R-U policy frontiers for health data de-identification.
The Health Insurance Portability and Accountability Act Privacy Rule enables healthcare organizations to share de-identified data via two routes. They can either 1) show re-identification risk is small (e.g., via a formal model, such as k-anonymity) with respect to an anticipated recipient or 2) apply a rule-based policy (i.e., Safe Harbor) that enumerates attributes to be altered (e.g., dates to years). The latter is often invoked because it is interpretable [...]
Author(s): Xia, Weiyi, Heatherly, Raymond, Ding, Xiaofeng, Li, Jiuyong, Malin, Bradley A
DOI: 10.1093/jamia/ocv004