Two NHS patient-data companies, Arcturis Data and Akrivia Health, have agreed a £140m merger. The combined company will have access to data from 40 NHS trusts, covering more than 20 million patients currently in treatment and 100 million aggregated patient records. It also already has relationships with major pharmaceutical companies including AstraZeneca, GSK and Johnson & Johnson.
There hasn't been a breach here.
And that's what makes this interesting. We're used to thinking about privacy in terms of hackers breaking into databases, but there's another question worth asking: what happens to your data when the organisation holding it changes, merges, gets acquired, or decides to use it for something else?
With a commercial app, you can at least read the terms and decide whether you want to use it. With the NHS, government systems, policing or social care, the relationship is different. You don't realistically get to say, "I'll just use another provider." Your medical history exists because you needed healthcare. Your information exists because you needed a public service.
That's a very different relationship between a person and their data, and it's something we should be paying much more attention to.
A breach isn't the only way your data can leave your control. With centralised systems, once your information is collected, it is no longer truly yours.
https://news.sky.com/story/nhs-patient-data-groups-arcturis-and-akrivia-agree-140m-merger-13575267
