NHS #5: Consent

The burning question, then, is: ‘will your permission be asked before your medical information is uploaded?’ To which the answer is a straightforward ‘no’. The default position is that the uploads will go ahead unless you do something to stop them.

The original plan was that nobody would have any say about the use of their data. After concerns were expressed by doctors, NHS England agreed that there could be a ‘right to object’. Following our meeting with the health minister Jeremy Hunt, he announced that there would be a right to ‘opt out’ and that the 750,000 patients who had already opted out of the Summary Care Record would automatically have their existing opt-out respected.

On 29th May, NHS England published its guidance to GPs  which makes it clear that existing opt-outs will not be respected. Those who opted out of the previous, more limited upload of their Summary Care Record will now need to opt out all over again.

NHS England is currently in discussions with the Information Commissioner. The Information Commissioner’s Office is obviously concerned that patients should be made aware of the data-upload plans, informed of their ability to opt-out and given sufficient time to exercise it. It should be noted, though, that the ICO’s powers are limited by the way in which the legislation has been framed.

NHS England has prepared posters and leaflets for GPs to display in their surgeries. You may feel that these are short on detail. More informative is the patient leaflet prepared by EMIS one of the main suppliers of GP surgery systems.

Pilots of the care.data system are imminent. They will be taking place in 82 GP surgeries dotted around England. Meanwhile, all GP practices in the north of England have been told to be ready for the full roll-out within the next 8 weeks.

NHS #6: ‘care.data’

care.data is the name of NHS England’s programme to extract information from GP surgery systems and from health and social care providers, and to link it all together. It is a massive undertaking. At the moment we are concentrating on the first stage of this programme – collecting patient data from GPs – but ultimately all health and social care will be drawn into the system. Hospitals have been told to be ready by 2014; social care will join in by 2015. We’ll talk about that later on.

The first care.data request has now been agreed. This is a set of coded instructions that tells each GP system what information should be uploaded. The full specification for the first upload of care.data can be seen in Appendix A (p.22) of this document.

Here’s how it works:

  • NHS England applies to the HSCIC to have the information (care.data) extracted from GP systems.
  • HSCIC puts the application through the ‘customer’ procedure that we will outline in blog #8. It then actions the request and instructs GPES  to go ahead and take the information from each surgery system
  • The collected data is passed on to a regional Data Management and Integration Centre (DMIC) which sends it to a number of places – like a giant traffic-direction system.

For now, we’re going to focus on just one of these traffic flows: the data that goes back to the HSCIC.

The information is stored on the HSCIC system, still in identifiable form – ie with NHS number, date of birth and the other identifying details attached to the diagnoses and treatments. It is used to create regular reports but ‘customers’ can also request linked data. In the words of the HSCIC  this ‘often contains patient level information‘ and ‘When stringent Information Governance controls allow‘ they can ‘provide extracts of linked data sets in an identifiable form’.

Tomorrow we will look at those ‘stringent’ controls in more detail.

 

NHS #7: ‘Stringent Information Governance Controls’ and Section 251

We have already touched on the issue of ‘anonymisation’, but that isn’t the only problem. Confidential information that identifies an individual can be processed – gathered, stored and passed on – without any consent at all if there is a lawful provision for doing so.

Section 251 of the NHS Act 2006 is just such a provision. It: ‘…was established to enable the common law duty of confidentiality to be overridden to enable disclosure of confidential patient information for medical purposes, where it was not possible to use anonymised information and where seeking consent was not practicable, having regard to the cost and technology available.’  (Health Research Authority)

To put it simply, if an organisation has been granted a s251 exemption by the Secretary of State, they don’t need to worry about getting patient consent to use identifiable information.

The GPES FAQs say that: ‘Normally, data extracted will be anonymised, however where data that could identify patient is requested, it will only be released where a legal basis for disclosure exists (e.g. explicit patient consent)’ …but another example that hasn’t been given in the FAQs would be where an organisation has that vital s251 exemption.

Although NHS England is the ‘boss’ of HSCIC, insofar as it can direct it to do pretty much what it wants, it is also a ‘customer’ of HSCIC. Because of this, NHS England needs a legal basis for processing and passing on information gathered via the care.data extraction without seeking patients’ consent.  In May, NHS England’s application for s251 exemption (or ‘support’) was approved, initially for six months: ‘The approval has been given subject to conditions until October 2013 at which point NHS England can provide a report for consideration to CAG to identify the requirements for continuing and or amended support.

This means that identifiable data gathered under NHS England’s ‘care.data’ request – the extraction of identifiable patient information from all GP surgery records – can be passed on to a range of bodies without patients’ knowledge or consent.

Tomorrow we’ll look at the process of becoming a customer of HSCIC.

NHS #8: How do you get to be a ‘customer’?

The first step is to complete an application form here BUT, as the HSCIC information tells you‘If you wish to apply for personal confidential data you will need one of the following:

  • The consent of the individuals to whom the data relates. In this case you will need to provide evidence of the consent of the individuals concerned, i.e. the consent form and consent information literature. These will be reviewed by the HSCIC to ensure they are appropriate and, where necessary, approval will be sought from the Data Access Advisory Group (DAAG).
  • Approval under section 251 of the NHS Act 2006  In this case you will need to provide evidence of approval under section 251, i.e. a letter from the Health Research Authority Confidentiality Advisory Group (HRA CAG).Or,
  • The appropriate statutory regulation covering your organisation for the work required. In this case you will need to provide evidence of the statutory regulation concerned. This will be reviewed by the HSCIC to ensure it is appropriate.

…and now it becomes rather Byzantine. We’re reasonably certain this is how it works, but if you think we’re wrong, please explain it to us and we’ll correct it. We are quoting throughout from the descriptions of each group’s function that appear on their official web pages.

If you apply for a ‘bespoke’ set of data, i.e. information that isn’t contained in the regular statistical bulletins, HSCIC forwards your application to its ‘Independent Advisory Group’ (IAG)

‘Acting as an advisory group to the GPES Business Unit, the IAG will consider requests for information from customers that could be collected and provided by GPES and recommend an appropriate course of action to the Information Centre.’

If you are applying for patient confidential data and you have each patient’s consent, or if there are reasons to believe that individual patients can be identified from the apparently ‘anonymised’ information you are requesting, your application will be passed to the Data Access Advisory Group (DAAG) – also hosted within the HSCIC.

‘The Data Access Advisory Group (DAAG) is an independent group hosted by the Health and Social Care Information Centre that considers applications for sensitive data.
This ensures that the use of patient data for research purposes and for improving patient care is done in a controlled environment where the risk of disclosure is minimised.’

If you are relying on s251 ‘support’, i.e. you have an exemption from seeking patients’ consent (see yesterday’s blog #7), or if DAAG believes the information you are seeking might identify individual patients, your application will go to the Confidentiality Advisory Group (CAG) of the Health Research Authority.

‘CAG has been established to provide independent expert advice to the Health Research Authority (for research applications) and the Secretary of State for Health (for non-research applications) on whether applications to access patient information without consent should or should not be approved’

NHS #9: Who gets to see your information?

What this all amounts to is a number of ways in which massively increased amounts of information from your medical record can be accessed by a range of organisations, including private companies.

One stated intention of GPES is to “drive economic growth through the effective use of linked data” [PDF, p6] with which researchers, public bodies and commercial organisations could match records at patient level, based on information they already hold. And NHS England’s chief data officer has revealed plans to reduce the cost of access to the ‘pipeline’ of pseudonymised patient data to just £1!

This on top of the register of customers already approved by the DAAG http://www.hscic.gov.uk/daag, including companies like Dr Foster and BUPA, who may pay a fee for direct access to “sensitive or identifiable” patient data.

Under the new arrangements a whole host of new commissioning-related organisations will be also able to access what is now being called personal confidential data (PCD).

While information from your medical record may initially go to HSCIC or one of the regional Data Management Integration Centres, it doesn’t stop there. As we mentioned before, NHS England has been given a Section 251 exemption to pass identifiable – not just anonymised – data on to its Area Teams, to Clinical Commissioning Groups and Commissioning Support Units. This, despite the conclusion of the Caldicott2 report that anonymised data should generally be sufficient for commissioning.

‘Commissioning’ itself covers a wide range of purposes – e.g. monitoring, surveillance and service planning, targeting treatment, even invoice reconciliation – not only expanding the number of people with access at local, regional and national level but creating a market for analysis and consultancy companies to sell services to the commissioners and their support organisations.

This commodification of your medical records means the default is to make them accessible to more and more people less and less directly related to your medical care, constrained not by the professional duty of confidentiality that most patients presume but by data protection compliance or contract terms and conditions.

And, of course, the merging of health and social care means ever more sharing between healthcare providers, social services and education. Following the abolition of the PCTs, local authority Public Health Teams have now taken on regulated public health functions such as the weighing and measuring of schoolchildren and providing some sexual health services, and may use data to target and drive additional discretionary services such as tobacco cessation, obesity initiatives, etc.

While it makes sense to integrate care delivery around those with particular needs, the direction of travel is towards a culture of universal health surveillance and ‘integrated’ records – whether you choose them or not.

Open letter to HSCIC: do you charge to release identifiable data or not?

What exactly is going on at the NHS Health and Social Care Information Centre (HSCIC)? A story in the Guardian last Saturday, ‘£140 could buy private firms data on NHS patients’, seems to have prompted some edits to the HSCIC website. The page for the HSCIC’s Data Access Advisory Group (DAAG) used to say, for example:

The Data Access Advisory Group (DAAG) is an independent group hosted by the Health and Social Care Information Centre which considers applications for sensitive or identifiable data. – our emphasis, source: Google web cache from 11 May 2013

But the current DAAG page on the HSCIC website – which, according to the page metadata meta name=”DC.date.modified” content=”2013-05-21T16:59:14+01:00″ scheme=”W3CDTF”, was modified at 4:59pm on Tuesday 21 May – four days after the publication of the Guardian article – to read simply:

The Data Access Advisory Group (DAAG) is an independent group hosted by the Health and Social Care Information Centre that considers applications for sensitive data.

Other pages have also been changed in recent weeks, such as the one about the HSCIC’s Bespoke data extract services. The top section of this page currently reads:

What is the data extract service?

Customers can order bespoke patient-level extracts or tabulations of health and social care data.

The data we supply is normally anonymised or de-identified. We only provide identifiable data when there is a lawful basis to do so e.g. with patient consent, a statutory gateway or with s251 support.

This data can only be made available to those who meet HSCIC’s robust Information Governance standards to protect and control how data is managed.

We oblige anyone who is eligible and whom we agree to supply with data to enter into a Data Sharing Agreement. These Agreements regulate how the data is shared and used and also detail storage security requirements and restrictions on onward sharing or publication of this data. We also reserve the right to audit adherence to the Agreement. The Data Sharing Agreement specifically prevents customers from attempting to link data and re-identify individuals.

You can find out more about our services for researchers, including how we are working with the Clinical Practice Research Datalink (CPRD), in the Data Linkage Research section of this website.

As compared to what it said on 7 April 2013 [web.archive.org snapshot]:

What is the data extract service?

Organisations can order bespoke patient-level extracts or tabulations of health and social care data.

Data will be provided in a de-identified form and we will only provide identifiable data where there is a legal basis on which to do so e.g. the patient has consented. Researchers can access this service via the Clinical Practice Research Datalink (CPRD)

or on 20 March [web.archive.org snapshot]:

What is the data extract service?

Researchers and organisations can order bespoke patient-level extracts or tabulations of health and social care data.

And on all of these pages, if you scroll down a bit further, you come to a link that says: “How do I apply for access to sensitive or identifiable data?” The clear implication being that one can apply for access to identifiable data.

As far as medConfidential understands, HSCIC does provide identifiable patient data to third parties and that – on top of any other fees it may levy – it charges (or has charged) an additional £140 processing fee for doing so. This seems like peanuts for access to identifiable data on individual patients, whatever procedures someone has to jump through to get it. And with the Commissioning Board (‘NHS England’) applying for blanket Section 251 exemption to pass around identifiable data amongst a whole range of commissioning bodies medConfidential believes patients have every right to be concerned that what may up until now have been relatively constained amounts of identifiable data leaving HSCIC may be about to become a flood.

In the interests of fairness and transparency, we decided to write to the folks at HSCIC so they can explain what’s going on. Here’s the text of our letter:

To: Dr Mark Davies, Director of Clinical and Public Assurance & Chair of Data Access Advisory Group, NHS Health & Social Care Information Centre

24 May 2013

Release of identifiable patient data from HSCIC

Dear Dr Davies,

We are writing to you regarding the circumstances in which HSCIC provides patient data in identifiable form to third parties. It appears that the HSCIC website may have contained some errors and, while we are aware that things are still adapting post-April 1st, we would like to clarify some details of the procedures around the release of patient identifiable data.

We have, of course, read the DAAG Terms of Reference and other information published on the website. We understand that HSCIC does receive patient data in identifiable form from a variety of sources and that HSCIC does provide patient data in identifiable form to third parties – not least because the HSCIC website lists three instances in which it provides patient data in identifiable form: where there is “patient consent, a statutory gateway or with s251 support.”

We therefore ask:

1) Other than by patient consent, a statutory gateway, or Section 251, what are the lawful bases on which HSCIC will provide patient data to any third party in identifiable form? “Where there is a lawful basis to do so” is broad and non-specific; what we would like is a specific and comprehensive list, something that a member of the general public could understand.

2) If a person or organisation has a lawful basis for requesting identifiable data and they satisfy the DAAG’s requirements as regards information governance and the particular request for data, is it the case that the DAAG will approve the provision of identifiable data from HSCIC? If this is not the case, who is the Senior Responsible Officer for such a release and what is the process by which they make that decision?

3) Can you confirm that HSCIC charges all third parties a fee for the provision of data in identifiable form? If there are circumstances in which this fee would be waived, please would you list them.

If any of these questions are not clear, please contact us on coordinator@medconfidential.org

Thank you for your attention. We look forward to hearing from you in due course.

Your sincerely,

Phil Booth and Terri Dowty, medConfidential

medConfidential launch and the Secretary of State

medConfidential launched on Wednesday with a highly successful conference event, after working for nearly two months behind the scenes. We’ve now published audio and video.

This morning the Secretary of State for Health responded to the Caldicott report, confirming that there would be a patient opt-out on the sharing of health data, the details of which have yet to be finalised.

Continue reading

YOUR HEALTH: YOUR RECORDS, YOUR CHOICE – medConfidential launch conference

Audio, presentations and coverage of medConfidential’s inaugural conference held on 24th April 2013. Thanks to everyone who came, especially to all our speakers and hard-working volunteers who helped ensure everything ran smoothly.

Sessions and speeches as per the programme:

An overview of current policy including the General Practice Extraction Service (GPES); online access to medical records; the single care plan; the ingredients of valid consent – Phil Booth and Terri Dowty, joint coordinators of medConfidential

Phil Booth – audio (MP3) |presentation (.ppt)
Terri Dowty – audio (MP3) |presentation (.ppt)

Online patient records: safety and privacy – Ross Anderson, Professor of Security Engineering at the University of Cambridge Computer Laboratory

Ross Anderson – audio (MP3) |presentation (.pptx)

The next step: Linking medical records, DNA and genetic information – Dr Helen Wallace, Director of Genewatch UK

Helen Wallace – audio (MP3) |presentation (.pptx)

NHS Confidentially and Patient Advice – Helen Wilkinson, Coordinator of TheBigOptOut Patient Advice Line

Helen Wilkinson – audio (MP3)

Our right to medical privacy – Shami Chakrabarti, Director of Liberty

Shami Chakrabarti – audio (MP3)

Plenary: feedback from workshops

Sue White, Ross Anderson, Ian Brown and Phil Booth – audio (MP3)

The workshops covered:

(1) The single care plan for children and its extension to adults – Sue White, Professor of Social Work (Children and Families) at Birmingham University + Terri Dowty

(2) The GP Extraction System and patient confidentiality – Dr John Cormack, GP and Professor Ross Anderson

(3) Keeping data safe and why ‘anonymisation’ isn’t the answer – Dr Ian Brown, Associate Director (Cyber Security Centre) and Senior Research Fellow of the Oxford Internet Institute + Sam Smith, Privacy International

(4) A brainstorming session to assess the potential risks for each sector and steps forward – Phil Booth

Online coverage of the conference, including some video:

Liveblog of the conference on Light Blue Touchpaper

Report by Shibley Rahman on the Socialist Healthcare Association’s website (3 videos)

A ‘hat-trick’ from TechEye.net:
UK’s ‘anonymous’ health records are wide open
Your genetic make up to be stored, without consent, for profit
Shami Chakrabarti lends support to new health privacy campaign

 

 

YOUR HEALTH: YOUR INFORMATION, YOUR CHOICE – conference in central London, 24th April 2013, 9:45 – 16:45

We assume that our medical records are private unless we give permission for information contained in them to be passed on. This is no longer true. New legislation and a raft of policy initiatives threaten the fundamental basis of medical confidentiality.

From the new ‘General Practice Extraction Service’, that will remove identifiable patient data directly from GP records without consent so that it can be passed around and made available to researchers and private companies, to the plans for online medical records and shared health and social care systems, everyone needs to know what is happening.

At this one-day conference in central London you can hear a range of expert speakers explain these new developments and put your questions about the safety and confidentiality of your own records and those of the people whose interests you represent.

Places are limited. If you would like to be offered one of the free slots, please let us know by completing this form.

* CONFERENCE PROGRAMME NOW FINALISED – DOWNLOAD A COPY HERE *

medConfidential at ORGCon North – 13th April 2013 in Manchester, 11:00 – 17:00

Phil Booth, medConfidential coordinator, will be speaking at ORGCon North on Saturday 13th April, taking part in a panel debate entitled Data Protection regulation: Citizen empowerment or red tape nightmare? along with Javier Ruiz of Open Rights Group, Judith Rauhofer from the University of Edinburgh and David Smith, Deputy Commissioner at the Information Commissioner’s Office.

In the afternoon, medConfidential will be offering an “unconference” session to explain and discuss changes in the NHS that threaten the fundamental basis of medical confidentiality – and what you can do about it! Here’s a quick preview on SoundCloud of what Phil will be talking about.

For more information or to book your ticket for ORGCon North, please visit:

http://www.openrightsgroup.org/events/2013/org-con-north/