Chris Lancelot on... The DOH and Data Security

In the wake of the recent child benefits fiasco, no one in their right mind will trust the government to keep their personal details confidential.

It beggars belief that a government department could act in such an incompetent and illegal manner. The situation is made even worse by ministers claiming that this was human error and not a system failure. Properly configured application software should never allow ordinary users to download an entire database, nor burn it to disk in an unencrypted form.

The episode highlights the government's cavalier disregard for personal data. In the wake of this, which patient will now allow their medical details to be uploaded to the spine?

Medical information is quite different from child benefit data because once a breach of medical confidentiality has occurred the genie can never be put back in the bottle. Those affected by the recent breach were able to change their bank accounts and passwords: but once the details of your schizophrenia at age 23, HIV status or recreational drug history are public then that is that. Your employment prospects, your personal relationships, indeed your whole life may well never be the same again.

A centralised medical database will improve the quality and efficiency of medical care enormously - but only if patient data is confidential, accessible only to clinicians and staff who have a direct need to know. Not only must the data be kept confidential, it has to be seen to be kept confidential. The child benefit fiasco, coupled with the government's insistence (against medical and professional IT advice) that everyone's medical data will be uploaded automatically to the spine unless a patient specifically objects, both shout that the DoH doesn't give two hoots over handling data responsibly. As a result patients in their droves will refuse to allow their data to be uploaded.

Connecting for Health needs, very urgently, to implement its data protection mechanisms completely, and very publicly; arrange for patients to opt in to uploading their data; and then go on a 'hearts and minds' campaign to persuade both professionals and patients that centrally kept data really is safe in their hands. It will be an uphill struggle.

Dr Lancelot is a GP from Lancashire. Email him at

Have you registered with us yet?

Register now to enjoy more articles and free email bulletins


Already registered?

Sign in

Follow Us:

Just published

Houses of Parliament

GP partnerships 'like collapsing Jenga stack' after Javid threat to nationalise practices

Sajid Javid's decision to back a report calling for the end of the GMS contract within...

£20 notes spread out

VAT trap for PCNs could strip millions of pounds from general practice

Tens of millions of pounds could be stripped from general practice because work carried...

Talking General Practice logo

Podcast: Is the BMA representing GPs effectively, why GPs face a pension tax hit, and views on the workload crisis

In our regular news review the team discusses representation of GPs, a new survey...

Man sleeping

NICE guidance on insomnia backs app to replace sleeping pills

Hundreds of thousands of people with insomnia could be offered treatment via a mobile...

Health worker prepares a dose of COVID-19 vaccine

JCVI backs autumn COVID-19 booster campaign for high-risk adults and NHS staff

Frontline health and social care staff and adults at increased risk of severe illness...

GP consultation

Government accused of 'misleading' claims on general practice workforce

GP leaders have accused the government of making misleading claims about the general...