Complaint:!NHS!Data!Storage!in!the!Google!Cloud!

Size: px
Start display at page:

Download "Complaint:!NHS!Data!Storage!in!the!Google!Cloud!"

Transcription

1 13 th March2014 ChristopherGraham, InformationCommissioner, WycliffeHouse,WaterLane, WILMSLOW,CheshireSK95AF DearChris, Complaint:NHSDataStorageintheGoogleCloud WearewritingaboutrecentdisclosuresoftheuseofNHSdatabyPAconsultingandwerequest thatyourofficeinvestigateapparentlyseriousbreachesofthedataprotectionact1998. Background Aspartofadataanalyticsproject,theNHSInformationCentre(NHSIC) apredecessorofthe Health&SocialCareInformationCentre(HSCIC) enteredintoanagreementtosharehospital EpisodeStatistics(HES)datawithPAConsultingGroup(PA)inNovember2011.Thedata sharingagreementallegedlyimposesanumberofrestrictionsonpa suseofthehesdata, includingalimitationonthenumberofpeoplethatcanaccessthedata,arestrictiononsharing thedatawiththirdparties,andanobligationtoerasethedatafollowingtheterminationofthe agreement. AccordingtoanHSCICpressstatement,theshareddatasetsinclude pseudonymised HESon allnhsinpatienttreatments,outpatientappointmentsanda&eattendancesinengland. 1 Each HESrecordgenerallycontainsabroadrangeofinformationaboutindividualNHSpatients,such asagegroup,genderandethnicity,diagnosticandtreatmentcodes,andinformationaboutthe 1 HSCIC%Statement:%Use%of%data%by%PA%consulting,3March2014,availableat: 2 See,HSCIC,What%HES%data%are%available?,availableat: 1

2 locationwherethepatientwastreatedandwherehe/shelives. 2 BydefaultHESdatacontain thepatient spostcodeanddateofbirth,whichincombinationareenoughtore_identifyabout 98%ofpatients;itisunclearwhetherthesedatawereredactedinthiscase.Evenwithoutthese data,longitudinalmedicalrecordsareoftenveryeasytore_identify. InordertoanalyseandmanipulatetheHESdata,PAdecidedtousethird_partytoolssupplied bygoogle.specifically,pauploadedthehesdatatogooglestorage,andprocesseditviaa Googleanalyticsservice,GoogleBigQuery.(GoogleBigQueryisacloudservicethatallows interactiveanalysisoflargedatasets.)whilelittleisknownabouttheagreementbetweenpa andgoogle,padidprovidenhsicwithawrittenconfirmationthatnogooglestaffwouldgain accesstothehesdataandthat accesscontinuedtoberestrictedtotheindividualsnamedin thedatasharingagreement. 3 NeitherPAnorHSCIChaveprovidedanyinformationaboutthe assurances,ifany,theyreceivedfromgoogle.itisdifficulttoseehowpacouldexcludethe possibilitythatgoogleengineersmightaccessthedata,whetheroftheirownvolitionor pursuanttoalawfulaccessrequestfromausgovernmentagency,andthisraisesthequestion ofwhetherpa sconfirmationwasanythingmorethanjustwishfulthinkingoradesperate attemptatblameavoidance. Whenthedetailsofthisdata_sharingarrangementbecamepublic,stakeholderswerehighly concerned.mpsarahwollaston,whositsonthehealthselectcommittee,tweeted:"sohes datauploadedto'google'simmensearmyofservers',whoconsentedtothat@hscic?" 4.This concernisunsurprisinggivengoogle srecordonprivacy;inrecentyears,googlewasfoundto havebreachedeudataprotectionlawbytheeu sarticle29workingparty,aswellasby regulatorsinanumberofmemberstates. Issues InrespectofthoseHESrecordsthatqualifyaspersonalhealthinformation,arangeofcomplex legalandprofessionalobligationsrestrictorprohibittheuseanddisclosureofsuchdata, includingtheukdataprotectionact1998,thecommon_lawdutyofconfidence,thehuman 2 See,HSCIC,What%HES%data%are%available?,availableat: 3 HSCIC%Statement,%supran ComplainttoICOregardinguseofNHSdata 2

3 RightsAct1998,theNHSConfidentialityCodeofPractice,andtheInformationSecurityNHS CodeofPractice. 5 AlthoughPA spressstatementclaimsthattheshareddatasetdoesnotcontainanyinformation thatcouldbelinkedaspecificindividual, 6 itisquiteunclearhowthatstatementcouldbe correct.evenifthehesdatasetstoredingoogle scloudservicesdoesnotcontainapatient s nameornhsnumber,thedatatheremaybeeasytolinktoaspecificindividualandhencewill oftenconstitutesensitivepersonaldata.arecordofacatheterablationprocedureat HammersmithHospitalonOctober19th2003canbelinkedwithhighprobabilitytoTonyBlair onthebasisofpressreportsofhistreatmentforatrialfibrillation,andifthedatasetpermits episodesrelatingtohimtobelinked,thensensitivepersonalinformationrelatingtohisother treatmentepisodesmaybeveryeasytofind.alargeresearchliteraturegoingbacktothelate 1970sexploresthesubstantialriskthatindividualsmaybere_identifiedfrompseudonymised datasets. 7 ThedatasenttotheGoogleCloudmustthereforebetreatedaspersonaldata,and indeedassensitivepersonaldata,forthepurposesofeuropeanandukdataprotectionlaw evenifpostcodesanddatesofbirthwereinfactremoved.wenotethatneitherhscicnorpa hassofarclaimedthatpostcodeswereremoved. Werequestthatyouconductaninvestigationtodeterminewhetherthepersonalhealth informationofnhspatients,includingthesignatoriestothisletter,wasuploadedtogoogle systems. Ifso,storingandprocessingsuchdatawouldprobablybreachnumerousrulesandregulations. Inparticular: Personalhealthinformationshouldnotbedisclosedtothirdpartiesexceptinvery limitedcircumstances.thedata_sharingagreementbetweennhsicandparestricts thenumberofindividualswhocanhaveaccesstothehesdata;pahasmadeaspecific commitmenttonhsicnottoallowgooglestafftoaccessthedata.yetitisunclearthat theygotadequateassurancesfromgoogle. 5 TheUKDepartmentofHealthhasdevelopedanonlineInformationGovernanceToolkit(IGT)thatconsolidatesall applicablelegalrulesandcentraldohguidanceasasetofinformationgovernance(ig)requirements.theigt enablesnhsorganisationsandthirdpartiesprovidingservicestonhsorganizationstoassesstheircompliance withcurrentlegislation,governmentpolicyandnationalguidance. 6 %PA%Consulting%Group%statement:%use%of%HSCIC%data,3March2014,availableat: /. 7 It has been clearly established (and has long since been known amongst academics, researchers and practitioners) that such minimal "de-identification" does not prevent data from large databases from being re-identifiable. ComplainttoICOregardinguseofNHSdata 3

4 ThepurposesforwhichpersonalinformationofNHSpatientscanbeusedarerestricted. Asageneralrule,unlessthereisalegalbasisfortheuseofdataforotherpurposes(e.g., patient sexpressconsent),personalinformationofpatientsmayonlybeusedto providecareservicesandforrelatedpurposes(e.g.,toimprovethequalityofhealthcare managementorservicedelivery).inparticular,theuseofpatienthealthinformationfor commercialpurposes,includingtheprovisionofadvertising,isprohibited.butgoogle s cloud_serviceagreementsallowgoogletoprocesscustomers dataforopen_endedand vaguepurposes,whichleavesopenthepossibilitythatgooglemaybeprocessing personalhealthinformationforitscommercialbenefitandinparticulartooptimisethe provisionofadvertising. Detailedsecuritystandardsapplytotheprocessingandstorageofhealthinformation. Amongotherobligations,theUKDepartmentofHealth(DoH)haspublisheddetailed guidanceonsuitableencryptionalgorithmsfornhspatientdata. 8 Itisunclearthatthe securitymeasuresgoogleappliestoitscloudservicesarecompliant.wereferyouin particulartorecentdisclosuresbyedwardsnowdentotheeffectthatforeign intelligenceagencieswereroutinelyharvestingpersonalinformationofgoogle customersontheunencryptedbackbonelinksbetweenitsdatacentres,andthatgchq didnotinsistonminimisationofpersonalinformationofukcitizenswithin5eyes (unlikethecsewhichinsistedonsuchminimisationforcanadiancitizens). ThetransferofNHSpatients personalinformationoutsidetheukisheavilyrestricted. Inparticular,theDoHguidancemakesclearthatsuchinformationmustnotbe transferredoutsidetheukunlessanappropriateassessmentofriskhasbeen undertakenandappropriatecontrolsimplemented;thetransferisnotifiedtoyour office;thedecisiontotransferthedatahasbeentakenbyaseniormanagerwiththe requiredauthority;anassurancestatementisobtainedfromthirdpartiesthatprocess thedataoverseas;and inmostcases thepatientstowhomthedatarelateshave beennotifiedaboutthetransfer.asgooglehasnodatacentresintheuk,andtakesthe positionthatitscustomers datamaybestoredinanyofitsdatacentres 9,managers contemplatingtheuseofgoogleservicesforpersonalhealthinformationshouldhave properlyfollowedtheprocedureforsendingsuchinformationoverseas. 8 See,NHSInformationGovernance,Guidelines%on%Use%of%Encryption%to%Protect%Person%Identifiable%and%Sensitive% Information,2008,availableat: 9 See,ITNews,Google:%Who%cares%where%your%data%is?,9June2011,quotingChiefsecurityofficerforGoogleApps, EranFeigenbaum,availableat: is.aspx. 4 ComplainttoICOregardinguseofNHSdata

5 Personalhealthinformationmustbedeletedwhenitisnolongerrequiredforaspecific purpose.thiscommitmenthasapparentlybeenrepeatedinthedatasharingagreement betweennhsicandpa,sothatpaissupposedtodeletethehesdataoncethe agreementterminates.butitisunclearthatgoogleissubjecttosimilarrestrictions. Indeed,inthepastGooglehasfailedtoprovidestrongcommitmentstoitscloud customerstodeletedataduringprovisionandafterterminationoftheservice. ThestorageoflargeamountsofsensitivepersonalhealthinformationinaUScloudserviceis particularlyconcerningbecauseoftheprecedentitmayset.googlemayadvertiseamottoof don tbeevil andsomeofusindividuallymaybepreparedtoacceptassurancesfromthem (oneofus Anderson isaformergoogleemployee).howevernotallukdatasubjectswillbe preparedtoacceptsuchassurances noteveryoneusesgmail.furthermore,therearemany otherserviceproviderswitharangeofcorporatecultures.someoverseasserviceprovidersare verymuchlesstrustworthy,andfallcompletelyoutsideyourregulatoryscopeastheyhaveno UKpresence;weareconcernedthatourpersonalhealthinformationwillenduptherenext.Yet thisneednothappen;therearemanyukandeuserviceproviderswhofallcompletelywithin thescopeofthedataprotectiondirective,andwenotethatevenmicrosoftwillnowstore personaldataintheeuifcustomersdemandit. Questions WerequestthatyouinvestigatethepotentialbreachesofUKlawsandregulationsresulting fromtheuploadingofpatientdatatogoogle scloudservices.thisrelatesnotjusttothedata ProtectionAct1998directly,buttotherelevantNHSregulationsandtherelevanthuman_rights law(includingivfinland)astheseallsetthereasonableexpectationsthatpatientshadwhen theysuppliedtheirinformationtothenhs,andthusarefundamentalforfairprocessing. Amongthequestionsthatmustbeasked: PreciselywhichpatientdatawerestoredoutsidetheUK?Didtheyrelatetosingle episodesorlinkedrecords?didtheycontainpostcode,dateofbirth,nhsnumber,ora pseudonymsuchanencryptednhsnumber?thestatementsfrompaandhscicdeny thatanameorfulladdresswasincluded,andpadeniedtherewasafulldateofbirth. Neitherhasdeniedpostcode,oryearofbirth,ortheuseofapseudonymthatwould enableepisoderecordstobelinked.hscicmentions pseudonymised data,which suggestsapseudonym.weaspatientsanddatasubjects(aswellasadvocates)would liketoknowthedetails. ComplainttoICOregardinguseofNHSdata 5

6 WhatkindofprivacyriskassessmentwascarriedoutbyPAandNHSICpriortodeciding tostore,ortoconsenttothestorageof,thedataingoogle scloudservices? IfdataweretransferredunderSafeHarbor(asonemightexpect),theControllerstill needsanart.17contractgoverningsecurityofprocessing.doesthiscontractexist,and ifso,haveitsadequacyandlawfulnessbeenverified?canweseeit? HowareHESdataprotectedagainstaccessbyunauthorisedparties,includingGoogle engineers?wereanyencryptionmethodsusedtoprotectthedata(otherthanthetls encryptionusedtoprotectthelinkfromtheclienttothegooglefrontend)andwho hasaccesstotheencryptionkeys? WhatassuranceswereobtainedthattheHESdatacouldonlybeusedforhealthcare purposes?inparticular,hasgooglemadeanycommitmentsnottousethedataforits owncommercialpurposes,suchastargetingadvertsoranalytics? AsthedataweretransferredtoserversoutsidetheUK,havetherequirementsunder thedataprotectionact1998andthedohguidancebeencompliedwith? WhatmeasureshavethepartiestakentoensurethattheHESdatacannotbeaccessed byforeigngovernmentagenciesusingtheirlocalpowers,ratherthanhavingtogo throughuklawful_accessprocedures? WereadequatearrangementsmadetoensurethatGoogle sdataprocessingactivities canbeaudited? HasthespecificcommitmenttoerasetheHESdataoncethedatasharingagreement terminatesbeenextendedtogoogle? Weaskyoutoinvestigatetheseissuesasamatterofurgency. ComplainttoICOregardinguseofNHSdata 6

7 Yourssincerely, RossAnderson Chair, FoundationforInformationPolicyResearch PhilBooth Coordinator, medconfidential NickPickles Director, BigBrotherWatch ComplainttoICOregardinguseofNHSdata 7

De-identification of Data using Pseudonyms (Pseudonymisation) Policy

De-identification of Data using Pseudonyms (Pseudonymisation) Policy De-identification of Data using Pseudonyms (Pseudonymisation) Policy Version: 2.0 Page 1 of 7 Partners in Care This is a controlled document. It should not be altered in any way without the express permission

More information

A Q&A with the Commissioner: Big Data and Privacy Health Research: Big Data, Health Research Yes! Personal Data No!

A Q&A with the Commissioner: Big Data and Privacy Health Research: Big Data, Health Research Yes! Personal Data No! A Q&A with the Commissioner: Big Data and Privacy Health Research: Big Data, Health Research Yes! Personal Data No! Ann Cavoukian, Ph.D. Information and Privacy Commissioner Ontario, Canada THE AGE OF

More information

Privacy Committee. Privacy and Open Data Guideline. Guideline. Of South Australia. Version 1

Privacy Committee. Privacy and Open Data Guideline. Guideline. Of South Australia. Version 1 Privacy Committee Of South Australia Privacy and Open Data Guideline Guideline Version 1 Executive Officer Privacy Committee of South Australia c/o State Records of South Australia GPO Box 2343 ADELAIDE

More information

37.5 (core office hours are 9:00am 5:30pm Monday to Friday)

37.5 (core office hours are 9:00am 5:30pm Monday to Friday) Job description Job title: Reporting to: Data Analyst Senior Data Analyst Salary: L13, 37,584 Hours per week: 37.5 (core office hours are 9:00am 5:30pm Monday to Friday) The Health Foundation The Health

More information

Observations on international efforts to develop frameworks to enhance privacy while realising big data s benefits

Observations on international efforts to develop frameworks to enhance privacy while realising big data s benefits Big Data, Key Challenges: Privacy Protection & Cooperation Observations on international efforts to develop frameworks to enhance privacy while realising big data s benefits Seminar arranged by the Office

More information

How to De-identify Data. Xulei Shirley Liu Department of Biostatistics Vanderbilt University 03/07/2008

How to De-identify Data. Xulei Shirley Liu Department of Biostatistics Vanderbilt University 03/07/2008 How to De-identify Data Xulei Shirley Liu Department of Biostatistics Vanderbilt University 03/07/2008 1 Outline The problem Brief history The solutions Examples with SAS and R code 2 Background The adoption

More information

Anonymisation Standard for Publishing Health and Social Care Data Specification

Anonymisation Standard for Publishing Health and Social Care Data Specification Title Anonymisation Standard for Publishing Health and Social Care Data Specification (Process Standard) Document ID ISB1523 Amd 20/2010 Sponsor Phil Walker Status Final Developer Clare Sanderson & Malcolm

More information

Data Management Strategy

Data Management Strategy Scope Data Management Strategy (v1.0, February 2015) 1. This document focuses primarily on the internal data management objectives of the CCG over the next three years. Due to the evolving nature of legislation

More information

Professional Practice Board. Guidelines on the use of Electronic Health Records

Professional Practice Board. Guidelines on the use of Electronic Health Records Professional Practice Board Guidelines on the use of Electronic Health Records October 2011 The British Psychological Society 2011 The British Psychological Society St Andrews House, 48 Princess Road East,

More information

UCL Data Safe Haven (IDHS) User Group Town Hall Meeting

UCL Data Safe Haven (IDHS) User Group Town Hall Meeting UCL Data Safe Haven (IDHS) UCL Data Safe Haven (IDHS) User Group Town Hall Meeting 16 th October 2014 Agenda Welcome Service Update Current software and services Usage statistics Project update Discussion:

More information

Degrees of De-identification of Clinical Research Data

Degrees of De-identification of Clinical Research Data Vol. 7, No. 11, November 2011 Can You Handle the Truth? Degrees of De-identification of Clinical Research Data By Jeanne M. Mattern Two sets of U.S. government regulations govern the protection of personal

More information

Considering De-Identification? Legacy Data. Kymberly Lee 16-Jul-2015

Considering De-Identification? Legacy Data. Kymberly Lee 16-Jul-2015 Considering De-Identification? Legacy Data Kymberly Lee 16-Jul-2015 Introduction This presentation provides an overview of Clinical data sharing, clinical data privacy, and clinical transparency. Discuss

More information

Global Alliance for Genomics & Health Data Sharing Lexicon

Global Alliance for Genomics & Health Data Sharing Lexicon Global Alliance for Genomics & Health Data Sharing Lexicon Preamble The Global Alliance for Genomics and Health ( GA4GH ) is an international, non-profit coalition of individuals and organizations working

More information

Privacy Impact Assessment: care.data

Privacy Impact Assessment: care.data High quality care for all, now and for future generations Document Control Document Purpose Document Name Information Version 1.0 Publication Date 15/01/2014 Description Associated Documents Issued by

More information

Council of the European Union Brussels, 15 January 2015 (OR. en) NOTE German delegation Working Party on Information Exchange and Data Protection

Council of the European Union Brussels, 15 January 2015 (OR. en) NOTE German delegation Working Party on Information Exchange and Data Protection Council of the European Union Brussels, 15 January 2015 (OR. en) Interinstitutional File: 2012/0011 (COD) 14705/1/14 REV 1 LIMITE DATAPROTECT 146 JAI 802 MI 805 DRS 135 DAPIX 150 FREMP 178 COMIX 568 CODEC

More information

ADVISORY GUIDELINES ON THE PERSONAL DATA PROTECTION ACT FOR SELECTED TOPICS ISSUED BY THE PERSONAL DATA PROTECTION COMMISSION ISSUED 24 SEPTEMBER 2013

ADVISORY GUIDELINES ON THE PERSONAL DATA PROTECTION ACT FOR SELECTED TOPICS ISSUED BY THE PERSONAL DATA PROTECTION COMMISSION ISSUED 24 SEPTEMBER 2013 ADVISORY GUIDELINES ON THE PERSONAL DATA PROTECTION ACT FOR SELECTED TOPICS ISSUED BY THE PERSONAL DATA PROTECTION COMMISSION ISSUED 24 SEPTEMBER 2013 REVISED 16 MAY 2014 PART I: INTRODUCTION AND OVERVIEW...

More information

NHS England Medical Appraisal Policy. Annex J: References Annex K: Glossary Annex L: Working group

NHS England Medical Appraisal Policy. Annex J: References Annex K: Glossary Annex L: Working group NHS England Medical Appraisal Policy Annex J: References Annex K: Glossary Annex L: Working group Annexes J, K & L Page 1 NHS England INFORMATION READER BOX Directorate Medical Operations Patients and

More information

Yale-Medtronic Experience. Richard Kuntz, MD MSc Chief Scientific, Clinical and Regulatory Officer Medtronic

Yale-Medtronic Experience. Richard Kuntz, MD MSc Chief Scientific, Clinical and Regulatory Officer Medtronic Yale-Medtronic Experience Richard Kuntz, MD MSc Chief Scientific, Clinical and Regulatory Officer Medtronic Medtronic INFUSE (rhbmp-2) Evidence and Reporting Challenge Background (1) INFUSE approved by

More information

HIPAA-Compliant Research Access to PHI

HIPAA-Compliant Research Access to PHI HIPAA-Compliant Research Access to PHI HIPAA permits the access, disclosure and use of PHI from a HIPAA Covered Entity s or HIPAA Covered Unit s treatment, payment or health care operations records for

More information

De-Identification of Health Data under HIPAA: Regulations and Recent Guidance" " "

De-Identification of Health Data under HIPAA: Regulations and Recent Guidance  De-Identification of Health Data under HIPAA: Regulations and Recent Guidance" " " D even McGraw " Director, Health Privacy Project January 15, 201311 HIPAA Scope Does not cover all health data Applies

More information

Comments of the World Privacy Forum To: Office of Science and Technology Policy Re: Big Data Request for Information. Via email to bigdata@ostp.

Comments of the World Privacy Forum To: Office of Science and Technology Policy Re: Big Data Request for Information. Via email to bigdata@ostp. 3108 Fifth Avenue Suite B San Diego, CA 92103 Comments of the World Privacy Forum To: Office of Science and Technology Policy Re: Big Data Request for Information Via email to [email protected] Big Data

More information

BEFORE USING THIS GUIDANCE, MAKE SURE YOU HAVE THE MOST UP TO DATE VERSION GUIDANCE 2 POLICY AREA: INFORMATION GOVERNANCE

BEFORE USING THIS GUIDANCE, MAKE SURE YOU HAVE THE MOST UP TO DATE VERSION GUIDANCE 2 POLICY AREA: INFORMATION GOVERNANCE GUIDANCE 1 TITLE: INFORMATION GOVERNANCE FRAMEWORK 2 POLICY AREA: INFORMATION GOVERNANCE 3 ACCOUNTABLE DIRECTOR FOR POLICY AREA: DIRECTOR OF QUALITY AND GOVERNANCE 4 GUIDANCE DRAFTED BY: INTEGRATED GOVERNANCE

More information

PUBLIC CONSULTATION ISSUED BY THE PERSONAL DATA PROTECTION COMMISSION

PUBLIC CONSULTATION ISSUED BY THE PERSONAL DATA PROTECTION COMMISSION PUBLIC CONSULTATION ISSUED BY THE PERSONAL DATA PROTECTION COMMISSION PROPOSED ADVISORY GUIDELINES ON THE PERSONAL DATA PROTECTION ACT FOR SELECTED TOPICS 05 FEBRUARY 2013 PART I: INTRODUCTION AND OVERVIEW...

More information

DATA MINING - 1DL105, 1DL025

DATA MINING - 1DL105, 1DL025 DATA MINING - 1DL105, 1DL025 Fall 2009 An introductory class in data mining http://www.it.uu.se/edu/course/homepage/infoutv/ht09 Kjell Orsborn Uppsala Database Laboratory Department of Information Technology,

More information

How To Respond To The Nti'S Request For Comment On Big Data And Privacy

How To Respond To The Nti'S Request For Comment On Big Data And Privacy Submission to the National Telecommunications and Information Administration (NTIA), U.S. Department of Commerce Docket No. 140514424 4424 01 RIN 0660 XC010 Comments of the Information Technology Industry

More information

(Big) Data Anonymization Claude Castelluccia Inria, Privatics

(Big) Data Anonymization Claude Castelluccia Inria, Privatics (Big) Data Anonymization Claude Castelluccia Inria, Privatics BIG DATA: The Risks Singling-out/ Re-Identification: ADV is able to identify the target s record in the published dataset from some know information

More information

ARTICLE 29 DATA PROTECTION WORKING PARTY

ARTICLE 29 DATA PROTECTION WORKING PARTY ARTICLE 29 DATA PROTECTION WORKING PARTY 0829/14/EN WP216 Opinion 05/2014 on Anonymisation Techniques Adopted on 10 April 2014 This Working Party was set up under Article 29 of Directive 95/46/EC. It is

More information

HIPAA POLICY REGARDING DE-IDENTIFICATION OF PROTECTED HEALTH INFORMATION AND USE OF LIMITED DATA SETS

HIPAA POLICY REGARDING DE-IDENTIFICATION OF PROTECTED HEALTH INFORMATION AND USE OF LIMITED DATA SETS HIPAA POLICY REGARDING DE-IDENTIFICATION OF PROTECTED HEALTH INFORMATION AND USE OF LIMITED DATA SETS SCOPE OF POLICY: What Units Are Covered by this Policy?: This policy applies to the following units

More information

LOBLAW COMPANIES LIMITED MANDATE OF THE BOARD OF DIRECTORS

LOBLAW COMPANIES LIMITED MANDATE OF THE BOARD OF DIRECTORS LOBLAW COMPANIES LIMITED MANDATE OF THE BOARD OF DIRECTORS LOBLAW COMPANIES LIMITED MANDATE OF THE BOARD OF DIRECTORS 1. ROLE The role of the Board is to provide governance and stewardship to the Corporation.

More information

Board Self-Evaluation Questionnaire

Board Self-Evaluation Questionnaire Board Self-Evaluation Questionnaire A Tool for Improving Governance Practice For Voluntary and Community Organizations Name (optional) For period from to Non-Profit Sector Leadership Program College of

More information

IAPT Data Standard. Frequently Asked Questions

IAPT Data Standard. Frequently Asked Questions IAPT Data Standard Frequently Asked Questions Version 1.0 March 2012 IAPT FAQs 1.0-1 - Contents Section 1: About the IAPT Data Standard.. 3 Section 2: Who is responsible for doing what?. 5 Section 3: How

More information

Recap of Thursday. Toya Paynter, Chair

Recap of Thursday. Toya Paynter, Chair Recap of Thursday Toya Paynter, Chair Economic Development & Workforce Challenges in Summit County Summit County Commissioner Karn Stiegelmeier Workforce System Performance Dashboards Tony Anderson, Business

More information

HIPAA Basics for Clinical Research

HIPAA Basics for Clinical Research HIPAA Basics for Clinical Research Audio options: Built-in audio on your computer OR Separate audio dial-in: 415-930-5229 Toll-free: 1-877-309-2074 Access Code: 960-353-248 Audio PIN: Shown after joining

More information

HSCIC Audit of Data Sharing Activities:

HSCIC Audit of Data Sharing Activities: Directorate / Programme Data Dissemination Services Project Data Sharing Audits Status Approved Director Terry Hill Version 1.0 Owner Rob Shaw Version issue date 20/04/2016 HSCIC Audit of Data Sharing

More information

SESSION DEPENDENT DE-IDENTIFICATION OF ELECTRONIC MEDICAL RECORDS

SESSION DEPENDENT DE-IDENTIFICATION OF ELECTRONIC MEDICAL RECORDS SESSION DEPENDENT DE-IDENTIFICATION OF ELECTRONIC MEDICAL RECORDS A Thesis Presented in Partial Fulfillment of the Requirements for the Degree Bachelor of Science with Honors Research Distinction in Electrical

More information

VALUE ANALYSIS TEAM (FORMERLY KNOWN AS MATERIALS USE EVALUATION MUE) POLICY

VALUE ANALYSIS TEAM (FORMERLY KNOWN AS MATERIALS USE EVALUATION MUE) POLICY VALUE ANALYSIS TEAM (FORMERLY KNOWN AS MATERIALS USE EVALUATION MUE) POLICY PURPOSE The purpose of this policy is to define the structure and operation of the Value Analysis Team process, through active

More information

Executive Diploma in Big Data Management & Analytics

Executive Diploma in Big Data Management & Analytics Executive Diploma in Big Data Management & Analytics Achieve More We encourage our students to challenge their thinking, to extend their boundaries, to strive for excellence. We create a positive environment

More information

Analysis of Variance (ANOVA) Using Minitab

Analysis of Variance (ANOVA) Using Minitab Analysis of Variance (ANOVA) Using Minitab By Keith M. Bower, M.S., Technical Training Specialist, Minitab Inc. Frequently, scientists are concerned with detecting differences in means (averages) between

More information

STELLENBOSCH UNIVERSITY DEPARTMENT OF CIVIL ENGINEERING POST GRADUATE STUDIES AT THE CHAIR IN CONSTRUCTION ENGINEERING AND MANAGEMENT

STELLENBOSCH UNIVERSITY DEPARTMENT OF CIVIL ENGINEERING POST GRADUATE STUDIES AT THE CHAIR IN CONSTRUCTION ENGINEERING AND MANAGEMENT STELLENBOSCH UNIVERSITY DEPARTMENT OF CIVIL ENGINEERING POST GRADUATE STUDIES AT THE CHAIR IN CONSTRUCTION ENGINEERING AND MANAGEMENT The construction industry needs creative and innovative graduates who

More information

Privacy Techniques for Big Data

Privacy Techniques for Big Data Privacy Techniques for Big Data The Pros and Cons of Syntatic and Differential Privacy Approaches Dr#Roksana#Boreli# SMU,#Singapore,#May#2015# Introductions NICTA Australia s National Centre of Excellence

More information

INCOSE Enterprise Working Group (ESWG) Charter

INCOSE Enterprise Working Group (ESWG) Charter 1 PURPOSE 2 GOAL The purpose of the working group is to advance and promote the application of Systems Engineering to understanding and managing the enterprise as a system. Enterprises are highly complex

More information

Comments of the EDPS in response to the public consultation on

Comments of the EDPS in response to the public consultation on Comments of the EDPS in response to the public consultation on the planned guidelines on recommended standard licences, datasets and charging for the reuse of public sector information initiated by the

More information

Abstract. It s peace of mind knowing that we ve done everything that is possible to meet industry standards for de-identification. Dr.

Abstract. It s peace of mind knowing that we ve done everything that is possible to meet industry standards for de-identification. Dr. Abstract In this presentation I will discuss the adoption of the Privacy Analytics Risk Assessment Tool (PARAT) by the Institute for Clinical Evaluative Sciences (ICES), for the Ontario Cancer Data Linkage

More information

Big Data, Not Big Brother: Best Practices for Data Analytics Peter Leonard Gilbert + Tobin Lawyers

Big Data, Not Big Brother: Best Practices for Data Analytics Peter Leonard Gilbert + Tobin Lawyers Big Data, Not Big Brother: Best Practices for Data Analytics Peter Leonard Gilbert + Tobin Lawyers March 2013 How Target Knew a High School Girl Was Pregnant Before Her Parents Did just because you can,

More information

1.2: DATA SHARING POLICY. PART OF THE OBI GOVERNANCE POLICY Available at: http://www.braininstitute.ca/brain-code-governance. 1.2.

1.2: DATA SHARING POLICY. PART OF THE OBI GOVERNANCE POLICY Available at: http://www.braininstitute.ca/brain-code-governance. 1.2. 1.2: DATA SHARING POLICY PART OF THE OBI GOVERNANCE POLICY Available at: http://www.braininstitute.ca/brain-code-governance 1.2.1 Introduction Consistent with its international counterparts, OBI recognizes

More information

From metabiobanks to translational research platforms: Integrating Big Data through CRIP Tools

From metabiobanks to translational research platforms: Integrating Big Data through CRIP Tools From metabiobanks to translational research platforms: Integrating Big Data through CRIP Tools 4 th Munich Biomarker Conference, November 26, 2014 [email protected] Access to goods

More information

Data Quality Policy SH NCP 2. Version: 5. Summary:

Data Quality Policy SH NCP 2. Version: 5. Summary: SH NCP 2 Summary: Keywords (minimum of 5): (To assist policy search engine) Target Audience: The Trust provides a framework to ensure all data that is recorded by the Trust is accurate and complies to

More information

Ann Cavoukian, Ph.D.

Ann Cavoukian, Ph.D. Protecting Privacy in an Era of Electronic Health Records Ann Cavoukian, Ph.D. Information and Privacy Commissioner Ontario Barrie and Community Family Health Team Royal Victoria Hospital Georgian College

More information

Pseudonymisation Implementation Project (PIP) Reference Paper 4

Pseudonymisation Implementation Project (PIP) Reference Paper 4 Pseudonymisation Implementation Project (PIP) Reference Paper 4 Pseudonymisation Technical White Paper - Design and MS-SQL FV2 24 th March 2010 Without Prejudice Programme NPFIT Document Record ID Key

More information

The collection, linking and use of data in biomedical research and health care: ethical issues

The collection, linking and use of data in biomedical research and health care: ethical issues The collection, linking and use of data in biomedical research and health care: ethical issues Nuffield Council on Bioethics Professor Jonathan Montgomery (Chair) Professor Simon Caney Professor Bobbie

More information

Privacy and EHR Information Flows in Canada. EHIL Webinar Series. Presented by: Joan Roch, Chief Privacy Strategist, Canada Health Infoway

Privacy and EHR Information Flows in Canada. EHIL Webinar Series. Presented by: Joan Roch, Chief Privacy Strategist, Canada Health Infoway Privacy and EHR Information Flows in Canada EHIL Webinar Series Presented by: Joan Roch, Chief Privacy Strategist, Canada Health Infoway March 1, 2011 Outline 1. Background 2. Infoway s privacy mandate

More information

Synapse Privacy Policy

Synapse Privacy Policy Synapse Privacy Policy Last updated: April 10, 2014 Introduction Sage Bionetworks is driving a systems change in data-intensive healthcare research by enabling a collective approach to information sharing

More information

Data De-identification and Anonymization of Individual Patient Data in Clinical Studies A Model Approach

Data De-identification and Anonymization of Individual Patient Data in Clinical Studies A Model Approach Data De-identification and Anonymization of Individual Patient Data in Clinical Studies A Model Approach Background TransCelerate BioPharma Inc. is a non-profit organization of biopharmaceutical companies

More information

North West London Whole Systems Integrated Care Information Sharing and Hosting Agreement

North West London Whole Systems Integrated Care Information Sharing and Hosting Agreement Dated 1 st October 2014 / amended 10 th February 2015 (1) NHS BRENT CLINICAL COMMISSIONING GROUP (Data Processor on behalf of Provider Partners as defined in this Agreement) - and - (2) SIGNATORY PARTNERS

More information

Information Governance in Dental Practices. Summary of findings from ICO reviews. September 2015

Information Governance in Dental Practices. Summary of findings from ICO reviews. September 2015 Information Governance in Dental Practices Summary of findings from ICO reviews September 2015 Executive summary The Information Commissioner s Office (ICO) is the regulator responsible for ensuring that

More information

ACEA PRINCIPLES OF DATA PROTECTION IN RELATION TO CONNECTED VEHICLES AND SERVICES

ACEA PRINCIPLES OF DATA PROTECTION IN RELATION TO CONNECTED VEHICLES AND SERVICES ACEA PRINCIPLES OF DATA PROTECTION IN RELATION TO CONNECTED VEHICLES AND SERVICES September 2015 INTRODUCTION We, the member companies of ACEA, are committed to providing our customers with a high level

More information

Winthrop-University Hospital

Winthrop-University Hospital Winthrop-University Hospital Use of Patient Information in the Conduct of Research Activities In accordance with 45 CFR 164.512(i), 164.512(a-c) and in connection with the implementation of the HIPAA Compliance

More information