DIMACS Working Group on Privacy - Confidentiality of Health .ppt
《DIMACS Working Group on Privacy - Confidentiality of Health .ppt》由会员分享,可在线阅读,更多相关《DIMACS Working Group on Privacy - Confidentiality of Health .ppt(51页珍藏版)》请在麦多课文档分享上搜索。
1、DIMACS Working Group on Privacy / Confidentiality of Health Data Rutgers University Center Piscataway, New Jersey December 10-12, 2003,Health Care Databases under HIPAA: Statistical Approaches to De-identification of Protected Health Information,Judith E. Beach, Ph.D., Esq. Associate General Counsel
2、, Regulatory Affairs Chief Privacy Officer Chair, Council on Data Protection and Council on Research Ethics,Outline,1.Evolution of De-identification Standards HIPAA Privacy Regulation 2.De-identification Standards for Health Information in Research a. Safe Harbor b. Statistician Method )HIPAA Provis
3、ions )Quintiles Experience and Methodology c. Limited Data Set 3.Preemption of State laws on De-identification Standards for Health Information 4.Health Information Privacy - Cases and Controversies,Evolution of De-Identification Standards in HIPAA Privacy Regulation,Federal Policy: De-Identificatio
4、n of Health Information,Governments intent - to provide a balance of stringent standards flexible enough not to be a disincentive to use or disclose de-identified health information, wherever possible. De-Identified health data is one of the best mechanisms for avoiding wrongful disclosure of Protec
5、ted Health Information (PHI).See Draft (05/27/03) DHHS Policy and Procedure Manual “De-Identification Policy d11” (effective date 6/1/03) - applies to DHHS agencies: HIPAA covered health care components and Internal Business Associates,5,Federal Policy: Use of De-identified Health Data Rather than P
6、HI for Research,“We HHS expressed the hope that covered entities, their business associates and others would make greater use of de-identified health information . . . when it is sufficient for the research purpose and that such practice would reduce the burden and the confidentiality concerns that
7、result from the use of individually identifiable health information for some of these purposes.” HHS, in final privacy rule, 65 Fed. Reg. at 82543 (Dec. 28, 2000), citing proposed privacy rule of Nov. 3, 1999,6,HIPAAs Jurisdiction,Individually Identifiable Health Information (IIHI): A subset of heal
8、th information, including demographic information, that identifies the individual or with respect to which there is a reasonable basis to believe the information can be used to identify the individual Protected health information (PHI): Means individually identifiable health information (IIHI = Heal
9、th Information + Identifier) that is transmitted or maintained electronically, or transmitted or maintained in any other form or medium An investigator who submits health claims would be a HIPAA covered entity (CE) CE + Health Information + Identifier = PHI CE + Identifier - Health Information = NOT
10、 PHI Health Information + Identifier - CE = NOT PHI,7,De-identification Standards for Health Information in Research,De-identified Health Information,Definition: health information that does not identify an individual and with respect to which there is no reasonable basis to believe that the informa
11、tion can be used to identify an individual. 45 CFR 164.514(a) The Privacy Rule permits de-identification of PHI so that such information may be used and disclosed freely, without being subject to the Privacy Rules requirements. Once de-identified, the data is out of the Privacy Rule.,9,HIPAA De-iden
12、tification Standards,Two methods for the de-identification of health information: “Safe Harbor” - remove 18 specified identifiers - intended to provide a simple, definitive method for de-identifying health information with protection from litigation “Statistician Method” - retain some of the 18 safe
13、 harbors specified identifiers and demonstrate the standard is met if person with appropriate knowledge of and experience with generally accepted statistical and scientific principles and methods, e.g., a Biostatistician, makes and documents that the risk of re-identification is very small.45 CFR 16
14、0.514,10,Limited Data Set,Final rule: added another method requiring removal of facial identifiers - “Limited Data Set” Under confidentiality agreements - for research, public health, and health care operations Regarded as PHI - NOT de-identified therefore, still subject to Privacy Rule requirements
15、 such as minimum necessary rule.,11,Safe Harbor Method,Safe Harbor,Covered entities must remove all of a list of 18 enumerated identifiers and have no actual knowledge that the information remaining could be used alone or in combination to identify a subject of the information. The identifiers to be
16、 removed include direct identifiers such as name, address, SSN indirect identifiers such as birth date, admission and discharge dates, and five-digit zip code 45 CFR 160.514(b)(2),13,Safe Harbor,The safe harbor does allow for the disclosure of All geographic subdivisions no smaller than a State, as
17、well as the initial three digits of a zip code IF the geographic unit formed by combining all zip codes with the same initial three digits contains more than 20,000 people AGE, if less than 90, gender, ethnicity and other demographic information not listed.,14,Safe Harbors 18 Identifiers,Names All g
18、eographic subdivisions smaller than a State, including street address, city, county, precinct, zip code, and their equivalent geocodes Except for the initial three digits of a zip code if according to the currently available data from the Bureau of the Census: The geographic unit formed by combining
19、 all zip codes with the same three initial digits contains more than 20,000 people; and The initial three digits of a zip code for all such geographic units containing 20,000 or fewer people are changed to 000; All elements of dates (except year) or dates directly relating to an individual, includin
20、g: birth date, admission date, discharge date, date of death; and all ages over 89 and all elements of dates (including year) indicative of such age, except that such ages and elements may be aggregated into a single category of age 90 or older;,Telephone numbers; Fax numbers; Electronic mail addres
21、ses; Social security numbers; Medical record numbers; Health plan beneficiary numbers; Account numbers; Certificate/license numbers; Vehicle identifiers and serial numbers, including license plate numbers; Device identifiers and serial numbers; Web Universal Resource Locators (URLs); Internet Protoc
22、ol (IP) address numbers; Biometric identifiers, including finger and voice prints; Full face photographic images and any comparable images; and Any other unique identifying number, characteristic, or code.,15,Sources of Authority,In Privacy Rule Preamble, HHS recognizes two sources of authority as t
23、o what constitutes such principles and methods for de-identification adequate for posting a de-identified database on the Internet 65 Fed. Reg. at 82,709-82,710 (Dec. 28, 2000) “Paper 22”: Statistical Policy Working Paper 22Report on Statistical Disclosure Limitation Methodology “The Checklist”: The
24、 Checklist on Disclosure Potential of Proposed Data Releases -“intended primarily for use in the development of public-use data products.”,16,16,Safe Harbor,BUT many researchers and other groups have complained that the Safe Harbor renders the de-identified data as virtually useless for research so
25、that the result will be MORE research using PHI. No dates of service, no patient initials, no date of birth Can have “deltas” such as number of patient visits over time However, the safe harbor was NOT designed for research, but to provide an approved method of de-identification for any purpose by a
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
2000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- DIMACSWORKINGGROUPONPRIVACYCONFIDENTIALITYOFHEALTHPPT

链接地址:http://www.mydoc123.com/p-374364.html