, , , ,

Before moving from “analogue to digital,” the NHS has to fix its privacy flaws

Create a centralized database to make patient health records easily accessible by all NHS services, like hospitals, GP surgeries, and ambulances. These so-called “patient passports” are the main innovation of the government plan unveiled on Monday, October 21, to transform the NHS from “analog to digital” over the next decade.

Wes Steering, the health secretary, promises these changes will modernize the country’s healthcare institutions to considerably speed up patient care and reduce human errors. A new law, the Data (Use and Access) Bill, is also expected to support this transition and create a standard system where sharing these digital records is the new norm.

At first glance, fixing the issues currently crippling the NHS by embracing the power of digital tools looks like a much-needed step. Some European countries have been using a similar system for years – Estonia began digitalizing all patient records in 2008, for example. Yet, privacy experts (myself included) can see how easy it might be for this ambitious plan to turn into yet another privacy nightmare at the cost of our most sensitive information.

NHS has a bad track record in protecting our data

Let’s start with the obvious – so far, the NHS has been really bad at protecting patients’ health data against hackers.

The health data of UK citizens has been leaked on several occasions this year, landing on the dark web. On March 15, for example, a ransomware gang hacked Into NHS Dumfries and Galloway‘s digital database and stole identifying information belonging to both staff and patients, including mental health data of children.

Pathology service provider Synnovis also suffered a major attack in June, resulting in hundreds of gigabytes of sensitive patient data leaking online. A National Cyber Security Centre (NCSC) executive, Professor Ciaran Martin, warned at the time against the risk of further attacks caused by the NHS IT systems being “out of date.”

I don’t trust that the NHS will take good care of my data anytime soon

More recently, in August, the UK Information Commissioner’s Office (ICO) filed a provisional fine of £6 million following the 2022 medical records hack that saw the personal information of almost 83k people compromised.

2023 was also a bad year for people’s health data security. Over a million NHS patients have had their sensitive information leaked following a ransomware attack on the University of Manchester – affecting 250 GB, or over a decade’s worth, of patient data. Worse still, the security vulnerabilities of the NHS go back as far as 2012 when the personal information of over 1.8 million patients and staff was exposed.

This trend is only likely to increase considering that cyberattacks are more frequent and destructive than ever thanks to the spread of AI and machine learning software. According to experts, healthcare is among the fields hit the most.

All this is even more worrying considering that, at the time of writing, the government’s ambitious plan is at a mere consultation stage – AKA, “we still have to figure out how to make these patient passports hacking-proof.”

Well, I don’t know about you but, as the situation stands now, I don’t trust that the NHS will take good care of my data anytime soon.

No clear plan to escape the “Big Brother” effect

Besides data security, there’s also another pressing question: how does the government plan to prevent privacy abuse? The plan is, Steering says, “to ensure patients’ data is protected and anonymized.” That’s great – on paper, at least. Again, authorities don’t have a clue how to do that in practice – and who knows if they ever will.

As health privacy advocates group medConfidential pointed out, these patient records will be accessible by any of the NHS’s 1.5 million staff. “Wes Streeting is planning a ’big brother’ database,” said Sam Smith, a spokesperson for the group, according to the Guardian. “A gift to stalkers and creeps who misuse NHS systems to find out the most basic private details that people only tell their doctors.”

Such a centralized database also increases the risk of private medical data being sold to big pharma and other companies without patients knowing about it. After all, something similar already happened with today’s messy and scattered health record system. Last year, an Observer investigation shed light on how a covert tracking tool placed on the websites of 20 NHS trusts has for years collected browsing information and shared it with Facebook.

I also agree with privacy expert Jamie Akhtar, co-founder and CEO at CyberSmart, when he says that medical records will pass from being managed by healthcare professionals to “the control of politicians, who might decide to sell this sensitive information to the highest bidder,” as Yahoo News reported.

NHS APP: now and tomorrow

The National Health Service (NHS) application is seen on a mobile device in this photo illustration on 13 July, 2023 in Warsaw, Poland.

(Image credit: Photo by Jaap Arriens/NurPhoto via Getty Images )

While an NHS App already exists, this comes with limitations as patients are still held locally (on their GP and visited hospitals system). The new app will de-facto reunite all the information about a patient across all parts of the health service in one place.

As we have seen, there’s still a lot that we don’t know about the current UK government’s plan of action to execute its ambitious goal of making the NHS great again. What we do know, though, is that Britons aren’t hopeful about the idea.

A public consultation published in May depicts a grim picture of public trust in the UK’s healthcare institutions, with respondents completely lacking confidence in the NHS cybersecurity system. Four out of five patients believe that NHS systems are vulnerable to cyberattacks. Moreover, almost half (49%) strongly believe that the NHS could make mistakes in the handling of their data.

Wes Steering is now urging both NHS staff and patients to take part in the “national conversation.” You have time until the start of next year to voice your concerns and share ideas at change.nhs.uk.

Yes, we all know that the NHS needs to be better, but to do so it’s crucial to have a solid plan of action to protect people’s data privacy and security. Noble ideas alone won’t save our most sensitive information from being leaked and abused.

https://www.techradar.com/computing/cyber-security/before-moving-from-analogue-to-digital-the-nhs-has-to-fix-its-privacy-flaws


November 2024
M T W T F S S
 123
45678910
11121314151617
18192021222324
252627282930  

About Us

Welcome to encircle News! We are a cutting-edge technology news company that is dedicated to bringing you the latest and greatest in everything tech. From automobiles to drones, software to hardware, we’ve got you covered.

At encircle News, we believe that technology is more than just a tool, it’s a way of life. And we’re here to help you stay on top of all the latest trends and developments in this ever-evolving field. We know that technology is constantly changing, and that can be overwhelming, but we’re here to make it easy for you to keep up.

We’re a team of tech enthusiasts who are passionate about everything tech and love to share our knowledge with others. We believe that technology should be accessible to everyone, and we’re here to make sure it is. Our mission is to provide you with fun, engaging, and informative content that helps you to understand and embrace the latest technologies.

From the newest cars on the road to the latest drones taking to the skies, we’ve got you covered. We also dive deep into the world of software and hardware, bringing you the latest updates on everything from operating systems to processors.

So whether you’re a tech enthusiast, a business professional, or just someone who wants to stay up-to-date on the latest advancements in technology, encircle News is the place for you. Join us on this exciting journey and be a part of shaping the future.

Podcasts

TWiT 1006: Underwater Alien Civilizations – Bluesky Growth, Tyson Vs. Paul, AI Granny This Week in Tech (Audio)

How Bluesky, Alternative to X and Facebook, Is Handling Explosive Growth Netflix's Live Mike Tyson Vs. Jake Paul Fight Battling Sound & Streaming Glitches In Lead-Up To Main Event Biden Asked Microsoft to "Raise the Bar on Cybersecurity." He May Have Helped Create an Illegal Monopoly. CFPB looks to place Google under federal supervision, setting up clash Apple's Tim Cook Has Ways to Cope With the Looming Trump Tariffs Apple Removes Another RFE/RL App At Request Of Russian Regulator Here's Why I Decided To Buy 'InfoWars' Elon Musk's X Corp. files notice in Alex Jones' Infowars bankruptcy case Spotify's Plans For AI Generated Music, Podcasts, and Recommendations, According To Its Co-President, CTO, and CPO Gustav Söderström This 'AI Granny' Bores Scammers to Tears Congress ponders underwater alien civilizations, human hybrids, and other unexplained stuff In Memoriam: Thomas E. Kurtz, 1928–2024 Host: Leo Laporte Guests: Alex Kantrowitz, Daniel Rubino, and Iain Thomson Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit
  1. TWiT 1006: Underwater Alien Civilizations – Bluesky Growth, Tyson Vs. Paul, AI Granny
  2. TWiT 1005: $125,000 in Baguettes – iPod Turns 23, The $1.1M AI Painting, Roblox
  3. TWiT 1004: Embrace Uncertainty – Political Texts, Daylight Saving Time, Digital Ad Market
  4. TWiT 1003: CrabStrike – Delta Sues Crowdstrike, Hospital AI, Surge Pricing
  5. TWiT 1002: Maximum Iceland Scenario – Data Caps, 3rd Party Android Stores, Nuclear Amazon