New study finds patient privacy risks in sharing research data
In publishing new studies, health care researchers take care to remove identifiable patient information when sharing their data.
But a UNT Health Science Center public health professor has found that despite such precautionary measures, often required by grant-funding organizations and research journals, online attackers can still identify individual patient health records through cross-referencing against publicly available databases.
Liam O’Neill, PhD, Associate Professor of Health Management and Policy at the UNTHSC School of Public Health, published the report in the June 2016 issue of Anesthesia & Analgesia with colleagues from the University of Iowa and George Washington University.
The article was featured as the June cover story and was also highlighted in a recent podcast. The journal’s editor-in-chief, Dr. Steven L. Shafer of Stanford University, said he believes the article “will have profound implications for digital sharing of patient data” in the future.
“Posting health information that has been properly ‘de-identified’ for public use is assumed to pose no risks to patient privacy, yet computer scientists have demonstrated that this assumption is flawed,” Dr. O’Neill said.
“Knowing a person’s date of birth is insufficient by itself, for example, to identify an individual,” he said, “yet, 87 percent of the specific combinations of date of birth, postal code and gender occur only once among the entire U.S. population.”
“The first step is for an online attacker to link two or more open databases based on overlapping attributes,” he said.
For their study, Dr. O’Neill and colleagues used the State of Texas surgical database – containing public information on more than 2.8 million records – to show that there is a 42.8 percent chance that an online attacker could match an anesthesia record to a de-identified hospital database to uncover sensitive patient information.
The percentage is even greater, they reported, for patients undergoing multiple procedures or from smaller states.
“Few people today would think that the combination of hospital and surgical procedures could be enough to link to a single inpatient record out of a database of millions,” Dr. O’Neill said, “which is why the use or exchange of this type of data is largely unregulated. But methods of online attack are advancing rapidly, faster than methods of defense.” Dr. O’Neill said.
While supporting research transparency, the authors recommended a change in peer-reviewed editorial policy, where study data could be requested from a journal’s editor, rather than being publicly shared in de-identified format.
Funding for this study was provided by the National Science Foundation.
The UNT Health Science Center will be closed for the Thanksgiving holiday on Thursday and Friday, Nov. 23-24. Administrative offices will reopen at 8 a.m. Monday, Nov. 27. All clinics staffed by UNT Health providers also will be closed Nov. 23-24 in observance of the holiday. Regular clinic hours...Read more
Nov 22, 2017
By Jan Jarvis When he becomes a psychiatrist, Paresh Jaini does not want to rely solely on medication and psychotherapy to treat his patients. “I want to utilize lifestyle interventions as another treatment tool when approaching my patients with mental illness,” he said. “I want to c...Read more
Nov 21, 2017
By Sally Crocker Within two months of graduating from the UNTHSC School of Public Health, Harleen Singh (MHA ’16) began a highly selective administrative residency with Baylor Scott & White Health (BS&W), one of the largest not-for-profit health care systems in the United States. ...Read more
Nov 21, 2017
By Sally Crocker UNTHSC students, faculty and staff are invited to the 2nd Annual Zoonotic Disease Fair from noon to 3 p.m. on Nov. 21 to learn about some of the common diseases found in Texas that can be passed from animals to humans. “It pays to be aware,” said public health st...Read more
Nov 16, 2017