Evaluating re-identification risks with respect to the HIPAA privacy rule

Evaluating re-identification risks with respect to the HIPAA privacy rule
复制标题

DOI:
10.1136/jamia.2009.000026
复制
发表时间:
2010-03-01
影响因子:
6.4
通讯作者:
Malin, Bradley
Malin, Bradley
中科院分区:
管理学2区
文献类型:
--
作者:
Benitez, Kathleen;Malin, Bradley

文献摘要

被引文献

相似文献

目的许多医疗保健组织遵循数据保护政策,规定必须隐藏哪些患者标识符才能共享“去身份”记录。然而,这种政策的实施往往不知道“重新识别”的风险。这项工作的目标是:(1)估计健康保险可携带性和问责法(HIPAA)隐私规则的数据共享策略的重新识别风险;以及(2)使用选民登记列表来评估特定重新识别攻击的风险。测量我们定义了几个风险指标:(1)重新识别的预期数量;(2)估计人口在g或更小的群体中的比例,以及(31)每次重新识别的货币成本。对于美国每个州,我们估计了受HIPAA安全港和有限数据集策略保护的假设数据集所构成的风险,攻击者完全知道患者身份,而选民登记册形式的知识有限。结果当通过安全港和有限数据集保护时,估计该州人口中易受唯一重新识别影响的百分比分别为0.01%到0.25%和10%到60%。在选民攻击中,由于现实世界中选民登记的可变可用性,许多州的这一数字下降,有些州的数字为0%。我们还发现,重新识别的成本从0美元到17000美元不等,进一步证实了风险的可变性。结论这项工作表明,安全港等全面保护政策使不同组织以不同的比率容易重新识别。它为共享数据之前在当地执行的重新识别风险估计提供了理由。
Objective Many healthcare organizations follow data protection policies that specify which patient identifiers must be suppressed to share "de-identified" records. Such policies, however, are often applied without knowledge of the risk of "re-identification". The goals of this work are: (1) to estimate re-identification risk for data sharing policies of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule; and (2) to evaluate the risk of a specific re-identification attack using voter registration lists.Measurements We define several risk nietrics: (1) expected number of re-identifications; (2) estimated proportion of a population in a group of size g or less, and (31 monetary cost per re-identification. For each US state, we estimate the risk posed to hypothetical datasets, protected by the HIPAA Safe Harbor and Limited Dataset policies by an attacker with full knowledge of patient identifiers and with limited knowledge in the form of voter registries.Results The percentage of a state's population estimated to be vulnerable to unique re-identification lie, g=1) when protected via Safe Harbor and Limited Datasets ranges from 0.01% to 0.25% and 10% to 60%, respectively. In the voter attack, this number drops for many states, and for some states is 0%, due to the variable availability of voter registries in the real world. We also find that re-identification cost ranges from $0 to $17000, further confirming risk variability.Conclusions This work illustrates that blanket protection policies, such as Safe Harbor, leave different organizations vulnerable to re-identification at different rates. It provides justification for locally performed re-identification risk estimates prior to sharing data.