The eternal conundrum between data protection rights and public health research and social care needs - lessons to be learned by Government on transparency and accountability in pandemic times
Mass patient data collection and exploitation may offer unprecedented benefits to advance public health research and social care at a critical time for the UK and the rest of the world, still grappling with the COVID-19 pandemic. But with great power comes great responsibility and governments have a duty to communicate, explain and obtain regulators' and public support for the public health policy they intend to pursue and the ways they intend to protect individuals data protection rights prior to implementing critical systemic changes to national GP data collection.
WHAT IS THE NEW GPDPR PROGRAMME ABOUT?
NHS Digital is the national custodian for health and care data in England and has responsibility for standardising, collecting, analysing, publishing and sharing data and information from across the health and social care system, including general practice. In April 2021, the Secretary of State for Health and Social Care issued a Direction under the Health and Social Care Act 2012 requiring NHS Digital to establish and operate an information system for the collection and analysis of General Practice data for health and social care purposes.
To date, NHS Digital collects patient data from general practices using a service called the General Practice Extraction Service (GPES). On May 12, NHS Digital issued a Data Provision Notice to GPs to let them know that the GPES will be replaced by the brand new GPDPR programme from 1 July 2021 with the aim to collect pseudonymised GP data daily to support vital health and care planning and research. However, if healthcare professionals may have been taken aback by the announcement of the forthcoming GPDPR, health industry organisations were quick to voice their concerns over the lack of communication and engagement with the public over the new service.
In practice, the data collected will not include patients' names and addresses but could include a patient's NHS number, date of birth, full postcode as well as information about mental health, domestic violence, treatments and addictions.
There is therefore a statutory basis for the information sharing under the GPDPR. This is not, however, a 'silver bullet' for the scheme. Concerns that not enough time has been given to let people know specific information about the service, its purposes, patient rights to opt-out and that patient trust could be destroyed have been raised. In response to growing general concerns, the implementation date for the programme has now been moved from 1 July to 1 September 2021 to ensure that more time is allocated to speak with patients, doctors and health charities about the plans.
WHAT ARE THE KEY DATA PROTECTION CONCERNS?
KEY TAKEAWAYS
This is not the first time that a data sharing programme relating to GP-held medical records has been exposed to widespread criticism. In 2013, NHS England launched its 'Care-data' project to extract GP medical records but this was quickly abandoned due to a lack of transparency and concerns about security and pseudonymisation.
Concerns with 'big tech' access to NHS data were previously addressed in 2016 when Google DeepMind entered into a data sharing arrangement with the Royal Free NHS Foundation Trust in London[1]. The Trust provided the personal data of around 1.6m patients to Google DeepMind as part of a data sharing trial but the ICO found that there was a lack of transparency about how the Trust would be using patient information and therefore patients could not exercise their statutory right to object to the processing of their information. The Information Commissioner said at the time: "There's no doubt the huge potential that creative use of data could have on patient care and clinical improvements, but the price of innovation does not need to be the erosion of fundamental privacy rights."
The COVID-19 pandemic has demonstrated that data sharing and data analysis is vital to improve patient outcomes and public health. However, compliance with privacy laws must be ensured beforehand and, above all, transparency for data subjects is key.
This was emphasised again recently by the UK Information Commissioner in reference to the programme: "The success of any project will rely on people trusting and having confidence in how their personal data will be used. It is crucial that, from the start, thought is given to how this can be explained clearly to people."
[1] Please see Dr Nathalie Moreno's article: The rise of big tech monetising healthcare data, Comments in Information Age published on 24 February 2020.