Protecting patient privacy by quantifiable control of disclosures in disseminated databases

被引:32
作者
Ohno-Machado, L [1 ]
Silveira, PSP
Vinterbo, S
机构
[1] Harvard Univ, Brigham & Womens Hosp, MIT, Decis Syst Grp,Div Hlth Sci & Technol, Boston, MA 02115 USA
[2] Univ Sao Paulo, Sch Med, Dept Pathol, Sao Paulo, Brazil
关键词
consumer informatics; patient privacy; confidentiality; anonymization; predictive modeling;
D O I
10.1016/j.ijmedinf.2004.05.002
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
One of the fundamental rights of patients is to have their privacy protected by health care organizations, so that information that can be used to identify a particular individual is not used to reveal sensitive patient data such as diagnoses, reasons for ordering tests, test results, etc. A common practice is to remove sensitive data from databases that are disseminated to the public, but this can make the disseminated database useless for important public health purposes. If the degree of anonymity of a disseminated data set could be measured, it would be possible to design algorithms that can assure that the desired level of confidentiality is achieved. Privacy protection in disseminated databases can be facititated by the use of special ambiguation algorithms. Most of these algorithms are aimed at making one individual indistinguishable from one or more of his peers. However, even in databases considered "anonymous", it may still be possible to obtain sensitive information about some individuals or groups of individuals with the use of pattern recognition algorithms. In this article, we study the problem of determining the degree of ambiguation in disseminated databases and discuss its implications in the development and testing of "anonymization" algorithms. (C) 2004 Elsevier Ireland Ltd. All rights reserved.
引用
收藏
页码:599 / 606
页数:8
相关论文
共 22 条
[1]   Security of the distributed electronic patient record: a case-based approach to identifying policy issues [J].
Anderson, JG .
INTERNATIONAL JOURNAL OF MEDICAL INFORMATICS, 2000, 60 (02) :111-118
[2]  
Andrews EB, 1999, PHARMACOEPIDEM DR S, V8, P247, DOI 10.1002/(SICI)1099-1557(199907)8:4<247::AID-PDS432>3.0.CO
[3]  
2-O
[4]   HIPAA regulations - A new era of medical-record privacy? [J].
Annas, GJ .
NEW ENGLAND JOURNAL OF MEDICINE, 2003, 348 (15) :1486-1490
[5]  
Armstrong MP, 1999, STAT MED, V18, P497, DOI 10.1002/(SICI)1097-0258(19990315)18:5<497::AID-SIM45>3.0.CO
[6]  
2-#
[7]   Patient data and security: an overview [J].
Barber, B .
INTERNATIONAL JOURNAL OF MEDICAL INFORMATICS, 1998, 49 (01) :19-30
[8]  
BATAMI S, 2001, INT J MED INFORM, V62, P41
[9]   Preserving confidentiality when sharing medical database with the Cellsecu system [J].
Chiang, YC ;
Hsu, TS ;
Kuo, S ;
Liau, CJ ;
Wang, DW .
INTERNATIONAL JOURNAL OF MEDICAL INFORMATICS, 2003, 71 (01) :17-23
[10]   Maximizing sharing of protected information [J].
Dawson, S ;
di Vimercati, SD ;
Lincoln, P ;
Samarati, P .
JOURNAL OF COMPUTER AND SYSTEM SCIENCES, 2002, 64 (03) :496-541