Scholarly record
HOW ANONYMIZATION MAY MASK HEALTH DATA IN COVID-19 CRISIS
Abstract
In an actual pandemic situation as part of COVID-19 crisis European Union face the challenge of data masking in the processing of sensitive data. European officials race to get a handle on COVID-19, the importance of collecting and sharing health data has never been poses many challenges for officials and national systems. The virus’ unpredictable and widespread nature makes tracing and testing critical to understanding transmission and treatment. Yet, this also poses a threat to personal health data: with data being collected in as many as 500 cities, millions of individual records are at stake. Straightforward techniques, is an effective way to enhance health data security. Data privacy is very essential attribute for information sharing in cloud applications. Privacy enhanced techniques (“PETs”) allow online users to protect the privacy of their personally identifiable information (“PII”) provided to and handled by services or applications. However, if there isn’t enough data to anonymize indirect identifiers, lines of data may have to be redacted, making them unusable. Researchers therefore walk a fine line between privacy and utility, but one that is necessary from a legal and ethical standpoint. In our article we will look in details at the situation of Slovak mobile application Moje eZdravie and the trivial vulnerability that allowed ethical hackers from Nethemba to obtain personal information about more than 390,000 patients who were tested for Covid-19 in Slovakia (for the demonstration this institution has access to get personal information about more than 130,000 patients, of which more than 1600 COVID-19 positive). If the state cannot protect the personal information of all people tested on COVID-19, why do we think it can protect the sensitive location data it can obtain from mobile operators? Mobile location data programs to combat COVID-19 may not be scientifically necessary and could lead to human rights abuses if they are not equipped with effective safeguards to protect privacy.
Publication Impact Profile
Publication details
References12
World Health Organization (2020) Information Sheet: Global Covid-19 Clinical Data Platform for clinical characterization and management of hospitalized patients with suspected or confirmed Covid-19. https://www.who.int/docs/default-source/documents/emergencies/information-sheet-global-covid19-data-platofrm.pdf?sfvrsn=ff1f4e64_2 [accessed 10 Nov, 2020]
Kee Yuan Ngiam MMBS, Ing. Wei Khor PhD.: Big Data and Machine Learning Algorithms for Health-Care Delivery, The Lancet, The Lancet Oncology , Volume 20, Issue 5, May 2019, Pages e262-e273
European Patients Forum – Data Protection Guide: The new EU Regulation on the protection of personal data: what does it mean for patients? https://www.eu-patient.eu/globalassets/policy/data-protection/data-protection-guide-for-patients-organisations.pdf [accessed 11 Nov, 2020]
See art. 35
,
and
GDPR.
Clete A. Kushida, M.D., Ph.D., Deborah A. Nichols, M.S., Rik Jadrnicek, Ric Miller, James K. Walsh, Ph.D., and Kara Griffin: Strategies for de-identification and anonymization of electronic health record data for use in multicenter research studies. Med Care. 2012 Jul; 50 (Suppl): S82–101. DOI: 10.1097/MLR.0b013e3182585355
EU MDR 2017/745 http://eumdr.com/timelines/ [accessed 11 Nov, 2020]
Security Techniques for the Electronic Health Records, Journal of Medical Systems, August 2017. https://link.springer.com/article/DOI: 10.1007/s10916-017-0778-4 [accessed 11 Nov, 2020]
Crucial data security measures every EMR must have in place, Becker’s Health IT & CIO Report, August, 2017.https://www.beckershospitalreview.com/healthcare-information-technology/4-crucial-data-security-measures-every-emr-must-have-in-place.html [accessed 11 Nov, 2020]
Securing the E-health cloud. Available from: https://www.researchgate.net/publication/221629904_Securing_the_E-health_cloud [accessed Nov 11 2020].
View or Download full articleAccess options
SWS access login
Login as SWS Scientific CommitteeLogin as SWS Scientific PartnerLogin as SWS AuthorAuthors and approved SWS contributors will read and export their own linked papers after identity matching by SWS profile, email and SGEM GlobalID.
For librarian assistance: [email protected]
Purchase Instant Access
- Article can be downloaded after successful payment.
- Article may be used according to SWS library access terms.
- Article cannot be redistributed.
