Australia's new e-health platform crashes as people rush to opt-out
zdnet.com
zdnet.com
What I found was a massive difference in policy coming out from the same government but in two seperate streams of work.
A) Consumer Data Right (legislation being built into Australia Privacy Act) focusing on banking, energy and then telecommunications: The user has complete control of their data. If a consumer asks a business to delete, they must do so (except for information that is legally required).
B) MyHealthRecords: The government has complete control of your data. You cannot delete your account or your data.
I'll add sources if I can, but its in the legislation.
5. Who do we share your information with?
- Service providers — for example, mortgage insurers, loyalty program partners and our product distributors
- Businesses who do some of our work for us — including direct marketing, statement production, debt recovery and IT - support
- Organisations involved in our funding arrangements — like loan purchasers, investors, advisers, researchers, trustees - and rating agencies
- Auditors, insurers and re-insurers
- Current or previous employers — for example, to confirm your employment
- Credit reporting bodies and credit providers
https://www.commbank.com.au/security-privacy/general-securit...
I can tell you at least that Accenture were heavily involved in NPfIT too. They were forced out with the work uncompleted, although they somehow managed to dodge most of the fine.
There are some obvious lessons to take away about trying to avoid projects which have massive scopes and vague, changing requirements.
Also that contracting out to a consortium doesn't mitigate risk or project size, because the hardest parts of most IT projects are 1) deciding what to build and 2) dividing up the work into the correct pieces.
For me, though the main lesson is that contracting IT systems is really risky if you don't have in-house engineers to vet it. Companies with no competence in delivering software will sell you the wrong things at the wrong prices, and they will do it really convincingly.
For those who work in government, those companies will also have a terrible track record, but your institutional amnesia will prevent you from noticing, so you will hire them anyway. (Probably someone in your department previously attempted to get a company wiki to organise this sort of information, but ended up getting Sharepoint instead, and now no-one looks at it.)
The last time we had a census the "census night" was totally bust since the majority of Australian internet users tried to use the online form and hardly anyone succeeded. They tried to blame it on "hackers".
Leading up to census night there were threats of fines if you didn't submit on time, but due to the shitstorm with their online failures people were still submitting their census data months later.
Summary: The project was outsourced to IBM (that alone probably says it all), who didn't purchase any DDoS protection. A small attack crashed the first firewall, and the backup firewall didn't have rules loaded. That caused IBM's monitoring tools to flag system logs as exfiltration, so they called in the Australian Signals Directorate (ie national security) and turned everything off until intelligence agencies completed an investigation of the false positive.
The Australia government is incentivising doctors to sell client data to the government.
What part of this is ok in any sense?
The Australian Medical Association has said that the interaction of the MHR system with their code of ethics implies that doctors must get positive consent from patients.
In practice, your new patient registration forms are getting another checkbox.
Edit: I don't know the specifics, but I sometimes wonder what good stats on more health records could do for future treatments.
This isn’t going to change even if all those records become public in some way.
But you also have a significant risk to your life if your
doctor can't get to them and orders the wrong treatment.
Don't you think I'm in a better position to make that decision than a central government bureaucrat, given that I have my medical records and an incentive to protect my own privacy, and he has neither?You have incentive to product your privacy, but you don't have the means. Are you going to bolt a fire-proof safe to your basement floor and keep a backup in a storage unit? Are you going to store them on a disconnected harddrive and create backups every 3-6-12 months? Can we expect every Australian to do this? Can we expect everyone to want to spend hundreds of dollars to make this happen?
Also, I worked with OSCAR, one of Canada's biggest EMRs. It is written by a bunch of academics at a local university and is individually deployed on under-the-desk computers at clinics. It is full of security holes, the whole process of managing this system is.
I get why you want rights over the medical records. You can still have those on a centralized system. Google and facebook are centralized and you have rights over them (in some jurisdictions anyways).
I feel that I should have a right to choose between the risk of death when both myself and my emergency contact are unable to provide medical information to a doctor, and the risk of my medical history becoming publicly available - or even just available to the Government. Forcing the latter risk on me is, imho, unethical.
If they have to order your medical journal from a completely separate jurisdiction, in a completely different format, and then import it that would take longer. If you require specialist care which is not available in your area this is an issue that comes up again and again.
Not saying a centralized system would fix all the problems, or be perfect, but if it improves 1% of cases that's potentially thousands of people saved every year. That's a huge return for a very minor improvement.
Again, just a few percent in efficiency could mean thousands upon thousands of lives saved. I'm sure a lot of HIV positive people who were mistreated would've loved that.
In my opinion, the risk-reward analysis is clearly in favor of a centralized system.
However, this government has no idea what is doing, the framework is poor, oversight is poor, without a doubt the implementation will be poor and its pulling a "swift on" on the public.
Lets not forget, this is a government that couldn't handle an IT system thad a few million people filling out a census form online.
Source: I'm an Australian doctor.
I used to get frustrated with doctors running late, until I became one. It's the patients that come before you that largely determine how late the doctor is. If someone might be having an MI but only came in to discuss "reflux" the doctor is going to run behind.
What would you do about it?
Though, I'm not sure why you're asking me this since it has nothing to do with this thread.
Never the less, I’ll bite because this is a topic of interest to me. What kind of wait times are you talking about?
Emergency room? Public non-emergent and elective surgery? Private practice specialists? Bulk billing or private billing general practice?
I am generally in favour of people signing up for this (or not opting out as the case is now) because it very well may save their life one day. Emergency departments especially will benefit in being able to look up details on the patient. It's amazing how little most people know about their own health history.
I suppose it may also help me if I end up in ED unconscious and have some health condition they would need to know about. That situation is unlikely, and even if it did happen they could call my wife, who is also a doctor, and she'd also know what's important in my history.
So for me, there's very little benefit I see. Couple that with my distrust of the Australian Government's ability to outsource their critical infrastructure to American companies (facepalm) and have it actually work (facepalm), I'm leaning towards opting out.
For patients in general, I think the benefit to them will outweigh the risk of their personal data being stolen.
If only our government wasn't so inept with IT (we have plenty of good developers here. Why not make our own teams to build things?) I would be able to recommend this health initiative to everyone.
Edit: autocorrect fail
It is not a complete record, and you will only be shown a summary of medical history not a clinically useful record. In addition the patient may have sought opinions from multiple doctors, any of whom may not use MHR.
The risk to most people who don’t actually need complex diagnoses will be endless calls from lawyers and insurance sales along with a web experience modified to keep them worried about that visit to the doctor about a possible STI last Valentine’s day.
So you've been a doctor working in ED?
> will only be shown a summary of medical history not a clinically useful record
I'm going to guess you're not a doctor, since then you'd know how much more useful a medical summary is than no information at all.
Hell, if I have NOTHING BUT the patient's medication list, I can usually make a pretty good guess about their medical history. If the health record contained only patients' medications it would prevent an enormous amount of morbidity and mortality, as well as saving time for doctors, nurses and pharmacists all around the country.
Sure, it might not be complete, but it's far more likely to be complete than patients' memory of what meds they take for which disease, in which doses and with which frequency.
It's not the government IT I'm worried about so much, it's all the local doctors that get access to medical records and have inept IT security. Previously if there was a breach at a practice it was only the data of the patients of that practice, now if there is a breach at a practice they can potentially access the medical records anyone in the country.
The attack surface is huge and largely unguarded and now there is a massive reward for breaching it.
> I suppose it may also help me if I end up in ED unconscious and have some health condition they would need to know about.
This can be solved with a card in your wallet, which they have to go into to find which health records to lookup anyway.
I disagree about the card in wallet thing. Patients won't keep it updated. Also, most patients won't have it on them. And for many patients it would have to be a book, rather than a card. See my other comment talking about medications.
I doubt medical practices are as bad as backyard shops like conveyancers but you are spot on, the incentives are definitely there
Then we have "NexuzHealth" in Belgium, which is an app you can install that shows you which data the hospital has about you. It's a network of 20+ hospitals but you can only view your data if you are actually a patient at these hospitals, and the goal was to provide the _patients_ with the same information doctors can see about you. Something you would normally not know about.
Source: I work in one of these hospitals (software engineer) but not directly related to the app nor the ehealth system, so this is my (limited) understanding of how it works from being around the people actually implementing this.
Waiting for the claims it's government sponsored Chinese hackers attacking the opt out website...
But there are problems with an electronic system: * A single point of attack * No way to assure people it is ultimately secure, because it can never be * Fluffy exemptions to the protection offer - especially if they are more far-reaching than existing exemptions used for accessing your paper records * Creeping requirements mean that a few years later, the government might change what they can use it for.
At the end of the day, neither system can be measured in terms of risk or reward in any meaningful way - many advantages are theoretical and risks are downplayed - so you pretty much have to accept the centralisation of the worlds systems or move to a Banana republic!
Totally the same with your data in that one primary doctor's office or whatever
* No way to assure people it is ultimately secure, because it can never be
Totally same with your paper records, someone could walk in and steal your data, imagine that.
* Creeping requirements mean that a few years later, the government might change what they can use it for.
Just like paper records, you can't say what they will use them for in the future.
This means single point of attsck for everyone with an ehealth record.
With paper records, or in-house digital records, a hacker / thief, or malicious government, or what have you, has to compromise many systems.
The same applies to your paper record comment.
Single point in who's perspective though, OP worded it more like (s)he cares about his/her data not everyone else's (e.g. "I visit another doctor when on holiday - they don't have my records"). But yes, you are right about it being in general a higher risk endeavour. The question now is though, when other commenters here describe how their life and career could get in danger when someone steals their data, which do you think is going to be much harder to breach, your local doctor's office or a central database that's guarded by armed guards and experts?
Who’s going to break in to a doctors office, then scan and upload your medical records? I don’t think thieves in Australia would even bother with doctors offices because no drugs or cash.
Rather, it seems certain that this database will be breached and the data sold on the black market, and / or some future government using it outside its intended scope.
I don't think this is all this black and white as you paint it to be.
You can't steal everyone's paper records all at once in the way you can with electronic records, for example.
You're assuming you can steal the entire database at once which most certainly will also be noticed and stopped swiftly.
But how about those already stolen? Photocopying paper records are slow. If you can get the original copy back quickly, you can be quite confident they are not copied. Not so for e-records.
Digital records can most likely be duplicated much more easily.
Or there's the classic "health records left on train" incident: http://news.bbc.co.uk/1/hi/uk/7449927.stm
That's not necessarily the case. It very much depends on how it's "stolen", the cluefulness of the attackers, etc.
For example, if the data is pulled out of the live system via (say) some kind of SQL exploit, then intrusion detection gear has a possibility of noticing and reacting in a reasonable time frame.
However, if (again, for example) the data is copied directly from backup tape when the tapes are transported to secondary storage, or are (in)correctly disposed of. That's extremely unlikely to be detected. Ever.
There are just so many attack vectors. :/
Even more, any country could enter in a future war, or send soldiers somewhere in the future. The possibility of the enemy remotely mixing or changing the medication of the soldiers would be devastating. In a single strike, somebody, somewhere could close down all the hospitals in the area and the chaos could last for days or weeks. All that is needed is to take one city with one hospital connected to the same net and asking for the password to one of the prisoners.
How are they easier to steal? I would really like to know.
Even without a breach, custodians are able to monetize “anonymized” data to third parties, who can often reconstruct it.
In olden times, all of our records were in a paper folder. Breaches were more often related to office staff losing said folder. Incidents where a bunch of guys with a truck stole shelves of folders were rare if they ever happened.
IMO, with the exception of inpatient orders, prescriptions and referral automation, most of the impact of EMR has been a net negative to the patient. The fact that all of my providers don't trust the system and ask me the same 5-15 questions every time I see them belies that.
still, it's a huge target compared to thousands of doctor's offices
>Totally same with your paper records, someone could walk in and steal your data, imagine that.
nowhere near as scaleable compared to hacking a site with everyone's records
source? that might be the case if you're including all the high resolution imagery, but I'd imagine all the text records can't be that big.
>and if you have state actor or corporate level of budget one could easily scale stealing paper medical records
that would either require an operation lasting weeks/months to hit all the doctors offices (with a small crew), or hitting all tho doctors offices at the same time (huge crew). the former increases risk of detection exponentially, as someone is going to notice eventually, and once people find out, capture of your crew by the police will be inevitable. the latter is also risky because you're going to make a lot of noise assembling said crew, and one of them is going to snitch on you. in contrast, if all the records were centralized in one online database, all you'd have to do is have a small team of experienced hackers hack it from a the safety of a country with no extradition treaty. low risk of one of them snitching on you AND low risk of capture.
>I'm not so sure it's going to be easier to compromise super-guarded database compared to a lot of paper records, would like some hard numbers, but those are going to be hard to get.
I'm sure on an individual level, it's definitely easier to burgle a doctor's office than a super secure government database. but see last paragraph about scaleability.
That's going to be true with the database theft too.
> All you'd have to do is have a small team of experienced hackers hack it from a the safety of a country with no extradition treaty
I'm not so sure that's won't raise any red flags anywhere (foreign IP and possibly a lot of data being transferred). Imo it should, but we can't really know?
I agree with rest of what you said though.
at that point, all the data is already gone. whereas with burgling doctors offices, they've been noticed within a few dozen break-ins.
>I'm not so sure that's won't raise any red flags anywhere (foreign IP and possibly a lot of data being transferred). Imo it should, but we can't really know?
that depends on how the system is accessed. if it's some webapp on some government intranet running off some random computer (that's also used for other stuff), then it's pretty easy to hide your tracks by compromising one of those machines. even if they have egress alerts (doubt it) it'd be pretty trivial to go for the high value to size ratio files first (text files), and exfiltrate over a long period of time.
Happened to a relative of mine.
Hilariously, they've already let on they're not going to renew the Accenture deal - which no doubt will _highly_ motivate them to provide exemplary support and security over the next two years:
"The Australian Digital Health Agency has begun talks to replatform the My Health Record system ahead of the 2020 expiry of its multi-million deal with national infrastructure provider Accenture."
I trust government with my private data, not Salesforce or any other corporation.
The only difference between government-fronted storage and direct-to-the-corporation like Salesforce is that corporations are mostly driven by profit and have slightly stronger reasons for protecting data to avoid losing your trust and money. Government motivation is mixed and changes over time.
Well, I'm not a customer to Salesforce, so they have no incentive to keep my trust and they get no money from me, but they can make money on my data, and likely would, why not?
So now google know everyone opting out I assume?
I'm about to create extensive guide on un-Googling yourself and your family. Mainly use Apple ecosystem, they make money selling you phones and macbooks, not your data.
First thing is don't give Google any info to identify who is behind that browser, if you go to google.com directly. Use VPN to shuffle IPs, use only Private browsing windows (kills cookies), don't stay logged in to Google, don't use Chrome.
Second, is to block tracking network requests from most of the websites to Google, like (googletagmanager.com, googletagservices.com, google-analytics.com, cloudflare.com) by using adblocker (uBlock Origin).
What a stupid conclusion.
I guess the outrage makes sense when looked from an American point of view where you distrust the government by principle?
Under the current government we have the broken NBN, the fractured MyGov that has been repeatedly hacked, the falling over census website, other broken health care systems.
We can't trust that they can build it safely.
Good engineers, who love coding, can design a big system, are unlikely to rule over the Design. It'll be bad engineers, now Managers, with good political skills, that got promoted because its their only way to survive, being otherwise useless.
It is totally upside-down, hence the mess.
It will be AWS, no nonsense like kubernetes, possibly a dash of OpenBSD for public layer, least privilege IAM, Cloudformation everywhere. Solid. :) Open Sourcing it is an option too.
But that's mostly convenience for me. My wife worked as a doctor in emergency for a while. The only way to get a new patient history including all the information you've said is to call their doctor or ask them. Many patients can't give a full medical history and very few can do so in detail when it's complex. Many doctors aren't at work 24/7 when you want to call them. An E-health record is better.