Have the Tories got the answer to the NHS IT problem [2]?
Well – sort of.
As a tax paying citizen, I am horrified at the £12.7 billion costs (and rising) of the current NHS National Programme for IT (NPfIT) programme. As an individual, I have no confidence, along with 90% of the population, that my personal information and medical records will be secure. But, as a patient, I recognise that my ‘brown manila file’, currently in a pile in a corridor somewhere, is not the answer.
I understand that the NHS have declared that personal medical records (a big, expensive and necessary job to computerise these files) held on their central database will be available not only to medical professionals but also sold to private organisations. This is what Philip Virgo wrote on his ‘When IT meets Politics’ blog back in October 2008
"Stop whinging and respond to the consultation on "Additional Uses of Patient Data". Once I have "joined", I get my number/password/security device and can visit the website: to volunteers for research panels, join patient groups, make donations to medical charities, get discounts on health care clubs and insurance, etc. etc. - but my data is owned by me, under my control and I decide who sees and uses it: the approach of PAOGA [3] and its clients, rather than that of the Secretary of State, who claims to "own" my medical record."
The NHS have also declared that patients will have the right to 'opt out' which poses the question – “Where to?” I asked Richard Grainger [then in charge of the NPfIT] this question back in 2002 when the NHS IT project started and he, grudgingly – for that was his way - admitted that I could ‘opt out’ and get a jiffy bag full of unintelligible paperwork. I know this to be true as I has previously had reason to request a copy of my mother’s medical records and was shocked at the state of the paperwork provided.
I have been extolling the benefits and virtues, ethical and financial, of what is now called VRM (Vendor Relationship Management) as the reciprocal to enterprise-centric CRM for some years now. During that time the 'trust' of the consumer/citizen/patient has been severely shaken by the continuous reporting of personal data loss and abuse in both the public and private sectors with little evidence of any accountability beyond a weak apology and promise to 'tighten up the rules'. I sincerely hope that a new government will provide the Information Commissioner’s Office sufficient resources to strictly enforce the Data Protection Act.
This loss of 'trust' will encourage many individuals to seek an alternative for securely managing their valuable personal information, including medical records, and that is what Shadow Health Minister, Stephen O’Brien is proposing following the independent review of NHS IT, chaired by Dr Glyn Hayes. What has been reported seems to address my ambition to take responsibility and manage my personal information ‘under my control, with my consent, for my benefit’.
Given the record of security of current data held on government silos (not encrypted but ‘password protected, copies stored and transported on CDs, memory sticks and laptops with no audit trail of responsibility) undermines the concern expressed by the government. Cloud Computing allows properly architected applications to enforce data encryption, stored and in transmission, as well as automating backup and IAM (Identity Access Management) audit trails – who accessed what data, when and why? I know which I trust more.
As a citizen/individual/patient, what I would like is the ability to:
I will leave the last words to Gwyn Headley, CEO of fotoLibra [4], who commented on a recent post on my own blog [5]:
"Graham's significant point is that giant US based conglomerates are not beholden to us or to our puny laws, whether British or European. They write the terms and conditions, and we get the choice. We accept what they write in its entirety, or not:. . . nor all thy Piety nor Wit Shall lure it back to cancel half a Line, Nor all thy Tears wash out a Word of it. Cameron is not yet in power, but it would be a foolish man who bet against him. He and his advisors need to be made aware that companies like PAOGA can keep this data secure and in our own hands, not left to the whim of foreign corporations and governments The first duty of any government is to protect its own citizens. I do not believe that duty will be best served by handing over our personal data to a foreign power."
Graham Sadd, Chairman & CEO of PAOGA [6], has been researching and developing ‘user-driven’ VRM applications respecting individuals’ privacy for many years.
Links:
[1] http://www.businesscloud9.com/image/graham-saddjpg
[2] http://www.businesscloud9.com/topic/applications/tories-pledge-nhs-it-revolution-cloud
[3] http://www.theregister.co.uk/2006/09/28/information_worth_money
[4] http://www.fotolibra.com
[5] http://blog.grahamsadd.com
[6] http://www.paoga.com