Statisticians are being asked to determine what methods must be applied to protect the privacy of research subjects. Careless, venal, or malicious release of confidential data can be harmful to research subjects and to the entire research enterprise. Under the Health Insurance Portability and Accountability Act (HIPAA), statisticians may be asked to certify the adequacy of nondisclosure methods for confidential health data used in research. Yet despite extensive methodological research on deidentification of datasets, we lack a comprehensive framework for evaluating risk and selecting optimal strategies for protecting confidentiality with minimum impact on research. Among the factors that should be considered in such a framework are (!) the properties of the population or sample under the nondisclosure regimen, (2) the availability of external key databases, (3) the nature of the intruder, (4) the losses associated with disclosure, (5) the analyses to be supported by disclosure-protected data, and (6) the information losses due to disclosure protection. Although the present state of our analyses does not afford a ready answer to the ethical dilemma faced by the statistician asked to certify the adequacy of nondisclosure measures, this perspective does help to identify some of the social questions that must be addressed in considering how to protect privacy. (January 2011)
Journal of Privacy and Confidentiality
2011
http://repository.cmu.edu/cgi/viewcontent.cgi?article=1080&context=jpc