Sunday, October 11, 2026

UDLCO CRH: Collecting patient identifiers in the form of consented signatures vs having a completely anonymously consented user driven healthcare platform usage

 Keywords




Knowledge Asymmetry | Patient Journey Records (PaJR) | Ayushman Bharat Digital Mission (ABDM) | Digital Personal Data Protection (DPDP) Act | Anonymization vs. De-identification | Ethical-Legal Tradeoffs | Gandhian Swaraj | Tagore's Sovereign Collectivism

I. Introduction: The Ethical-Legal Paradox of Digital Healthcare


  • The Core Dilemma: How can a digital health platform remain genuinely ethical when severe knowledge asymmetry separates expert caregivers from vulnerable care seekers?

  • The Legal Compromise: Driven by strict regulatory frameworks (such as India's DPDP Act and ABDM guidelines), platforms and users often settle for a barely valid legal equilibrium—relying on explicit consent portals, signed audit trails, and mandatory identifiers.

  • The Philosophical Question: Is this bureaucratic compliance an authentic moral safeguard, or is it a paternalistic imposition that alienates users, forcing a false trade-off between privacy and clinical survival? Furthermore, how can decentralized healthcare find legitimacy without reverting to top-down surveillance, drawing instead on the principles of Anarchism found in M.K. Gandhi’s Swaraj and Rabindranath Tagore’s "Amra Sobai Raja"?

II. Methods: Analytical Framework & Discourse Synthesis


  • The Socratic Steelman Approach: We examine the friction points exposed in recent dyadic and collective transcripts among healthtech volunteers, researchers, and platform architects.

  • The Evaluative Lens:

    • Analyzing the tension between formal institutional workflows (ABDM/DPDP compliance, Fiduciary liability, KYC verification) and grassroots patient realities (digital literacy gaps, reliance on local intermediaries, fear of legal exposure).

    • Juxtaposing modern data governance against classical Indian political philosophy—specifically Gandhian self-reliance (Swaraj) and Tagore’s non-hierarchical communal sovereignty.

III. Results: Findings from the Decentralized Frontier


  • The Illusion of Frictionless Consent:

    • While digital onboarding appears seamless for digitally literate users, underprivileged populations frequently engage in superficial compliance—scrolling past complex legalese and trading signatures blindly to secure clinical care.

  • The Anonymity vs. Accountability Impasse:

    • Complete user anonymity preserves privacy but destroys medico-legal accountability, leaving platforms vulnerable to fraudulent entries or liability disasters.

    • Conversely, strict institutional identification (e.g., ABHA/Aadhaar integration) protects the platform legally but introduces state-adjacent surveillance, alienating privacy-conscious participants who seek collective intelligence without institutional capture.

  • The Regulatory Gray Area:

    • Researchers operate in a state of high anxiety, balancing statutory research exemptions under Section 17(2)(b) of the DPDP Act against fears of severe penalties and the practical impossibility of meaningful secondary research using strictly anonymized data.

IV. Discussion: Towards an Anarchic, Self-Governed Health Commons


  • Beyond Coercive Legalese:

    • Relying on standardized legal contracts assumes a level of market participation and literacy that marginalized care seekers do not possess. True ethical architecture cannot rely solely on "I Agree" checkboxes that mask deep structural inequalities.

  • Gandhi’s Swaraj and Medical Autonomy:

    • Gandhian self-rule suggests that true order emerges not from state-enforced compliance or punitive laws (like multi-crore penalties), but from moral self-governance and decentralized, community-anchored trust.

  • Tagore’s "Amra Sobai Raja" (We Are All Kings):

    • Tagore’s vision posits a realm where hierarchy dissolves and every individual acts as a sovereign entity participating in a shared cooperative. Applied to digital health, this mirrors a peer-to-peer collective cognition model—similar to an organic support group—where participants share insights horizontally rather than ceding their agency to a centralized data fiduciary.

  • Conclusion:

    • The path forward requires moving past the false binary between illegal anarchy and bureaucratic authoritarianism. By decoupling deep clinical learning from rigid personal identifiers and building transparent, community-vetted layers, health platforms can honor both individual dignity and collective medical progress.

Follow-Up Question: In light of these tensions, how can grassroots health networks best balance the legal necessity of accountability with Tagore's vision of non-hierarchical, peer-driven sovereignty?

Provide a socratic steelman imrad summary with key words focusing on how knowledge assymetry between care givers and care seekers considerably make it more and more challenging to project a system that is ethical and finally both sides settle for something that's just barely valid legally as in having to collect and store real patient identifiers in the form of consented signatures vs having a completely anonymously consented user driven healthcare platform usage with it's risk of having no legal or valid mechanism of those individual realities getting governed by collective congnition and yet getting governed through Anarchism as propounded by MK Gandhi in his Swaraj and Rabindranath Tagore in his "amar sobai raja amader aei rajar rajotte"?

Fortuitously there was a dyadic as well as collective discussion triggered at nearly the same time. The dyadic was between two PaJR volunteers around privacy issues and the collective conversation in another group discussing similar issues:

Collective group conversational transcripts:



[29/09, 14:26]hu4: Are these all DPDP compliant. What about consent for secondary use of data ?
Is that taken by all abdm users at source ,?

@⁨dpdp expert?

[29/09, 14:29]hu3: there is a grey area in DPDP allowing secondary use for research. can anyone share light on that?


[29/09, 14:30]hu3: I keep attending panels and talks on this - but everyone is as confused as everyone else. It is causing irreparable harm to AI research and development in the country.

[29/09, 14:31]hu3: I would for once welcome a precedence from any govt body which can be followed as an example by rest of researchers in the academia

[29/09, 14:33] hu5: I work for IIB (Private medical Insurance data registry) in India under IRDAI. We do use data that is anonymised and aggregated for research and AI models to improve Insurance cover and Healthcare delivery. This is safe from DPDPA as there is no personal identifier that needs patients consent.

[29/09, 14:35] hu6: Just like we closely follow the movements of the car/ truck in the front of us on a water logged road to judge the number location and depth of ditches underneath πŸ€“

[29/09, 14:37]hu7: Precedence is good
But not safe when a law exists. Then action can be taken on selective users.

[29/09, 14:38]hu8: DPDP will cause irreparable harm to entire HealthTech implementation in India.

[29/09, 14:38]hu1: Govt themselves publishing data... Hence I would wish to know how compliant this data set is.

[29/09, 14:40]hu3: I am aware that NHA has provided this for insurance startups

[29/09, 14:40]hu3: Thanks for sharing. But DPDP clauses are very tricky and left so much to interpretation.

[29/09, 14:40]hu8: Isn't that true for all laws

[29/09, 14:41]hu5: Values drive precedence…. also, DPDPA allows statutory bodies to use data for research and studies

[29/09, 14:42]hu3: All of us using retrospective data - are doing at our own risk. And it is fine, personally I have come to terms that I am okay with spending some time in jail, if that is what it ends up requiring.

[29/09, 14:43]hu6: There is jail also? Or just fine

[29/09, 14:43]hu3: Sir I cannot pay 250 crore - Leave that I cannot even pay 2.5 Crore

[29/09, 14:43]hu8: That's how the damage begins, with such half in fear, half in jest statements.

One of the top medical researchers of the country is now afraid of doing research.

[29/09, 14:45]hu6: And I am sure a new form of indemnity insurance for DPDP compliance is going to come out soon

[29/09, 14:47]hu2: For a high-value coverage limit of ₹250 crores, annual premiums can vary drastically—ranging from ₹15 lakh to over ₹2.5 crore per year


[29/09, 14:48]hu2: He didn't say he was afraid.

He has already come to terms with going to jail


[29/09, 15:26]hu9: Too early to call it DPDP compliant. NHA says the Secure Data Environment will use de-identified/anonymized data in a secure environment. For secondary research, DPDP can rely on genuine anonymization or the research exemption under S.17(2)(b)/Rule 16, subject to conditions, and not necessarily fresh consent. The key question is how effectively the SDE actually anonymizes the data.

[29/09, 15:40]hu9: Yes, there is a grey area, but DPDP does expressly provide a research route. Section 17(2)(b), read with Rule 16 and the Second Schedule, permits certain research/statistical processing subject to specified safeguards. So secondary use does not necessarily require fresh consent in every case.

[29/09, 15:42]hu2 with Gemini 2.5 flash lite in google chrome browser: No, ABDM compliance does not automatically equal DPDP compliance. 

While they overlap, they serve fundamentally different legal and architectural roles. [1] 
The integration of the Digital Personal Data Protection (DPDP) Act alongside the Ayushman Bharat Digital Mission (ABDM) introduces critical rules regarding primary collection, secondary use, and source consent. [1, 2] 
------------------------------
## 1. Are ABDM Consent Forms DPDP Compliant?
The answer is conditional: ABDM provides the technical framework, but the hospital/app must handle the legal compliance. [3] 

* 
* Where they align: The ABDM [Health Information Exchange and Consent Manager (HIE-CM)](https://abdm.gov.in/strapicms/uploads/privacypolicy_178041845b.pdf) natively satisfies several core DPDP mandates, such as providing itemised, time-bound, and fully revocable consent. [4, 5] 
* Where they gap: An ABDM electronic "consent artefact" only authorizes the transfer of a record for a specific window. It does not cover how that hospital (the Data Fiduciary) processes, logs, or secures that data within its internal servers. To be fully DPDP compliant, the hospital or healthtech app must issue a standalone, multi-lingual DPDP privacy notice detailing how they handle data internally. [1, 6, 7] 
* 

------------------------------
## 2. What About Consent for Secondary Use of Data?

Under Section 6(1) of the DPDP Act and Clause 10.2 of the ABDM Health Data Management Policy, secondary use requires fresh, separate, and granular consent. [4, 6] 

Secondary use refers to using your medical data for anything other than your direct clinical treatment—such as medical research, training artificial intelligence health models, or insurance underwriting. [1, 8] 

* 
* The Law: Consent obtained for medical treatment cannot be bundled with secondary uses. If a hospital wants to use your diagnostic records for public health research, they cannot use your clinical care consent. [1] 

* How it's handled: They must issue a brand-new consent request via the ABDM framework. For research, the ABDM system uses a specific purpose code (RESCH). If data is completely anonymized (stripped of all personal identifiers so it can never be linked back to you), it falls outside the scope of the DPDP Act and can be used for broad statistical analytics. [4, 8, 9, 10] 
* 

------------------------------
## 3. Is Consent for Secondary Use Taken by All ABDM Users at Source?
No, it is not systematically bundled or taken at the source. Because ABDM utilizes a federated, decentralized architecture, there is no single central repository collecting broad, upfront consent for secondary data usage. [11, 12] 

Instead, data processing happens via two distinct gates:

| Gate Type | Who Initiates It | How Consent is Captured |
|---|---|---|
| Primary Use (Clinical Care / Treatment) | Your attending doctor or hospital at the time of your check-in. | Requested at the source through a real-time ping to your ABHA app or a physical intake form. |
| Secondary Use (Research, Analytics, AI) | The specific research institution, healthtech company, or university. | They must trigger a completely separate, dedicated request to your ABHA ID later on. You must explicitly tap "Approve" for that specific secondary purpose. |

Government health programs and external entities operating inside the ABDM sandbox are legally categorized as Data Fiduciaries. They face severe financial penalties under the phased DPDP rules if they pull your data for secondary purposes without an audited, explicit opt-in. [7, 13, 14] 



[29/09, 16:15]hu4: @⁨hu3⁩ the research clause as explained here may serve well right ? What were your concerns on that ?

How about imaging data ? Completely anonymised with no traceability ?


[29/09, 16:32]hu10 : We discussed all this during our AI in Onco conference in detail

A few key points 

Anonymisation not equal to deidentification.

Even meta data should be deidentified when it comes to images.

2) there is a particular clause in dpdp there is an exception to research


[29/09, 19:44]hu11: Anonymous clinical data can be used for research etc. activities

The 'ReUse' or the 'Secondary Use' of data is the foundation of digital data

All public data sets available on the internet are the ReUse or Secondary Use examples of clinical data. 

HIPPA allows for it & DPDP also follows the same principles on the secondary use of the clinical data

[30/09, 08:49]hu12: please explain anonymisation vs deidentification ..


[30/09, 08:52]hu9: De-identification reduces identifiability; anonymisation aims to eliminate it.

[30/09, 09:00]hu10: So from my understanding
Deidentification as per certain methods in HIPAA involves removal of atleast 18 parameters linked to a data
However there still exists a possibility of reidentification either through a key or some linkage
Anonymisation is an irreversible process and is a  datset which has been processed with absolutely no chance of reidentification 
No keys, no linkage dataset etc
No reversibility at all
How does this apply in the Indian context is always going to be a challenge 

@⁨hu9

[30/09, 09:14]hu13: well.. typically the basic things everyone needs to do is at least mask the personal identifiers when sharing data to protect the identity of patients..beyond that there is much more that can be done by encryption of data..the problem in today's world quasi-identifiers can be used to establish identity even if the PII is hidden..for example, if someone has access to the tea shop near the hospital and the lab data is available to them with a timestamp..they can potentially identify the person..at least narrow it down to a list of suspects..so deanonymization is going to be tougher in the days of AI..the other issue is if you deidentify to the requirement of safe harbor act referred by..you will not be able to do meaningful research..for example length of stay cannot be determined if date of admission and date of discharge is not available, in this case someone has to work up the data to calculate the LOS and send prepared data to researcher..controlling quasi identifiers has become a real challenge these days with all the apps installed on our phones tracking location and holding our PII

[30/09, 09:20]hu2: Allocate dates of admission as day 1 to day n of admission

[30/09, 09:22]hu13: yes..so basically the data has to be prepared for purpose..removing all identifiers and sharing will serve no purpose often


[30/09, 09:24]hu2: Yes layer 1 is the care wing of the data workflow and layer 2 is the research wing where this process and preparation can be done 

One can find it being done in separate layers here: https://research.pajrhealth.com/about


[30/09, 09:29]hu10: Yes. This takes time but is what we are following
Esp for our oncology research where we calculate parameters like progression free survival and overall survival

[30/09, 09:31]hu2: With separately layered workflows, I guess this can be automated and made more efficient

[30/09, 09:31] hu13 : there was a proposal originally to create a healthcare specific law called Disha on the lines of HIPAA..then somehow it got all lumped up into one DPA..healthcare data needs both portability and protection..we should put together a white paper on what needs to be specified for healthcare data portability

[30/09, 09:35]hu13: often the prep is done in Excel..and that is not  secure.. ideally what one needs to do is create a platform that preps such data for research..like OMOP..data on Excel sheets is hard to protect

[30/09, 09:46]hu2: It's regularly solved by making trained offline data gatherers,  gathering de-identified data right at the point of capturing into their online uploading devices.

Can be scaled if the powers that be take interest in such workflows

Dyadic conversational learning transcripts:

[29/09, 13:58]hu2: Has the email address been again mandatory for consent driven registration? Was unable to onboard a patient in OPD today due to the same reason

[29/09, 14:01]hu14: Not at all, only if they want access to the research database, then yes

[29/09, 14:04]hu2: Alright. Our research assistant was trying to learn how to onboard a patient and may have inadvertently added him through that interface

[29/09, 20:33]hu14: Sorry but I don't want this to happen - Huge medicolegal issues


[29/09, 20:34]hu14: @⁨hu2 will ask @⁨hu15⁩ to reach out directly to them - this consent form is null and void and we should not accept it

[29/09, 20:43]hu2: What about the email showing her actual name and also her signature?

Also how do we guard against global users doing whatever they want on the consent form? Is there a way AI could sense that a user is using a false name or signature?

[29/09, 21:02]hu14: I cannot speculate on the email being her name or not but I do know her name is not real

[29/09, 21:19]hu15: Sent message

[29/09, 21:35]hu14: Apologies but the consent form is a medico-legal document and I cannot accept willfully wrong names. I'm sorry that you advised otherwise @⁨hu2

[29/09, 21:37]hu14: There was no signature btw. Seriously undermines what we are doing

[29/09, 21:58]hu2: I'm suggesting that our interface is such that anyone can share wrong names and signatures.

We need to think of a better workaround to this problem besides most people may not want to share their identifiers online unless they are very hard pressed.


[29/09, 22:19]hu14: They are not 'sharing' their identifiers online are they? They are signing a secure private form, which must legally identify them. We could ask them to submit a copy of their aadhar but that would fast track us out of business in no time. The end is the moral limit where you trust the other party entering into a contract/transaction with you has not lied to you


[29/09, 22:21]hu14: There is no end to this, as has been evident in India recently, to vote you must apparently show your parents' documents as well. We will become a bureaucratic organization if we dig that hole but I will not wilfully tell anyone to put in a wrong name for a medicolegal document


[30/09, 08:19]hu2: The learning lessons from yesterday's debacle:

Patients signing in locally under supervision using false names or signatures can still be caught if they have used weird names that are not normal such as PA3 etc and perhaps just touched the signature interface.

If they put a false name that sounds normal and put a false signature then the current set up can't catch them and the veracity of the record may remain in limbo until the patient meets the platform physician locally and the physician can confirm the veracity by taking a locally verified picture of their aadhar card and uploading it to the platform and also make sure that what the patient or his her advocate is signing is genuine.

While that would still leave global users uploading to the platform unverifiable till they meet the platform consent manager locally, henceforth perhaps the local physician data gatherer needs to be personally responsible for whatever consents are being signed locally and also upload or send the aadhar card of the patient to the consent manager in line with the Indian national guidelines here: 

To verify the genuineness of patients uploading or sharing data within the Ayushman Bharat Digital Mission (ABDM), the ecosystem uses a strict multi-layered digital identity framework. Medical records are not centrally stored; instead, they are federated and tied directly to verified identities. [1, 2] 
The system ensures the authenticity of every patient and their uploaded data through three primary mechanisms:

## 1. Mandatory Identity Verification (KYC Verification)
Every patient participating in the ABDM ecosystem must create a unique 14-digit Ayushman Bharat Health Account (ABHA) number. The ABHA number cannot be generated anonymously; it acts as the verified legal identity using strict government databases: [3, 4, 5] 

* Aadhaar-based Authentication: The primary method involves e-KYC using Aadhaar. The system verifies the identity via Aadhaar OTP or biometric authentication (fingerprint or iris scan) directly linked with the Unique Identification Authority of India (UIDAI) database. [3, 6, 7] 

* Other Official Documents: If Aadhaar is not used, patients must submit other valid KYC documents (such as a Driving License or PAN card). The demographic details entered are cross-matched against those government registries to prevent duplication and spoofing. [3, 4] 

## 2. Cryptographic Source Verification (Data Integrity)
ABDM prevents individuals from simply creating fake medical documents and uploading them to the system as official history. The data flows through two strictly separated pathways:

* Facility-Generated Records: The vast majority of digital health records (prescriptions, lab reports, discharge summaries) are not uploaded by the patient. They are generated directly by hospitals, clinics, or diagnostic labs registered in the Health Facility Registry (HFR). Furthermore, these records must be digitally signed by a practitioner authenticated via the Healthcare Professionals Registry (HPR). This ensures that the data is originating from a legitimate, verified source, not an unverified user. [5, 8, 9, 10] 

* Self-Uploaded Documents: When a patient uses an interoperable Personal Health Record (PHR) app or an approved ABDM-compliant health locker to upload physical legacy files (like past paper reports), the system categorizes them clearly as "self-uploaded". These records are separated from verified institution-pushed data so that subsequent doctors or insurers can easily distinguish between untrusted, manually uploaded documents and certified clinical data. [11, 12] 

## 3. The Consent Manager System (HIE-CM)

To prevent unauthorized data access or identity fraud, the data is bound by the Health Information Exchange & Consent Manager (HIE-CM). [9] 

* Data cannot move or be linked without the patient actively authorizing the action via their ABHA Address (e.g., name@consentmanager). [7, 9] 
* Every request triggers a secure, time-bound notification to the patient's verified mobile app requiring multi-factor approval or active digital signature validation. [9, 13] 





[30/09, 08:27]hu2: πŸ‘†Our current Identity collection approach still makes us vulnerable to data leakage and encryption hacking that we had previously circumvented by collecting paper based signatures although storing them online in gmail still made it vulnerable.

One option to make the leakage restricted only to the patient's name, address and signature with date and still not allow that identifier leak to connect to the patient's health details would be to remove the patient's history and even diagnosis from the consent form.

The patient's history and diagnosis are anyways open access in the published layer 1,2,3 case report and if the consent form contains just the signature, date and address the patient wouldn't be vulnerable in terms of healthcare data leakage especially if we leave no way for hackers to join the dots between the patient's identifiers in the consent form and their case report?


[30/09, 08:48]hu2: I guess I have been looking at this workflow through two different lenses.

One is from that of a patient's perspective, someone who doesn't want to get his health issues discovered and yet wants to benefit from collective medical cognition as well as contribute to its progress through CBR enabling online engines to gather insights by matching similar events.

From a patient's perspective who has understood ways to do this within a system, I would be more comfortable with sharing in the web where my identity cannot be connected and it's left totally up to me on how to share my own data. 

From a researcher perspective, I understand that most humans can't be currently trained to do that on their own and hence have to trade off their data with trustworthy platforms and the trust is generally created by local word of mouth

[30/09, 12:46]hu1: I think this is a blindsided view - completely. 

The fact that someone is using WhatsApp, Google and an Android phone effectively means they've given their identity in some form to different 3rd parties. And Google or WhatsApp or Android set their own rules and people have gotten onto them in the billions. 

Our platform too has a set policy. It is a formal company which abides by its own conditions and rules. If the user does not want to abide by those set policies, they are free to do it outside?

The user can setup a WhatsApp group, not sign a consent form and simply add the people they want and still get collective cognition?

[30/09, 12:50]hu1: You see what happened here, 99 patients did not have a problem, it was the one (not blaming any one person particularly) who has now kicked off a conversation on ABDM

On another day, we want other species on the same platform. 

This makes us unserious. I would greatly encourage them to setup a whatsapp group privately and add as many people as they want. Just not with a wrong consent form with us.

[30/09, 12:51]hu1: This does not apply to us.


[30/09, 13:52]hu2: Nailed it in the last stanza!

This is what we need:

The interface needs to be simple as in how any user can set up something like a WhatsApp group, not have to sign a consent form (think of getting to use any online sites such as Facebook or Instagram without a signed consent) and simply add the people they want and still get collective cognition.

Because in healthcare getting the above made that easy is still evolving essentially due to privacy issues, we are stuck to the next best albeit rate limiting workflow which is getting them through a signed consent portal

[30/09, 13:53]hu1: The interface is simple, just not my job in telling people how to do it?

[30/09, 14:00]hu1: Also two points- one, the consent form is secure and private and not exposed publicly. It must (morally) be truthful from both parties. 

Two, the entire premise of our company is that someone chose to build an organisation that does a decent job at making it easier to join the project, de-identify any potential PIIs, and publish it externally, while taking responsibility and ownership of this process. Also providing free database access and premium tiers too. One party is doing what it's promised, the other did not ?


[30/09, 14:00]hu2: The person who has been doing it locally may have a different view from his her end? 

Most patients don't read all that TLDR in the consent form and don't understand any of it even if they try (this is some of our intern's feedback) and we know from childhood experiences of setting up any electronic service or registering to any online portal that there is a lot of legalese that we simply scroll down to click on "I agree!" 

So while we may be legally safe globally, the local person encouraging the patient to sign in is able to see that the patient is simply signing as a trade off to please the physician in lieu of his continued support to his health issues 

Most of our interns don't even encourage patients to read the consent script but simply click everything and ask the patient to sign 

Maybe we see more patients who are underprivileged to have reading skills and maybe  the company should be just an online service with only those eligible who should not need local help to fill up the consent form but then that may drastically reduce it's user base

[30/09, 14:01]hu2: I thought there was only one party?

Who's the other?


[30/09, 14:02]hu1: The one signing the consent and voluntarily engaging with us?

[30/09, 14:03]hu2: Okay but then this other party has no clue about the company's premise due to his her reading comprehension skills!

[30/09, 14:04]hu2: And this surely happens in all online platforms where most users even like us simply sign without reading because it's a tradeoff for the goodies at the other end of the login


[30/09, 14:10]hu1: They also have no clue about the treatment they take locally due to their interpretation skills? I don't get your point sir

An entire generation of people were left behind for a million reasons. And it is precisely their inability to participate in markets, that led to these shoddy outcomes?

No wonder very few have started paying us - even when left to their own behest - because Indians generally do not know how to participate in markets and the deeper cause is that they do not know self-advocacy and as a result their comprehension and interpretation is always ceded to someone else and thus the cyclical loop of inability to participate in a market. 

The only way to bring them out of that loop is to not further nanny them , which I suspect you may be advocating for but gently put them through processes of self advocacy, which the online platform actually does, as also demonstrated by the 82M geriatric patient who is now in a much better position to handle his health and through this process also benefitted his wife and advocates like @⁨hu15


[30/09, 14:12]hu1: Yeah even I do that and the entire idea pivots on trust ?


[30/09, 14:16]hu2: As I said I am probably seeing largely the crowd who are, to use the politically correct term, underprivileged in terms of literacy etc because of my chosen location of practice.

Others who may be in other locations would get to see a better breed of humans who have better interpretation skills and are much better humans who can pay for whatever services they receive. A large number of underprivileged people at the bottom of the pyramid are perhaps not among those better humans


[30/09, 14:20]hu2: Yes trust and legalese appear to be two different workflows.

A trusting human who simply scrolls down quickly through the legalese and trades off his her signature because s/he trusts there would be more ROI on this signature investment 

vs 

An overthinking distrusting human who wants the same learning returns without the identifiers investment


[30/09, 14:23]hu1: Alright, let's go back to the case in point

How many people have given a willfully wrong name yet ? 1/347

What did the director suggest? Tidy up the consent or get expelled as per policy

What is the discussion around? - how do we confirm identity absolutely. 

What was suggested? Show aadhar or verify identity in person

Did 346 people have frictionless on boarding? Pretty much and in good faith. 

How many people have chosen to not follow policy? 1

How many people will have friction because 1 person chose to antagonise policy? 346

What would a sensible and reasonable entity do?

I will leave that you. Please correct me if my interpretation is wrong.


[30/09, 14:24]hu1: You've answered it. Thank you.


[30/09, 14:24]hu1: There can also be trusting humans who can read through our incredibly thin and non bureaucratic guidelines and consent form.


[30/09, 14:27]hu2: Did 346 people have frictionless onboarding is perhaps the actual discussion here which this one patient causing a lot of friction triggered 

For those who had a ringside view of the apparently frictionless boarding , it was just a trade off by the patients for better care and none of them understood anything about what they were signing up for aka company premise.

[30/09, 14:28]hu1: Was the on onboarding friction less though? Yes


[30/09, 14:29]hu1: Trade off is a zero sum view. We are offering them a service for post hospital care, what is being traded off where their identity too is meticulously removed?

[30/09, 14:31]hu1: My ringside view is that no one, absolutely no one except me knows how much I have to put in daily for the service to run smoothly and how much it costs us. 

I am a fiercely positive sum thinker, hence the design of not wanting aadhar bureaucracy for ID verification and instead trusting them they would be truthful and hence making it as frictionless as possible.

[30/09, 14:33]hu2: We cannot trust them because we are setting up all these guard rails so that they don't sue us in court.

If we did trust them we wouldn't have needed their consent to do what we are doing

[30/09, 14:35]hu1: Incorrect, the consent is to show a voluntary transaction and not a means to tide over lack of trust.

[30/09, 14:37]hu1: You are suggesting guard rails with Aadhar etc. Not me. 

How do we know that the data in the aadhar card is absolutely true. Where does the buck stop - Im sure your final answer will stop at trust. 

This is exactly why low trust societies like India, in their zero sum ways, invite more and more and more bureaucracy into their lives! And as the recent SIR shows, there is no end and turns out absolutism is ultimately based on trust.


[30/09, 14:38]hu2: Then wouldn't it be best to have a de-identified sign in voluntary transactional interface where the patient signs with an anonymous id (like the random generated one we currently provide after they register) and at no point do we collect any of their identifiers except broad geographical such as state of origin etc?

[30/09, 14:40]hu1: Example - And how will a local hospital know that this person can be mapped to the online platform ID?

Wait, it is trusting the person's word at the end isn't it

[30/09, 14:40]hu2: I was suggesting aadhar to confirm in a better manner for the current workflow but I would be happier if we could simply evolve from the current consent form workflow to that of a completely user anonymized workflow where even the patient's IP address is incognito

[30/09, 14:42]hu2: The local hospital shouldn't know but the patient is free to share it with whoever he or she trusts

[30/09, 14:42]hu1: In other news - we tied up with ..., developed by a type 1 diabetic to help with carb counting and potentially insulin doses for carbs in a plate. 

Disappointingly, look who and what we are talking about - the one bad apple

Law of minor transigencies


[30/09, 14:43]hu2: I did notice in the 32F group.

Kudos to the team πŸ‘

Let's see how it works out

[30/09, 14:43]hu2: That one bad apple was a research assistant who triggered a lot of research hypothesis! πŸ˜…

[30/09, 14:43]hu1: Yes let's see how this evolves. Real people offering real solutions

[30/09, 14:44] hu1: I know yes but what she did was morally wrong


[30/09, 14:45]hu1: And how do you confirm the patient is in fact of that pajr ID?

[30/09, 14:50]hu2: Local perspective:

Yesterday or was it day before, she was helping another patient fill up the consent form when I realised even she didn't know how to do it so I asked her to read it well first, which I had asked her earlier as well and then finally she started doing both hers as well as the other patients and then again there was a very slow internet connection for both of them in the OPD so they went out and when she came back she said her's was taking her to a research page and asking her to share about herself hence I said alright write research assistant or RA and then she came up with PA3 and again went outside for the internet connection and now I realise she was actually filling up the consent form.

At the end, I feel it has given us a lot of food for thought to try and eliminate this currently rate limiting consent gathering step altogether in favour of a mandatory anonymizing platform that will not need to be DPDP compliant and the onus will be on the online user. Only current issue with that is we'll lose a lot of our local new user base who aren't online savvy


[30/09, 14:55]hu2: The patient can be interviewed and asked if the platform story matches his her story and if a few clinical images albeit de-identified actually look like her or objects he or she may have worn and at the end we just would have to trust the patient it's them and if we are their local doctor responsible for having gathered that data it would be easier to believe the patient

[30/09, 15:02]hu1: The part where hers was taking to a research page is what I want to know. What exactly happened there?

I was quite sure the intent was not to malign but that's how the outcome turned out to be.

[30/09, 15:03]hu1: The zero sum thinking hospital will not budge and install wifi but our poor little online platform will have to buckle!

[30/09, 15:04]hu1: If anything, the rate limits have drastically fallen!

[30/09, 15:05]hu1: Blimey! More rate limits for doctors who should be doing clinical work and cognition rather than ID confirming clerks!

[30/09, 15:05]hu1: I agree


[30/09, 15:07]hu2: Actually interestingly she was using the hospital wifi that day which even I hardly ever use but then even that WiFi stopped for her


[30/09, 15:07] hu1: Yes I will tag the earlier conversation around it here again

[30/09, 15:16]hu1 : I think that was quite frictionless and self explanatory

[30/09, 15:17]hu1: Easy peasy as far as I can tell


[30/09, 15:04]hu1: If anything, the rate limits have drastically fallen!


[30/09, 14:57]hu2: What we talked about today is perhaps something very novel and original that I'm not sure if anyone has talked about before and in the coming months or years this discussion will bring rich dividends


[30/09, 15:01]hu1: Lets not lose perspective here, we are still in healthcare so consented pathways are the best way forward. 

Imagine about 1 year ago, we needed patients to get a photocopy of the consent, sign it and then we stored it in Google drive. And then there was manual logging where there was acres of TLDR data. 

To now where the consent takes 3 to 5 minutes (on a server we own, this is the part nobody gets because that is the IT part I'm solving), the group is automated and the logging is automatically deidentified (with a very good sensitivity and specificity from both humans and AI) and the log can be searched easily with SQL based searches. The log is also converted into numerical vectors ,where meaning or intent of the search is also matched. 

Doing away with a consent entirely would be going opposite ways.

[30/09, 15:22]hu2: Not really!

What I'm proposing now was decades ahead and when we were writing a text book on these issues published in 2012 here: https://www.irma-international.org/book/user-driven-healthcare-narrative-medicine/41908/, we actually utilised quite a lot of data for some of the chapters borrowing from the healthboards website, itself begun at 1998 where all patients login using an anonymous name and nothing other than perhaps their email address is collected (at that time in 1998 email was perhaps the only media)!


[30/09, 15:23]hu1: Isn't it pretty much the same, if not even easier - name, dob +/- email is what we are taking privately and none exposed publicly


[30/09, 15:23]hu2: If someone asks what should we call you, doesn't it mean we have a choice to provide whatever name we like?

[30/09, 15:24]hu1: It says your name doesn't it? And that is a colloquial way of asking

[30/09, 15:26]hu1: I'm convinced both you and I know that we are dilly dallying here and that there is no end to this bottomless pit of how we see and answer these questions. Ironically, the more we don't declare upfront, the more we invite invisible logging and mining!


[30/09, 15:28]hu2: Yes I did do some invisible logging and mining from the healthboards site...

It still influences my thinking I'm forced to admitπŸ‘‡

"Participation on HealthBoards is free and requires registration and agreement and adherence to the Posting Policy, enforced by volunteer member moderators."



[30/09, 15:30]hu2: Agree about the dilly dallying and one of the reasons I got into this consent workflow is because of publishing of our local patients into the BMJ case reports workflow that drove me in this consent form direction instead of my gunning for a totally anonymized patient data collection which that one bad apple triggered recently!

[30/09, 15:31]hu2: Either we are still thinking about these issues as the entire globe is at a crossroads as to how one can meet this challenge

[30/09, 15:49]hu1: How do you propose the anonymised consent workflow looks like without adding 2nd or 3rd order burden to practitioners ?


[30/09, 15:54]hu2: This will only work once most of our patients are at the level of 42M or even 44F, 49F etc 

Typically these net savvy users will register to login themselves once we share the web page and the website will not keep any of their real traces but simply get them to go through the same legalese minus their having to share their identifiers except state of origin like WB or Telangana etc and simply allow them to click on "I agree" to the terms as a transactional proof of their enthusiasm and trust for our project toward helping in their local caring using our global learning.

The subsequent workflow would be same where the system would automatically create a PaJR group with that anonymized ID

[30/09, 15:58]hu1: Okay but login where? On the research website?

[30/09, 16:00]hu2: One login and one website for patient participants could make it less confusing


[30/09, 16:06]hu1: Yes it is how it is currently. Phone number across whatsapp, database and everything PaJR


[30/09, 16:10]hu2: Yes just minus the name and signature and preserving the broad geolocation would make it easy for online savvy users to own their own records although not so much for our local population of under privileged net unsavvy users. Till then we will need to continue to get the signed consent from the local users.

Could we give online net savvy users the option to opt for a non signature, unnamed, untraceable version similar to what google provides in the incognito tab? This could be a breakthrough


[30/09, 16:12]hu1: They can choose alternatives but I won't anytime soon 

The cost of one black swan legal issue is more than the cost of these ventures


[30/09, 16:40]hu2: Yes the law can be twisted anyways anytime and at the end of the day one just needs to heed whatever is optimal