Personal Demographics Service: Department of Health

I’ve blogged before about some of the security issues around the NHS’s Personal Demographics Service – a mammoth database with 80,000,000 personal records in it, yet with 700,000 people granted access to it – and with such limited auditing systems that experts have concluded it is “incredibly difficult if not impossible” to detect or trace misuse of the data.

So it was good to see Julian Huppert take up with issue with a Parliamentary question, asking the Department of Health what assessments it has made of how adequate the safeguards in the PDS really are at preventing illegal access to personal data.

Two points are notable in the answer from Health Minister Simon Burns. First, despite being asked what assessments had been made, his answer does not give details of any assessments having been carried out – which is hardly reassuring as it implies that no recently thorough assessments have been conducted.

Second, the answer makes the classic IT security mistake of talking at some length about the protections against outsiders hacking in and then glossing over the risks of insiders misusing data. It is a classic mistake, because insiders are often the cause of IT security problems – even when the number of insiders with access is far fewer than the 700,000 with access to the records in the case of the PDS. All Simon Burns had to say about this is that it is the responsibility of hundreds of other bodies, all of which should be following the rules – and without any action having been taken to check if they really are.

All a bit of a gamble. Or rather, given 80,000,000 records, 700,000 people having access and no proper audit systems – a mammoth gamble.

Read more by or more about , , or .
This entry was posted in News.
Advert

4 Comments

  • Ruth McCullough 17th Oct '11 - 2:19pm

    My house mate & I specifically wrote to our local Surgery saying we did NOT want our details put on this database – only for the very good reason that we didn’t want to be on yet another official database. I thought it had since died a death. As it very obviously has not died, have you got any advice on how do we should go about checking whether we’re on it or not.? Thank you.

Post a Comment

Lib Dem Voice welcomes comments from everyone but we ask you to be polite, to be on topic and to be who you say you are. You can read our comments policy in full here. Please respect it and all readers of the site.

To have your photo next to your comment please signup your email address with Gravatar.

Your email is never published. Required fields are marked *

*
*
Please complete the name of this site, Liberal Democrat ...?

Advert

Recent Comments

  • Tom Arms
    I meant to say that the UK supplies the nuclear warheads for its deterrent....
  • Tom Arms
    There are some areas where the US is likely to dominate for a very long time. Space is an obvious one. Ukraine would be up the proverbial creek without America'...
  • Ruth Bright
    @Paul is surely right, do we have age breakdowns for stats on members and active supporters?...
  • Tom Bailey
    Alex Macfie says: "He [Farage], has just seized on one case of supposed “anti-white bias” by the police (the only one available)" So the 3 decades of Brit...
  • Alex Macfie
    @Simon Robinson &c: Please stop pretending Nigel Farage is acting in good faith. He has just seized on one case of supposed "anti-white bias" by the police ...