Building public trust in uses of Health Insurance Portability and Accountability Act de-identified data
نویسنده
چکیده
OBJECTIVES The aim of this paper is to summarize concerns with the de-identification standard and methodologies established under the Health Insurance Portability and Accountability Act (HIPAA) regulations, and report some potential policies to address those concerns that were discussed at a recent workshop attended by industry, consumer, academic and research stakeholders. TARGET AUDIENCE The target audience includes researchers, industry stakeholders, policy makers and consumer advocates concerned about preserving the ability to use HIPAA de-identified data for a range of important secondary uses. SCOPE HIPAA sets forth methodologies for de-identifying health data; once such data are de-identified, they are no longer subject to HIPAA regulations and can be used for any purpose. Concerns have been raised about the sufficiency of HIPAA de-identification methodologies, the lack of legal accountability for unauthorized re-identification of de-identified data, and insufficient public transparency about de-identified data uses. Although there is little published evidence of the re-identification of properly de-identified datasets, such concerns appear to be increasing. This article discusses policy proposals intended to address de-identification concerns while maintaining de-identification as an effective tool for protecting privacy and preserving the ability to leverage health data for secondary purposes.
منابع مشابه
ATTACHMENT TO THE NOVA SOUTHEASTERN UNIVERSITY RESEARCH USES AND DISCLOSURES POLICY AND PROCEDURE: IRB GUIDANCE ON RESEARCH VERSUS EDUCATIONAL ACTIVITY Case Studies
It is sometimes unclear whether the presentation of one or more case studies constitutes education or research. It is generally well accepted that case studies presentations made in classroom settings or in the on-line equivalent of a classroom setting constitute education. Such cases need to follow HIPAA privacy rules for consent and require use of the NSU Disclosure for Educational and Relate...
متن کاملUsing lessons from health care to protect the privacy of library users: Guidelines for the de-identification of library data based on HIPAA
While libraries have employed policies to protect the data about use of their services, these policies are rarely specific or standardized. Since 1996 the U.S. healthcare system has been grappling with the Health Insurance Portability and Accountability Act (HIPAA), which is designed to provide those handling personal health information with standardized, definitive instructions as to the prote...
متن کاملHealth insurance reform legislation.
The Health Insurance Portability and Accountability Act of 1996 (HIPAA), enacted on August 21, 1996 (Public Law 104-19), provides for improved access and renewability with respect to employment-related group health plans, to health insurance coverage sold in connection with group plans, and to the individual market (by amending the Public Health Service Act). The Act's provisions include improv...
متن کاملChallenges and Insights in Using HIPAA Privacy Rule for Clinical Text Annotation
The Privacy Rule of Health Insurance Portability and Accountability Act (HIPAA) requires that clinical documents be stripped of personally identifying information before they can be released to researchers and others. We have been manually annotating clinical text since 2008 in order to test and evaluate an algorithmic clinical text de-identification tool, NLM Scrubber, which we have been devel...
متن کامل[National committees of vital and health statistics].
NCVHS is your advisory committee on health data, statistics, privacy, and national health information policy. NCVHS advises the Secretary on the adoption of standards, unique identifiers and code sets under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as well as the Patient Protection and Affordable Care Act (ACA) of 2010, which calls for NCVHS to assist in the achie...
متن کامل