Estonian police and ISS say most health data queries are lawful

An internal review by the Police and Border Guard Board (PPA) and the Internal Security Service (ISS) found that most health data queries made by officials were justified, but the thousands of checks raise concerns from attorney-at-law Carri Ginter about eroding trust between patients and doctors.
Interior Minister Igor Taro instructed the heads of the PPA and ISS in early June to review all queries their officials made about people's health data.
"Queries are made because of work-related needs," Taro said about the main results of the review.

ISS Director General Margo Palloson said the ISS made health data queries about roughly 13,000 people over 13 months. The review confirmed that the queries were made on a legal basis and for duties assigned to the ISS by law. 80 percent of the queries were related to security and background checks, including checks on ISS officials, candidates and service providers. 20 percent were made as part of intelligence gathering and criminal proceedings.
2 percent of all queries were incorrectly labeled but were lawful and justified in substance. One violation was found in which an official made queries about a close relative, and supervisory proceedings were launched.
Police reviewed all health data queries made this year. The review covered queries made to The Health and Welfare Information Systems Centre (TEHIK), the Health Insurance Fund's information system via X-Road, and directly to healthcare institutions, totaling 2,139. The review confirmed that all queries were related to police duties or proceedings and that a technical trace exists for each query. The vast majority were lawful and justified. There were 135 cases that were not assessed as correct or lawful or that require further review.

PPA Deputy Director General Kristi Mäe said police must always weigh any infringement of people's fundamental rights, and the reliability of sensitive data is especially important.
The PPA's most serious critical finding concerned the use of prescription data — retrieving information through X‑Road about purchased medication to determine a person's possible location. Using prescription data for searches in this way is not seen as proportionate, and the PPA instructed investigators to immediately stop the practice.
Minister Taro said oversight of state databases is reliable and citizens' information is secure. He said legislation on data protection needs updating, but the audit results from the PPA and ISS show that agencies' daily internal controls work effectively.
"Queries are not made only because of crime. For example, when the ISS makes queries, they carry the responsibility of conducting background checks on everyone who deals with state secrets or applies for a state secrets permit. There are also certain sensitive positions, such as structures of vital service providers that handle sensitive information. For example, the Defense Forces are a major requester because we must know that these people do not have drug addictions," Taro said.

Attorney-at-law Carri Ginter said officials' overly free access to sensitive data undermines trust between doctors and patients and urgently requires a stricter legal framework and judicial oversight.
"When it comes to health data, the most important thing is that I must be able to tell my doctor the truth. I must be able to trust that information with my doctor without police getting it through email," Ginter said. "The functioning of internal audits has been confirmed, which is great. But what we learned is that a thousand people a month are queried, and I refuse to believe that Estonia has a thousand potential criminals whose health data must be checked monthly — meaning 13,000 queries. It comes to about a thousand queries a month. This system clearly needs clearer regulation and much stricter oversight."
--
Editor: Johanna Alvin, Argo Ideon
Source: ERR interviews by Margus Saar and Iida-Mai Einmaa











