Showing posts with label Data Protection. Show all posts
Showing posts with label Data Protection. Show all posts

Sunday, November 23, 2014

How to protect Medical Data

Medical information and Database Systems


How does one model a data system, this was a question posed in recent discussion. Normally this should be implemented based on best practice of Database analysis and Requirements engineering.




This therefore involves a number of stages.

1- Talk to the clients
2- Create various use cases
3- Model the data using Entity-Relationship Diagrams
4- Normalise the Data from above.
5- Create the database
None of these directly impinges on legal matters, beyond the normal contractual obligations a designer owes the employer and the standard data protection rules that are present in now nearly all jurisdictions.

However, there is one aspect of data modeling where there is special emphasis, is that of sensitive data :specifically that which has its origins from medical patients. Sensitive data is of the kind mentioned as per the EU's Data Privacy Directive Article 8 as "racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, and the processing of data concerning health". Given the confidenital nature of the Doctor/Patient relationship, there must be a reasonable expectation of privacy.


Therefore the best practices which can be designed to secure this are:
- Ensure that there is adequate physical security. For instance where the data is being processed on site that simple steps such as having secure ids to enter a lockable room should be standard.
- Ensure that there is adequate electronic security. That access to computers must depend on at least one stage security methods; such as fingerprints or passwords unique to each user.
- That the Sysadmin ensures that the virus protections are functional and has a process for updating & patching the underlying operating system to combat Zero-Day exploits.
- Use the Database system itself as a tool to provide security. Instead of allowing a normal access user to view the underlying table, create views which filter out only data which the user can access to fulfill their role, but no more than that. In additional engaging auditing of who viewed, updated or deleted records, This provides an excellent tool to investigators overseeing any potential issues.
- Finally, if the data were encrypted this would potentially foil any large scale data breach.

Medical data is valuable. The UK's NHS has advanced plans in place to sell such to companies - link. This data will undergo anonymization so as to purge the personal details of patients: thus removing the data from the remit of the EU Data Directive. That this process can sometimes be undone is known from such well documented cases as Netflix. 

Thus this implies a need to design security considerations within the DNA of any database system which processes medical records. This should be done both to protect a valued economic resource and to remain within a statutory duty.



Sunday, November 9, 2014

Data Privacy at Work and Anton Piller Orders

Data Privacy at Work and Anton Piller Orders

Privacy is a right. But like a majority of such is not absolute. There are usually a slew of other rights (several hundred according to Eric Posner's "Twilight of human rights") which need be balanced. Thus at work the employer has a measured right as well to monitor employees, within a reasonable limit.



The cases of Halford v UK (1997) 24 EHRR 523 and Copland v UK (2007) 45 EHRR 37  suggest there also has to be reasonable expectation of privacy at work to balance this. So if there was a credible threat of larceny involved it would seem to be correct to monitor, provided the employees were informed clearly and in good time. This type of data is also a resource so has a measure of value: for instance if companies are being merged, then up to a certain point it would be sensible not to swap employee personal data or at least make real efforts to anonymise the records in a commercial context.

Thus from an IT perspective, how does this relate to company supplied mobile devices such as smart phones? The data found within these, both in internal or external storage thanks to Moore's law, is always expanding. Even if no personal data or apps were permitted, the fact that geo-location data is captured during non-core office hours means not only is personal data being stored, but the protected class known as sensitive data could be viewed by employers. For instance, that an employee is going to a specialist doctor or at a rival's place of business would not be facts that the employee would wish to share.

These are not the only non-state actor that could view the personal data. There is the civil search warrant present in Common law countries known as the Anton Piller order. This is basically a search and seize order. This has been called the "Stealthbomber" of litigation. However, given that Data Protection is of EU Directive origin, would suggest that such orders need to modified to respect the personal information of the employee.
If there were to be shown the existence of procedural problems with the safety of this data, this would call into question the proportionality of any such order and would likely result in the designated Data Protection office becoming involved. The adverse publicity and possible fines could then apply as core individual EU rights are not lightly breached.


Sunday, October 26, 2014

Has Data Protection gone a step too far in Europe?


Data protection is very much part and parcel of the human rights driven approach that the EU has taken for personal data. Leaving aside the rather broad exceptions that are present for the state when it comes to gathering information on people when it comes to revenue and taxes (under section 8 of the Data Directive 1995) this is broadly a positive step. However as the saying goes, too much of a good intention can lead inter alia to a poor outcome. In this case, the use of data to better serve customer needs being waylaid.



This has in part been prompted by the reading of the book, What Stays in Vegas: The World of Personal Data by Adam Tanner. Here there are numerous negative examples of how Big Data and how the prevalence of digitization has lead to personal data being used for morally questionable outcomes. For instance the use of criminal mugshots in websites for the titillation of the general populace would likely give a typical Data Protection commissioner fits. This is very much in keeping with the commercial driven agenda where the worth of the data is key to understanding how the US crafts their rather minimalist data protection laws.

On the other hand, where commercial interests are present so too are the technological innovation that goes hand in hand with such. Key to this was the paper, written in part by CEO of a Vegas Corp. Gary Loveman, "Putting the Service-Profit Chain to Work" which traces the importance of the regular customer. Whilst he/she in an average transaction might not spend much, a satisfied customer in their lifetime would be the sum total of their entire spending and as such would be equivalent to the occasional bigger spender. This insight lead to more emphasis on data gathering on these heretofore unremarked segments of the market place and the use of Big data to better craft personalised products to keep them as regular spenders. As Tanner in his book mentions in the context of gathering this data, there is a market imperative to keep much of this open and voluntary as even the suggestion of "creepiness" would lose the client and perhaps draw the ire of the legislators. As well in parallel, this drives the technological innovation of Big data.


Thus while not saying their should be a whole scale rollback of the EU data protection, given that the current directive is being overhauled to make it fit for the Cloud/Big Data purpose, it would be relevant to note that the societal good can as well be serviced by for-profit motivations.