{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,13]],"date-time":"2026-03-13T05:12:23Z","timestamp":1773378743247,"version":"3.50.1"},"reference-count":17,"publisher":"Oxford University Press (OUP)","issue":"3","funder":[{"DOI":"10.13039\/100000002","name":"National Institutes of Health","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100000002","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000054","name":"National Cancer Institute","doi-asserted-by":"publisher","award":["HHSN26100038"],"award-info":[{"award-number":["HHSN26100038"]}],"id":[{"id":"10.13039\/100000054","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000054","name":"National Cancer Institute","doi-asserted-by":"publisher","award":["HHSN261201500003I"],"award-info":[{"award-number":["HHSN261201500003I"]}],"id":[{"id":"10.13039\/100000054","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,3,1]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:sec>\n                    <jats:title>Objective<\/jats:title>\n                    <jats:p>The National Cancer Institute (NCI), part of the National Institutes of Health (NIH) supports efforts to address critical challenges in advancing cancer research. As part of this effort, NCI sponsored the development of a privacy-preserving record linkage (PPRL) software that transforms identifying patient information into multiple tokens through a set of cryptographically secure keyed hash functions. This project aims to evaluate the PPRL software in the perspective of re-identification risks and propose effective strategies to sufficiently mitigate these risks.<\/jats:p>\n                  <\/jats:sec>\n                  <jats:sec>\n                    <jats:title>Materials and Methods<\/jats:title>\n                    <jats:p>To achieve the goals, we developed a novel re-identification risk assessment framework, based on token frequency analysis, to estimate the privacy impact of hashed tokens shared for record linkage. We assessed privacy risk through empirical analysis on a state-level voter registration database, a public dataset commonly used for re-identification, under various scenarios. These scenarios are defined based on several factors, including the size of the dataset used for linkage and a group size parameter that determines when an adversary can claim that a record has been re-identified.<\/jats:p>\n                  <\/jats:sec>\n                  <jats:sec>\n                    <jats:title>Results<\/jats:title>\n                    <jats:p>We found that the re-identification risk based on frequency analysis attack is approximately 0.0002 (ie, 2 patients out of 10\u00a0000 are potentially identifiable) under reasonable adversarial settings, with a group size parameter of k\u2009=\u200912 and a dataset size of 400\u00a0000 patients. Additionally, our analysis reveals a negative correlation between dataset size and re-identification risk.<\/jats:p>\n                  <\/jats:sec>\n                  <jats:sec>\n                    <jats:title>Discussion<\/jats:title>\n                    <jats:p>Re-identification risk is deemed low for the new NCI PPRL software. Token frequency analysis provides a reliable estimate of the re-identification risk in token-based PPRL tools.<\/jats:p>\n                  <\/jats:sec>","DOI":"10.1093\/jamia\/ocaf172","type":"journal-article","created":{"date-parts":[[2025,9,25]],"date-time":"2025-09-25T11:58:27Z","timestamp":1758801507000},"page":"663-669","source":"Crossref","is-referenced-by-count":0,"title":["A novel analysis methodology for assessment of re-identification risks for the National Cancer Institute cancer registry privacy preserving record linkage technique"],"prefix":"10.1093","volume":"33","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9795-9063","authenticated-orcid":false,"given":"Murat","family":"Kantarcioglu","sequence":"first","affiliation":[{"name":"Department of Computer Science, Virginia Tech , Blacksburg, VA 24061,","place":["United States"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-4227-5217","authenticated-orcid":false,"given":"Will","family":"Howe","sequence":"additional","affiliation":[{"name":"Information Management Services, Inc. , Calverton, MD 20705,","place":["United States"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0096-139X","authenticated-orcid":false,"given":"Benmei","family":"Liu","sequence":"additional","affiliation":[{"name":"Surveillance Research Program, Division of Cancer Control & Population Sciences, National Cancer Institute , Bethesda, MD 20892,","place":["United States"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-8297-5381","authenticated-orcid":false,"given":"Valentina","family":"Petkov","sequence":"additional","affiliation":[{"name":"Surveillance Research Program, Division of Cancer Control & Population Sciences, National Cancer Institute , Bethesda, MD 20892,","place":["United States"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9704-0812","authenticated-orcid":false,"given":"Esmeralda","family":"Casas-Silva","sequence":"additional","affiliation":[{"name":"Center for Biomedical Informatics and Information Technology, National Cancer Institute , Bethesda, MD 20892,","place":["United States"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-1866-6281","authenticated-orcid":false,"given":"Diana","family":"Velasquez-Kolnik","sequence":"additional","affiliation":[{"name":"Frederick National Laboratory for Cancer Research , Frederick, MD 21701,","place":["United States"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3040-5175","authenticated-orcid":false,"given":"Bradley A","family":"Malin","sequence":"additional","affiliation":[{"name":"Department of Biomedical Informatics, Vanderbilt University Medical Center , Nashville, TN 37232,","place":["United States"]},{"name":"Department of Computer Science, Vanderbilt University , Nashville, TN 37232,","place":["United States"]},{"name":"Department of Biostatistics, Vanderbilt University Medical Center , Nashville, TN 37232,","place":["United States"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9372-9869","authenticated-orcid":false,"given":"Lynne","family":"Penberthy","sequence":"additional","affiliation":[{"name":"Surveillance Research Program, Division of Cancer Control & Population Sciences, National Cancer Institute , Bethesda, MD 20892,","place":["United States"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"286","published-online":{"date-parts":[[2025,10,27]]},"reference":[{"key":"2026031216463592600_ocaf172-B1","doi-asserted-by":"crossref","first-page":"1072","DOI":"10.1093\/jamia\/ocv038","article-title":"Design and implementation of a privacy preserving electronic health record linkage tool in Chicago","volume":"22","author":"Kho","year":"2015","journal-title":"J Am Med Inform Assoc"},{"key":"2026031216463592600_ocaf172-B2","doi-asserted-by":"crossref","first-page":"4966","DOI":"10.1109\/TIFS.2021.3114026","article-title":"Modern privacy-preserving record linkage techniques: an overview","volume":"16","author":"Gkoulalas-Divanis","year":"2021","journal-title":"IEEE Trans Inform Forensic Secur"},{"key":"2026031216463592600_ocaf172-B3","first-page":"257","volume-title":"Proceedings of the 15th ACM Conference on Computer and Communications Security (CCS '08)","author":"Ben-David","year":"2008"},{"key":"2026031216463592600_ocaf172-B4","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-45239-0_4","volume-title":"Cryptography and Coding","author":"Bos","year":"2013"},{"key":"2026031216463592600_ocaf172-B5","doi-asserted-by":"crossref","first-page":"245","DOI":"10.1016\/j.inffus.2011.04.004","article-title":"Quantifying the correctness, computational complexity, and security of privacy-preserving string comparators for record linkage","volume":"13","author":"Durham","year":"2012","journal-title":"Inf Fusion"},{"key":"2026031216463592600_ocaf172-B6","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-642-31164-2","volume-title":"Data Matching: Concepts and Techniques for Record Linkage, Entity Resolution, and Data Deduplication","author":"Christen","year":"2012"},{"key":"2026031216463592600_ocaf172-B7","volume-title":"MatchPro*","author":"National Cancer Institute","year":"2023"},{"key":"2026031216463592600_ocaf172-B8","author":"National Cancer Institute","year":"2023"},{"key":"2026031216463592600_ocaf172-B9","doi-asserted-by":"crossref","first-page":"169","DOI":"10.1136\/jamia.2009.000026","article-title":"Evaluating re-identification risks with respect to the HIPAA privacy rule","volume":"17","author":"Benitez","year":"2010","journal-title":"J Am Med Inform Assoc"},{"key":"2026031216463592600_ocaf172-B10","doi-asserted-by":"crossref","first-page":"557","DOI":"10.1142\/S0218488502001648","article-title":"K-anonymity: a model for protecting privacy","volume":"10","author":"Sweeney","year":"2002","journal-title":"Int J Uncertainty Fuzziness Knowledge-Based Syst"},{"key":"2026031216463592600_ocaf172-B11"},{"key":"2026031216463592600_ocaf172-B12","volume-title":"HMAC: Keyed-Hashing for Message Authentication","author":"Krawczyk","year":"1997"},{"key":"2026031216463592600_ocaf172-B13","doi-asserted-by":"crossref","first-page":"207","DOI":"10.1016\/0166-218X(92)90177-C","article-title":"Birthday paradox, coupon collectors, caching algorithms and self-organizing search","volume":"39","author":"Flajolet","year":"1992","journal-title":"Discrete Appl Math (1979)"},{"key":"2026031216463592600_ocaf172-B14","author":"Gosney","year":"2024"},{"key":"2026031216463592600_ocaf172-B15","author":"Picchi","year":"2024"},{"key":"2026031216463592600_ocaf172-B16","author":"North Carolina Voter Registration Database","year":"2022"},{"key":"2026031216463592600_ocaf172-B17","first-page":"160","volume-title":"IEEE Annual Symposium on Foundations of Computer Science","author":"Yao","year":"1982"}],"container-title":["Journal of the American Medical Informatics Association"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/academic.oup.com\/jamia\/article-pdf\/33\/3\/663\/64959702\/ocaf172.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/academic.oup.com\/jamia\/article-pdf\/33\/3\/663\/64959702\/ocaf172.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,12]],"date-time":"2026-03-12T20:46:44Z","timestamp":1773348404000},"score":1,"resource":{"primary":{"URL":"https:\/\/academic.oup.com\/jamia\/article\/33\/3\/663\/8304360"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,27]]},"references-count":17,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2025,10,27]]},"published-print":{"date-parts":[[2026,3,1]]}},"URL":"https:\/\/doi.org\/10.1093\/jamia\/ocaf172","relation":{},"ISSN":["1067-5027","1527-974X"],"issn-type":[{"value":"1067-5027","type":"print"},{"value":"1527-974X","type":"electronic"}],"subject":[],"published-other":{"date-parts":[[2026,3]]},"published":{"date-parts":[[2025,10,27]]}}}