Evaluating re-identification risks with respect to the HIPAA privacy rule.
Many healthcare organizations follow data protection policies that specify which patient identifiers must be suppressed to share "de-identified" records. Such policies, however, are often applied without knowledge of the risk of "re-identification". The goals of this work are: (1) to estimate re-identification risk for data sharing policies of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule; and (2) to evaluate the risk of a specific re-identification attack using [...]
Author(s): Benitez, Kathleen, Malin, Bradley
DOI: 10.1136/jamia.2009.000026