SlideShare a Scribd company logo
Privacy and mobile health: how to 
reduce our apptimism* 
* an unrealistic belief that apps solve every health problem 
Prof Jeremy Wyatt, University of Leeds 
Acknowledgements: Prof Justin Keen & Dr Jon Fistein
Outline 
1. Our data and why “anonymised” no longer means 
much 
2. How did we share our data in the pre-mobile era ? 
3. How do social media & mobile change this ? 
4. Does this “mHealth privacy gap” matter ? 
5. How professionals & the NHS manage your data 
6. What options do you have if this worries you ? 
7. Conclusions
1. What is “Our data” ? 
Information about us which: 
 We feel is ours 
 If revealed without permission could make us feel 
bad 
 Could also affect our reputation or prospects - of 
education, a job, social status, insurance, 
marriage…
Some views about who controls my data 
 It’s all mine and no-one can touch it unless I say 
so – not even researchers, security services etc. 
 It’s mine and I don’t want it published, but if 
society needs access it can look - as long as it 
takes care 
 There is no personal data: all data belong to the 
State
Guess who said this: 
“We’re … opening up the vast amounts of data generated in 
our health service. From this month huge amounts of new data 
are going to be released online. We’re going to consult on 
actually changing the NHS constitution so that the default 
setting is for patients’ data to be used for research unless of 
course they want to opt out. Now let me be clear, this does not 
threaten privacy, it doesn’t mean anyone can look at your 
health records but it does mean using anonymous data to 
make new medical breakthroughs... Now the end result will 
be… that every time you use the NHS you’re playing a part in 
the fight against disease at home and around the world.”
Open personal data 
 Voter registration 
 House prices 
 Care.data – health 
 HMRC tax records
How easy is it to identify you with no name ? 
 87% of US residents can be identified from 
age (not dob), sex, zip code (5 digits) 
 HES contains all hospital admissions from 
2001, partial postcode, sex and dob ! 
 Personal fitness data eg. Fitbit – can infer 
height, weight, gender from data; adding 
location makes it 100% unique,
2. Ways we already share data with companies 
 Loyalty cards 
 Motor insurance 
 Mailing lists & census data 
Web searches and mobile phones
Loyalty cards 
 We trade very small benefits for big companies 
knowing all about our shopping habits: 
 They know our fruit & veg, alcohol, contraceptive, 
OTC medicine purchases, clothing sizes, kid’s 
ages… 
 Man who discovered daughter was pregnant from 
supermarket vouchers 
 What use do they make of this knowledge – as 
well as putting the pasta sauce next to spaghetti 
?
Motor insurance 
 They know our driving history, type of car, 
miles per year, names of extended family, 
accidents 
 Telemetric insurance – box under bonnet 
measures location, speed, acceleration, 
braking, time of day / night to calculate risk & 
monthly premium 
 Industry share data “to prevent fraud”
How our data is shared in the information age 
 Google searches 
 Gmail - adverts 
Web cookies – just adverts ? 
 Social media - adverts 
 Location of our phone 
 Apps
Google flu trends
How do Google traffic maps work ? 
Cambridge traffic at 0600, 12-3- 
Since 2012, Google 14 
captures GPS data from 
Android phones, then 
processes it to give 
average speeds 
http://googleblog.blogsp 
ot.co.uk/2009/08/bright-side- 
of-sitting-in-traffic. 
html
3. Smart phone apps and beyond 
Apple’s App store contains > 1,000,000 apps 
32,000 lifestyle & 25,000 medical apps 
http://148apps.biz/app-store-metrics/?mpage=catcount 
3,000,000,000 downloads in December 
2013, costing $1,000,000,000 
http://www.apple.com/pr/library/2014/01/07App-Store-Sales-Top-10-Billion-in-2013.htmli 
https://openclipart.org/detail/182175/white-iphone-5-by-barrettward-182175
Privacy and mHealth apps 
 Permissions requested: use accounts, 
modify USB, read phone ID, find files, 
full net access, view connections… 
 Our study of 80 apps: average of 4 
clear privacy breaches for health apps, 
only 1 for medical apps 
 We know that - we read the Terms & 
Conditions ! (this one only 1200 words, 
but many much longer…) 
First Folio As You Like It Public Domain Photo taken by Cowardly 
Lion - Folio Society edition of 1996 
With Hannah Panayiotou & Anam Noel, 
Leeds medical students
Data brokers 
 “Even as you’re reading this, your smart 
phone can reveal your location… data 
brokers are going to know more about us 
than we know ourselves”. – Madhumita 
Venkataraman, Wired Nov 2014
Data you are currently sharing 
 Any phone – call data record (unique phone ID, 
phone no. called, time, location – every 7 
seconds) 
 Smart phone: 
 Wifi networks – unique MAC id (Viasense wifi 
sniffers) 
 Apps: everything you browse (WebMD); pregnancy 
due date (MyPregnancyToday), name, email, height, 
weight (Fitbit)
The data market 
Data sources Data aggregators 
Smart phone 
Credit agency 
Open data 
(electoral roll 
etc.) 
Social media 
Marketing agency 
Insurance data 
Data users 
Advertising 
Financial services 
Insurance industry 
brokers Health services ? 
Your 
purchase 
s 
and 
behaviou 
r 
Browsing history 
Purchase history 
(online, point of 
sale)
4. Does it matter - how companies use your data 
 Tailored mailings (everyone), tailored vouchers (eg. Tesco 
Clubcard) 
 Tailored adverts on web (Doubleclick, Eyeota, Experian…), 
 Tailored adverts in shopfronts – Tesco, Godiva (Shoppertrak 
instore wifi sensors) 
 Tailored products shown on websites, eg. CapitalOne cards – [x+1] 
website tracker product (200mS to generate your profile) 
 Tailored critical illness insurance – Inst of Actuaries, based on 
HES data 
 Make money – Facebook make £4 & Google £12 selling your 
cookie data to advertisers 
Total US interactive advertising market 2013: $43Bn
The Amscreen technology 
You stand outside a shop 
you want to 
enter shop 
TV camera TV screen 
Quividi algorithm 
Shop’s product database 
your age, 
gender 
time, location, 
stock levels 
images of suitable 
items, given age, 
gender, location, time
5. Health data: professional ethics 
 GMC and other professional bodies: 
obligation on clinicians to protect all personal 
data to best of their ability 
 Exceptions: 
 Notifiable diseases 
 High risk of immediate harm to others
How your GP and hospital manage your data 
 Personal data captured by GPs & hospitals is 
governed by Caldicott 2 principles 
 All data for management, research, quality 
improvement etc. must be stripped of identifiers 
 Caldicott Guardians help resolve grey areas 
 Central data returns to HSCIC: 
 National Hospital Episode Statistics 
 Many national audits on specific diseases 
 GPs may have to send in their data soon
Caldicott 2 principles 
 Justify the purpose(s) 
 Don't use patient identifiable information unless it is 
necessary 
 Use the minimum necessary patient-identifiable information 
 Access to patient identifiable information should be on a 
strict need-to-know basis 
 Everyone with access to patient identifiable information 
should be aware of their responsibilities 
 Understand and comply with the law 
 The duty to share information can be as important as the 
duty to protect patient confidentiality.
Three categories of data the NHS recognises 
Category of data Example How NHS manages it 
1. Personal level 
My diagnosis, blood 
identifiable data 
results 
Access by health professionals with a 
smart ID card and “legitimate 
relationship” only; audit trail of access 
2. Aggregated 
data 
Average waiting 
time; rate of 
anaemia 
Open publication - NHSChoices etc. 
3. Everything else 
– ie. anonymised 
personal level 
data 
Blood results for the 
last 1000 patients 
Secure “safe haven” to which 
researchers must log in after getting 
ethical approval, & where their actions 
are monitored
6. What options do you have if this worries you ? 
Option Pros Cons 
1. Do nothing, ignore it, it’ll 
go away 
Simple You get manipulated & 
your life choices may 
reduce 
2. Take an informed, 
sceptical approach to 
apps & data sharing 
Should improve your life a 
bit 
Untidy, never know if it’s 
helping or not 
3. Explore user controlled 
data schemes 
Empowers you by 
controlling your data 
Few organisations can 
cope with it yet 
4. Become a complete 
data recluse 
No erosion of privacy No smart phone, apps, 
social media…
Some questions to ask of any app before using it 
1. Who published this app ? 
2. Who is it for, and what is the purpose ? 
3. Where does my data go after it leaves the 
app ? 
4. Where did the content come from, and when ? 
5. Is its advice accurate ? 
6. Is there any evidence that it actually works ? 
(work of Leeds, Warwick & Coventry Universities & UCL, in 
collaboration with the Royal College of Physicians, London)
Our Data Mutual - www.ourdatamutual.org 
OUR MANIFESTO 
ONE 
Our data has a value. We want a cut of that value - and a say in how it's used. 
TWO 
We want our data to be used for good. 
THREE 
No one is responsible for protecting us from abuse of our data, so we're creating 'our data 
mutual' to protect ourselves.
MyDex 
 We provide you with a hyper-secure storage 
area so you can manage your personal 
data your way, from any aspect of your life. 
 This includes text, numbers, images, video, 
certificates and sound. 
 No-one but the individual can access or see the 
data 
 https://mydex.org/ - a social enterprise
Patients know best www.patientsknowbest.com 
 We put patients in control of their medical 
records. Everyone benefits, including 
clinicians, researchers and charities 
 We are a social enterprise, and our mission 
is that patients know best 
 BMJ online poll: 58% of 667 responders 
voted in favour of giving patients control of 
their records
MiData www.midatalab.org.uk/midata-explained 
 Midata programme (from BIS) encourages companies to hand 
personal transaction data they hold back to customers in machine 
readable format so they can use the data for their own purposes 
 MiData means every individual can get not just their personal 
data back but also valuable proof of relationships - ID Assurance 
 ID Assurance means using third-party evidence to prove claims, 
for example of name or address. 
 In paper world we do this with documents such as a passport or 
electricity bill. Midata delivers electronic versions of these. 
 Properly encrypted and signed, these help build up to a 
trustworthy online identity people can use to get things done.
7. Conclusions 
1. We knowingly (?) trade off our privacy for benefits 
2. Your GP and hospital work hard to protect your data 
3. Google, Facebook, Experian and now HSCIC don’t 
4. They trade your data as a commodity in a $43Bn+ 
global business 
5. The EU is tightening up data protection law soon, which 
may help a bit 
6. Meanwhile, you have several options to protect your 
data, including (soon) to control all your data yourself
The Law 
 EU Data Protection Directive now 
 UK Data Protection Act 
 EU Data Protection Regulation from 2015 
 Human Rights Act right to privacy
Current UK law 
Eight data protection principles: 
1. Fair processing: consent, vital interests or legal requirement to 
process data 
2. Obtained only for specified purpose 
3. Relevant, not excessive for purpose 
4. Accurate and kept up to date 
5. Not kept longer than needed 
6. Processed according to rights of data subjects 
7. Protection against unauthorised access or loss of data 
8. Not transferred outside EU
Additional requirements for processing sensitive 
data 
 Explicit consent* 
 Necessary to comply with law, or in course of legal proceedings 
 Necessary to protect vital interests of individual or another person 
 Carried out by not for profit & not disclosed elsewhere 
 Individual has published their data 
 Necessary for statutory or government functions (eg. RIP), carried out by 
health professional & necessary for medical purposes 
 Necessary to monitor equal opportunity 
* …”any freely given specific and informed indication of his wishes by which the 
data subject signifies his agreement to personal data relating to him being 
processed”.
EU General Data Protection Regulation 2015 
 Data controllers must be able to prove consent (opt-in – eg. 
cookies must ask for permission) 
 Consent may be withdrawn 
 Limited consent: scope and timescale 
 Right to erasure (replaced right to be forgotten) 
 Privacy by design; privacy defaults to highest setting 
 Sanctions: fine of up to 100M EUR or 5% of annual 
worldwide turnover, whichever is greater 
 Data Protection Impact Assessments to be conducted 
when specific risks may occur to rights or freedoms of data 
subjects

More Related Content

What's hot

COVID-19 Impact: Emerging Trends in Digital Health
COVID-19 Impact: Emerging Trends in Digital HealthCOVID-19 Impact: Emerging Trends in Digital Health
COVID-19 Impact: Emerging Trends in Digital Health
ExpertsConsult
 
Data, Ethics and Healthcare
Data, Ethics and HealthcareData, Ethics and Healthcare
Data, Ethics and Healthcare
Lee Schlenker
 
Rewarding Fitness Tracking —The Communication and Promotion of Health Insurer...
Rewarding Fitness Tracking —The Communication and Promotion of Health Insurer...Rewarding Fitness Tracking —The Communication and Promotion of Health Insurer...
Rewarding Fitness Tracking —The Communication and Promotion of Health Insurer...
iwhhu
 
5 healthcare technology transformation trends to watch out for in 2017
5 healthcare technology transformation trends to watch out for in 20175 healthcare technology transformation trends to watch out for in 2017
5 healthcare technology transformation trends to watch out for in 2017
Rahul Gupta
 
Telemedicine and the Transformation of Primary Care 2020/2021
Telemedicine and the Transformation of Primary Care 2020/2021Telemedicine and the Transformation of Primary Care 2020/2021
Telemedicine and the Transformation of Primary Care 2020/2021
Robert Mittendorff, MD, MBA
 
How Fitness And Wellness Apps Are Transforming The Healthcare Industry In Los...
How Fitness And Wellness Apps Are Transforming The Healthcare Industry In Los...How Fitness And Wellness Apps Are Transforming The Healthcare Industry In Los...
How Fitness And Wellness Apps Are Transforming The Healthcare Industry In Los...
Moon Technolabs Pvt. Ltd.
 
Social Media Considerations In Pharmacovigilance Visiongain 20110317 (Sande...
Social Media Considerations In Pharmacovigilance   Visiongain 20110317 (Sande...Social Media Considerations In Pharmacovigilance   Visiongain 20110317 (Sande...
Social Media Considerations In Pharmacovigilance Visiongain 20110317 (Sande...
Sandeep Bhat
 
A Few thoughts about Pharma Retailing
A Few thoughts about Pharma RetailingA Few thoughts about Pharma Retailing
A Few thoughts about Pharma RetailingScott McLaughlin
 
WEGO Health FDA Post-Presentation Data
WEGO Health FDA Post-Presentation DataWEGO Health FDA Post-Presentation Data
WEGO Health FDA Post-Presentation Data
WEGO Health
 
The Incredible Ways Artificial Intelligence Is Now Used In Mental Health
The Incredible Ways Artificial Intelligence Is Now Used In Mental HealthThe Incredible Ways Artificial Intelligence Is Now Used In Mental Health
The Incredible Ways Artificial Intelligence Is Now Used In Mental Health
Bernard Marr
 
TDI Startup Insurtech Award - Bct presentation
TDI Startup Insurtech Award - Bct presentationTDI Startup Insurtech Award - Bct presentation
TDI Startup Insurtech Award - Bct presentation
The Digital Insurer
 
Digital Health Care Technology
Digital Health Care TechnologyDigital Health Care Technology
Digital Health Care Technology
Nawanan Theera-Ampornpunt
 
Rock Health Demo Day June 2012
Rock Health Demo Day June 2012Rock Health Demo Day June 2012
Rock Health Demo Day June 2012
Lindsay Meyer
 
Social Media and Medicine: Fad or Shift?
Social Media and Medicine: Fad or Shift?Social Media and Medicine: Fad or Shift?
Social Media and Medicine: Fad or Shift?
Gregg Masters
 
The Complete Guide To Create A Telemedicine App Like Doctor-On-Demand
The Complete Guide To Create A Telemedicine App Like Doctor-On-DemandThe Complete Guide To Create A Telemedicine App Like Doctor-On-Demand
The Complete Guide To Create A Telemedicine App Like Doctor-On-Demand
Sparx IT Solutions Pvt Ltd
 
Consumer ED ILHIE toolkit for consumers
Consumer ED ILHIE toolkit for consumersConsumer ED ILHIE toolkit for consumers
Consumer ED ILHIE toolkit for consumers
Wirehead Technology
 
Health IT, Ethics & Law for Pathologists: Perils or Promises? (March 1, 2019)
Health IT, Ethics & Law for Pathologists: Perils or Promises? (March 1, 2019)Health IT, Ethics & Law for Pathologists: Perils or Promises? (March 1, 2019)
Health IT, Ethics & Law for Pathologists: Perils or Promises? (March 1, 2019)
Nawanan Theera-Ampornpunt
 
Wego Health FDA Post Presentation Data Ppt
Wego Health FDA Post Presentation Data PptWego Health FDA Post Presentation Data Ppt
Wego Health FDA Post Presentation Data Ppt
guest4c357f
 
Dose of Digital FDA Pharma Social Media Hearing Testimony - Corrective Inform...
Dose of Digital FDA Pharma Social Media Hearing Testimony - Corrective Inform...Dose of Digital FDA Pharma Social Media Hearing Testimony - Corrective Inform...
Dose of Digital FDA Pharma Social Media Hearing Testimony - Corrective Inform...
Jonathan Richman
 
Microsoft for healthcare storytelling
Microsoft for healthcare    storytellingMicrosoft for healthcare    storytelling
Microsoft for healthcare storytelling
Adrien Lainé ✪
 

What's hot (20)

COVID-19 Impact: Emerging Trends in Digital Health
COVID-19 Impact: Emerging Trends in Digital HealthCOVID-19 Impact: Emerging Trends in Digital Health
COVID-19 Impact: Emerging Trends in Digital Health
 
Data, Ethics and Healthcare
Data, Ethics and HealthcareData, Ethics and Healthcare
Data, Ethics and Healthcare
 
Rewarding Fitness Tracking —The Communication and Promotion of Health Insurer...
Rewarding Fitness Tracking —The Communication and Promotion of Health Insurer...Rewarding Fitness Tracking —The Communication and Promotion of Health Insurer...
Rewarding Fitness Tracking —The Communication and Promotion of Health Insurer...
 
5 healthcare technology transformation trends to watch out for in 2017
5 healthcare technology transformation trends to watch out for in 20175 healthcare technology transformation trends to watch out for in 2017
5 healthcare technology transformation trends to watch out for in 2017
 
Telemedicine and the Transformation of Primary Care 2020/2021
Telemedicine and the Transformation of Primary Care 2020/2021Telemedicine and the Transformation of Primary Care 2020/2021
Telemedicine and the Transformation of Primary Care 2020/2021
 
How Fitness And Wellness Apps Are Transforming The Healthcare Industry In Los...
How Fitness And Wellness Apps Are Transforming The Healthcare Industry In Los...How Fitness And Wellness Apps Are Transforming The Healthcare Industry In Los...
How Fitness And Wellness Apps Are Transforming The Healthcare Industry In Los...
 
Social Media Considerations In Pharmacovigilance Visiongain 20110317 (Sande...
Social Media Considerations In Pharmacovigilance   Visiongain 20110317 (Sande...Social Media Considerations In Pharmacovigilance   Visiongain 20110317 (Sande...
Social Media Considerations In Pharmacovigilance Visiongain 20110317 (Sande...
 
A Few thoughts about Pharma Retailing
A Few thoughts about Pharma RetailingA Few thoughts about Pharma Retailing
A Few thoughts about Pharma Retailing
 
WEGO Health FDA Post-Presentation Data
WEGO Health FDA Post-Presentation DataWEGO Health FDA Post-Presentation Data
WEGO Health FDA Post-Presentation Data
 
The Incredible Ways Artificial Intelligence Is Now Used In Mental Health
The Incredible Ways Artificial Intelligence Is Now Used In Mental HealthThe Incredible Ways Artificial Intelligence Is Now Used In Mental Health
The Incredible Ways Artificial Intelligence Is Now Used In Mental Health
 
TDI Startup Insurtech Award - Bct presentation
TDI Startup Insurtech Award - Bct presentationTDI Startup Insurtech Award - Bct presentation
TDI Startup Insurtech Award - Bct presentation
 
Digital Health Care Technology
Digital Health Care TechnologyDigital Health Care Technology
Digital Health Care Technology
 
Rock Health Demo Day June 2012
Rock Health Demo Day June 2012Rock Health Demo Day June 2012
Rock Health Demo Day June 2012
 
Social Media and Medicine: Fad or Shift?
Social Media and Medicine: Fad or Shift?Social Media and Medicine: Fad or Shift?
Social Media and Medicine: Fad or Shift?
 
The Complete Guide To Create A Telemedicine App Like Doctor-On-Demand
The Complete Guide To Create A Telemedicine App Like Doctor-On-DemandThe Complete Guide To Create A Telemedicine App Like Doctor-On-Demand
The Complete Guide To Create A Telemedicine App Like Doctor-On-Demand
 
Consumer ED ILHIE toolkit for consumers
Consumer ED ILHIE toolkit for consumersConsumer ED ILHIE toolkit for consumers
Consumer ED ILHIE toolkit for consumers
 
Health IT, Ethics & Law for Pathologists: Perils or Promises? (March 1, 2019)
Health IT, Ethics & Law for Pathologists: Perils or Promises? (March 1, 2019)Health IT, Ethics & Law for Pathologists: Perils or Promises? (March 1, 2019)
Health IT, Ethics & Law for Pathologists: Perils or Promises? (March 1, 2019)
 
Wego Health FDA Post Presentation Data Ppt
Wego Health FDA Post Presentation Data PptWego Health FDA Post Presentation Data Ppt
Wego Health FDA Post Presentation Data Ppt
 
Dose of Digital FDA Pharma Social Media Hearing Testimony - Corrective Inform...
Dose of Digital FDA Pharma Social Media Hearing Testimony - Corrective Inform...Dose of Digital FDA Pharma Social Media Hearing Testimony - Corrective Inform...
Dose of Digital FDA Pharma Social Media Hearing Testimony - Corrective Inform...
 
Microsoft for healthcare storytelling
Microsoft for healthcare    storytellingMicrosoft for healthcare    storytelling
Microsoft for healthcare storytelling
 

Similar to Jeremy Wyatt's Presentation on Privacy for the mHealthHabitat Heart of the Habitat Breakfast Session - 6th Nov 2014

The mobile health IT security challenge: way bigger than HIPAA?
The mobile health IT security challenge: way bigger than HIPAA?The mobile health IT security challenge: way bigger than HIPAA?
The mobile health IT security challenge: way bigger than HIPAA?
Stephen Cobb
 
Running head DATA PRIVACY 1 DATA PRIVACY10Short- and .docx
Running head DATA PRIVACY 1 DATA PRIVACY10Short- and .docxRunning head DATA PRIVACY 1 DATA PRIVACY10Short- and .docx
Running head DATA PRIVACY 1 DATA PRIVACY10Short- and .docx
todd271
 
Data set Legislation
Data set   Legislation Data set   Legislation
Data set Legislation
Data-Set
 
Commercial access to health data
Commercial access to health dataCommercial access to health data
Commercial access to health data
Ipsos UK
 
Smart Data Module 5 d drive_legislation
Smart Data Module 5 d drive_legislationSmart Data Module 5 d drive_legislation
Smart Data Module 5 d drive_legislation
caniceconsulting
 
Data set Legislation
Data set LegislationData set Legislation
Data set Legislation
Data-Set
 
Data set Legislation
Data set LegislationData set Legislation
Data set Legislation
Data-Set
 
Age Friendly Economy - Legislation and Ethics of Data Use
Age Friendly Economy - Legislation and Ethics of Data UseAge Friendly Economy - Legislation and Ethics of Data Use
Age Friendly Economy - Legislation and Ethics of Data Use
AgeFriendlyEconomy
 
Healthcare preparedness 2010
Healthcare preparedness 2010Healthcare preparedness 2010
Healthcare preparedness 2010DataMotion
 
Healthcare preparedness 2010
Healthcare preparedness 2010Healthcare preparedness 2010
Healthcare preparedness 2010DataMotion
 
Nicolas Terry, "Big Data, Regulatory Disruption, and Arbitrage in Health Care"
Nicolas Terry, "Big Data, Regulatory Disruption, and Arbitrage in Health Care"Nicolas Terry, "Big Data, Regulatory Disruption, and Arbitrage in Health Care"
Nicolas Terry, "Big Data, Regulatory Disruption, and Arbitrage in Health Care"
The Petrie-Flom Center for Health Law Policy, Biotechnology, and Bioethics
 
Data set module 4
Data set   module 4Data set   module 4
Data set module 4
Data-Set
 
Citizen controlled health data lockers as a game changer
Citizen controlled health data lockers as a game changerCitizen controlled health data lockers as a game changer
Citizen controlled health data lockers as a game changer
Wessel Kraaij
 
Unprecedented Technological Trends Push the Envelope in Life Sciences
Unprecedented Technological Trends Push the Envelope in Life SciencesUnprecedented Technological Trends Push the Envelope in Life Sciences
Unprecedented Technological Trends Push the Envelope in Life Sciences
Cognizant
 
Health data sharing from patients' perspective
Health data sharing from patients' perspectiveHealth data sharing from patients' perspective
Health data sharing from patients' perspective
ipposi
 
Data Privacy: What you need to know about privacy, from compliance to ethics
Data Privacy: What you need to know about privacy, from compliance to ethicsData Privacy: What you need to know about privacy, from compliance to ethics
Data Privacy: What you need to know about privacy, from compliance to ethics
AT Internet
 
Tmi spy health autumn 2013
Tmi spy health autumn 2013Tmi spy health autumn 2013
Tmi spy health autumn 2013
hoo384
 
Big data and cyber security legal risks and challenges
Big data and cyber security legal risks and challengesBig data and cyber security legal risks and challenges
Big data and cyber security legal risks and challenges
Kapil Mehrotra
 
4 Big Data Challenges In Healthcare
4 Big Data Challenges In Healthcare4 Big Data Challenges In Healthcare
4 Big Data Challenges In Healthcare
HPC Asia
 
Privacy and personal information presention of professional practice.pptx
Privacy and personal information presention of professional practice.pptxPrivacy and personal information presention of professional practice.pptx
Privacy and personal information presention of professional practice.pptx
sadia456189
 

Similar to Jeremy Wyatt's Presentation on Privacy for the mHealthHabitat Heart of the Habitat Breakfast Session - 6th Nov 2014 (20)

The mobile health IT security challenge: way bigger than HIPAA?
The mobile health IT security challenge: way bigger than HIPAA?The mobile health IT security challenge: way bigger than HIPAA?
The mobile health IT security challenge: way bigger than HIPAA?
 
Running head DATA PRIVACY 1 DATA PRIVACY10Short- and .docx
Running head DATA PRIVACY 1 DATA PRIVACY10Short- and .docxRunning head DATA PRIVACY 1 DATA PRIVACY10Short- and .docx
Running head DATA PRIVACY 1 DATA PRIVACY10Short- and .docx
 
Data set Legislation
Data set   Legislation Data set   Legislation
Data set Legislation
 
Commercial access to health data
Commercial access to health dataCommercial access to health data
Commercial access to health data
 
Smart Data Module 5 d drive_legislation
Smart Data Module 5 d drive_legislationSmart Data Module 5 d drive_legislation
Smart Data Module 5 d drive_legislation
 
Data set Legislation
Data set LegislationData set Legislation
Data set Legislation
 
Data set Legislation
Data set LegislationData set Legislation
Data set Legislation
 
Age Friendly Economy - Legislation and Ethics of Data Use
Age Friendly Economy - Legislation and Ethics of Data UseAge Friendly Economy - Legislation and Ethics of Data Use
Age Friendly Economy - Legislation and Ethics of Data Use
 
Healthcare preparedness 2010
Healthcare preparedness 2010Healthcare preparedness 2010
Healthcare preparedness 2010
 
Healthcare preparedness 2010
Healthcare preparedness 2010Healthcare preparedness 2010
Healthcare preparedness 2010
 
Nicolas Terry, "Big Data, Regulatory Disruption, and Arbitrage in Health Care"
Nicolas Terry, "Big Data, Regulatory Disruption, and Arbitrage in Health Care"Nicolas Terry, "Big Data, Regulatory Disruption, and Arbitrage in Health Care"
Nicolas Terry, "Big Data, Regulatory Disruption, and Arbitrage in Health Care"
 
Data set module 4
Data set   module 4Data set   module 4
Data set module 4
 
Citizen controlled health data lockers as a game changer
Citizen controlled health data lockers as a game changerCitizen controlled health data lockers as a game changer
Citizen controlled health data lockers as a game changer
 
Unprecedented Technological Trends Push the Envelope in Life Sciences
Unprecedented Technological Trends Push the Envelope in Life SciencesUnprecedented Technological Trends Push the Envelope in Life Sciences
Unprecedented Technological Trends Push the Envelope in Life Sciences
 
Health data sharing from patients' perspective
Health data sharing from patients' perspectiveHealth data sharing from patients' perspective
Health data sharing from patients' perspective
 
Data Privacy: What you need to know about privacy, from compliance to ethics
Data Privacy: What you need to know about privacy, from compliance to ethicsData Privacy: What you need to know about privacy, from compliance to ethics
Data Privacy: What you need to know about privacy, from compliance to ethics
 
Tmi spy health autumn 2013
Tmi spy health autumn 2013Tmi spy health autumn 2013
Tmi spy health autumn 2013
 
Big data and cyber security legal risks and challenges
Big data and cyber security legal risks and challengesBig data and cyber security legal risks and challenges
Big data and cyber security legal risks and challenges
 
4 Big Data Challenges In Healthcare
4 Big Data Challenges In Healthcare4 Big Data Challenges In Healthcare
4 Big Data Challenges In Healthcare
 
Privacy and personal information presention of professional practice.pptx
Privacy and personal information presention of professional practice.pptxPrivacy and personal information presention of professional practice.pptx
Privacy and personal information presention of professional practice.pptx
 

Recently uploaded

Bringing AI into a Mid-Sized Company: A structured Approach
Bringing AI into a Mid-Sized Company: A structured ApproachBringing AI into a Mid-Sized Company: A structured Approach
Bringing AI into a Mid-Sized Company: A structured Approach
Brian Frerichs
 
CANSA support - Caring for Cancer Patients' Caregivers
CANSA support - Caring for Cancer Patients' CaregiversCANSA support - Caring for Cancer Patients' Caregivers
CANSA support - Caring for Cancer Patients' Caregivers
CANSA The Cancer Association of South Africa
 
定制(wsu毕业证书)美国华盛顿州立大学毕业证学位证书实拍图原版一模一样
定制(wsu毕业证书)美国华盛顿州立大学毕业证学位证书实拍图原版一模一样定制(wsu毕业证书)美国华盛顿州立大学毕业证学位证书实拍图原版一模一样
定制(wsu毕业证书)美国华盛顿州立大学毕业证学位证书实拍图原版一模一样
khvdq584
 
Champions of Health Spotlight On Leaders Shaping Germany's Healthcare.pdf
Champions of Health Spotlight On Leaders Shaping Germany's Healthcare.pdfChampions of Health Spotlight On Leaders Shaping Germany's Healthcare.pdf
Champions of Health Spotlight On Leaders Shaping Germany's Healthcare.pdf
eurohealthleaders
 
DELIRIUM BY DR JAGMOHAN PRAJAPATI.......
DELIRIUM BY DR JAGMOHAN PRAJAPATI.......DELIRIUM BY DR JAGMOHAN PRAJAPATI.......
DELIRIUM BY DR JAGMOHAN PRAJAPATI.......
DR Jag Mohan Prajapati
 
Tips for Pet Care in winters How to take care of pets.
Tips for Pet Care in winters How to take care of pets.Tips for Pet Care in winters How to take care of pets.
Tips for Pet Care in winters How to take care of pets.
Dinesh Chauhan
 
PET CT beginners Guide covers some of the underrepresented topics in PET CT
PET CT  beginners Guide  covers some of the underrepresented topics  in PET CTPET CT  beginners Guide  covers some of the underrepresented topics  in PET CT
PET CT beginners Guide covers some of the underrepresented topics in PET CT
MiadAlsulami
 
Under Pressure : Kenneth Kruk's Strategy
Under Pressure : Kenneth Kruk's StrategyUnder Pressure : Kenneth Kruk's Strategy
Under Pressure : Kenneth Kruk's Strategy
Kenneth Kruk
 
TEST BANK For Accounting Information Systems, 3rd Edition by Vernon Richardso...
TEST BANK For Accounting Information Systems, 3rd Edition by Vernon Richardso...TEST BANK For Accounting Information Systems, 3rd Edition by Vernon Richardso...
TEST BANK For Accounting Information Systems, 3rd Edition by Vernon Richardso...
rightmanforbloodline
 
CMHPSM Regional Compliance Training 2024
CMHPSM Regional Compliance Training 2024CMHPSM Regional Compliance Training 2024
CMHPSM Regional Compliance Training 2024
JColaianne
 
DECODING THE RISKS - ALCOHOL, TOBACCO & DRUGS.pdf
DECODING THE RISKS - ALCOHOL, TOBACCO & DRUGS.pdfDECODING THE RISKS - ALCOHOL, TOBACCO & DRUGS.pdf
DECODING THE RISKS - ALCOHOL, TOBACCO & DRUGS.pdf
Dr Rachana Gujar
 
How Effective is Homeopathic Medicine for Anxiety and Stress Relief.pdf
How Effective is Homeopathic Medicine for Anxiety and Stress Relief.pdfHow Effective is Homeopathic Medicine for Anxiety and Stress Relief.pdf
How Effective is Homeopathic Medicine for Anxiety and Stress Relief.pdf
Dharma Homoeopathy
 
The positive impact of SGRT – The Berkshire Cancer Centre experience
The positive impact of SGRT – The Berkshire Cancer Centre experienceThe positive impact of SGRT – The Berkshire Cancer Centre experience
The positive impact of SGRT – The Berkshire Cancer Centre experience
SGRT Community
 
Cardiac Arrhythmias (2).pdf for nursing student
Cardiac Arrhythmias (2).pdf for nursing studentCardiac Arrhythmias (2).pdf for nursing student
Cardiac Arrhythmias (2).pdf for nursing student
fahmyahmed789
 
Rate Controlled Drug Delivery Systems.pdf
Rate Controlled Drug Delivery Systems.pdfRate Controlled Drug Delivery Systems.pdf
Rate Controlled Drug Delivery Systems.pdf
Rajarambapu College of Pharmacy Kasegaon Dist Sangli
 
Luxurious Spa In Ajman Chandrima Massage Center
Luxurious Spa In Ajman Chandrima Massage CenterLuxurious Spa In Ajman Chandrima Massage Center
Luxurious Spa In Ajman Chandrima Massage Center
Chandrima Spa Ajman
 
Deep Leg Vein Thrombosis (DVT): Meaning, Causes, Symptoms, Treatment, and Mor...
Deep Leg Vein Thrombosis (DVT): Meaning, Causes, Symptoms, Treatment, and Mor...Deep Leg Vein Thrombosis (DVT): Meaning, Causes, Symptoms, Treatment, and Mor...
Deep Leg Vein Thrombosis (DVT): Meaning, Causes, Symptoms, Treatment, and Mor...
The Lifesciences Magazine
 
INFECTION OF THE BRAIN -ENCEPHALITIS ( PPT)
INFECTION OF THE BRAIN -ENCEPHALITIS ( PPT)INFECTION OF THE BRAIN -ENCEPHALITIS ( PPT)
INFECTION OF THE BRAIN -ENCEPHALITIS ( PPT)
blessyjannu21
 
Cold Sores: Causes, Treatments, and Prevention Strategies | The Lifesciences ...
Cold Sores: Causes, Treatments, and Prevention Strategies | The Lifesciences ...Cold Sores: Causes, Treatments, and Prevention Strategies | The Lifesciences ...
Cold Sores: Causes, Treatments, and Prevention Strategies | The Lifesciences ...
The Lifesciences Magazine
 
CCSN_June_06 2024_jones. Cancer Rehabpptx
CCSN_June_06 2024_jones. Cancer RehabpptxCCSN_June_06 2024_jones. Cancer Rehabpptx
CCSN_June_06 2024_jones. Cancer Rehabpptx
Canadian Cancer Survivor Network
 

Recently uploaded (20)

Bringing AI into a Mid-Sized Company: A structured Approach
Bringing AI into a Mid-Sized Company: A structured ApproachBringing AI into a Mid-Sized Company: A structured Approach
Bringing AI into a Mid-Sized Company: A structured Approach
 
CANSA support - Caring for Cancer Patients' Caregivers
CANSA support - Caring for Cancer Patients' CaregiversCANSA support - Caring for Cancer Patients' Caregivers
CANSA support - Caring for Cancer Patients' Caregivers
 
定制(wsu毕业证书)美国华盛顿州立大学毕业证学位证书实拍图原版一模一样
定制(wsu毕业证书)美国华盛顿州立大学毕业证学位证书实拍图原版一模一样定制(wsu毕业证书)美国华盛顿州立大学毕业证学位证书实拍图原版一模一样
定制(wsu毕业证书)美国华盛顿州立大学毕业证学位证书实拍图原版一模一样
 
Champions of Health Spotlight On Leaders Shaping Germany's Healthcare.pdf
Champions of Health Spotlight On Leaders Shaping Germany's Healthcare.pdfChampions of Health Spotlight On Leaders Shaping Germany's Healthcare.pdf
Champions of Health Spotlight On Leaders Shaping Germany's Healthcare.pdf
 
DELIRIUM BY DR JAGMOHAN PRAJAPATI.......
DELIRIUM BY DR JAGMOHAN PRAJAPATI.......DELIRIUM BY DR JAGMOHAN PRAJAPATI.......
DELIRIUM BY DR JAGMOHAN PRAJAPATI.......
 
Tips for Pet Care in winters How to take care of pets.
Tips for Pet Care in winters How to take care of pets.Tips for Pet Care in winters How to take care of pets.
Tips for Pet Care in winters How to take care of pets.
 
PET CT beginners Guide covers some of the underrepresented topics in PET CT
PET CT  beginners Guide  covers some of the underrepresented topics  in PET CTPET CT  beginners Guide  covers some of the underrepresented topics  in PET CT
PET CT beginners Guide covers some of the underrepresented topics in PET CT
 
Under Pressure : Kenneth Kruk's Strategy
Under Pressure : Kenneth Kruk's StrategyUnder Pressure : Kenneth Kruk's Strategy
Under Pressure : Kenneth Kruk's Strategy
 
TEST BANK For Accounting Information Systems, 3rd Edition by Vernon Richardso...
TEST BANK For Accounting Information Systems, 3rd Edition by Vernon Richardso...TEST BANK For Accounting Information Systems, 3rd Edition by Vernon Richardso...
TEST BANK For Accounting Information Systems, 3rd Edition by Vernon Richardso...
 
CMHPSM Regional Compliance Training 2024
CMHPSM Regional Compliance Training 2024CMHPSM Regional Compliance Training 2024
CMHPSM Regional Compliance Training 2024
 
DECODING THE RISKS - ALCOHOL, TOBACCO & DRUGS.pdf
DECODING THE RISKS - ALCOHOL, TOBACCO & DRUGS.pdfDECODING THE RISKS - ALCOHOL, TOBACCO & DRUGS.pdf
DECODING THE RISKS - ALCOHOL, TOBACCO & DRUGS.pdf
 
How Effective is Homeopathic Medicine for Anxiety and Stress Relief.pdf
How Effective is Homeopathic Medicine for Anxiety and Stress Relief.pdfHow Effective is Homeopathic Medicine for Anxiety and Stress Relief.pdf
How Effective is Homeopathic Medicine for Anxiety and Stress Relief.pdf
 
The positive impact of SGRT – The Berkshire Cancer Centre experience
The positive impact of SGRT – The Berkshire Cancer Centre experienceThe positive impact of SGRT – The Berkshire Cancer Centre experience
The positive impact of SGRT – The Berkshire Cancer Centre experience
 
Cardiac Arrhythmias (2).pdf for nursing student
Cardiac Arrhythmias (2).pdf for nursing studentCardiac Arrhythmias (2).pdf for nursing student
Cardiac Arrhythmias (2).pdf for nursing student
 
Rate Controlled Drug Delivery Systems.pdf
Rate Controlled Drug Delivery Systems.pdfRate Controlled Drug Delivery Systems.pdf
Rate Controlled Drug Delivery Systems.pdf
 
Luxurious Spa In Ajman Chandrima Massage Center
Luxurious Spa In Ajman Chandrima Massage CenterLuxurious Spa In Ajman Chandrima Massage Center
Luxurious Spa In Ajman Chandrima Massage Center
 
Deep Leg Vein Thrombosis (DVT): Meaning, Causes, Symptoms, Treatment, and Mor...
Deep Leg Vein Thrombosis (DVT): Meaning, Causes, Symptoms, Treatment, and Mor...Deep Leg Vein Thrombosis (DVT): Meaning, Causes, Symptoms, Treatment, and Mor...
Deep Leg Vein Thrombosis (DVT): Meaning, Causes, Symptoms, Treatment, and Mor...
 
INFECTION OF THE BRAIN -ENCEPHALITIS ( PPT)
INFECTION OF THE BRAIN -ENCEPHALITIS ( PPT)INFECTION OF THE BRAIN -ENCEPHALITIS ( PPT)
INFECTION OF THE BRAIN -ENCEPHALITIS ( PPT)
 
Cold Sores: Causes, Treatments, and Prevention Strategies | The Lifesciences ...
Cold Sores: Causes, Treatments, and Prevention Strategies | The Lifesciences ...Cold Sores: Causes, Treatments, and Prevention Strategies | The Lifesciences ...
Cold Sores: Causes, Treatments, and Prevention Strategies | The Lifesciences ...
 
CCSN_June_06 2024_jones. Cancer Rehabpptx
CCSN_June_06 2024_jones. Cancer RehabpptxCCSN_June_06 2024_jones. Cancer Rehabpptx
CCSN_June_06 2024_jones. Cancer Rehabpptx
 

Jeremy Wyatt's Presentation on Privacy for the mHealthHabitat Heart of the Habitat Breakfast Session - 6th Nov 2014

  • 1. Privacy and mobile health: how to reduce our apptimism* * an unrealistic belief that apps solve every health problem Prof Jeremy Wyatt, University of Leeds Acknowledgements: Prof Justin Keen & Dr Jon Fistein
  • 2. Outline 1. Our data and why “anonymised” no longer means much 2. How did we share our data in the pre-mobile era ? 3. How do social media & mobile change this ? 4. Does this “mHealth privacy gap” matter ? 5. How professionals & the NHS manage your data 6. What options do you have if this worries you ? 7. Conclusions
  • 3. 1. What is “Our data” ? Information about us which:  We feel is ours  If revealed without permission could make us feel bad  Could also affect our reputation or prospects - of education, a job, social status, insurance, marriage…
  • 4. Some views about who controls my data  It’s all mine and no-one can touch it unless I say so – not even researchers, security services etc.  It’s mine and I don’t want it published, but if society needs access it can look - as long as it takes care  There is no personal data: all data belong to the State
  • 5. Guess who said this: “We’re … opening up the vast amounts of data generated in our health service. From this month huge amounts of new data are going to be released online. We’re going to consult on actually changing the NHS constitution so that the default setting is for patients’ data to be used for research unless of course they want to opt out. Now let me be clear, this does not threaten privacy, it doesn’t mean anyone can look at your health records but it does mean using anonymous data to make new medical breakthroughs... Now the end result will be… that every time you use the NHS you’re playing a part in the fight against disease at home and around the world.”
  • 6. Open personal data  Voter registration  House prices  Care.data – health  HMRC tax records
  • 7. How easy is it to identify you with no name ?  87% of US residents can be identified from age (not dob), sex, zip code (5 digits)  HES contains all hospital admissions from 2001, partial postcode, sex and dob !  Personal fitness data eg. Fitbit – can infer height, weight, gender from data; adding location makes it 100% unique,
  • 8. 2. Ways we already share data with companies  Loyalty cards  Motor insurance  Mailing lists & census data Web searches and mobile phones
  • 9. Loyalty cards  We trade very small benefits for big companies knowing all about our shopping habits:  They know our fruit & veg, alcohol, contraceptive, OTC medicine purchases, clothing sizes, kid’s ages…  Man who discovered daughter was pregnant from supermarket vouchers  What use do they make of this knowledge – as well as putting the pasta sauce next to spaghetti ?
  • 10. Motor insurance  They know our driving history, type of car, miles per year, names of extended family, accidents  Telemetric insurance – box under bonnet measures location, speed, acceleration, braking, time of day / night to calculate risk & monthly premium  Industry share data “to prevent fraud”
  • 11. How our data is shared in the information age  Google searches  Gmail - adverts Web cookies – just adverts ?  Social media - adverts  Location of our phone  Apps
  • 13. How do Google traffic maps work ? Cambridge traffic at 0600, 12-3- Since 2012, Google 14 captures GPS data from Android phones, then processes it to give average speeds http://googleblog.blogsp ot.co.uk/2009/08/bright-side- of-sitting-in-traffic. html
  • 14. 3. Smart phone apps and beyond Apple’s App store contains > 1,000,000 apps 32,000 lifestyle & 25,000 medical apps http://148apps.biz/app-store-metrics/?mpage=catcount 3,000,000,000 downloads in December 2013, costing $1,000,000,000 http://www.apple.com/pr/library/2014/01/07App-Store-Sales-Top-10-Billion-in-2013.htmli https://openclipart.org/detail/182175/white-iphone-5-by-barrettward-182175
  • 15. Privacy and mHealth apps  Permissions requested: use accounts, modify USB, read phone ID, find files, full net access, view connections…  Our study of 80 apps: average of 4 clear privacy breaches for health apps, only 1 for medical apps  We know that - we read the Terms & Conditions ! (this one only 1200 words, but many much longer…) First Folio As You Like It Public Domain Photo taken by Cowardly Lion - Folio Society edition of 1996 With Hannah Panayiotou & Anam Noel, Leeds medical students
  • 16. Data brokers  “Even as you’re reading this, your smart phone can reveal your location… data brokers are going to know more about us than we know ourselves”. – Madhumita Venkataraman, Wired Nov 2014
  • 17. Data you are currently sharing  Any phone – call data record (unique phone ID, phone no. called, time, location – every 7 seconds)  Smart phone:  Wifi networks – unique MAC id (Viasense wifi sniffers)  Apps: everything you browse (WebMD); pregnancy due date (MyPregnancyToday), name, email, height, weight (Fitbit)
  • 18. The data market Data sources Data aggregators Smart phone Credit agency Open data (electoral roll etc.) Social media Marketing agency Insurance data Data users Advertising Financial services Insurance industry brokers Health services ? Your purchase s and behaviou r Browsing history Purchase history (online, point of sale)
  • 19. 4. Does it matter - how companies use your data  Tailored mailings (everyone), tailored vouchers (eg. Tesco Clubcard)  Tailored adverts on web (Doubleclick, Eyeota, Experian…),  Tailored adverts in shopfronts – Tesco, Godiva (Shoppertrak instore wifi sensors)  Tailored products shown on websites, eg. CapitalOne cards – [x+1] website tracker product (200mS to generate your profile)  Tailored critical illness insurance – Inst of Actuaries, based on HES data  Make money – Facebook make £4 & Google £12 selling your cookie data to advertisers Total US interactive advertising market 2013: $43Bn
  • 20. The Amscreen technology You stand outside a shop you want to enter shop TV camera TV screen Quividi algorithm Shop’s product database your age, gender time, location, stock levels images of suitable items, given age, gender, location, time
  • 21. 5. Health data: professional ethics  GMC and other professional bodies: obligation on clinicians to protect all personal data to best of their ability  Exceptions:  Notifiable diseases  High risk of immediate harm to others
  • 22. How your GP and hospital manage your data  Personal data captured by GPs & hospitals is governed by Caldicott 2 principles  All data for management, research, quality improvement etc. must be stripped of identifiers  Caldicott Guardians help resolve grey areas  Central data returns to HSCIC:  National Hospital Episode Statistics  Many national audits on specific diseases  GPs may have to send in their data soon
  • 23. Caldicott 2 principles  Justify the purpose(s)  Don't use patient identifiable information unless it is necessary  Use the minimum necessary patient-identifiable information  Access to patient identifiable information should be on a strict need-to-know basis  Everyone with access to patient identifiable information should be aware of their responsibilities  Understand and comply with the law  The duty to share information can be as important as the duty to protect patient confidentiality.
  • 24. Three categories of data the NHS recognises Category of data Example How NHS manages it 1. Personal level My diagnosis, blood identifiable data results Access by health professionals with a smart ID card and “legitimate relationship” only; audit trail of access 2. Aggregated data Average waiting time; rate of anaemia Open publication - NHSChoices etc. 3. Everything else – ie. anonymised personal level data Blood results for the last 1000 patients Secure “safe haven” to which researchers must log in after getting ethical approval, & where their actions are monitored
  • 25. 6. What options do you have if this worries you ? Option Pros Cons 1. Do nothing, ignore it, it’ll go away Simple You get manipulated & your life choices may reduce 2. Take an informed, sceptical approach to apps & data sharing Should improve your life a bit Untidy, never know if it’s helping or not 3. Explore user controlled data schemes Empowers you by controlling your data Few organisations can cope with it yet 4. Become a complete data recluse No erosion of privacy No smart phone, apps, social media…
  • 26. Some questions to ask of any app before using it 1. Who published this app ? 2. Who is it for, and what is the purpose ? 3. Where does my data go after it leaves the app ? 4. Where did the content come from, and when ? 5. Is its advice accurate ? 6. Is there any evidence that it actually works ? (work of Leeds, Warwick & Coventry Universities & UCL, in collaboration with the Royal College of Physicians, London)
  • 27. Our Data Mutual - www.ourdatamutual.org OUR MANIFESTO ONE Our data has a value. We want a cut of that value - and a say in how it's used. TWO We want our data to be used for good. THREE No one is responsible for protecting us from abuse of our data, so we're creating 'our data mutual' to protect ourselves.
  • 28. MyDex  We provide you with a hyper-secure storage area so you can manage your personal data your way, from any aspect of your life.  This includes text, numbers, images, video, certificates and sound.  No-one but the individual can access or see the data  https://mydex.org/ - a social enterprise
  • 29. Patients know best www.patientsknowbest.com  We put patients in control of their medical records. Everyone benefits, including clinicians, researchers and charities  We are a social enterprise, and our mission is that patients know best  BMJ online poll: 58% of 667 responders voted in favour of giving patients control of their records
  • 30. MiData www.midatalab.org.uk/midata-explained  Midata programme (from BIS) encourages companies to hand personal transaction data they hold back to customers in machine readable format so they can use the data for their own purposes  MiData means every individual can get not just their personal data back but also valuable proof of relationships - ID Assurance  ID Assurance means using third-party evidence to prove claims, for example of name or address.  In paper world we do this with documents such as a passport or electricity bill. Midata delivers electronic versions of these.  Properly encrypted and signed, these help build up to a trustworthy online identity people can use to get things done.
  • 31. 7. Conclusions 1. We knowingly (?) trade off our privacy for benefits 2. Your GP and hospital work hard to protect your data 3. Google, Facebook, Experian and now HSCIC don’t 4. They trade your data as a commodity in a $43Bn+ global business 5. The EU is tightening up data protection law soon, which may help a bit 6. Meanwhile, you have several options to protect your data, including (soon) to control all your data yourself
  • 32.
  • 33. The Law  EU Data Protection Directive now  UK Data Protection Act  EU Data Protection Regulation from 2015  Human Rights Act right to privacy
  • 34. Current UK law Eight data protection principles: 1. Fair processing: consent, vital interests or legal requirement to process data 2. Obtained only for specified purpose 3. Relevant, not excessive for purpose 4. Accurate and kept up to date 5. Not kept longer than needed 6. Processed according to rights of data subjects 7. Protection against unauthorised access or loss of data 8. Not transferred outside EU
  • 35. Additional requirements for processing sensitive data  Explicit consent*  Necessary to comply with law, or in course of legal proceedings  Necessary to protect vital interests of individual or another person  Carried out by not for profit & not disclosed elsewhere  Individual has published their data  Necessary for statutory or government functions (eg. RIP), carried out by health professional & necessary for medical purposes  Necessary to monitor equal opportunity * …”any freely given specific and informed indication of his wishes by which the data subject signifies his agreement to personal data relating to him being processed”.
  • 36. EU General Data Protection Regulation 2015  Data controllers must be able to prove consent (opt-in – eg. cookies must ask for permission)  Consent may be withdrawn  Limited consent: scope and timescale  Right to erasure (replaced right to be forgotten)  Privacy by design; privacy defaults to highest setting  Sanctions: fine of up to 100M EUR or 5% of annual worldwide turnover, whichever is greater  Data Protection Impact Assessments to be conducted when specific risks may occur to rights or freedoms of data subjects