3 ms·
> As long as they de-identify the records — removing information like patient names, locations, and phone numbers — they can give or sell the data to partners f
by jtaft 5y ago
> As long as they de-identify the records — removing information like patient names, locations, and phone numbers — they can give or sell the data to partners for research.
I don’t feel this is enough to deidentify.
If timestamps or a patient # is associated with records, should be possible to combine with credit card records to discover who someone is.
I wonder if we can request what is shared.
- organsnyder 5y agoI work in healthcare (though not with any efforts like those described in the article). Anonymizing data is much more complicated than simply removing the obvious PII: depending on what the data is, even things like procedure codes with dates might be enough to identify a patient. HIPAA and other related regs account for this, and have pretty strict procedures that must be followed before data can be considered officially deidentified.