PATIENT PRIVACY AND DATA CONFIDENTIALITY AND THE USE OF SECONDARY DATA
Author(s)
Bonnie B Dean, PhD, MPH, Principal Investigator1, Daniel Aguilar, MPH, Research Project Leader1, Joanna Whyte, MS, RD, MSPH, Senior Manager2, Robert Nordyke, PhD, MS, Director21Cerner LifeSciences, Beverly Hills, CA, USA; 2 Amgen, Inc., Thousand Oaks, CA, USA
OBJECTIVES: No well-defined standards, including provisions in HIPAA, currently provide clear guidance for merging, linking, and analyzing secondary health data that were originally collected for patient care, such as electronic medical record (EMR) data. A literature review explored factors that may affect potential risks of secondary data research from the perspective of patient privacy and data confidentiality. METHODS: The PubMed database and internet sites of CDC, DHHS, and patient advocacy groups were searched to identify publications from January 1, 1998 to March 7, 2008 involving patient privacy and secondary use of data. Search terms included (but were not limited to): confidentiality, privacy, consent, ethics, secondary data, secondary analysis, patient data, de-identified, and identifiable. RESULTS: A total of 33 documents were identified. Several discussion topics that address patient privacy within the context of secondary data research were identified in the literature. These issues were assessed and grouped into four domains: 1) concerns about inadequacy of patient consent [76% of articles] (eg, no patient consent is needed or that consent obtained for general research purposes may not be adequate for specific research hypotheses); 2) concerns about identifiability of the data and the degree to which the data can be de-identified [88%]; 3) concerns about data access, including monitoring, controlling, and regulation of data access [85%]; and (4) concerns about the investigators' objectives for analyzing and using the data [52%] (eg, epidemiology and surveillance studies caused less concern than did market research). CONCLUSIONS: We identified four recurrent themes in the evidence: they touched upon patient consent, identifiability of data, data access, and research objectives. Dialogue about these issues between investigators, research oversight administrators and patient advocates may help clarify standards to ensure that secondary data research is broadly acceptable from a patient privacy and data confidentiality perspective.
Conference/Value in Health Info
2009-05, ISPOR 2009, Orlando, FL, USA
Value in Health, Vol. 12, No. 3 (May 2009)
Code
PHP72
Topic
Health Service Delivery & Process of Care
Topic Subcategory
Health Care Research
Disease
Multiple Diseases