• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

《医疗保险可携性与责任法案》安全港条款二十年:未解挑战与前行之路

Twenty Years of the Health Insurance Portability and Accountability Act Safe Harbor Provision: Unsolved Challenges and Ways Forward.

作者信息

Krzyzanowski Brittany, Manson Steven M

机构信息

University of Minnesota, Minneapolis, MN, United States.

出版信息

JMIR Med Inform. 2022 Aug 3;10(8):e37756. doi: 10.2196/37756.

DOI:10.2196/37756
PMID:35921140
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC9386597/
Abstract

The Health Insurance Portability and Accountability Act (HIPAA) was an important milestone in protecting the privacy of patient data; however, the HIPAA provisions specific to geographic data remain vague and hinder the ways in which epidemiologists and geographers use and share spatial health data. The literature on spatial health and select legal and official guidance documents present scholars with ambiguous guidelines that have led to the use and propagation of multiple interpretations of a single HIPAA safe harbor provision specific to geographic data. Misinterpretation of this standard has resulted in many entities sharing data at overly conservative levels, whereas others offer definitions of safe harbors that potentially put patient data at risk. To promote understanding of, and adherence to, the safe harbor rule, this paper reviews the HIPAA law from its creation to the present day, elucidating common misconceptions and presenting straightforward guidance to scholars. We focus on the 20,000-person population threshold and the 3-digit zip code stipulation of safe harbors, which are central to the confusion surrounding how patient location data can be shared. A comprehensive examination of these 2 stipulations, which integrates various expert perspectives and relevant studies, reveals how alternative methods for safe harbors can offer researchers better data and better data protection. Much has changed in the 20 years since the introduction of the safe harbor provision; however, it continues to be the primary source of guidance (and frustration) for researchers trying to share maps, leaving many waiting for these rules to be revised in accordance with the times.

摘要

《健康保险流通与责任法案》(HIPAA)是保护患者数据隐私方面的一个重要里程碑;然而,HIPAA中关于地理数据的条款仍然模糊不清,阻碍了流行病学家和地理学家使用和共享空间健康数据的方式。关于空间健康的文献以及一些法律和官方指导文件为学者们提供了模棱两可的指导方针,导致对HIPAA中一项特定于地理数据的安全港条款产生了多种解释并加以使用和传播。对这一标准的误解导致许多实体在数据共享时过于保守,而另一些实体给出的安全港定义则可能使患者数据面临风险。为促进对安全港规则的理解和遵守,本文回顾了从HIPAA法律制定至今的情况,阐明常见的误解,并为学者们提供直接的指导。我们聚焦于安全港的2万人人口阈值和三位邮政编码规定,这两点是围绕患者位置数据如何共享的困惑的核心。对这两项规定进行全面审视,综合各种专家观点和相关研究,揭示了安全港的替代方法如何能为研究人员提供更好的数据和更好的数据保护。自引入安全港条款以来的20年里,情况发生了很大变化;然而,它仍然是试图共享地图的研究人员的主要指导来源(也是挫折来源),让许多人等待这些规则与时俱进地修订。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1ea2/9386597/d4dba1b74f81/medinform_v10i8e37756_fig6.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1ea2/9386597/891d164f8829/medinform_v10i8e37756_fig1.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1ea2/9386597/0e75fe1c827a/medinform_v10i8e37756_fig2.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1ea2/9386597/f071f6eec39e/medinform_v10i8e37756_fig3.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1ea2/9386597/e66b16bc7404/medinform_v10i8e37756_fig4.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1ea2/9386597/dc87e6b3a22d/medinform_v10i8e37756_fig5.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1ea2/9386597/d4dba1b74f81/medinform_v10i8e37756_fig6.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1ea2/9386597/891d164f8829/medinform_v10i8e37756_fig1.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1ea2/9386597/0e75fe1c827a/medinform_v10i8e37756_fig2.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1ea2/9386597/f071f6eec39e/medinform_v10i8e37756_fig3.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1ea2/9386597/e66b16bc7404/medinform_v10i8e37756_fig4.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1ea2/9386597/dc87e6b3a22d/medinform_v10i8e37756_fig5.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1ea2/9386597/d4dba1b74f81/medinform_v10i8e37756_fig6.jpg

相似文献

1
Twenty Years of the Health Insurance Portability and Accountability Act Safe Harbor Provision: Unsolved Challenges and Ways Forward.《医疗保险可携性与责任法案》安全港条款二十年:未解挑战与前行之路
JMIR Med Inform. 2022 Aug 3;10(8):e37756. doi: 10.2196/37756.
2
The effects of the Health Insurance Portability and Accountability Act privacy rule on influenza research using geographical information systems.《医疗保险可携性与责任法案》隐私规则对使用地理信息系统进行流感研究的影响。
Geospat Health. 2010 Nov;5(1):3-9. doi: 10.4081/gh.2010.182.
3
Health Insurance Portability and Accountability Act of 1996 (HIPAA): a provider's overview of new privacy regulations.1996年《健康保险流通与责任法案》(HIPAA):医疗机构对新隐私法规的概述
Conn Med. 2002 Feb;66(2):91-5.
4
Review of HIPAA, Part 1: History, Protected Health Information, and Privacy and Security Rules.《健康保险流通与责任法案》(HIPAA)综述,第1部分:历史、受保护的健康信息以及隐私和安全规则。
J Nucl Med Technol. 2019 Dec;47(4):269-272. doi: 10.2967/jnmt.119.227819. Epub 2019 Jun 10.
5
Biobanking Research and Privacy Laws in the United States.美国的生物样本库研究与隐私法
J Law Med Ethics. 2016 Mar;44(1):106-27. doi: 10.1177/1073110516644203.
6
Evaluation of Privacy Risks of Patients' Data in China: Case Study.中国患者数据隐私风险评估:案例研究
JMIR Med Inform. 2020 Feb 5;8(2):e13046. doi: 10.2196/13046.
7
Re-identification Risks in HIPAA Safe Harbor Data: A study of data from one environmental health study.《健康保险流通与责任法案》安全港数据中的重新识别风险:一项对来自一项环境卫生研究数据的研究
Technol Sci. 2017;2017. Epub 2017 Aug 28.
8
Protecting Privacy: Health Insurance Portability and Accountability Act of 1996, Twenty-First Century Cures Act, and Social Media.保护隐私:1996 年《健康保险携带和责任法案》、《21 世纪治愈法案》和社交媒体。
Neurol Clin. 2023 Aug;41(3):513-522. doi: 10.1016/j.ncl.2023.03.007. Epub 2023 May 31.
9
The Health Insurance Portability and Accountability Act: does it live up to the promise?《健康保险流通与责任法案》:它是否兑现了承诺?
J Med Syst. 2006 Feb;30(1):45-50. doi: 10.1007/s10916-006-7403-2.
10
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) privacy rule: implications for clinical research.1996年《健康保险流通与责任法案》(HIPAA)隐私规则:对临床研究的影响
Annu Rev Med. 2006;57:575-90. doi: 10.1146/annurev.med.57.121304.131257.

引用本文的文献

1
Large language models for efficient whole-organ MRI score-based reports and categorization in knee osteoarthritis.用于膝关节骨关节炎中基于MRI评分的高效全器官报告和分类的大语言模型
Insights Imaging. 2025 May 14;16(1):100. doi: 10.1186/s13244-025-01976-w.
2
A resource for Logical Observation Identifiers Names and Codes terms that may be associated with identifying information.一个可能与识别信息相关联的逻辑观察标识符名称和代码术语的资源。
J Am Med Inform Assoc. 2025 Jun 1;32(6):1066-1070. doi: 10.1093/jamia/ocaf061.
3
Data linkage multiplies research insights across diverse healthcare sectors.

本文引用的文献

1
Enabling qualitative research data sharing using a natural language processing pipeline for deidentification: moving beyond HIPAA Safe Harbor identifiers.使用自然语言处理管道进行去识别以实现定性研究数据共享:超越《健康保险流通与责任法案》安全港标识符。
JAMIA Open. 2021 Aug 23;4(3):ooab069. doi: 10.1093/jamiaopen/ooab069. eCollection 2021 Jul.
2
How differential privacy will affect our understanding of health disparities in the United States.差分隐私将如何影响我们对美国健康差异的理解。
Proc Natl Acad Sci U S A. 2020 Jun 16;117(24):13405-13412. doi: 10.1073/pnas.2003714117. Epub 2020 May 28.
3
Re-Identification Risk in HIPAA De-Identified Datasets: The MVA Attack.
数据关联可成倍增加跨不同医疗保健领域的研究见解。
Commun Med (Lond). 2025 Mar 4;5(1):58. doi: 10.1038/s43856-025-00769-y.
4
Making the Case for an International Childhood Cancer Data Partnership.推动建立国际儿童癌症数据伙伴关系的理由。
J Natl Cancer Inst. 2025 Jan 12. doi: 10.1093/jnci/djaf003.
5
The glycemic gap as a prognostic indicator in cardiogenic shock: a retrospective cohort study.血糖差距作为心源性休克预后指标的研究:一项回顾性队列研究。
BMC Cardiovasc Disord. 2024 Sep 2;24(1):468. doi: 10.1186/s12872-024-04138-w.
6
Community-Engaged Data Science (CEDS): A Case Study of Working with Communities to Use Data to Inform Change.社区参与式数据科学 (CEDS):与社区合作使用数据推动变革的案例研究。
J Community Health. 2024 Dec;49(6):1062-1072. doi: 10.1007/s10900-024-01377-y. Epub 2024 Jul 3.
7
The Costs of Anonymization: Case Study Using Clinical Data.匿名化的成本:使用临床数据的案例研究
J Med Internet Res. 2024 Apr 24;26:e49445. doi: 10.2196/49445.
8
Best Practices in Evolving Privacy Frameworks for Patient Age Data: Census Data Study.患者年龄数据隐私框架演变的最佳实践:人口普查数据研究
JMIR Form Res. 2024 Mar 25;8:e47248. doi: 10.2196/47248.
9
LionVu: A Data-Driven Geographical Web-GIS Tool for Community Health and Decision-Making in a Catchment Area.LionVu:一种用于集水区社区健康与决策的数据驱动型地理网络地理信息系统工具。
Geographies. 2023 Jun;3(2):286-302. doi: 10.3390/geographies3020015. Epub 2023 Apr 18.
10
For-profit versus non-profit cybersecurity posture: breach types and locations in healthcare organisations.营利性与非营利性网络安全态势:医疗机构中的漏洞类型和位置。
Health Inf Manag. 2024 Sep;53(3):198-205. doi: 10.1177/18333583231158886. Epub 2023 Feb 24.
《健康保险流通与责任法案》(HIPAA)去标识化数据集中的重新识别风险:多元变量分析(MVA)攻击
AMIA Annu Symp Proc. 2018 Dec 5;2018:1329-1337. eCollection 2018.
4
Re-identification Risks in HIPAA Safe Harbor Data: A study of data from one environmental health study.《健康保险流通与责任法案》安全港数据中的重新识别风险:一项对来自一项环境卫生研究数据的研究
Technol Sci. 2017;2017. Epub 2017 Aug 28.
5
Electronic Health Records: Then, Now, and in the Future.电子健康记录:过去、现在与未来。
Yearb Med Inform. 2016 May 20;Suppl 1(Suppl 1):S48-61. doi: 10.15265/IYS-2016-s006.
6
The Risks to Patient Privacy from Publishing Data from Clinical Anesthesia Studies.临床麻醉研究数据发表对患者隐私的风险。
Anesth Analg. 2016 Jun;122(6):2017-27. doi: 10.1213/ANE.0000000000001331.
7
Challenges and Insights in Using HIPAA Privacy Rule for Clinical Text Annotation.使用《健康保险流通与责任法案》隐私规则进行临床文本注释的挑战与见解。
AMIA Annu Symp Proc. 2015 Nov 5;2015:707-16. eCollection 2015.
8
A Place-Oriented, Mixed-Level Regionalization Method for Constructing Geographic Areas in Health Data Dissemination and Analysis.一种用于健康数据传播与分析中构建地理区域的面向地点的混合层次区域划分方法。
Ann Assoc Am Geogr. 2014;105(1):48-66. doi: 10.1080/00045608.2014.968910.
9
The Challenges of Creating a Gold Standard for De-identification Research.为去识别化研究创建金标准所面临的挑战。
AMIA Annu Symp Proc. 2014 Nov 14;2014:353-8. eCollection 2014.
10
A linear programming model for preserving privacy when disclosing patient spatial information for secondary purposes.用于在为次要目的披露患者空间信息时保护隐私的线性规划模型。
Int J Health Geogr. 2014 May 29;13:16. doi: 10.1186/1476-072X-13-16.