Conforming to HIPAA regulations and compilation of research data

Conforming to HIPAA regulations and compilation of research data
复制标题

DOI:
10.1093/ajhp/61.10.1025
复制
发表时间:
2004-05-15
影响因子:
2.7
通讯作者:
Cosler, LE
Cosler, LE
中科院分区:
医学4区
文献类型:
--
作者:
Clause, SL;Triller, DM;Cosler, LE

文献摘要

被引文献

相似文献

目的.汇编了一组符合《健康信息携带和责任法案》(HIPAA)的去识别患者数据,测量了作为唯一数据元素(UDE)函数的数据丢失,并测试了去识别数据的重新识别潜力。在综合卫生系统的机构审查委员会批准后,通过查询2000年1月1日至12月31日期间出院的患者的卫生系统药房、行政和财务档案,创建了一个有限的数据集。使用HIPAA“安全港”方法,将此有限数据集转换为去识别数据表,用于未来的统计分析,并对两个数据集中的UDE进行识别和量化。还确定了常用数据的独特组合。代表4,738例患者出院的有限数据集包含322,657条记录中的810,456个UDE,这些记录被组织成4个数据表(人口统计学、诊断、药物医嘱和实验室检查结果)。去标识化数据表表示4,722次放电,在单个数据表的128个数据类型列中包含562,171个UDE。大约31%的数据量丢失。丢失的大部分信息都是研究人员特别感兴趣的类型(例如,护理事件之间的时间,年龄>89岁)。一项研究表明,具有合理程度的保护以防止重新识别的去识别患者数据不如良好研究所需的完整。
Purpose. A set of deidentified patient data compliant with the Health Information Portability and Accountability Act (HIPAA) was compiled, the data lost as a function of unique data elements (UDEs) were measured, and the deidentified data were tested for potential for reidentification.Methods. After approval by the institutional review board of an integrated health system, a limited-data set was created by querying the health system's pharmacy, administrative, and financial files for patients discharged between January 1 and December 31, 2000. Using the HIPAA "safe-harbor" method, this limited-data set was converted into a deidentified-data table for future statistical analysis, and UDEs in both data sets were identified and quantified. Unique combinations of commonly available data were also identified.Results. The limited-data set, representing 4,738 patient discharges, contained 810,456 UDEs in 322,657 records organized into four data tables (demographics, diagnoses, medication orders, and laboratory test results). The deidentified-data table, representing 4,722 discharges, contained 562,171 UDEs in 128 data-type Columns in a single data table. About 31% of the data volume was lost. Much of the information lost was of the type that is of special interest to researchers (e.g., time between episodes of care, ages of >89 years).Conclusion. A study suggested that deidentified patient data with a reasonable degree of protection against reidentification were less complete than may be necessary for good research.