• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

一种用于改善疾病登记中隐私和保密性保护的提议架构及操作方法。

A proposed architecture and method of operation for improving the protection of privacy and confidentiality in disease registers.

作者信息

Churches Tim

机构信息

Centre for Epidemiology and Research, New South Wales Department of Health, Locked Mail Bag 961, North Sydney NSW 2059, Australia.

出版信息

BMC Med Res Methodol. 2003 Jan 6;3:1. doi: 10.1186/1471-2288-3-1.

DOI:10.1186/1471-2288-3-1
PMID:12515580
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC140307/
Abstract

BACKGROUND

Disease registers aim to collect information about all instances of a disease or condition in a defined population of individuals. Traditionally methods of operating disease registers have required that notifications of cases be identified by unique identifiers such as social security number or national identification number, or by ensembles of non-unique identifying data items, such as name, sex and date of birth. However, growing concern over the privacy and confidentiality aspects of disease registers may hinder their future operation. Technical solutions to these legitimate concerns are needed.

DISCUSSION

An alternative method of operation is proposed which involves splitting the personal identifiers from the medical details at the source of notification, and separately encrypting each part using asymmetrical (public key) cryptographic methods. The identifying information is sent to a single Population Register, and the medical details to the relevant disease register. The Population Register uses probabilistic record linkage to assign a unique personal identification (UPI) number to each person notified to it, although not necessarily everyone in the entire population. This UPI is shared only with a single trusted third party whose sole function is to translate between this UPI and separate series of personal identification numbers which are specific to each disease register.

SUMMARY

The system proposed would significantly improve the protection of privacy and confidentiality, while still allowing the efficient linkage of records between disease registers, under the control and supervision of the trusted third party and independent ethics committees. The proposed architecture could accommodate genetic databases and tissue banks as well as a wide range of other health and social data collections. It is important that proposals such as this are subject to widespread scrutiny by information security experts, researchers and interested members of the general public, alike.

摘要

背景

疾病登记旨在收集特定人群中某种疾病或病症的所有病例信息。传统的疾病登记操作方法要求通过唯一标识符(如社会保障号码或国民身份证号码)或由非唯一识别数据项组合(如姓名、性别和出生日期)来识别病例通知。然而,对疾病登记隐私和保密性的日益关注可能会阻碍其未来的运作。需要针对这些合理担忧的技术解决方案。

讨论

提出了一种替代操作方法,即在通知源处将个人标识符与医疗细节分开,并使用非对称(公钥)加密方法分别对每个部分进行加密。识别信息被发送到单个人口登记处,医疗细节被发送到相关的疾病登记处。人口登记处使用概率记录链接为每个向其通报的人分配一个唯一的个人识别(UPI)号码,尽管不一定是整个人口中的每个人。这个UPI仅与一个单一的可信第三方共享,该第三方的唯一功能是在这个UPI与每个疾病登记处特定的单独一系列个人识别号码之间进行转换。

总结

所提议的系统将显著提高隐私和保密性的保护,同时在可信第三方和独立伦理委员会的控制和监督下,仍允许疾病登记处之间高效地链接记录。提议的架构可以容纳基因数据库和组织库以及广泛的其他健康和社会数据收集。重要的是,这样的提议要受到信息安全专家、研究人员和广大公众中感兴趣成员的广泛审查。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/2780/140307/025bc7219220/1471-2288-3-1-1.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/2780/140307/025bc7219220/1471-2288-3-1-1.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/2780/140307/025bc7219220/1471-2288-3-1-1.jpg

相似文献

1
A proposed architecture and method of operation for improving the protection of privacy and confidentiality in disease registers.一种用于改善疾病登记中隐私和保密性保护的提议架构及操作方法。
BMC Med Res Methodol. 2003 Jan 6;3:1. doi: 10.1186/1471-2288-3-1.
2
Privacy preserving probabilistic record linkage (P3RL): a novel method for linking existing health-related data and maintaining participant confidentiality.隐私保护概率性记录链接(P3RL):一种链接现有健康相关数据并维护参与者隐私的新方法。
BMC Med Res Methodol. 2015 May 30;15:46. doi: 10.1186/s12874-015-0038-6.
3
Some methods for blindfolded record linkage.一些用于盲态记录链接的方法。
BMC Med Inform Decis Mak. 2004 Jun 28;4:9. doi: 10.1186/1472-6947-4-9.
4
Protecting Record Linkage Identifiers Using a Language Model for Patient Names.使用语言模型保护患者姓名的记录链接标识符
Stud Health Technol Inform. 2018;253:91-95.
5
De-identified linkage of data across separate registers: a proposal for improved protection of personal information in registry-based clinical research.跨独立登记处的数据去识别链接:以改进基于登记的临床研究中个人信息保护的建议。
Ups J Med Sci. 2019 Jan;124(1):29-32. doi: 10.1080/03009734.2018.1527420. Epub 2019 Feb 7.
6
Perspectives of Australian adults about protecting the privacy of their health information in statistical databases.澳大利亚成年人对保护其健康信息在统计数据库中隐私的看法。
Int J Med Inform. 2012 Apr;81(4):279-89. doi: 10.1016/j.ijmedinf.2012.01.005. Epub 2012 Feb 10.
7
Privacy preserving interactive record linkage (PPIRL).隐私保护交互式记录链接(PPIRL)。
J Am Med Inform Assoc. 2014 Mar-Apr;21(2):212-20. doi: 10.1136/amiajnl-2013-002165. Epub 2013 Nov 7.
8
Method for identifying eligible individuals for a prevalence survey in the absence of a disease register or population register.在没有疾病登记册或人口登记册的情况下,确定患病率调查中合格个体的方法。
Intern Med J. 2012 Nov;42(11):1207-12. doi: 10.1111/j.1445-5994.2012.02754.x.
9
[Encryption technique for linkable anonymizing].[可链接匿名化的加密技术]
Nihon Koshu Eisei Zasshi. 2004 Jun;51(6):445-51.
10
Mainzelliste SecureEpiLinker (MainSEL): privacy-preserving record linkage using secure multi-party computation. Mainzelliste SecureEpiLinker (MainSEL):使用安全多方计算进行隐私保护的记录链接。
Bioinformatics. 2022 Mar 4;38(6):1657-1668. doi: 10.1093/bioinformatics/btaa764.

引用本文的文献

1
Serum cardiac and inflammatory biomarker levels following chemotherapy among female patients with breast cancer attending at Tikur Anbessa Specialized Hospital, Addis Ababa, Ethiopia.埃塞俄比亚亚的斯亚贝巴提库尔·安贝萨专科医院的乳腺癌女性患者化疗后的血清心脏和炎症生物标志物水平。
BMC Cancer. 2025 Jan 30;25(1):175. doi: 10.1186/s12885-025-13583-5.
2
Report of the Medical Image De-Identification (MIDI) Task Group -- Best Practices and Recommendations.医学图像去识别化(MIDI)任务组报告——最佳实践与建议
ArXiv. 2025 Mar 16:arXiv:2303.10473v3.
3
Using global unique identifiers to link autism collections.

本文引用的文献

1
DNA databanks and consent: a suggested policy option involving an authorization model.DNA数据库与知情同意:一种涉及授权模式的政策建议选项
BMC Med Ethics. 2003 Jan 3;4:E1. doi: 10.1186/1472-6939-4-1.
2
The ethics of health sector databases.卫生部门数据库的伦理问题。
eHealth Int. 2002 Sep 17;1(1):6. doi: 10.1186/1476-3591-1-6.
3
Research use of linked health data--a best practice protocol.关联健康数据的研究用途——最佳实践方案。
使用全球唯一标识符来链接自闭症数据集。
J Am Med Inform Assoc. 2010 Nov-Dec;17(6):689-95. doi: 10.1136/jamia.2009.002063.
4
An evaluation of the current state of genomic data privacy protection technology and a roadmap for the future.基因组数据隐私保护技术的现状评估与未来路线图。
J Am Med Inform Assoc. 2005 Jan-Feb;12(1):28-34. doi: 10.1197/jamia.M1603. Epub 2004 Oct 18.
5
Some methods for blindfolded record linkage.一些用于盲态记录链接的方法。
BMC Med Inform Decis Mak. 2004 Jun 28;4:9. doi: 10.1186/1472-6947-4-9.
Aust N Z J Public Health. 2002;26(3):251-5. doi: 10.1111/j.1467-842x.2002.tb00682.x.
4
Consent, confidentiality, and the threat to public health surveillance.同意、保密与公共卫生监测面临的威胁。
BMJ. 2002 May 18;324(7347):1210-3. doi: 10.1136/bmj.324.7347.1210.
5
Improving the use of clinical databases.改善临床数据库的使用。
BMJ. 2002 May 18;324(7347):1194. doi: 10.1136/bmj.324.7347.1194.
6
The Swiss solution for anonymously chaining patient files.瑞士对患者档案进行匿名链接的解决方案。
Stud Health Technol Inform. 2001;84(Pt 2):1239-41.
7
Registries will have to apply for right to collect patients' data without consent.登记机构将必须申请在未经患者同意的情况下收集其数据的权利。
BMJ. 2001 May 19;322(7296):1199.
8
Cancer registries fear collapse. BUPA wants to ensure systematic transfer of data.癌症登记机构担心崩溃。保柏集团希望确保数据的系统转移。
BMJ. 2001 Mar 24;322(7288):730-1.
9
PKI (public key infrastructure)--how and why it works.公钥基础设施(PKI)——其工作方式及原理。
Health Manag Technol. 2001 Jan;22(1):20-1.
10
Anonymous statistical methods versus cryptographic methods in epidemiology.流行病学中的匿名统计方法与加密方法
Int J Med Inform. 2000 Nov 1;60(2):177-183.