Data analytics are making an impact on the healthcare industry, but as concerns remain over patient privacy and security, the industry is turning to de-identification as a way to keep information private.
The two ways to de-identify data include the statistician method and the "safe harbor" method, Anna Spencer, a partner in Sidley Austin's Washington office and global coordinator for health IT privacy, tells HealthITSecurity.com.
Safe harbor, Spencer says, gives details around de-identification standards, but the method is not popular with everyone in the industry. The method removes or codes information such as names, birth dates, phone numbers, Social Security numbers and 14 other pieces of identifying information.
The problem healthcare professionals see with the method, Spencer says, is that it doesn't cover every possible identifier. It is criticized as both over and under-inclusive, and some say it isn't enough.
Stripping identifiable elements also has the potential to decrease the value of the data, according to Scot Ganow, privacy attorney at Faruki Ireland & Cox.
In addition, there is always the possibility of re-identification of data. In 2012, the U.S. Department of Health & Human Services' Office for Civil Rights said in guidance that while the expert determination and the safe harbor methods lower the risk of re-identifying data to miniscule levels, neither are completely secure.
According to Spencer, there's a balance that needs to be found between privacy and analytics. There are ways to tone down the rules, but keep privacy in place, she says.
"Research provisions generally require individual authorization unless you have privacy board approval," she tells HealthITSecurity.com. "This is a significant administrative hurdle. And there are other, more-relaxed rules for data sets that are not identifiable."
To learn more:
- read the HealthITSecurity.com article