Title: Privacy and Security Symposium for Health Information
1Privacy and Security Symposium for Health
Information
- MEDINFO 2007
- Brisbane
- Workshop S017
2a symposium?
- 1. A drinking-party a convivial meeting for
drinking, conversation, and intellectual
entertainment - Oxford English Dictionary
3a symposium?
- 2. transf. A meeting or conference for discussion
of some subject hence, a collection of opinions
delivered, or a series of articles contributed,
by a number of persons on some special topic. - Oxford English Dictionary
4defining the scope
- 1. Privacy and Security
- 2. Health Information
Why combine PS? All of health information? All
aspects? - Legal, social, technical, ethical,
organizational, political, individual,
psychological, etc.. Should we move towards a
unified approach?
5What is Privacy?
- First what do we mean by Privacy?
- Physical Privacy
- Communication Privacy
- Personal Privacy
- Information Privacy?
- Focus on Information Privacy Security ?
Privacy - specifically digital electronic information
WHAT YOU STARING AT?
6What is Security?
- The safety or safeguarding against danger
- A protection, guard, defence
- Securely fixed or attached
- Well-founded confidence, certainty
- Information Security?
- Focus on Information Security
Security ? Safety - specifically digital electronic information
7User name - password
Identification Authentication Authorization
8Outline the critical issues with Privacy and
Security (PS)
- 5Ws
- What are we protecting?
- Who are our adversaries?
- Will current technologies suffice (sustainable)?
- Where are our qualified professional staff?
- When do we take action?
9Whats been happening in Australia?
- National Health and Social Services Access
(Smart) Card - National E-Health Transition Authority
- Australian Law Reform Commission review of
Privacy Laws - NCRIS population health
- NHMRC - National statement on ethics
- Data Linkage technologies and centres
10(No Transcript)
11(No Transcript)
12(No Transcript)
13NEHTA
14Ongoing Impact Assessments?
- Types of assessment (PIA)
- When to apply, reapply
- Interpreting the outcomes
- Sharing knowledge
15ALRC review of Privacy
16can legislation be neutral?
17NCRIS Population Health and Clinical data Linkages
18NHMRC National statement on ethics
19National Statement on Ethical Conduct in Human
Research
- individually identifiable data, where the
identity of a specific individual can reasonably
be ascertained. Examples of identifiers include
the individuals name, image, date of birth or
address - re-identifiable data, from which identifiers have
been removed and replaced by a code, but it
remains possible to re-identify a specific
individual by, for example, using the code or
linking different data sets - non-identifiable data, which have never been
labelled with individual identifiers or from
which identifiers have been permanently removed,
and by means of which no specific individual can
be identified. A subset of non-identifiable data
are those that can be linked with other data so
it can be known that they are about the same data
subject, although the persons identity remains
unknown.
20National Statement on Ethical Conduct in Human
Research
- 3.2.4 Where research involves linkage of data
sets, approval may be given to the use of
identifiable data to ensure that the linkage is
accurate, even if consent has not been given for
the use of identifiable data in research. Once
linkage has been completed, identifiers should be
removed from the data to be used in the research
unless consent has been given for its
identifiable use.
21Outline the critical issues with Privacy and
Security (PS)
- 5Ws
- What are we protecting?
- Who are our adversaries?
- Will current technologies suffice (sustainable)?
- Where are our qualified professional staff?
- When do we take action?
22A drinking-party?
23Aims
- Outline the critical issues with Privacy and
Security (PS) - Establish what PS covers in Health and
Healthcare Services - Outline what has been happening with PS in
Australia and Internationally - Where does Trust fit in?
- Discuss the way forward to an International
approach
24Establish what PS covers in Health and
Healthcare Services
- EHR
- People
- Prescriptions
- Telehealth homecare
- - are these all safety
issues?