Chris Lancelot on... The DOH and Data Security

In the wake of the recent child benefits fiasco, no one in their right mind will trust the government to keep their personal details confidential.

It beggars belief that a government department could act in such an incompetent and illegal manner. The situation is made even worse by ministers claiming that this was human error and not a system failure. Properly configured application software should never allow ordinary users to download an entire database, nor burn it to disk in an unencrypted form.

The episode highlights the government's cavalier disregard for personal data. In the wake of this, which patient will now allow their medical details to be uploaded to the spine?

Medical information is quite different from child benefit data because once a breach of medical confidentiality has occurred the genie can never be put back in the bottle. Those affected by the recent breach were able to change their bank accounts and passwords: but once the details of your schizophrenia at age 23, HIV status or recreational drug history are public then that is that. Your employment prospects, your personal relationships, indeed your whole life may well never be the same again.

A centralised medical database will improve the quality and efficiency of medical care enormously - but only if patient data is confidential, accessible only to clinicians and staff who have a direct need to know. Not only must the data be kept confidential, it has to be seen to be kept confidential. The child benefit fiasco, coupled with the government's insistence (against medical and professional IT advice) that everyone's medical data will be uploaded automatically to the spine unless a patient specifically objects, both shout that the DoH doesn't give two hoots over handling data responsibly. As a result patients in their droves will refuse to allow their data to be uploaded.

Connecting for Health needs, very urgently, to implement its data protection mechanisms completely, and very publicly; arrange for patients to opt in to uploading their data; and then go on a 'hearts and minds' campaign to persuade both professionals and patients that centrally kept data really is safe in their hands. It will be an uphill struggle.

Dr Lancelot is a GP from Lancashire. Email him at

Have you registered with us yet?

Register now to enjoy more articles and free email bulletins


Already registered?

Sign in

Just published

Clinical trials: Microscope in a lab

GPs could be incentivised to recruit patients onto commercial clinical trials

GPs could be offered incentives to recruit patients onto commercial clinical trials...

Talking General Practice logo

Podcast: How many GPs do we need for safe general practice, pay restoration, the state of premises

Talking General Practice looks at safe working limits and the number of GPs we need...

Stethoscope and a computer

EMIS to keep panic button after outcry from GPs

EMIS, one of the main GP IT system providers, has backtracked on plans to phase out...

Health minister Lord Markham

Health minister Lord Markham: How we will support GPs to offer patients greater choice

Health minister Lord Markham explains what the government's plans for using the NHS...

Patient receives the flu vaccine

Flu vaccination campaign to return to pre-pandemic cohorts this year

This year's flu vaccination campaign is set to be reduced after it was expanded during...

Plant-based diet

Vegan and vegetarian diets can play key role in reducing cardiovascular risk, study finds

Plant-based diets can play a significant role in lowering the risk of stroke and...