Service for the Pseudonymization of Electronic Healthcare Records Based on ISO/EN 13606 for the Secondary Use of Information

The availability of electronic health data favors scientific advance through the creation of repositories for secondary use. Data anonymization is a mandatory step to comply with current legislation. A service for the pseudonymization of electronic healthcare record (EHR) extracts aimed at facilitat...

Descripción completa

Detalles Bibliográficos
Autores: Somolinos, Roberto, Hernando, M Elena, Fragua, Juan A, Serrano, Pablo, Muñoz Carrero, Adolfo, Pascual-Carrasco, Mario, Caceres Tello, Jesus, Sánchez-de-Madariaga, Ricardo, Hernandez-Salvador, Carlos
Tipo de recurso: artículo
Fecha de publicación:2015
País:España
Institución:Instituto de Salud Carlos III (ISCIII)
Repositorio:Repisalud
Idioma:inglés
OAI Identifier:oai:repisalud.isciii.es:20.500.12105/10622
Acceso en línea:http://hdl.handle.net/20.500.12105/10622
Access Level:acceso abierto
Palabra clave:Electronic medical records
Identification of persons
ISO standards
Medical information systems
Pseudonymization
Telemedicine
Web services
Medical Informatics Applications
Confidentiality
Electronic Health Records
Humans
Descripción
Sumario:The availability of electronic health data favors scientific advance through the creation of repositories for secondary use. Data anonymization is a mandatory step to comply with current legislation. A service for the pseudonymization of electronic healthcare record (EHR) extracts aimed at facilitating the exchange of clinical information for secondary use in compliance with legislation on data protection is presented. According to ISO/TS 25237, pseudonymization is a particular type of anonymization. This tool performs the anonymizations by maintaining three quasi-identifiers (gender, date of birth, and place of residence) with a degree of specification selected by the user. The developed system is based on the ISO/EN 13606 norm using its characteristics specifically favorable for anonymization. The service is made up of two independent modules: the demographic server and the pseudonymizing module. The demographic server supports the permanent storage of the demographic entities and the management of the identifiers. The pseudonymizing module anonymizes the ISO/EN 13606 extracts. The pseudonymizing process consists of four phases: the storage of the demographic information included in the extract, the substitution of the identifiers, the elimination of the demographic information of the extract, and the elimination of key data in free-text fields. The described pseudonymizing system was used in three telemedicine research projects with satisfactory results. A problem was detected with the type of data in a demographic data field and a proposal for modification was prepared for the group in charge of the drawing up and revision of the ISO/EN 13606 norm.