Simply giving patients access to their records is relatively pointless, apart from showing openness and transparency.1 There is already a legal obligation (under the Data Protection Act 1998) to provide copies of records on request. Patients often assume that their records are very detailed and …
The European Institute for Innovation through Health Data (i~HD) has been formed as one of the sustainable entities arising from the Electronic Health Records for Clinical Research (EHR4CR) and SemanticHealthNet projects, in collaboration with other European Commission projects and initiatives. The vision of i~HD is to become the European organisation of reference for guiding and catalysing the best, most efficient and trustworthy uses of health data and interoperability, for optimizing health and knowledge discovery. i~HD has been established in recognition that there is a need to tackle areas of challenge in the successful scaling up of innovations that rely on high-quality and interoperable health data, to sustain and propagate the results of eHealth research, and to address current-day obstacles to using health data. i~HD was launched at an inaugural conference in Paris, in March 2016. This was attended by over 200 European clinicians, healthcare providers and researchers, representatives of the pharma industry, patient associations, health professional associations, the health ICT industry and standards bodies. The event showcased issues and approaches, that are presented in this paper to highlight the activities that i~HD intends to pursue as enablers of the better uses of health data, for care and research.
Simply giving patients access to their records is relatively pointless, apart from showing openness and transparency.1 There is already a legal obligation (under the Data Protection Act 1998) to provide copies of records on request. Patients often assume that their records are very detailed and …
There is increasing investment in large-scale repositories of clinical data, sometimes as a direct result of the need to house the rapidly growing datasets arising from longitudinal studies, and sometimes through the compilation of information from multiple sources of clinical data such as EHRs. The possible benefits for medicine – including large-scale multilevel epidemiological research, effective analysis of small sub-groups and research lead clinical care – are significant. Against these undoubted benefits lie the risks to individual privacy. Effective solutions to this trade-off are vital for the future advances of medicine and healthcare delivery. A practical, risk-based approach needs to be taken, which uses a range of techniques to minimize privacy risks while preserving data utility. This article shows how, using a suite of different techniques, it is possible to manage privacy risks while enabling re-use of clinical data for research purposes. Moving beyond simplistic anonymisation to more sophisticated disclosure control processes requires consideration of the various means of re-identification, taking into account both the properties of the data and that data’s environment (including security systems and the governance processes for the data). Drawing on our experience of research projects and services that cut across all aspects of this area, we outline a framework for managing that risk. The framework embodies technical, statistical and governance components that need to be applied at various stages of the data flow to create a coherent and usable solution.
Peter Singleton considers the application of autonomy to what are commonly called ‘secondary uses’ of healthcare data.
Perspective on the paper by Knowles et al Research governance has a number of functions: the first is to protect the interests of the research participants themselves and to ensure that they understand the implications of and agree to the risks involved in the particular research project; second, there is the assurance of the research methodology, both in its scientific effectiveness and in its limitation of risks to the individuals concerned; finally, there is a cost-effectiveness or opportunity-cost review to ensure that this piece of research should proceed rather than another, or even not at all. Generally, the first is the domain of the research ethics committees (RECs), whereas the last is down to funders and/or the healthcare system where it is involved, although RECs might decide that the risks to participants are not worth the likely scientific benefits. The second area is often a bone of contention where researchers may feel it is not for RECs to adjudge their expertise in deciding on a scientific methodology, and funders may not be happy with the increased costs that RECs may effectively add to a project through additional consent procedures. The article by Knowles et al 1 in this issue nicely illustrates some of the three-way tension between researchers who are focused on their scientific interests and want to just do it, patients who may have strong confidentiality and privacy interests to protect and regulatory bodies who want to be seen to be providing that protection. The article also raises the question of whether researchers know enough about the workings of RECs or the wider approval processes or whether RECs know enough about the wider scope of research rather than clinical trials where the questions of more immediate harm to participants are paramount. Researchers spend a …
This paper considers issues of trust and privacy in healthcare around increased data-sharing through Electronic Health Records (EHRs). It uses a model structured around different aspects of trust in the healthcare organisation's reasons for greater data-sharing and their ability to execute EHR projects, particularly any associated confidentiality controls. It reflects the individual's personal circumstances and attitude to use of health records. This model is extended by considering the relative gains and risks from greater data-sharing as viewed by population segments to give a range of 'attitudes': positive, negative, ambivalent/marginal, or contingent. The model is compared with results from a recent literature survey by the authors published by the UK General Medical Council (GMC) on Public and Professional Attitudes to Privacy. Various policy options are considered which may modify attitudes to make the proposal more or less attractive to patients, recognising that there are those that have little to gain or will always view the proposition of EHRs negatively, and that time and experience may be needed to resolve doubts. The paper does not consider legal questions of privacy and medical confidentiality, although the authors are very familiar with these, preferring to focus on how to meet public expectations and concerns.
Problems with technology, contracts, timescales, organisational change, and user acceptance have continually dogged the NHS national programme for IT (NPfIT),1 but critics need to get these into perspective before seeking to tear down the enterprise. Similar difficulties have historically beset most large information technology projects in the corporate and public …
Novel methods for helping patients to access and manage their personal electronic health data are emerging in the UK and internationally. Claudia Pagliari, Don Detmer, and Peter Singleton examine their potential benefits and challenges
[8-14C]Theophylline was infused into mice with an osmotic minipump. Theophylline and its metabolites were separated from urine, blood, and feces by high-performance liquid chromatography and the radioactivity was determined by liquid-scintillation counting. The strains examined were SJL, DBA/2, C57BL/6, A/J, C3H/HeJ, AKR, SWR, and BALB/c. The theophylline clearance ranged from 479 +/- 30 ml/kg/hr in the A/J strain to 845 +/- 58 ml/kg/hr in the SJL strain. The total clearance in the A/J strain was signficantly different (p < 0.05) from that in the BALB/c, C57BL/6, and SJL strains. The metabolic pathway primarily responsible for this variation was the production of 1,3-dimethyluric acid.
Properly obtained consent is needed for all clinical trials, yet one size doesn't necessarily fit all. This article looks at different consent models and emphasises the need to support choice rather than just observing the formalities of “gaining consent”
The issues of confidentiality and privacy have become increasingly important as Grid technology is being adopted in public sectors such as healthcare. This paper discusses the importance of protecting the confidentiality and privacy of patient health/medical records, and the challenges exhibited in enforcing this protection in a Grid environment. It proposes a novel algorithm to allow traceable/linkable identity privacy in dealing with de-identified medical records. Using the algorithm, de-identified health records associated to the same patient but generated by different healthcare providers are given different pseudonyms. However, these pseudonymised records of the same patient can still be linked by a trusted entity such as the NHS trust or HealthGrid manager. The paper has also recommended a security architecture that integrates the proposed algorithm with other data security measures needed to achieve the desired security and privacy in the HealthGrid context.
CLEF (Co-operative Clinical e-Science Framework) is an MRC sponsored project in the e-Science programme that aims to establish methodologies and a technical infrastructure forthe next generation of integrated clinical and bioscience research. It is developing methodsfor managing and using pseudonymised repositories of the long-term patient histories whichcan be linked to genetic, genomic information or used to support patient care. CLEF concentrateson removing key barriers to managing such repositories ? ethical issues, informationcapture, integration of disparate sources into coherent ?chronicles? of events, userorientedmechanisms for querying and displaying the information, and compiling the requiredknowledge resources. This paper describes the overall information flow and technicalapproach designed to meet these aims within a Grid framework.
CLEF (Co-operative Clinical E-Science Framework) is an MRC sponsored project in the E-Science programme that aims to establish methodologies and a technical infrastructure for the next generation of integrated clinical and bioscience research. It is developing methods for managing and using pseudonymised repositories of the long-term patient histories which can be linked to genetic, genomic information or used to support patient care. CLEF concentrates on removing key barriers to managing such repositories - ethical issues, information capture, integration of disparate sources into coherent chronicles of events, user-oriented mechanisms for querying and displaying the information, and compiling the required knowledge resources. This paper describes the overall information flow and technical approach designed to meet these aims within a Grid framework.
The CLEF project aims to establish a secure socio-technical framework that enables sharing patient data for the purposes of research whilst maintaining patient privacy and confidentiality. The value of shared data is increased by integrating, within a secure repository, both existing structured information (lab reports etc) with information extracted from texts (clinic letters), and using clinical inferencing and filtering techniques to derive a canonical view of the record called the 'chronicle'. Statistical disclosure control and Language generation technologies are used to simplify and control access to this complex resource.