Simon Marie, Looten Vincent
Université Paris-Est Créteil, Créteil, France.
UMRS 1138, Centre de Recherche des Cordeliers, Université de Paris, Paris, France.
Stud Health Technol Inform. 2020 Nov 23;275:192-196. doi: 10.3233/SHTI200721.
Although the consequences of the General Data Protection Regulation (GDPR) have been widely discussed, the violations have not been described in medical literature. In this study, we focus our analyses on the data breach notifications, in France, defined in the article 4 of GDPR as "a breach of security resulting, accidentally or unlawfully, in the destruction, loss, alteration, unauthorized disclosure of personal data transmitted, stored or otherwise processed, or unauthorized access to such data." Among 3,824 data breach notifications reported between May 2018 and February 2020, 244 (6.4%) is related to the health sector. Loss of confidentiality is the most important breach (80.7%) in this sector, followed by the loss of availability (27.5%). Malicious cause occurred in 58.2% of them. We hypothesized a phenomenon of underreported data breach incidents in health due to a mismatch between cybersecurity and data privacy issues.
尽管《通用数据保护条例》(GDPR)的影响已得到广泛讨论,但医学文献中尚未描述其违规情况。在本研究中,我们将分析重点放在法国的数据泄露通知上,GDPR第4条将其定义为“因意外或非法导致传输、存储或以其他方式处理的个人数据被销毁、丢失、更改、未经授权披露,或未经授权访问此类数据的安全漏洞”。在2018年5月至2020年2月期间报告的3824起数据泄露通知中,有244起(6.4%)与卫生部门有关。保密性丧失是该部门最重要的违规行为(80.7%),其次是可用性丧失(27.5%)。其中58.2%是由恶意原因导致的。我们推测,由于网络安全和数据隐私问题不匹配,卫生领域的数据泄露事件可能存在报告不足的现象。