US Government Agencies Will Soon Be Able To Access Foreign Medical Dossiers Due To Patriot Act

from the radical-transparency dept

The US Patriot Act has suddenly scared an entire nation, and it’s not the US itself this time. The Netherlands is currently going nuts about the US government being able to request medical details of all its citizens when the Dutch Electronic Patient Database (EPD) is implemented next month. This will not be the only country that freaks out because of the Patriot Act, as this sort of thing is likely to happen a lot more often. A recent study explained that US government agencies can secretly request anyone’s data if they are using a cloud-computing service which ‘conducts systematic business in the US’. It is already sufficient when the service provider is somehow a subsidiary of a US company.

That turns out to be a problem in the Netherlands, because the company that has developed the EPD and will be hosting the patients’ data on its cloud computing systems is the US-based CSC. The Dutch government and the organization responsible for implementing the EPD are convinced there is no problem, because there are clear contracts which have assigned Dutch jurisdiction, and fortunately the Dutch have stringent data protection laws that will protect patients’ sensitive data. Because that’s what data protection laws do, right?

False! At least with regard to information law, researchers from Amsterdam University warn that this analysis is way too simplistic. According to the scholars, it is quite possible the US government agencies can circumvent data protection laws and could easily request access to medical information of every single person in the Netherlands. The study doesn’t just cover the Netherlands (though it is especially timely for that), but rather looks at how these risks may apply more globally. Here are just a few of the findings that should raise eyebrows across the globe:

“When using a cloud service provider that is subject to U.S. jurisdiction, data may be requested directly from the company in question in the United States. […] From a legal point of view, access to such information cannot be denied and cloud service providers can give no guarantees in this respect. […] The possibility that foreign governments request information is a risk that cannot be eliminated by contractual guarantees. Nor do Dutch privacy laws offer any safeguards in this respect. […] It is a persistent misconception that U.S. jurisdiction does not apply if the data government requests for information do not apply to Dutch users of the cloud. […] legal protection under specific U.S. laws applies primarily to U.S. citizens and residents. […] Given the nature of intelligence work, it is not possible to gain insight into actual requests for information by the U.S. authorities […] Cloud providers will typically not be able to disclose whether such requests are made”

If the above doesn’t yet lead to a new international outrage against the US Patriot Act, then the following sentence on the extra-territorial effects of the Patriot Act should at least send shivers down the spines of sovereignty-loving non-US government officials:

“The transition to cloud computing will, in principle, result in a lower degree of autonomy […]”

Filed Under: , , ,

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “US Government Agencies Will Soon Be Able To Access Foreign Medical Dossiers Due To Patriot Act”

Subscribe: RSS Leave a comment
Anonymous Coward says:

Re: Own Goal

I have been advising people not to use any US-based service providers for quite some time now, partly because of things like the above, but also because most if not all companies tend to shut down service to the whim of any government official (and a number of non-gov other companies). So no GoDaddy, Amazon, etc. Not that local companies may not do the same, but at least you know what your rights are and where you can get them (up to a point).

And of course the same goes for companies that use them.

So yes, this is already costing the US business, and it will probably only get worse.

gorehound (profile) says:

Re: Own Goal

I stay away from using US Business when I can in regards to this type of stuff.
And I do not use Cloud at all.I do use a VPN which is on a Foreign Company who does not keep Logs.

I advise folks to do the same and stay away from US as your info will be known.

It will be great to see folks around the World wake up and realize what is going on if they use the US stuff.

Anonymous Coward says:

and if people world wide still cant see why the USA conducts secret ‘negotiations’ over new ‘treaties’, why they freak out when bodies like the ITU try to take over running something or implementing more control over something, more fool them. the US is doing whatever it takes, whatever it can to take control of the whole nine yards! it wants to have every bit of data on everyone and everything, but doesn’t want anyone else to have that data. to go down this route of being able to access info on non-US citizens or even US citizens that live in other countries is taking the piss. talk about defeat German Fascism so as to gradually bring in the home-grown version. what a joke!

The Real Michael says:

Re: Re: Re:2 Re:

The only logical explanation seems to be that they’d want to create a profiling database to be freely accessed by all interested gov/law parties. The thing is, much of that data would be acquired without rhyme or reason and with zero oversight, then inevitably be used against certain individuals. Sort of like playing god with people’s lives.

Anonymous Coward says:

Data Security

If you do not control the machines that hold your data then you do not control access to that data. This holds true when cloud services and/or external companies running your machines.
Whenever a person or organization does not have control over their data storage they can be held hostage by another entity, and risk losing all their data if they fall out with that entity, or it ceases to exist.
How long before the US government uses cloud services as coercion in gaining their way in trade treaties.

G Thompson (profile) says:

Thankfully here in Australia the Government has mandated that at a Federal and State level (under our own Privacy Rules) NO data of any sort by any government or quasi-government (or even ones that tender to govt) can be held outside of Australia at all.

This strangely enough has made the US companies annoyed with the Australian Government to the extent that the USG has queried it and made an issue about it to no effect whatsoever. Our Privacy laws cannot be diluted, changed, nor removed for any reason for anyone no matter what any treaty the USG wants to rant about.

Michael (profile) says:

Re: Re:

“Federal and State level (under our own Privacy Rules) NO data of any sort by any government or quasi-government (or even ones that tender to govt) can be held outside of Australia at all”

Sure, but the US government has access to lots of private company information (Facebook, Google, Microsoft, and health providers that use something remotely attached to a US company, etc.).

G Thompson (profile) says:

Re: Re: Re:

All health records from Private or Public health providers are NOT allowed out of the country in any way shape nor form. In fact the Records are highly restricted and come under the National Privacy principals specifically that have full criminal (not just civil/governmental fines) sanctions attached for all knowing individuals (glass ceiling for PTY/LTD is gone in this respect)

The info that private individuals and in a limited way business’s place upon Google, Facebook, are fair game yes. But a company that uses these venues is still liable believe it or not under the Privacy Act, and also under numerous other acts like the one that creates criminal sanctions for SPAM and selling of identifiable lists of people who are placed upon the DNC register.

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...