{"id":4096,"date":"2017-01-20T15:35:33","date_gmt":"2017-01-20T15:35:33","guid":{"rendered":"https:\/\/www.wma.net\/wp-content\/uploads\/2017\/01\/WMA-HDB-Seoul_KIM.pdf"},"modified":"2017-01-20T15:35:33","modified_gmt":"2017-01-20T15:35:33","slug":"wma-hdb-seoul_kim-2","status":"inherit","type":"attachment","link":"https:\/\/www.wma.net\/es\/wma-hdb-seoul_kim-2\/","title":{"rendered":"WMA-HDB-Seoul_KIM"},"author":2,"comment_status":"open","ping_status":"closed","template":"","meta":[],"acf":[],"description":{"rendered":"<p class=\"attachment\"><a href='https:\/\/www.wma.net\/wp-content\/uploads\/2017\/01\/WMA-HDB-Seoul_KIM.pdf'>WMA-HDB-Seoul_KIM<\/a><\/p>\n<p>1<br \/>\nData Confidentiality<br \/>\nand Gene Privacy<br \/>\nJu Han Kim, M.D., Ph.D.<br \/>\nProfessor and Founding Chair, Div. of Biomedical<br \/>\nInformatics, Seoul Nat\u2019l Univ. College of Medicine<br \/>\njuhan@snu.ac.kr<br \/>\nNo one wants to expose\u2026<br \/>\n\u2022 credit card numbers<br \/>\n\u2022 bank account numbers<br \/>\n\u2022 passwords<br \/>\n\u2022 sensitive data (patient data)<br \/>\n2<br \/>\nProtecting\u2026<br \/>\n\u2022 What?<br \/>\n\u2022 Security<br \/>\n\u2022 Privacy<br \/>\n\u2022 Confidentiality<br \/>\n\u2022 Against what?<br \/>\n\u2022 Evil hackers<br \/>\n\u2022 Malicious insiders<br \/>\n\u2022 Stupidity<br \/>\nPrivacy<br \/>\n\u2022 Right to be alone; e.g.:<br \/>\n\u2022 applies mostly to known individuals<br \/>\n\u2022 Correlation among pervasive databases<br \/>\n\u2022 sensus<br \/>\n\u2022 marketing<br \/>\n\u2022 health<br \/>\n3<br \/>\nConfidentiality<br \/>\n\u2022 Use of sharing information by multiple<br \/>\nusers at many institutions<br \/>\n\u2022 Should be controlled by coherent policy<br \/>\n\u2022 Enforced by appropriate technology<br \/>\n\u2022 E.g., who may use your results of life<br \/>\ninsurance, for what purposes?<br \/>\n\ud504\ub77c\uc774\ubc84\uc2dc \/ \uae30\ubc00\uc720\uc9c0 \/ \ubcf4\uc548<br \/>\n\u2022 Privacy: managing your own information<br \/>\nto suit your needs<br \/>\n\u2022 Confidentiality: managing someone else\u2019s<br \/>\ninformation to protect their privacy<br \/>\n\u2022 Security: physical security<br \/>\nright to remain unknown<br \/>\n4<br \/>\nPrivacy &#038; Intruders<br \/>\nFreedom from<br \/>\n1. intrusion<br \/>\n2. surveillance<br \/>\n3. right to self control \u00e0 (Patient control)<br \/>\n\u00fc Giving patients control of the use of their data<br \/>\n\u00fc To be informed and to control who, when, how, and why<br \/>\ntheir health information is accessed\/used<br \/>\n\u00fc Broader concept than the right to inspect\/read<br \/>\n5<br \/>\nPrivacy as the right to life<br \/>\n\u2022 Competition<br \/>\n\u00fc Competition at equality condition<br \/>\n\u2022 Autonomy and Freewill<br \/>\n\u00fc Right to choose religion and good and evil<br \/>\n\u00fc Right to belief<br \/>\n\u2022 Right to forget or not recognize discrimination<br \/>\n\u00fc Race, gender, regional sentiment<br \/>\n* Privacy Case Nydia Vel\u00c3\u00a1zquez \u00c2 (1982) Three weeks after<br \/>\nNydia Vel\u00c3\u00a1zquez won the New York Democratic Party&#8217;s<br \/>\nnomination to serve in the U.S. House of Representatives,<br \/>\nsomebody at St. Claire Hospital in New York faxed<br \/>\nVel\u00c3\u00a1zquez&#8217;s medical records to the New York Post. The<br \/>\nrecords detailed the care that Vel\u00c3\u00a1zquez had received at the<br \/>\nhospital after a suicide attempt&#8211;an attempt that had happened<br \/>\nseveral years before the election.<br \/>\nDatabase Nation: The Death of Privacy in the 21st Century, Simson<br \/>\nGarfinkel, Jan 2000, 1-56592-653-6<br \/>\n6<br \/>\nThe intruders<br \/>\nl The Big Brother<br \/>\nl The Little Sisters<br \/>\nl Intrusive Technologies<br \/>\nl Stupidity<br \/>\nl Internal breaches<br \/>\nl Ever increasing stakeholders<br \/>\nl Data integration<br \/>\nl Re-identification of the de-identified<br \/>\nBig brother is watching you!<br \/>\n\u2022 Governmental DBs<br \/>\n\u2022 National Surveillance<br \/>\n\u2022 International Collaborations<br \/>\nThe Intruders \u2013 Big Brother<br \/>\n7<br \/>\nThe Sisters are nearer than the Bros<br \/>\n\u2022 Flaming<br \/>\n\u2022 Flame war<br \/>\n\u2022 Cyberbullying<br \/>\n\u2022 Internet Trolling<br \/>\n\u2022 Smack Talk<br \/>\nThe Intruders \u2013 Little Sisters<br \/>\nThe Intruders \u2013Technologies<br \/>\n8<br \/>\nThe Intruders \u2013 Stupidity<br \/>\n\u2022 frigidity<br \/>\n\u2022 ignorance<br \/>\n\u2022 divide<br \/>\n\ucd9c\ucc98: \uc911\uc559\uc77c\ubcf4 2005\ub1446\uc6d423\uc77c\uc790<br \/>\nInternal breaches<br \/>\nThe dark side<br \/>\n9<br \/>\n\u2022 Dr.<br \/>\n\u2022 Nr.<br \/>\n\u2022 Therapists<br \/>\n\u2022 Laboratory<br \/>\n\u2022 Radiology<br \/>\n\u2022 Pharmacy<br \/>\n\u2022 Admissions<br \/>\n\u2022 Administrations<br \/>\n\u2026 more than 70<br \/>\n\u2022 Managers<br \/>\n\u2022 Patients<br \/>\n\u2022 Payers<br \/>\n\u2022 Reviewers<br \/>\n\u2022 Gov. Institutions<br \/>\n\u2022 Insurance Company, Pharma<br \/>\n\u2022 Hackers<br \/>\n\u2022 and more and more people\u2026<br \/>\nThe Intruders &#8211; ever increasing stakeholders<br \/>\nThe Intruders \u2013 Data Integration<br \/>\n10<br \/>\nThe Intruders \u2013 Data Integration<br \/>\nThe Intruders \u2013 Data Integration<br \/>\n11<br \/>\nFormer Governor, William F. Weld<br \/>\nGroup Insurance Commission RecordDecoded<br \/>\nMessachusettes<br \/>\nGroup Insurance<br \/>\nCommission Released<br \/>\nMedical Records<br \/>\nof Gov. Officers<br \/>\n(de-identified)<br \/>\nVoter list for $20<br \/>\n\ucd9c\ucc98: Sherman E. It doesn\u2019t take much to make you stand out. Cambridge, Mass.:<br \/>\nHarvard University Extension School Bulletin, Fall 2001<br \/>\nDe-identification &#038;Re-identification<br \/>\nNames of the 35% of the victims<br \/>\nwere reidentified<br \/>\n(only with public data)<br \/>\n12<br \/>\nMalin and Sweeney at Carnegie Mellon Univ. integrated<br \/>\n(1) Illinois\u2019publicly available de-identified discharge summary data (1990-<br \/>\n1997) with (2) Census data and (3) Voter list,<br \/>\nsurprisingly re-identifying real names of rare disease patients by using the<br \/>\npublicly available data only<br \/>\nCystic fibrosis: 33%<br \/>\nHuntington disease: 50%<br \/>\nFanconi Anemia: 70%<br \/>\nRefsum disease: 100%<br \/>\nRe-identification < Rare disease ><br \/>\nNew England Journal of Medicine (2005)<br \/>\nBritish Medical Journal (2001)<br \/>\n13<br \/>\nEfforts<br \/>\nregional and international<br \/>\nLegislative efforts in Korea<br \/>\n\u2022 Constitution<br \/>\n\u00fc \uc81c17\uc870: \u201c\ubaa8\ub4e0 \uad6d\ubbfc\uc740 \uc0ac\uc0dd\ud65c\uc758 \ube44\ubc00\uacfc \uc790\uc720\ub97c \uce68\ud574\ubc1b\uc9c0 \uc544\ub2c8\ud55c\ub2e4.\u201d<br \/>\n\u2022 Criminal Laws:<br \/>\n\u00fc \uc81c316\uc870, \ube44\ubc00\uce68\ud574 \ud589\uc704 \ucc98\ubc8c;<br \/>\n\u00fc \uc81c317\uc870, \uc758\uc0ac, \ud55c\uc758\uc0ac, \uce58\uacfc\uc758\uc0ac, \uc57d\uc81c\uc0ac, \uc870\uc0b0\uc0ac \ub4f1\uc774 \uc5c5\ubb34\ucc98\ub9ac \uc911 \uc9c0\ub4dd\ud55c \ud0c0\uc778<br \/>\n\uc758 \ube44\ubc00\uc744 \ub204\uc124\uc2dc \ucc98\ubc8c<br \/>\n\u2022 Privacy Act<br \/>\n\u2022 Acts on Information and Communication:<br \/>\n\u00fc \uc815\ubcf4\ud1b5\uc2e0\ub9dd\uc774\uc6a9\ucd09\uc9c4\ubc0f\uc815\ubcf4\ubcf4\ud638\ub4f1\uc5d0\uad00\ud55c\ubc95\ub960 \uc81c21\uc870(\uc804\uc790\ubb38\uc11c \ub4f1\uc758 \uacf5\uac1c \uc81c\ud55c)<br \/>\n\ubc0f \uc81c49\uc870(\ube44\ubc00 \ub4f1\uc758 \ubcf4\ud638)<br \/>\n\u00fc \uc804\uc790\uc11c\uba85\ubc95 \uc81c24\uc870(\uac1c\uc778\uc815\ubcf4\uc758 \ubcf4\ud638)<br \/>\n\u00fc \uacf5\uacf5\uae30\uad00\uc758\uac1c\uc778\uc815\ubcf4\ubcf4\ud638\uc5d0\uad00\ud55c\ubc95\ub960 \uc81c13\uc870(\ucc98\ub9ac\uc815\ubcf4\uc758 \uc5f4\ub78c\uc81c\ud55c)<br \/>\n\u2022 Medicine-related Acts<br \/>\n\u00fc \ubcf4\uac74\uc758\ub8cc\uae30\ubcf8\ubc95 \uc81c12\uc870(\ube44\ubc00\ubcf4\uc7a5)<br \/>\n\u00fc \uc758\ub8cc\ubc95 \uc81c19\uc870(\ube44\ubc00\ub204\uc124\uc758 \uae08\uc9c0)<br \/>\n\u00fc \uc804\uc5fc\ubcd1\uc608\ubc29\ubc95 \uc81c54\uc870\uc758 6<br \/>\n\u00fc \ud6c4\ucc9c\uc131\uba74\uc5ed\uacb0\ud54d\uc99d\uc608\ubc29\ubc95 \uc81c7\uc870<br \/>\n\u00fc \uc7a5\uae30\uc774\uc2dd\ub4f1\uc5d0\uad00\ud55c\ubc95\ub960 \uc81c27\uc870 26\/62<br \/>\n14<br \/>\nHIPAA<br \/>\n\u2022 Since 1996, U.S. congress<br \/>\n\u2022 data interchange standards<br \/>\n\u2022 data security<br \/>\n\u2022 patient privacy<br \/>\n\u2022 HIPAA Security and Electronic Signature<br \/>\nStandards, 1998<br \/>\n\u2022 HIPAA Standards for Privacy of Individually<br \/>\nIdentifiable Health Information, 2000<br \/>\n\u2022 HIPAA regulation starts in 2003<br \/>\nHealth Insurance Portability and Accountability Act<br \/>\nResearch<br \/>\n15<br \/>\nMulti-center studies<br \/>\n&#8211; The challenges<br \/>\nl Registries and Large databases<br \/>\n\u00fc Cancer<br \/>\n\u00fc Childhood immunizations<br \/>\n\u00fc Cardiovascularsurgery<br \/>\n\u00fc Mammography screening<br \/>\nl Quality improvement and assurance<br \/>\nl Technologic advancement, large-scale data sharing<br \/>\nl Federal, state laws &#038; institutional policies<br \/>\nl Collection, storage, utilization and sharing<br \/>\nCategories of Information<br \/>\n16<br \/>\nMember sites<br \/>\nl Research endeavor vs. confidentiality protection<br \/>\nl Protect from unauthorized access<br \/>\nl Usage only in sanctioned and approved ways<br \/>\nl Prompt report and corrective measures against<br \/>\nbreaches of the policy<br \/>\nl Prompt response to inquires from concerned<br \/>\nparticipants<br \/>\nCategories of Information<br \/>\n17<br \/>\nUK Association of Cancer Registries<br \/>\nl Regulation 2 of the Statutory Instrument (SI) on confidentiality \u2013 No. 1438, The Health<br \/>\nService (Control of Patient Information) Regulations 2002 \u2013 permits cancer registries to<br \/>\nreceive patient identifiable data without the need for informed consent.<br \/>\nl However, there remains uncertainty about the circumstances when cancer registries are<br \/>\nallowed to disclose patient identifiable data held by them to third parts.<br \/>\nl PIAG has requested UKACR to develop explicit guidance for cancer registries advising<br \/>\nthem that they must comply with requests from patients to delete identifiable data about<br \/>\nthemselves from their databases.<br \/>\nl The basic idea for protecting patient privacy has been de-identification.<br \/>\nl However, the dichotomy of identifiable vs. non-identifiable distinction cannot be<br \/>\nmade.<br \/>\nl In reality, most of health data are \u2018Potentially Identifiable\u2019.<br \/>\n\u00fc Individual records<br \/>\n\u00fc Tabular data,basedon small geographic areas, with cell counts of fewer than five<br \/>\ncases\/events (or where counts of lessthanfive can be inferredby simple arithmetic)<br \/>\n\u00fc Tabular data containing cellsthat have underlying population denominatorsof less than<br \/>\napproximately 1000<br \/>\n34\/62<br \/>\nUK Association of Cancer Registries<br \/>\n18<br \/>\nPotentially identifiable data<br \/>\nl the intended use(s) of the data should be stated clearly<br \/>\nl the use(s) of the data should be justified and the data should not be used for any<br \/>\nother purposes<br \/>\nl the registry should not release data that are more detailed than necessary to fulfill<br \/>\nthe stated purpose<br \/>\nl the data should not be passed on to other third parties or released into the public<br \/>\ndomain<br \/>\nl the data should be kept securely for the period of time that can be justified by the<br \/>\nstated purpose, and then destroyed<br \/>\nl no attempt should be made to identify information pertaining to particular<br \/>\nindividuals or to contact individuals<br \/>\nl no attempt should be made to link the data to other data sets, unless agreed with<br \/>\nthe data providers<br \/>\nl any public domain reports or papers resulting from analyses of the provided data<br \/>\nshould be shared prior to publication with the cancer registry (or registries)<br \/>\nsupplying the information.<br \/>\nAmerican College of Epidemiology<br \/>\nPolicy Statements<br \/>\nl Routine anonymization of archivedmedical data :<br \/>\n\u00fc difficulty in tracing back to individuals<br \/>\n\u00fc Unable to predict what linkage might be useful in the future<br \/>\ninvestigations<br \/>\nl Individual informedconsent<br \/>\n\u00fc Untenable administrative, financial, and logistical burdens<br \/>\n\u00fc Non-participation and selection bias<br \/>\n19<br \/>\nACE with bigger challenges<br \/>\nNew Challenges<br \/>\n20<br \/>\nLife Logs &#038; Genomes<br \/>\nNew Challenges<br \/>\nl Personal Genomes<br \/>\n\u00fc Fundamentally identifiable in itself<br \/>\n\u00fc Non-editability<br \/>\n\u00fc Beyond person, sharedby family members<br \/>\nl Life logging<br \/>\nl Bio-Banksand biomedical research<br \/>\nl TaxonomyforSecondary Uses<br \/>\n21<br \/>\n22<br \/>\nMom the worrier<br \/>\nYou<br \/>\nCrazy Uncle Bill<br \/>\nSkeptical<br \/>\nbrother<br \/>\nEarly adopter<br \/>\nsister<br \/>\nDad already signed up<br \/>\nto get sequenced<br \/>\nGrandpa says<br \/>\nno way!<br \/>\nAunt Erma worried<br \/>\nabout losing her<br \/>\ninsurance because<br \/>\nof her son\u2019s DNA<br \/>\nsequence<br \/>\nCousin Betty<br \/>\nwants to donate<br \/>\nher sequence to<br \/>\nscience and make<br \/>\nit totally public<br \/>\nGrandma is gone,<br \/>\nbut a sample<br \/>\nof her DNA still<br \/>\nexists\u2026<br \/>\nImpact on Family<br \/>\nHSLS, U.Pitt<br \/>\npersonal genetics<br \/>\neducation project<br \/>\n(link)<br \/>\nYour kids<br \/>\nYour potential kid?<br \/>\nEthical<br \/>\nand<br \/>\nTechnological<br \/>\n23<br \/>\nThank you!<br \/>\nhttp:\/\/www.snubi.org\/<\/p>\n"},"caption":{"rendered":"<p>WMA-HDB-Seoul_KIM 1 Data Confidentiality and Gene Privacy Ju Han Kim, M.D., Ph.D. Professor and Founding Chair, Div. of Biomedical Informatics, Seoul Nat\u2019l Univ. College of Medicine juhan@snu.ac.kr No one wants to expose\u2026 \u2022 credit card numbers \u2022 bank account numbers \u2022 passwords \u2022 sensitive data (patient data) 2 Protecting\u2026 \u2022 What? \u2022 Security \u2022 Privacy [&hellip;]<\/p>\n"},"alt_text":"","media_type":"file","mime_type":"application\/pdf","media_details":{},"post":null,"source_url":"https:\/\/www.wma.net\/wp-content\/uploads\/2017\/01\/WMA-HDB-Seoul_KIM.pdf","_links":{"self":[{"href":"https:\/\/www.wma.net\/es\/wp-json\/wp\/v2\/media\/4096"}],"collection":[{"href":"https:\/\/www.wma.net\/es\/wp-json\/wp\/v2\/media"}],"about":[{"href":"https:\/\/www.wma.net\/es\/wp-json\/wp\/v2\/types\/attachment"}],"author":[{"embeddable":true,"href":"https:\/\/www.wma.net\/es\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wma.net\/es\/wp-json\/wp\/v2\/comments?post=4096"}]}}