Cross-sectional health research has produced real public benefit, and nothing here argues against that. The question is why getting that benefit currently requires the same sensitive record to be handed, whole, to every hospital, insurer, pharmacy, and study that might one day want a piece of it.
Every hospital, clinic, insurer, pharmacy, and research programme an individual deals with typically keeps its own copy of the relevant medical history. Each copy is a separate liability: it has to be secured, backed up, audited, migrated between systems over the years, and eventually archived or deleted. A meaningful share of healthcare IT spending goes not toward using medical information but toward maintaining thousands of partially overlapping copies of it.
A Databank replaces duplication with controlled access. Providers query a patient's record when they need it, rather than each keeping an independent replica — the same principle that lets a bank balance be checked without copying the account itself. The result is lower administrative overhead and a smaller, more contained breach surface, on top of the privacy benefit.
Medical information tends to become more useful with time: a complete longitudinal record spanning decades is often worth more, clinically, than any number of isolated snapshots held by individual providers. Today that record is fragmented across every institution a patient has ever seen, and even where legal portability exists, practical interoperability between their systems usually doesn't.
A Databank naturally supports a single longitudinal record, owned by the individual rather than by any one provider. Each visit enriches the same record; each provider accesses only what a specific episode of care requires. Continuity of care improves at the same time privacy does — the two are not in tension here.
Health data is usually where privacy and scientific progress are framed as opposites. In the current model, patients are typically asked to sign away broad rights to their data for vaguely defined future research, with consent obtained once and interpreted broadly for years afterward.
Under Databanking, research access becomes its own auditable transaction. Individuals can choose, per study:
Researchers, in turn, query consolidated, anonymised, cross-sectional data drawn across every contributing account, with the same stricter opt-in and anonymisation safeguards — k-anonymity or differential privacy among them — that any aggregate analysis under this model requires. The aggregate research benefit doesn't go away; what goes away is the need for blanket, indefinite consent as the price of contributing to it.
The strongest objection to tightening individual control over health data is the need for fast, broad action during epidemics and other emergencies — an outbreak cannot wait for millions of individual opt-ins. A Databanking architecture can accommodate this without abandoning custodial control by default: a predefined emergency-access mechanism, fixed in legislation in advance, would permit broader, time-limited access under conditions that are explicit, logged, and independently reviewable afterward.
Today, patients are asked to trust dozens of institutions simultaneously with the same highly sensitive information, and trust, spread that thin, becomes hard to assess or hold anyone accountable for. Under Databanking, the patient holds a single custodial relationship with a chosen Databank, while every provider receives only what a given episode of treatment requires. Responsibility for protecting the record concentrates in a regulated institution whose sole purpose is information custody — not care delivery, insurance underwriting, pharmaceutical marketing, or research. That restores a distinction that today's fragmented model has largely erased: between those who care for patients and those who hold their information.
The problem is not that medical information is used. The problem is that medical information is copied. This is the same distinction, applied to health data specifically, that motivates the rest of the Databanking proposal: the problem is not that data is analysed, but that data custody and data analysis are currently performed by the same institutions.