Suppr超能文献

通用治理模式:避免现有可信研究环境中数据隔离的一种方式。

Common governance model: a way to avoid data segregation between existing trusted research environment.

机构信息

Population Data Science, Swansea University, Swansea, SA2 8PP.

Dementias Platform U, Swansea University, Swansea, SA2 8PP.

出版信息

Int J Popul Data Sci. 2023 Nov 8;8(4):2164. doi: 10.23889/ijpds.v8i4.2164. eCollection 2023.

Abstract

BACKGROUND

Trusted Research Environments provide a legitimate basis for data access along with a set of technologies to support implementation of the "five-safes" framework for privacy protection. Lack of standard approaches in achieving compliance with the "five-safes" framework results in a diversity of approaches across different TREs. Data access and analysis across multiple TREs has a range of benefits including improved precision of analysis due to larger sample sizes and broader availability of out-of-sample records, particularly in the study of rare conditions. Knowledge of governance approaches used across UK-TREs is limited.

OBJECTIVE

To document key governance features in major UK-TRE contributing to UK wide analysis and to identify elements that would directly facilitate multi TRE collaborations and federated analysis in future.

METHOD

We summarised three main characteristics across 15 major UK-based TREs: 1) data access environment; 2) data access requests and disclosure control procedures; and 3) governance models. We undertook case studies of collaborative analyses conducted in more than one TRE. We identified an array of TREs operating on an equivalent level of governance. We further identify commonly governed TREs with architectural considerations for achieving an equivalent level of information security management system standards to facilitate multi TRE functionality and federated analytics.

RESULTS

All 15 UK-TREs allow pooling and analysis of aggregated research outputs only when they have passed human-operated disclosure control checks. Data access requests procedures are unique to each TRE. We also observed a variability in disclosure control procedures across various TREs with no or minimal researcher guidance on best practices for file out request procedures. In 2023, six TREs (40.0%) held ISO 20071 accreditation, while 9 TREs (56.2%) participated in four-nation analyses.

CONCLUSION

Secure analysis of individual-level data from multiple TREs is possible through existing technical solutions but requires development of a well-established governance framework meeting all stakeholder requirements and addressing public and patient concerns. Formation of a standard model could act as the catalyst for evolution of current TREs governance models to a multi TRE ecosystem within the UK and beyond.

摘要

背景

可信研究环境为数据访问提供了合法依据,并提供了一组技术来支持实施隐私保护的“五重安全”框架。由于缺乏实现“五重安全”框架合规性的标准方法,导致不同的 TRE 之间存在多种方法。在多个 TRE 中进行数据访问和分析具有一系列好处,包括由于更大的样本量和更广泛的可用样本外记录,分析的精度得到提高,特别是在罕见情况的研究中。对英国 TRE 中使用的治理方法的了解有限。

目的

记录主要英国 TRE 中的关键治理特征,以促进全英范围内的分析,并确定将直接促进未来多 TRE 合作和联合分析的要素。

方法

我们总结了 15 个主要基于英国的 TRE 中的三个主要特征:1)数据访问环境;2)数据访问请求和披露控制程序;和 3)治理模型。我们对在多个 TRE 中进行的合作分析进行了案例研究。我们确定了一系列在同等治理水平上运作的 TRE。我们进一步确定了具有架构考虑因素的共同治理 TRE,以实现等效级别的信息安全管理系统标准,以促进多 TRE 功能和联合分析。

结果

当经过人工操作的披露控制检查后,所有 15 个英国 TRE 都允许汇总和分析聚合的研究成果。数据访问请求程序是每个 TRE 独有的。我们还观察到,在各种 TRE 之间,披露控制程序存在差异,并且对文件请求程序的最佳实践几乎没有或没有研究人员指导。2023 年,有 6 个 TRE(40.0%)获得了 ISO 20071 认证,而有 9 个 TRE(56.2%)参与了四国分析。

结论

通过现有的技术解决方案,可以对来自多个 TRE 的个人层面数据进行安全分析,但需要制定一个满足所有利益相关者要求并解决公众和患者关切的完善治理框架。形成一个标准模型可以作为催化剂,推动英国和其他国家当前 TRE 治理模型向多 TRE 生态系统的发展。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/30a0/10900179/12da6c363227/ijpds-08-2164-g001.jpg

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验