Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In the USA the federal government has established clear rules for anonymizing (de-identifying) healthcare data. So it's clearly possible to do so.

http://www.hhs.gov/hipaa/for-professionals/privacy/special-t...



You can only conclude it is clearly possible from that if you assume the USA federal government is infallible. I don't think that's the case.

The way I read it, the "Safe Harbor" part of that standard allows keeping around part of the zip code if that designates over 20,000 people.

For such a group of just over 20,000, add in birth year and sex (both allowed), and you're down to smallest groups of around 200 people. For the topic at hand (publish the data set so that critics can draw their own conclusions), often general health, education level and race, maybe even line of work (blue collar/white collar/agriculture) must be added, so that critics can check that your sample is representative.

I bet that gets you down to a single person in quite a few of those groups.

Yes, they end with "The covered entity does not have actual knowledge that the information could be used alone or in combination with other information to identify an individual who is a subject of the information.", but the earlier list doesn't make me confident that the USA federal government can make that judgment.


It should be pointed out that thanks to the explosion of data anonymizing is a lot harder than you might expect.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: