Sharing patient data: understanding anonymisation.
Sharing patient data: understanding anonymisation.
复制标题
共享患者数据:理解匿名化。
DOI:
10.1136/bmj.k2700
复制
发表时间:
2018
期刊:
影响因子:
--
通讯作者:
Affleck P
中科院分区:
文献类型:
--
作者:
Affleck P
The BMJ reported on Public Health England’s clarification that the data it shared with William E Wecker Associates were anonymised. 1 But comparing these data with the Australian example of re-identification was misleading. Public Health England shared a table of aggregated counts, whereas the Federal Department of Health in Australia released individual data. The Australian data were “de-identified,” meaning that strong identifiers were removed but some people could be identified by combining the data with other information. Given that these data were longitudinal prescribing records, the threat to patient confidentiality is clear.The Public Health England dataset is publicly available (https://data. gov. uk/dataset/4d69e312-da1f-4a7d-819c-8eff414ae9f7/epidemiology-of-lung-cancer-tumours-in-england-2009-to-2013) and only contains eight data columns (count of tumours, sex, age band, cause of death, ethnicity, year of diagnosis, morphology, and year of death). Notably, some of the counts are in single figures, meaning that only one person met all of those conditions. Theoretically this means that the person could be identified if you possessed most of the information already. Also, if you knew a person’s sex, approximate age, cause of death, ethnicity, diagnosis year, and morphology classification of their cancer, you might be able to find out their year of death. Presumably, Public Health England did not judge this to be a threat to patient confidentiality.