{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2022,8,4]],"date-time":"2022-08-04T21:11:05Z","timestamp":1659647465807},"reference-count":19,"publisher":"Oxford University Press (OUP)","issue":"3","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018,3,1]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:sec><jats:title>Objective<\/jats:title><jats:p>Recent growth in the number of population health researchers accessing detailed datasets, either on their own computers or through virtual data centers, has the potential to increase privacy risks. In response, a checklist for identifying and reducing privacy risks in population health analysis outputs has been proposed for use by researchers themselves. In this study we explore the usability and reliability of such an approach by investigating whether different users identify the same privacy risks on applying the checklist to a sample of publications.<\/jats:p><\/jats:sec><jats:sec><jats:title>Methods<\/jats:title><jats:p>The checklist was applied to a sample of 100 academic population health publications distributed among 5 readers. Cohen\u2019s \u03ba was used to measure interrater agreement.<\/jats:p><\/jats:sec><jats:sec><jats:title>Results<\/jats:title><jats:p>Of the 566 instances of statistical output types found in the 100 publications, the most frequently occurring were counts, summary statistics, plots, and model outputs. Application of the checklist identified 128 outputs (22.6%) with potential privacy concerns. Most of these were associated with the reporting of small counts. Among these identified outputs, the readers found no substantial actual privacy concerns when context was taken into account. Interrater agreement for identifying potential privacy concerns was generally good.<\/jats:p><\/jats:sec><jats:sec><jats:title>Conclusion<\/jats:title><jats:p>This study has demonstrated that a checklist can be a reliable tool to assist researchers with anonymizing analysis outputs in population health research. This further suggests that such an approach may have the potential to be developed into a broadly applicable standard providing consistent confidentiality protection across multiple analyses of the same data.<\/jats:p><\/jats:sec>","DOI":"10.1093\/jamia\/ocx129","type":"journal-article","created":{"date-parts":[[2017,10,18]],"date-time":"2017-10-18T11:09:59Z","timestamp":1508324999000},"page":"315-320","source":"Crossref","is-referenced-by-count":3,"title":["Assessing privacy risks in population health publications using a checklist-based approach"],"prefix":"10.1093","volume":"25","author":[{"given":"Christine M","family":"O\u2019Keefe","sequence":"first","affiliation":[{"name":"CSIRO, Canberra, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Adrien","family":"Ickowicz","sequence":"additional","affiliation":[{"name":"CSIRO, Hobart, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tim","family":"Churches","sequence":"additional","affiliation":[{"name":"Sax Institute, Sydney, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mark","family":"Westcott","sequence":"additional","affiliation":[{"name":"CSIRO, Canberra, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Maree","family":"O\u2019Sullivan","sequence":"additional","affiliation":[{"name":"CSIRO, Sydney, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Atikur","family":"Khan","sequence":"additional","affiliation":[{"name":"CSIRO, Melbourne, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"286","published-online":{"date-parts":[[2017,11,10]]},"reference":[{"key":"2020110612383755600_ocx129-B1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1197\/jamia.M2273","article-title":"Toward a national framework for the secondary use of health data: an American Medical Informatics Association White Paper","volume":"14","author":"Safran","year":"2007","journal-title":"J Am Med Inform Assoc."},{"key":"2020110612383755600_ocx129-B2","doi-asserted-by":"crossref","first-page":"359","DOI":"10.7326\/0003-4819-151-5-200909010-00141","article-title":"Toward reuse of clinical data for research and quality improvement: the end of the beginning?","volume":"151","author":"Weiner","year":"2009","journal-title":"Ann Intern Med."},{"key":"2020110612383755600_ocx129-B3","doi-asserted-by":"crossref","first-page":"426","DOI":"10.1111\/insr.12021","article-title":"A summary of attack methods and confidentiality protection measures for fully automated remote analysis systems","volume":"81","author":"O\u2019Keefe","year":"2013","journal-title":"Int Stat Rev."},{"key":"2020110612383755600_ocx129-B4","doi-asserted-by":"crossref","first-page":"544","DOI":"10.1093\/jamia\/ocw152","article-title":"Anonymization for outputs of population health and health services research conducted via an online data center","volume":"24","author":"O\u2019Keefe","year":"2017","journal-title":"J Am Med Inform Assoc."},{"key":"2020110612383755600_ocx129-B5","doi-asserted-by":"crossref","first-page":"3081","DOI":"10.1002\/sim.6543","article-title":"Individual privacy versus public good: protecting confidentiality in health research","volume":"34","author":"O'Keefe","year":"2015","journal-title":"Stat Med."},{"key":"2020110612383755600_ocx129-B6","doi-asserted-by":"crossref","DOI":"10.1002\/9781118348239","volume-title":"Statistical Disclosure Control","author":"Hundepool","year":"2012"},{"key":"2020110612383755600_ocx129-B7","doi-asserted-by":"crossref","DOI":"10.1007\/978-1-4419-7802-8","volume-title":"Statistical Confidentiality","author":"Duncan","year":"2011"},{"key":"2020110612383755600_ocx129-B8","doi-asserted-by":"crossref","first-page":"2","DOI":"10.1136\/amiajnl-2012-001509","article-title":"Biomedical data privacy: problems, perspectives, and recent advances","volume":"20","author":"Malin","year":"2013","journal-title":"J Am Med Inform Assoc."},{"key":"2020110612383755600_ocx129-B9","article-title":"Protecting confidentiality in statistical analysis outputs from a virtual data centre","volume-title":"Joint UNECE\/Eurostat Work Session on Statistical Data Confidentiality","author":"O'Keefe","year":"2013"},{"key":"2020110612383755600_ocx129-B10","article-title":"The anonymisation decision-making framework","volume-title":"UK Anonymisation Network","author":"Elliot"},{"key":"2020110612383755600_ocx129-B11","volume-title":"Guidance Regarding Methods for De-Identification of Protected Health Information in Accordance with the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule","author":"US Department of Health & Human Services"},{"key":"2020110612383755600_ocx129-B12","first-page":"1021","article-title":"Process-driven data privacy","volume-title":"Proceedings of the 24th ACM International Conference on Information and Knowledge Management","author":"Xia","year":"2015"},{"issue":"1","key":"2020110612383755600_ocx129-B13","doi-asserted-by":"crossref","first-page":"11","DOI":"10.2310\/JIM.0b013e3181c9b2ea","article-title":"Technical and policy approaches to balancing patient privacy and data sharing in clinical and translational research","volume":"58","author":"Malin","year":"2010","journal-title":"J Invest Med."},{"issue":"12","key":"2020110612383755600_ocx129-B14","doi-asserted-by":"crossref","first-page":"e28071","DOI":"10.1371\/journal.pone.0028071","article-title":"A systematic review of re-identification attacks on health data","volume":"6","author":"El Emam","year":"2011","journal-title":"PLoS One."},{"key":"2020110612383755600_ocx129-B15","volume-title":"Data Lab Output Guide","author":"Statistics New Zealand","year":"2011"},{"key":"2020110612383755600_ocx129-B16","doi-asserted-by":"crossref","DOI":"10.1201\/b14764","volume-title":"A Guide to the De-identification of Health Information","author":"El Emam","year":"2013"},{"issue":"1","key":"2020110612383755600_ocx129-B17","doi-asserted-by":"crossref","first-page":"66","DOI":"10.1186\/1472-6947-12-66","article-title":"Estimating the re-identification risk of clinical data sets","volume":"12","author":"Dankar","year":"2012","journal-title":"BMC Med Inform Dec Mak."},{"key":"2020110612383755600_ocx129-B18","doi-asserted-by":"crossref","first-page":"37","DOI":"10.1177\/001316446002000104","article-title":"A coefficient of agreement for nominal scales","volume":"20","author":"Cohen","year":"1960","journal-title":"Educ Psychol Meas."},{"key":"2020110612383755600_ocx129-B19","doi-asserted-by":"crossref","first-page":"105","DOI":"10.1177\/014662168100500115","article-title":"Balanced incomplete block designs for inter-rater reliability studies","volume":"5","author":"Fleiss","year":"1981","journal-title":"Appl Psychol Meas."}],"container-title":["Journal of the American Medical Informatics Association"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/academic.oup.com\/jamia\/article-pdf\/25\/3\/315\/34150288\/ocx129.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"http:\/\/academic.oup.com\/jamia\/article-pdf\/25\/3\/315\/34150288\/ocx129.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,8,4]],"date-time":"2022-08-04T20:35:00Z","timestamp":1659645300000},"score":1,"resource":{"primary":{"URL":"https:\/\/academic.oup.com\/jamia\/article\/25\/3\/315\/4616789"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,11,10]]},"references-count":19,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2017,11,10]]},"published-print":{"date-parts":[[2018,3,1]]}},"URL":"https:\/\/doi.org\/10.1093\/jamia\/ocx129","relation":{},"ISSN":["1067-5027","1527-974X"],"issn-type":[{"value":"1067-5027","type":"print"},{"value":"1527-974X","type":"electronic"}],"subject":[],"published-other":{"date-parts":[[2018,3]]},"published":{"date-parts":[[2017,11,10]]}}}