processed, stored and disseminated to others.

The data will be made available to researchers in universities and hospitals, but also to private companies – in fact, to anyone who can make a case for access to the data. Although the precise arrangements for charging are not yet entirely clear, the existence of a pricing structure indicates that there will be a charge for this data.

NHS England repeatedly insists that the information will be ‘anonymised’ before release. In reality, the standard they are using requires that they ‘…ensure that, as far as it is reasonably practicable to do so, information published does not identify individuals.’ In other words, they will do their best to ensure that information cannot be re-identified as being about a specific patient, but there can be no guarantee.

It’s also clear that there are times when identifiable data (aka ‘Patient Confidential Data’ or PCD) will be made available – we will come back to that later. The next step here is to discuss what ‘anonymisation’ means and why it is such a misleading term.

NHS #4 ‘Anonymisation’

If you’ve ever played ‘twenty questions’, you will already know how easy it can be to identify an individual from a relatively small amount of information. Each question narrows down the field, and the more unusual the person’s attributes, the easier it becomes to guess who it is.The same principle applies to data. If we say that someone is male, that tells us only that he belongs to a group that represents one half of the population. By adding that he is aged 42 we reduce the size of that group, but we’re still not going to guess his identity.

Such general information isn’t likely to be of much use to researchers either. They are approaching their research from a different angle: they are likely to be investigating the unusual and are therefore looking for certain characteristics in their study subjects. The rarer those characteristics or the more of them in combination, the easier it becomes to identify individuals within the study. Consider, for example, a study examining the prevalence of skin disorders caused by exposure to the sun in red-headed males aged 40-45 who live in Devon and Cornwall.

The more data that can be linked together about an individual, the easier it becomes to find out who they are. Journalists and private investigators already know this – and so do large companies. There is a huge industry around data-matching aimed at identifying those who can be targeted with specific advertising and products.

Removing or obscuring pieces of information that most obviously identify a person doesn’t make data about them ‘anonymous’. And in any case, despite claims it will only ever share ‘anonymised’ data, NHS England has already applied for and been granted permission to pass around patient data in identifiable form. (We’ll explain more about that later)

So does it matter if you can be identified? Your answer might well depend on whether you suffer from a condition, or live in circumstances, that you would prefer to keep as a secret between you and your doctor. It might also depend on whether you are actually asked if you will participate in a research study. Probably most red-headed 42-year-olds would be happy to contribute to research that could conceivably help them, although even then they might want to draw some lines about what exactly is released.

The point is, people generally regard their medical records as private and want to keep control of access to them. They can talk to their doctors about highly sensitive and embarrassing things like sexual health problems, worries about their erratic moods or their alcohol intake precisely because they believe they are talking in confidence. If they are to continue talking to their doctors, they need to know that they will be asked for permission before that confidence is breached.