A security architecture for query tools used to access large biomedical databases

Proc AMIA Symp. 2002:552-6.

Abstract

Disseminating information from large biomedical databases can be crucial for research. Often this data will be patient-specific, and therefore require that the privacy of the patient be protected. In response to this requirement, HIPAA released regulations for the dissemination of patient data. In many cases, the regulations are so restrictive as to render data useless for many purposes. We propose in this paper a model for obfuscation of data when served to a client application, that will make it extremely unlikely that an individual will be identified. At Partners Healthcare Inc, with over 1.4 million patients and 400 research clinician users, we implemented this model. Based on the results, we believe that a web-client could be made generally available using the proposed data obfuscation scheme that could allow general usage of large biomedical databases of patient information without risk to patient privacy.

Publication types

  • Research Support, Non-U.S. Gov't

MeSH terms

  • Computer Security*
  • Confidentiality*
  • Databases, Factual
  • Humans
  • Medical Records Systems, Computerized*