Assessing data protection and governance in health information systems: a novel methodology of Privacy and Ethics Impact and Performance Assessment (PEIPA)

被引:13
|
作者
Di Iorio, Concetta Tania [1 ]
Carinci, Fabrizio [2 ]
Oderkirk, Jillian [3 ]
Smith, David [4 ]
Siano, Manuela [5 ]
de Marco, Dorotea Alessandra [5 ]
de Lusignan, Simon [6 ,7 ]
Hamalainen, Paivi [8 ]
Benedetti, Massimo Massi [9 ]
机构
[1] Serectrix snc, Execut Off, Pescara, Italy
[2] Univ Bologna, Dept Stat Sci, Bologna, Italy
[3] Org Econ Cooperat & Dev OECD, Hlth Div, Directorate Employment Labour & Social Affairs, Paris, France
[4] Informat Commissioners Off ICO, Wilmslow, Cheshire, England
[5] Data Protect Author, Dept Digital Technol & Informat Secur, Dept Int & EU Relat Serv, Rome, Italy
[6] Univ Oxford, Nuffield Dept Primary Care & Hlth Sci, Oxford, England
[7] Univ Surrey, Dept Clin & Expt Med, Guildford, Surrey, England
[8] Natl Inst Hlth & Welf THL, Helsinki, Finland
[9] Hub Int Hlth Res HIRS, Execut Off, Perugia, Italy
关键词
right to healthcare; confidentiality; privacy; regulation; technology; risk assessment; DESIGN;
D O I
10.1136/medethics-2019-105948
中图分类号
B82 [伦理学(道德学)];
学科分类号
摘要
Background Data processing of health research databases often requires a Data Protection Impact Assessment to evaluate the severity of the risk and the appropriateness of measures taken to comply with the European Union (EU) General Data Protection Regulation (GDPR). We aimed to define and apply a comprehensive method for the evaluation of privacy, data governance and ethics among research networks involved in the EU Project Bridge Health. Methods Computerised survey among associated partners of main EU Consortia, using a targeted instrument designed by the principal investigator and progressively refined in collaboration with an international advisory panel. Descriptive measures using the percentage of adoption of privacy, data governance and ethical principles as main endpoints were used for the analysis and interpretation of the results. Results A total of 15 centres provided relevant information on the processing of sensitive data from 10 European countries. Major areas of concern were noted for: data linkage (median, range of adoption: 45%, 30%-80%), access and accuracy of personal data (50%, 0%-100%) and anonymisation procedures (56%, 11%-100%). A high variability was noted in the application of privacy principles. Conclusions A comprehensive methodology of Privacy and Ethics Impact and Performance Assessment was successfully applied at international level. The method can help implementing the GDPR and expanding the scope of Data Protection Impact Assessment, so that the public benefit of the secondary use of health data could be well balanced with the respect of personal privacy.
引用
收藏
页数:8
相关论文
共 8 条
  • [1] Beyond privacy: the right to health information, personal data protection, and governance
    Ventura, Miriam
    Coeli, Claudia Medina
    [J]. CADERNOS DE SAUDE PUBLICA, 2018, 34 (07):
  • [2] Privacy impact assessment in the design of transnational public health information systems: the BIRO project
    Di Iorio, C. T.
    Carinci, F.
    Azzopardi, J.
    Baglioni, V.
    Beck, P.
    Cunningham, S.
    Evripidou, A.
    Leese, G.
    Loevaas, K. F.
    Olympios, G.
    Federici, M. Orsini
    Pruna, S.
    Palladino, P.
    Skeie, S.
    Taverner, P.
    Traynor, V.
    Benedetti, M. Massi
    [J]. JOURNAL OF MEDICAL ETHICS, 2009, 35 (12) : 753 - 761
  • [3] Insights on Data Protection and Privacy Impact on the Accounting Information Systems - An Overview of the Impact of GDPR in the Romanian Accounting Profession
    Stanciu, Victoria
    Rindasu, Sinziana-Maria
    [J]. INNOVATION MANAGEMENT AND EDUCATION EXCELLENCE THROUGH VISION 2020, VOLS I -XI, 2018, : 5856 - 5864
  • [4] A data-driven methodology for assessing impact of earthquakes on the health of building structural systems
    Bernal, D
    Hernandez, E
    [J]. STRUCTURAL DESIGN OF TALL AND SPECIAL BUILDINGS, 2006, 15 (01): : 21 - 34
  • [5] Approaching the Data Protection Impact Assessment as a legal methodology to evaluate the degree of privacy by design achieved in technological proposals. A special reference to Identity Management systems
    Timon Lopez, Cristina
    Alamillo Domingo, Ignacio
    Valero Torrijos, Julian
    [J]. ARES 2021: 16TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, 2021,
  • [6] Towards a privacy impact assessment methodology to support the requirements of the general data protection regulation in a big data analytics context: A systematic literature review
    Georgiadis, Georgios
    Poels, Geert
    [J]. COMPUTER LAW & SECURITY REVIEW, 2022, 44
  • [7] Assessing the readiness of Turkish health information systems for integrating genetic/genomic patient data: System architecture and available terminologies, legislative, and protection of personal data
    Sik, Ayhan Serkan
    Aydinoglu, Arsev Umur
    Son, Yesim Aydin
    [J]. HEALTH POLICY, 2021, 125 (02) : 203 - 212
  • [8] The Impact of the new European General Data Protection Regulation (GDPR) on the Information Governance Toolkit in Health and Social care with special reference to Primary care in England
    Shu, Ignatius Ndumbe
    Jahankhani, Hamid
    [J]. 2017 CYBERSECURITY AND CYBERFORENSICS CONFERENCE (CCC), 2017, : 31 - 37