Cross-border flow of health information: is 'privacy by design' enough? Privacy performance assessment in EUBIROD

被引:18
作者
Di Iorio, Concetta Tania [1 ]
Carinci, Fabrizio [1 ]
Brillante, Massimo [2 ]
Azzopardi, Joseph [3 ]
Beck, Peter [4 ]
Bratina, Natasa [5 ]
Cunningham, Scott G. [2 ]
De Beaufort, Carine [6 ]
Debacker, Noemi [7 ]
Jarosz-Chobot, Przemyslawa [8 ]
Jecht, Michael [9 ]
Lindblad, Ulf [10 ]
Moulton, Tony [11 ]
Metelko, Zeliko [12 ]
Nagy, Attila [13 ]
Olympios, George [14 ]
Pruna, Simion [15 ]
Roder, Michael [16 ]
Skeie, Svein [17 ]
Storms, Fred [18 ]
Benedetti, Massimo Massi [19 ]
机构
[1] Serectrix Snc, I-65121 Pescara, Italy
[2] Univ Dundee, Ninewells Hosp, Div Med & Therapeut, Dundee, Scotland
[3] Univ Malta, Sch Med, Dept Med, Mater Dei Hosp, Tal Qroqq, Malta
[4] Joanneum Res, Graz, Austria
[5] Univ Childrens Hosp, Dept Paediat Endocrinol Diabet & Metab, Ljubljana, Slovenia
[6] Ctr Hosp Luxembourg, Luxembourg, Luxembourg
[7] Inst Scient Sante Pub WIV, Brussels, Belgium
[8] Med Univ Silesia, Upper Silesia Ctr Child Hlth, Katowice, Poland
[9] Havelhohe, Berlin, Germany
[10] Univ Gothenburg, Dept Primary Hlth Care, Gothenburg, Sweden
[11] Adelaide & Meath Hosp, Dublin, Ireland
[12] Vuk Vrhovac Univ, Diabet Clin, Zagreb, Croatia
[13] Univ Debrecen, Dept Prevent Med, H-4012 Debrecen, Hungary
[14] Minist Hlth, Nicosia, Cyprus
[15] Telemed Consulting, Bucharest, Romania
[16] Hillerod Univ Hosp, Hillerod, Denmark
[17] NOKLUS, Bergen, Norway
[18] Dutch Inst Healthcare Improvement CBO, Utrecht, Netherlands
[19] Univ Perugia, Dept Internal Med, I-06100 Perugia, Italy
关键词
D O I
10.1093/eurpub/cks043
中图分类号
R1 [预防医学、卫生学];
学科分类号
1004 ; 120402 ;
摘要
Background: The EUBIROD project aims to perform a cross-border flow of diabetes information across 19 European countries using the BIRO information system, which embeds privacy principles and data protection mechanisms in its architecture (privacy by design). A specific task of EUBIROD was to investigate the variability in the implementation of the EU Data Protection Directive (DPD) across participating centres. Methods: Compliance with privacy requirements was assessed by means of a specific questionnaire administered to all participating diabetes registers. Items included relevant issues e.g. patient consent, accountability of data custodian, communication (openness) and complaint procedures (challenging compliance), authority to disclose, accuracy, access and use of personal information, and anonymization. The identification of an ad hoc scoring system and statistical software allowed an overall quali-quantitative analysis and independent evaluation of questionnaire responses, automated through a dedicated IT platform ('privacy performance assessment'). Results: A total of 18 diabetes registers from different countries completed the survey. Over 50% of the registers recorded a maximum score for accountability, openness, anonymization and challenging compliance. Low average values were found for disclosure and disposition, access, consent, use of personal information and accuracy. A high heterogeneity was found for anonymization, consent, accuracy and access. Conclusions: The novel method of privacy performance assessment realized in EUBIROD may improve the respect of privacy in each data source, reduce overall variability in the implementation of privacy principles and favour a sound and legitimate cross-border exchange of high quality data across Europe.
引用
收藏
页码:247 / 253
页数:7
相关论文
共 17 条
  • [1] [Anonymous], 2010, R LANG ENV STAT COMP
  • [2] [Anonymous], 2009, Official Journal of the European Communities. L
  • [3] [Anonymous], 2008, PRIV DES
  • [4] [Anonymous], 2008, Official Journal of the European Union, C, V115/47, 9.5
  • [5] Revision of the European Data Protection Directive: opportunity or threat for public health monitoring?
    Carinci, Fabrizio
    Di Iorio, Concetta Tania
    Ricciardi, Walter
    Klazinga, Niek
    Verschuuren, Marieke
    [J]. EUROPEAN JOURNAL OF PUBLIC HEALTH, 2011, 21 (06) : 684 - +
  • [6] Privacy impact assessment in the design of transnational public health information systems: the BIRO project
    Di Iorio, C. T.
    Carinci, F.
    Azzopardi, J.
    Baglioni, V.
    Beck, P.
    Cunningham, S.
    Evripidou, A.
    Leese, G.
    Loevaas, K. F.
    Olympios, G.
    Federici, M. Orsini
    Pruna, S.
    Palladino, P.
    Skeie, S.
    Taverner, P.
    Traynor, V.
    Benedetti, M. Massi
    [J]. JOURNAL OF MEDICAL ETHICS, 2009, 35 (12) : 753 - 761
  • [7] Shekelle PG., 2009, COSTS BENEFITS HLTH
  • [8] Treasury Board of Canada Secretariat, 2002, PRIV IMP ASS GUID FR
  • [9] The European data protection legislation and its consequences for public health monitoring: a plea for action
    Verschuuren, Marieke
    Badeyan, Gerard
    Carnicero, Javier
    Gissler, Mika
    Asciak, Renzo Pace
    Sakkeus, Luule
    Stenbeck, Magnus
    Deville, Walter
    [J]. EUROPEAN JOURNAL OF PUBLIC HEALTH, 2008, 18 (06) : 550 - 551
  • [10] [No title captured]