Releasing individually identifiable microdata with privacy protection against Stochastic threat: An application to health information

被引:22
|
作者
Garfinkel, Robert [1 ]
Gopal, Ram [1 ]
Thompson, Steven [1 ]
机构
[1] Univ Connecticut, Sch Business, Dept Operat & Informat Management, Storrs, CT 06029 USA
关键词
data security; privacy; health information; optimization;
D O I
10.1287/isre.1070.0112
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
The ability to collect and disseminate individually identifiable microdata is becoming increasingly important in a number of arenas. This is especially true in health care and national security, where this data is considered vital for a number of public health and safety initiatives. In some cases legislation has been used to establish some standards for limiting the collection of and access to such data. However, all such legislative efforts contain many provisions that allow for access to individually identifiable microdata without the consent of the data subject. Furthermore, although legislation is useful in that penalties are levied for violating the law, these penalties occur after an individual's privacy has been compromised. Such deterrent measures can only serve as disincentives and offer no true protection. This paper considers security issues involved in releasing microdata, including individual identifiers. The threats to the confidentiality of the data subjects come from the users possessing statistical information that relates the revealed microdata to suppressed confidential information. The general strategy is to recode the initial data, in which some subjects are "safe" and some are at risk, into a data set in which no subjects are at risk. We develop a technique that enables the release of individually identifiable microdata in a manner that maximizes the utility of the released data while providing preventive protection of confidential data. Extensive computational results show that the proposed method is practical and viable and that useful data can be released even when the level of risk in the data is high.
引用
收藏
页码:23 / 41
页数:19
相关论文
共 49 条
  • [1] Privacy protection of binary confidential data against deterministic, stochastic, and insider threat
    Garfinkel, R
    Gopal, R
    Goes, P
    [J]. MANAGEMENT SCIENCE, 2002, 48 (06) : 749 - 764
  • [2] Avoiding Disclosure of Individually Identifiable Health Information: A Literature Review
    Prada, Sergio I.
    Gonzalez-Martinez, Claudia
    Borton, Joshua
    Fernandes-Huessy, Johannes
    Holden, Craig
    Hair, Elizabeth
    Mulcahy, Tim
    [J]. SAGE OPEN, 2011, 1 (03): : 1 - 16
  • [3] Protection of privacy against protection of health
    Bjerkedal, T
    [J]. ACTA OBSTETRICIA ET GYNECOLOGICA SCANDINAVICA, 2000, 79 (06) : 520 - 522
  • [4] Compelled disclosure of health information - Protecting against the greatest potential threat to privacy
    Rothstein, MA
    Talbott, MK
    [J]. JAMA-JOURNAL OF THE AMERICAN MEDICAL ASSOCIATION, 2006, 295 (24): : 2882 - 2885
  • [5] A Threat Tree for Health Information Security and Privacy
    Landry, Jeff
    Pardue, Harold
    Johnsten, Tom
    Campbell, Matt
    Patidar, Priya
    [J]. AMCIS 2011 PROCEEDINGS, 2011,
  • [6] Privacy Protection Schemes against Easy Information Access
    Hong, Bigang
    [J]. INFORMATION TECHNOLOGY FOR MANUFACTURING SYSTEMS II, PTS 1-3, 2011, 58-60 : 2152 - 2157
  • [7] Taking stock of organisations' protection of privacy: categorising and assessing threats to personally identifiable information in the USA
    Posey, Clay
    Raja, Uzma
    Crossler, Robert E.
    Burns, A. J.
    [J]. EUROPEAN JOURNAL OF INFORMATION SYSTEMS, 2017, 26 (06) : 585 - 604
  • [8] Shared expectations for protection of identifiable health care information - Report of a national consensus process
    Wynia, MK
    Coughlin, SS
    Alpert, S
    Cummins, DS
    Emanuel, LL
    [J]. JOURNAL OF GENERAL INTERNAL MEDICINE, 2001, 16 (02) : 100 - 111
  • [9] Privacy protection of health information: Patient rights and pediatrician responsibilities
    Chilton, L
    Berger, JE
    Melinkovich, P
    Nelson, R
    Rappo, PD
    Stoddard, J
    Swanson, J
    Vanchiere, C
    Lustig, J
    Gotlieb, EM
    Deutsch, L
    Gerstle, R
    Lieberthal, A
    Shiffman, R
    Spooner, SA
    Stern, M
    [J]. PEDIATRICS, 1999, 104 (04) : 973 - 977
  • [10] A Revival of the Privacy Protection of Health-Related Personal Information?
    Abbing, Henriette
    [J]. EUROPEAN JOURNAL OF HEALTH LAW, 2011, 18 (03) : 247 - 254