Generating evidence on privacy outcomes to inform privacy risk management: A way forward?

被引:0
|
作者
Strech, Daniel [1 ]
Haven, Tamarinde [1 ]
Madai, Vince I. [1 ,2 ]
Meurers, Thierry [3 ]
Prasser, Fabian [3 ]
机构
[1] Charite Univ Med Berlin, Berlin Inst Hlth, QUEST Ctr Responsible Res, Charitepl 1, D-10117 Berlin, Germany
[2] Birmingham City Univ, City Ctr Campus, Sch Comp & Digital Technol, City Ctr Campus, Birmingham B4 7XG, England
[3] Charite Univ Med Berlin, Berlin Inst Hlth, Ctr Hlth Data Sci, Charitepl 1, D-10117 Berlin, Germany
关键词
Privacy; Risk management; Data sharing; Evidence;
D O I
10.1016/j.jbi.2022.104257
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Effective and efficient privacy risk management (PRM) is a necessary condition to support digitalization in health care and secondary use of patient data in research. To reduce privacy risks, current PRM frameworks are rooted in an approach trying to reduce undesired technical/organizational outcomes such as broken encryption or unintentional data disclosure. Comparing this with risk management in preventive or therapeutic medicine, a key difference becomes apparent: in health-related risk management, medicine focuses on person-specific health outcomes, whereas PRM mostly targets more indirect, technical/organizational outcomes. In this paper, we illustrate and discuss how a PRM approach based on evidence of person-specific privacy outcomes might look using three consecutive steps: i) a specification of undesired person-specific privacy outcomes, ii) empirical assessments of their frequency and severity, and iii) empirical studies on how effectively the available PRM interventions reduce their frequency or severity. After an introduction of these three steps, we cover their status quo and outline open questions and PRM-specific challenges in need of further conceptual clarification and feasibility studies. Specific challenges of an outcome-oriented approach to PRM include the potential delays between concrete threats manifesting and the resulting person/group-specific privacy outcomes. Moreover, new ways of exploiting privacy-sensitive information to harm individuals could be developed in the future. The challenges described are of technical, legal, ethical, financial and resource-oriented nature. In health research, however, there is explicit discussion about how to overcome such challenges to make important outcome-based assessments as feasible as possible. This paper concludes that it might be the time to have this discussion in the PRM field as well.
引用
收藏
页数:6
相关论文
共 50 条
  • [21] Applying Risk Management Strategies to Information Privacy Protection: A Conceptual Approach
    Greenaway, Kathleen
    Zabolotniuk, Susan
    AMCIS 2011 PROCEEDINGS, 2011,
  • [22] Patient-Centered Outcomes: A Way Forward When Evidence Is Lacking
    Marlow, Julia A.
    Willer, Robert J.
    HOSPITAL PEDIATRICS, 2024, 14 (03) : e164 - e166
  • [23] Op-ed: Climate risk management: A way forward
    Kump, Lee
    Bridge, 2018, 48 (01) : 37 - 38
  • [24] A Data Security And Privacy Risk Management Framework For WBAN Based Healthcare Applications
    Paul, Pangkaj Chandra
    Loane, John
    McCaffery, Fergal
    Regan, Gilbert
    2021 IEEE INTERNATIONAL CONFERENCE ON PERVASIVE COMPUTING AND COMMUNICATIONS WORKSHOPS AND OTHER AFFILIATED EVENTS (PERCOM WORKSHOPS), 2021, : 704 - 710
  • [25] Digital risk management: Protecting your privacy, improving security, and preparing for emergencies
    Huettner, Brenda
    2006 IEEE International Professional Communication Conference, 2006, : 136 - 138
  • [26] SECURITY AND PRIVACY OF PERFORMING DATA ANALYTICS IN THE CLOUD A Three-way Handshake of Technology, Policy, and Management
    Rastogi, Nidhi
    Gloria, Marie Joan Kristine
    Hendler, James
    JOURNAL OF INFORMATION POLICY, 2015, 5 : 129 - 154
  • [27] Intelligent Strategies for Secure Complex Systems Integration and Design, Effective Risk Management and Privacy
    Hooper, Emmanuel
    2009 IEEE INTERNATIONAL SYSTEMS CONFERENCE, PROCEEDINGS, 2009, : 257 - 261
  • [28] Can Stress Put Digital Privacy at Risk? Evidence from a Controlled Experiment Examining the Impact of Acute Stress on Privacy Decisions on a Simulated Social Network Site
    Liu, Yizhou
    Byrne, Kaileigh A.
    Aly, Heba
    Anaraky, Reza Ghaiumy
    Knijnenburg, Bart
    CYBERPSYCHOLOGY BEHAVIOR AND SOCIAL NETWORKING, 2024, 27 (09) : 664 - 672
  • [29] How internet use affects personal privacy risk perception: empirical evidence from China
    Liu, Xiao Zhou
    Ling, Shuang
    Liu, Ying
    ONLINE INFORMATION REVIEW, 2024, 48 (04) : 676 - 693
  • [30] A privacy protection method for health care big data management based on risk access control
    Shi, Mingyue
    Jiang, Rong
    Hu, Xiaohan
    Shang, Jingwei
    HEALTH CARE MANAGEMENT SCIENCE, 2020, 23 (03) : 427 - 442