Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Is The NHS Rushing Into Tackling Record Waiting Lists With AI
Articles

Is The NHS Rushing Into Tackling Record Waiting Lists With AI

Kingsley HayesBy Kingsley HayesJuly 1, 2021Updated:May 2, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The NHS plans to deploy AI to tackle the backlog of waiting lists exacerbated by the coronavirus pandemic. A £160 million scheme announced last month plans to implement some radical new technology-driven measures in order to reduce the NHS’s record 4.7 million waiting list.

For example, more GP patients will be given the option to be assessed by AI chatbots which can refer them on to other services such as physiotherapy. In Bristol, elderly patients are already trialling support robots which enable them to be assessed remotely. Multidisciplinary weekend clinics are also planned.

Needless to say, a careful data protection risk assessment of all such schemes will need to be conducted. The most concerning scenario would be where incorrect AI decision making led to a patient receiving the wrong treatment or prioritisation, which ultimately led to a worsening of their conditions or to death. AI does not have a great reputation for dealing with the complexities of healthcare. For example, it was reported that the QCovid algorithm designed to identify priority groups for vaccination was likely to miss those with rare illnesses.

Aspects of the scheme have been roundly criticised by the BMA. BMA council chair Dr Chaand Nagpaul said that “The Government is already aware that many of the technological innovations, such as ‘pop-up clinics’, previously launched during this pandemic have ended up actually increasing workload”. Mr Nagpaul went on to suggest that, “Technological innovation should be used to address some really basic and simple issues, which the BMA has been calling for, such as enabling hospitals to be able to prescribe electronically for patients and to have direct access to community diagnostics”.

The decision to adopt AI carries with it significant consequences in terms of data protection law. Article 22 GDPR has rules designed to protect individuals where automated decision making is being used. In this context, the informed consent of patients is key. There is as yet little detail as to how the NHS plans to secure consent. Nor do we know how such requests for consent might be framed. Nor do we know if any future use of the patient’s consent to processing by AI will be made once the processing of waiting list data is completed.

In a time of increasing public concern around the misuse of personal data, a further risk to the success of such schemes is that many patients might simply refuse to consent to their data being processed by AI.

Too often organisations see AI as a panacea against all ills. It is often touted as a miracle cure for supposedly insurmountable administrative obstacles. The result is often that organisations rush headlong to implement algorithms without adequate development and testing.

The NHS needs support to deal with the effects which the coronavirus pandemic had on waiting lists. Before AI becomes part of the solution, the NHS will need to ensure that appropriate data protection processes and technical security are implemented with great care. If this is seen to be the case, the public’s confidence in such schemes will grow, thus ensuring that the public are willing to consent to participate. In order to be certain that consent to AI processing is valid, it is also vital to ensure that patients fully understand what they are consenting to and that it is written in simple terms.

The NHS should also be careful to avoid seeing unduly broad consent as where an organisation refuses to provide services unless the consumer gives it more data than is required to provide those services, the person’s consent to process such data may be deemed invalid. Recital 43 GDPR states that “Consent is presumed not to be freely given… [if] the provision of a service, is dependent on the consent despite such consent not being necessary for such performance.”

The NHS should avoid any suggestion that consenting to having personal data processed by AI would result in patients having quicker access to services. Where consent to process data is obtained under the shadow of a suggestion that something detrimental may happen if consent is not given, such consent could be argued to be invalid.

The NHS will have to overcome significant technical legal obstacles before it fulfils the promise of AI.

Kingsley Hayes
  • Kingsley Hayes
    Why Data Protection Is More Than Just A Tick Box For Charities

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}