Hacker News new | past | comments | ask | show | jobs | submit login

Did you look at the price list ?

Standard extract – no personal confidential data £9,565

Alternatively for just under £1,000 more :

Standard extract – containing personal confidential data £10,453

They're specifically enticing people to purchase the confidental data version since it is only 10% extra to get all the juicy information.

Trouble connecting people to their parents, siblings, children, (ex)partners ? Simple, they'll even do that for you - look at Patient Tracking, Cohort Event Notification (!) etc.

The value of this data to marketers (e.g. health insurance, private hospitals - which do exist in the UK, etc. makes the price list charges trivial and insignificant to just slurp up everything they can and start targeting people). Want someone to try and sell you cancer insurance 2 weeks after your mother dies of breast cancer ? Cohort event notification report makes this simple.

Remember the toothpaste does not go back into the tube - once the data is sold, it's basically wild and free for all sorts of use and abuse. You have absolutely no guarantee it will only be used by benign 'good actors'.

edit:spelling




They're charging a nominal additional fee for the additional paperwork involved in ensuring the necessary approvals have been met. You can see the types of organizations that get their "personally identifiable" data requests approved by a separate body here: http://www.hra.nhs.uk/about-the-hra/our-committees/section-2...

A quick glance at some of the approvals suggests that yes, the information is very personally-identifying indeed but the cohorts are pretty small and not obviously commercially valuable, and the types of organisations getting the data sound no more likely to resell it than my GP (and even less likely to make a profit on it). And my GP and his admin staff and various other NHS employees have had access to it for some years now.


You can't just buy what you want from them without a legitimate legal basis.

http://www.hscic.gov.uk/dlesaac


Right, you "can't". Just like developers on Facebook's Graph API "can't" use social graph data for unapproved purposes. Because they signed an agreement.

Contracts are not the same as controls.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: