Prevent health code data from leaking or being abused

□ Our reporter Han Dandong

□ Our intern Qi Zengbei

How to achieve a balance between orderly resumption of work and production and epidemic prevention and control? How to identify the health status of people and avoid cluster infections? Recently, the implementation of Health Code across the country has provided a new idea for these issues.

The health code was first introduced by Zhejiang Province. It is based on real data. Citizens or reworkers return to work through their own online declaration. After background verification, a QR code that belongs to the individual can be used as an electronic voucher for access. In general, health codes are divided into three colors: green, yellow, and red. Green code, the city's bright code is accessible; yellow code, implementation of centralized or home isolation within 7 days, continuous application for health check-in for more than 7 days will be converted to green code; red code, implementation of centralized or home isolation for 14 days, continuous reporting Health check-in will be converted to green code.

At present, Beijing, Guangdong, Hubei and other places have launched official health code application channels, and data connectivity between provinces is also being initiated.

However, the consequent concerns about information security have also attracted people's attention.

One yard pass simplifies the process

Avoid contact to prevent infection

On February 9, the General Office of the Zhejiang Provincial People's Government issued the "Zhejiang Epidemic Prevention and Control Responsibility Order" (No. 2). The document proposes that the relationship between epidemic prevention and control, people's livelihood protection, and resumption of production should be grasped in a coordinated manner, and key personnel, places, and areas should be classified and controlled. Under the premise of proper protection measures, localities should minimize the inconvenience caused by epidemic prevention and control to the people's production and life.

In this context, on February 11, Hangzhou took the lead in launching the health code, using the "red, yellow, green" three-color QR code as a digital health certificate. Residents and visitors to Hangzhou only need to nail it or pay with Alipay. The green code can be obtained. Pass by code, red code and yellow code need to be isolated according to regulations and health check-in.

"Health code is a digital health assessment certificate based on real data. Citizens or reworkers return to work through their own online declaration. After background review, they can generate a personal QR code as an individual in the region. An electronic voucher for entry and exit enables one-time declaration, which is universal across the region. Through online security granting cards, offline code scanning verification, judging the health status of personnel, recording body temperature, identifying high-risk groups, and guiding the nationwide autonomous health declaration to achieve community, Collecting data hierarchically in enterprises, schools, etc. Government officials can view the epidemic data in stages, which can reach more groups, cover more scenes, and access more data, which is extremely convenient for users and management departments. "China Zheng Ning, director of the Department of Law of the Cultural Industry Management School of Communication University, told the reporter of Legal Daily.

After the application of the health code, residents no longer need to fill out health forms repeatedly, and staff at highway intersections and community checkpoints have also implemented "contactless" inspections, reducing the risk of cross-infection. According to the guidelines for the declaration of resumption of work issued by the Hangzhou Municipal Government, resumption of work needs to be reported on the nails. After passing the review, the employees of the company also need to make a health check in on the nails every day. Soon after, Tencent also launched its own health code.

Zheng Ning believes that health codes have three main advantages. First, the electronic version of the health code replaces the paper pass, reducing the annoyance of individuals and managers from forms at all levels. The health code can be filled out online once and used many times, which can simplify the clearance detection procedures, which not only saves time, but also reduces the risk of congregation of personnel. Secondly, with the help of big data technology, relevant government functional departments can monitor and manage personnel in real time, solve problems such as different forms, different data, inconsistent data, and cross unavailability, and improve the efficiency of joint prevention and control. Third, various types of units can also grasp the health information of their employees in time, and take targeted and accurate joint prevention and control measures.

Implement mutual recognition mechanisms in multiple places

Information security concerns

Because the health code has many advantages, it is rapidly and widely used throughout the country. As of February 24, the health code has been launched in nearly 200 cities across the country.

With the adoption of health codes in various regions, data integration between provinces has become a problem. Because health codes in different places rely on different data resources, citizens who have already received health codes often need to register health codes when they go to work in different places, and even need to be isolated for 14 days to resume normal work. This has brought many returnees. Troubled.

"Although health codes have been implemented in many places in China, some results have been achieved, but the relevant data in different places and different departments have not been fully interconnected. 'Data islands' are widespread, which greatly wastes existing data resources. "Said Zheng Ning.

On February 28, Henan and Zhejiang signed relevant agreements confirming that Zhejiang Health Code replaced the health certificate in Henan Province and the province's general agreement to resolve the “blocking point” of Henan workers in Zhejiang returning to work and resuming production in Zhejiang.

On February 29, the Hainan Provincial Bureau of Big Data released news that Hainan and Zhejiang Provinces signed the nation ’s first mutual recognition cooperation agreement on health codes for new-type coronavirus pneumonia on February 28, which also means holding green. The people of Hainan can pass smoothly in Zhejiang Province.

On March 1, a press conference on the prevention and control of the new crown pneumonia in Beijing was held. At the meeting, Pan Feng, deputy director of the Beijing Municipal Bureau of Economics and Information Technology, said that Beijing will strengthen its linkage with Tianjin and Hebei, actively promote the sharing of epidemic prevention-related data, and ensure the interoperability of Beijing's "health treasure" and related services in Tianjin and Hebei Recognized to provide technical support for the joint defense and control of the three places. In the future, the health codes of the three places will be mutually recognized.

Zheng Ning analyzed that according to the "Interim Measures for the Management of Government Information Resource Sharing", the sharing of government information resources should follow the principle of "sharing without sharing as an exception." Governmental information resources formed by various government departments should be shared in principle, and those involving state secrets and security shall be implemented in accordance with relevant laws and regulations. In addition, according to the "Government Information System Integration and Sharing Implementation Plan", in order to save resources and improve efficiency, some of the joint defense and joint control databases that have been established should open the corresponding data and work with the enterprise to build a large database of health code platforms to report to individuals independently. The information is automatically matched and verified to achieve effective joint prevention and control of the new crown pneumonia epidemic.

Once the health code mutual recognition mechanism is completed, the problem of mutual trust in different places can be solved through technical means. While ensuring epidemic prevention, it will facilitate personnel circulation, resume work and resume production, and promote economic recovery. However, as a lot of personal information is recorded on the health code, data security and privacy issues have also caused concern.

"The health code involves a large amount of personal information such as name, ID number, contact information, location, travel, health, etc. Once leaked or abused, the consequences are unthinkable. It will not only cause personal and property security risks, but may also be fueled by 'user portraits' Geographical discrimination and crowd discrimination. "Zheng Ning said.

Zhu Wei, deputy director of the Communication Law Research Center of China University of Political Science and Law, told the reporter of the Legal Daily that according to the Supreme People's Court's Provisions on the Application of Laws to the Trial of Civil Disputes in Infringing Personal Rights and Interests Using Information Networks, health information and medical conditions are the core privacy . In the public interest, with the consent of the parties, it should be used in accordance with the three principles of legality, legitimacy and necessity.

Two-pronged supervision and punishment

Keep personal information safe

At a press conference on the joint prevention and control mechanism of the State Council on March 4, the Ministry of Industry and Information Technology encouraged the provinces to strengthen their own prevention and control, promote mutual trust and benefit among provinces, and provide convenience to the people who resumed work and resumed production. At the same time, the Ministry of Industry and Information Technology will strictly implement data security and personal information protection measures to prevent data breaches and abuses.

Earlier, the "Notice on Doing a Good Job in Protecting Personal Information and Using Big Data to Support Joint Prevention and Control" issued by the Office of the Cyber ​​Security and Informatization Committee of the Central Committee of the Communist Party of China also required that "the institutions that collect or hold personal information Is responsible for security protection, and adopts strict management and technical protection measures to prevent theft and leakage. "

In Zhu Wei's view, the core of the health code is information security. The key lies in who collects these personal information, whether the user agrees to be collected, and how to use the information.

Zhu Wei said: "First of all, personal information cannot be collected by anyone, and only when authorized by government agencies can be collected. Second, individual users should have control over personal information. After the epidemic has passed, users' right to be forgotten should Guaranteed. Third, the information must not be used for commercial purposes in any way. If the health code does not need to exist after the epidemic, it should be destroyed in a timely manner. "

Zheng Xueqian, director of Beijing Huawei Law Firm, believes that the government should issue normative documents to ensure that the collection of information has a legal basis. At the same time, privacy protection and use methods must be stipulated. Government departments and public security departments should strengthen cooperation and self-fill The data are combined with state-controlled data.

Han Yingwei, a senior partner of Beijing Yingke Law Firm, also believes that the administrative department should strengthen the supervision of the platform, establish a disciplinary mechanism, increase channels for complaints and reports; increase publicity of law, and increase the public's awareness of legal rights protection; related platforms must be improved The level of science and technology, increase the protection of citizens' information, and prevent the leakage of personal information from the source.

"Health codes are important for epidemic prevention and control, but as a new thing, there are inevitably some problems that need to be improved by relevant departments." Han Yingwei said.