4 ms·
Actually, sufficiently aggregated health data is generally fine to release publicly since it can not be tied to an individual. Anonymized data you must be very
by pvnick 10y ago
Actually, sufficiently aggregated health data is generally fine to release publicly since it can not be tied to an individual. Anonymized data you must be very careful with, since individual data elements can frequently be combined to re-identify someone.
- sopooneo 10y agoIn support of your point about "sufficently aggregated" data, I occasionally work on projects that publish aggregate health statistics, and you have to be very careful about the size of your denominators. For instance, even without telling what numbers you are dividing, you probably couldn't publish the percentage of HIV positive results among pacific islanders in Nebraska. Because there might be only six such people.
- pvnick 10y agoGood point!
- facetube 10y agoIIRC this is why HHS and HIPAA regulations specify "all ages over 89" as protected health information for purposes of data deidentification – there just aren't that many people who have lived that long.
- dragonwriter 10y agoIt also specifies all date elements for patient-specific events (including treatment) more specific than the year must be removed for deidentification generally.
- deleted 10y ago[deleted]
- robryk 10y agoSo "I treated a skier with a broken leg in the last skiing season" is something a doctor can't say? (Skiing season is shorter than a year.) Actually, giving a year of a winter/summer sport-related accident already provides a shorter window for when the accident has occurred. So should all case reports about such be giving at least a two year long window?
- sib 10y agoOddly enough, it turns out to be 836(!), which is definitely higher than I would have guessed. http://www.infoplease.com/us/census/data/nebraska/demographic.html http://www.infoplease.com/us/census/data/nebraska/demographi...
- semi-extrinsic 10y agoThose are presumably not all HIV positive.
- sokoloff 10y agoYes, but what personal or privacy-compromising information does "6 of this list of 836 people have HIV" convey? That that population has a higher-than-normal incidence of HIV as compared the US at large? That's potentially valuable aggregate health information, but I don't see how that compromises anyone's privacy. It would if you reported "6 of 836 were HIV+ on Tuesday. The next day, a new couple moved into town. On Wednesday, 7 of 838 were HIV+." I don't think the aggregated data that is contemplated here is released on nearly that frequency.
- dekhn 10y agoAll of the responses to my comment are missing the point: you're discussing medical researchers. This was a random doctor in the affected area who spoke to reporters. I'm quite aware of what is acceptable to release in a medical context; this was not that.
- pvnick 10y agoI'm not sure what the problem is though. In all likelihood the doctor has been trained on HIPAA procedures.
- dragonwriter 10y agoAnd yet seems to have violated them (I've cited the specific section of regs elsewhere in the thread). But deidentification is one of those things people who don't freak with it often, even trained in the rules, always seem to think is easier than it is.
- dekhn 10y agoI never said the doctor violated a law. I think what the doctor said (in speaking about a specific patient): "The doctor said one corrected report is for a patient she sent to the emergency room after receiving abnormally elevated test results from Theranos in late 2014." was ethically dubious. Most of the people who are replying negatively to my comments are misinterpreting my position: either suggesting that I implied there was a HIPAA violation, or that I think medical research data should be suppressed. Neither of those is true.
- CamperBob2 10y agoI'm quite aware of what is acceptable to release in a medical context; this was not that. I'm sure you'll be able to cite the regulation that was broken, then.