메뉴 건너뛰기




Volumn 83, Issue 12, 2014, Pages 941-957

A standardised graphic method for describing data privacy frameworks in primary care research using a flexible zone model

Author keywords

Anonymisation; Confidentiality; Data linkage; Medical research; Privacy; Pseudonymisation; Zones

Indexed keywords

CLINICAL RESEARCH; DATA FLOW ANALYSIS; DATA TRANSFER; GRAPHIC METHODS; HOSPITAL DATA PROCESSING; INFORMATION ANALYSIS; METADATA; MODELING LANGUAGES; ZONING;

EID: 84919340449     PISSN: 13865056     EISSN: 18728243     Source Type: Journal    
DOI: 10.1016/j.ijmedinf.2014.08.009     Document Type: Article
Times cited : (33)

References (69)
  • 1
    • 84919401917 scopus 로고    scopus 로고
    • NHS (UK) observational data and interventional research service
    • (accessed 17.07.13).
    • NHS (UK) observational data and interventional research service: (accessed 17.07.13). http://www.cprd.com/.
  • 3
    • 85071033167 scopus 로고    scopus 로고
    • Privacy - the next generations
    • Tene O. Privacy - the next generations. Int. Data Privacy Law 2011, 1(1):15-27.
    • (2011) Int. Data Privacy Law , vol.1 , Issue.1 , pp. 15-27
    • Tene, O.1
  • 4
    • 84871886591 scopus 로고    scopus 로고
    • Biomedical data privacy: problems, perspectives, and recent advances
    • Malin B.A., El Emam K., O'Keefe C.M. Biomedical data privacy: problems, perspectives, and recent advances. J. Am. Med. Inform. Assoc. 2013, 20:2-6.
    • (2013) J. Am. Med. Inform. Assoc. , vol.20 , pp. 2-6
    • Malin, B.A.1    El Emam, K.2    O'Keefe, C.M.3
  • 5
    • 84919401916 scopus 로고    scopus 로고
    • TRANSFoRm project: (accessed 22.08.14).
    • TRANSFoRm project: (accessed 22.08.14). http://www.transformproject.eu/.
  • 6
    • 84855756190 scopus 로고    scopus 로고
    • Envisioning a learning health care system: the electronic primary care research network: a case study
    • Delaney B.C., Peterson K.A., Speedie S., Taweel A., Arvanitis T.N., Hobbs F.D.R. Envisioning a learning health care system: the electronic primary care research network: a case study. Ann. Fam. Med. 2012, 10(1):54-59.
    • (2012) Ann. Fam. Med. , vol.10 , Issue.1 , pp. 54-59
    • Delaney, B.C.1    Peterson, K.A.2    Speedie, S.3    Taweel, A.4    Arvanitis, T.N.5    Hobbs, F.D.R.6
  • 7
    • 84919385179 scopus 로고    scopus 로고
    • EU Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data
    • No. L281/31-281/39.
    • EU Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data. Off. J. Eur. Communities, 1999; No. L281/31-281/39.
    • (1999) Off. J. Eur. Communities
  • 9
    • 84919381064 scopus 로고    scopus 로고
    • Office of the Secretary: 45 CFR Parts 160 and 164. Standards for Privacy of Individually Identifiable Health Information
    • Department of Health and Human Services, Office of the Secretary: 45 CFR Parts 160 and 164. Standards for Privacy of Individually Identifiable Health Information; Final Rule. Federal Register vol. 67, No. 157 (2002).
    • (2002) Final Rule. Federal Register , vol.67 , Issue.157
  • 10
    • 84919401914 scopus 로고    scopus 로고
    • OECD Paris, France (2013). Online available (accessed 22.08.14).
    • The OECD Privacy Framework, OECD Paris, France (2013). Online available (accessed 22.08.14). http://www.oecd.org/sti/ieconomy/oecd_privacy_framework.pdf.
  • 11
    • 84919401819 scopus 로고    scopus 로고
    • APEC Secretariat, Singapore.
    • APEC Privacy Framework, APEC Secretariat, Singapore (2005), ISBN 981-05-4471-5.
    • (2005)
  • 12
    • 84919401818 scopus 로고    scopus 로고
    • The Madrid Resolution
    • Spanish Data Protection Agency
    • International Standards on the Protection of Personal Data and Privacy, The Madrid Resolution, Spanish Data Protection Agency (2009).
    • (2009)
  • 13
    • 84919401817 scopus 로고    scopus 로고
    • US Federal Register, July 24, Online available: (accessed 23.08.14).
    • U.S.-EU Safe Harbor Framework Documents, US Federal Register, July 24, 2000. Online available: (accessed 23.08.14). http://export.gov/safeharbor/eu/eg_main_018493.asp.
    • (2000)
  • 14
    • 56749173754 scopus 로고    scopus 로고
    • Working group on Confidentiality and Data Protection of the Network of competent Authorities of the Health Information and Knowledge strand of the EU Public Health Programme 2003-08
    • Verschuuren M., Badeyan G., Carnicero J., Gissler M., Asciak R.P., Sakkeus L., Sternbeck M., Devillé W. Working group on Confidentiality and Data Protection of the Network of competent Authorities of the Health Information and Knowledge strand of the EU Public Health Programme 2003-08. Eur. J. Public Health 2008, 18:550-551.
    • (2008) Eur. J. Public Health , vol.18 , pp. 550-551
    • Verschuuren, M.1    Badeyan, G.2    Carnicero, J.3    Gissler, M.4    Asciak, R.P.5    Sakkeus, L.6    Sternbeck, M.7    Devillé, W.8
  • 15
    • 78751700368 scopus 로고    scopus 로고
    • A new pathway for the regulation and Non-care of health research
    • January, available at: (accessed 23.08.14).
    • Academy of Medical Sciences (AMS). A new pathway for the regulation and Non-care of health research. January 2011, available at: (accessed 23.08.14). http://www.acmedsci.ac.uk/p47prid88.html.
    • (2011)
  • 16
    • 44949258868 scopus 로고    scopus 로고
    • Obstacles to European research projects with data and tissue: solutions and further challenges
    • van Veen E.B. Obstacles to European research projects with data and tissue: solutions and further challenges. Eur. J. Cancer 2008, 44:1438-1450.
    • (2008) Eur. J. Cancer , vol.44 , pp. 1438-1450
    • van Veen, E.B.1
  • 17
    • 49949104335 scopus 로고    scopus 로고
    • Title 45 of the Code of Federal Regulations Parts 160 and 164
    • Department of Health and Human Services. HIPAA Privacy Rule. Washington, D.C, Feb 2009, available at: (accessed 23.08.13).
    • Office for Civil Rights, Department of Health and Human Services. HIPAA Privacy Rule. Title 45 of the Code of Federal Regulations Parts 160 and 164. Washington, D.C, Feb 2009, available at: (accessed 23.08.13). http://www.hhs.gov/ocr/privacy/hipaa/administrative/privacyrule/adminsimpregtext.pdf.
  • 18
    • 84919391054 scopus 로고    scopus 로고
    • Paving the regulatory road to the "learning health care system"
    • (February 8, 2012), available at: (accessed 23.08.13).
    • McGraw D. Paving the regulatory road to the "learning health care system". Sanford Law Rev. Online 2012, 64:75. (February 8, 2012), available at: www.stanfordlawreview.org/online/privacy-paradox/learning-health-care-system (accessed 23.08.13).
    • (2012) Sanford Law Rev. Online , vol.64 , pp. 75
    • McGraw, D.1
  • 19
  • 20
    • 84919351253 scopus 로고    scopus 로고
    • US Department of Health and Human Services: Nationwide Privacy and Security Framework for Electronic Exchange of Individually Identifiable Health Information
    • December 15, available at: (accessed 23.08.14).
    • Office of the National Coordinator for Health information Technology, US Department of Health and Human Services: Nationwide Privacy and Security Framework for Electronic Exchange of Individually Identifiable Health Information, December 15, 2008, available at: (accessed 23.08.14). http://www.healthit.gov/policy-researchers-implementers/standards-interoperability-si-framework.
    • (2008)
  • 23
    • 54449091768 scopus 로고    scopus 로고
    • Advancing the framework: Use of health data - a report of a working conference of the American Medical Informatics Association
    • Bloomrosen M., Detmer D. Advancing the framework: Use of health data - a report of a working conference of the American Medical Informatics Association. JAMIA 2008, 15:715-722.
    • (2008) JAMIA , vol.15 , pp. 715-722
    • Bloomrosen, M.1    Detmer, D.2
  • 25
    • 84919401815 scopus 로고    scopus 로고
    • The ACGT ethical and legal requirements
    • (Ed.), ACGT deliverable 10.2. 13.03.2007, available at: (accessed 22.08.14).
    • N. Forgó (Ed.), The ACGT ethical and legal requirements. ACGT deliverable 10.2. 13.03.2007, available at: (accessed 22.08.14). http://acgt.ercim.eu/uploads/media/ACGT_D10.2_IRI_Final_01.pdf.
    • Forgó, N.1
  • 26
    • 84884284603 scopus 로고    scopus 로고
    • October, Available at: (accessed 23.08.14).
    • E.-B. van Veen, Patient data for health research. October 2011. Available at: (accessed 23.08.14). http://www.medlaw.nl/wp-content/uploads/patient-data-for-health-research.pdf.
    • (2011) Patient data for health research
    • van Veen, E.-B.1
  • 28
    • 84919401814 scopus 로고    scopus 로고
    • Has been renamed as: Clinical Practice Research Datalink (CPRD), available at: (accessed 23.08.14).
    • General Practice Research Database (GPRD), Has been renamed as: Clinical Practice Research Datalink (CPRD), available at: (accessed 23.08.14). http://www.cprd.com/intro.asp.
  • 29
    • 84963572076 scopus 로고    scopus 로고
    • What is a model? Language engineering for model-driven software development 2005; 04101
    • Kuehne T. What is a model? Language engineering for model-driven software development 2005; 04101. Dagstuhl Seminar Proceedings 2005, March.
    • (2005) Dagstuhl Seminar Proceedings
    • Kuehne, T.1
  • 30
    • 84919401812 scopus 로고    scopus 로고
    • Unified Modelling Language (UML), Object Management Group, available at: (accessed 23.08.14).
    • Unified Modelling Language (UML), Object Management Group, available at: (accessed 23.08.14). http://www.uml.org/.
  • 31
    • 0037293378 scopus 로고    scopus 로고
    • Patient-doctor relationships
    • Friedenberg R.M. Patient-doctor relationships. Radiology 2003, February, 226:306-308.
    • (2003) Radiology , vol.226 , pp. 306-308
    • Friedenberg, R.M.1
  • 32
    • 0038778076 scopus 로고    scopus 로고
    • IEEE Recommended Practice for Architectural Description of Software-Intensive Systems (2000)
    • Replaced by 42010-2007.
    • Institute of Electrical and Electronics Engineers: IEEE standard 1471. IEEE Recommended Practice for Architectural Description of Software-Intensive Systems (2000). Replaced by 42010-2007.
  • 34
    • 84919401811 scopus 로고    scopus 로고
    • available at: (accessed 23.08.14).
    • OASIS Privacy Management Reference Model, available at: (accessed 23.08.14). https://www.oasis-open.org/.
  • 35
    • 77952811382 scopus 로고    scopus 로고
    • Nationwide Privacy and Security Framework for Electronic Exchange of Individually Identifiable Health Information (HHS, US)
    • 15 December 2008, available at: (accessed 23.08.14).
    • Nationwide Privacy and Security Framework for Electronic Exchange of Individually Identifiable Health Information (HHS, US), 15 December 2008, available at: (accessed 23.08.14). http://www.healthit.gov/sites/default/files/nationwide-ps-framework-5.pdf.
  • 36
    • 84919401810 scopus 로고    scopus 로고
    • Health privacy framework
    • National Health and Medical Research Council Australia, available at: (accessed 23.08.14).
    • Health privacy framework, National Health and Medical Research Council Australia, available at: (accessed 23.08.14). http://www.nhmrc.gov.au/health-ethics/human-research-ethics-committees-hrecs/health-research-privacy-framework.
  • 37
    • 84919401809 scopus 로고    scopus 로고
    • Clinical E-Science Framework (CLEF)
    • University of Sheffield, UK, available at: (accessed 23.08.14).
    • Clinical E-Science Framework (CLEF), University of Sheffield, UK, available at: (accessed 23.08.14). http://nlp.shef.ac.uk/clef/.
  • 38
    • 84919401808 scopus 로고    scopus 로고
    • (Legal and Ethical issues), available at: (accessed 23.08.13).
    • ACGT (Legal and Ethical issues), available at: (accessed 23.08.13). http://acgt.ercim.eu/documents/legal-and-ethical-issues.html.
  • 39
    • 84919401807 scopus 로고    scopus 로고
    • available at: (accessed 23.08.13).
    • GenoMatch, available at: (accessed 23.08.13). http://www.tembit.de/.
  • 42
    • 84884281436 scopus 로고    scopus 로고
    • Europe and tissue research: a regulatory patchwork
    • van Veen E.B. Europe and tissue research: a regulatory patchwork. Diagn. Histopathol. 2013, 19(9):331-336.
    • (2013) Diagn. Histopathol. , vol.19 , Issue.9 , pp. 331-336
    • van Veen, E.B.1
  • 43
    • 84873238927 scopus 로고    scopus 로고
    • Nederlands instituut voor onderzoek van de gezondheidszorg
    • available at: (accessed 23.08.13).
    • Nederlands instituut voor onderzoek van de gezondheidszorg, available at: (accessed 23.08.13). http://www.nivel.nl/taxonomy/term/all%3Fgegevensverzameling%5B%5D=45.
  • 44
    • 84919401805 scopus 로고    scopus 로고
    • Code of Conduct health research, Commissie Regelgeving en Onderzoek, available at: (accessed 23.08.14).
    • Code of Conduct health research, Commissie Regelgeving en Onderzoek, available at: (accessed 23.08.14). http://www.federa.org/sites/default/files/bijlagen/coreon/code_of_conduct_for_medical_research_1.pdf.
  • 45
    • 84919401804 scopus 로고    scopus 로고
    • Central Bureau of Statistics Act
    • Staatsblad, available at: (accessed 23.08.14).
    • Central Bureau of Statistics Act, Staatsblad 2004, 695, available at: (accessed 23.08.14). http://www.cbs.nl/NR/rdonlyres/F10515CB-91C6-426C-9BD9-177F743F72C6/0/cbswet15122004.pdf.
    • (2004) , vol.695
  • 46
    • 84919401803 scopus 로고    scopus 로고
    • Legal Dictionary (Lawyers.com)
    • available at: (accessed 23.08.14).
    • Legal Dictionary (Lawyers.com), available at: (accessed 23.08.14). http://research.lawyers.com/glossary/zone-of-privacy.html.
  • 47
    • 84919401802 scopus 로고    scopus 로고
    • Trusted privacy domains - challenges for trusted computing in privacy-protecting information sharing. Information Security Practice and Experience
    • Loehr H., Sadeghi A.R., Vishik C., et al. Trusted privacy domains - challenges for trusted computing in privacy-protecting information sharing. Information Security Practice and Experience. 5th International Conference, ISPEC 2009: Proceedings, vol. 5451 2009.
    • (2009) 5th International Conference, ISPEC 2009: Proceedings, vol. 5451
    • Loehr, H.1    Sadeghi, A.R.2    Vishik, C.3
  • 48
    • 72049092946 scopus 로고    scopus 로고
    • Recent progress in database privacy
    • Domingo-Ferrer J., Saygin Y. Recent progress in database privacy. Data Knowl. Eng. 2009, 68(11):1157-1159.
    • (2009) Data Knowl. Eng. , vol.68 , Issue.11 , pp. 1157-1159
    • Domingo-Ferrer, J.1    Saygin, Y.2
  • 49
    • 84871886591 scopus 로고    scopus 로고
    • Biomedical data privacy: problems, perspectives, and recent advances (Editorial)
    • Malin B.A., Emam K.E., O'Keefe C.M. Biomedical data privacy: problems, perspectives, and recent advances (Editorial). J. Am. Med. Inform. Assoc. 2013, 20:2-6.
    • (2013) J. Am. Med. Inform. Assoc. , vol.20 , pp. 2-6
    • Malin, B.A.1    Emam, K.E.2    O'Keefe, C.M.3
  • 51
    • 84919401801 scopus 로고    scopus 로고
    • Harmonized Security and Privacy Framework - Exchange Reference Architecture Supplement
    • Version 1.0, August 1
    • CMS Centres for Medicare Medicaid Services: Harmonized Security and Privacy Framework - Exchange Reference Architecture Supplement. Version 1.0, August 1, 2012.
    • (2012)
  • 52
    • 85048308904 scopus 로고    scopus 로고
    • CMS Centres for Medicare Medicaid Services
    • May 8, Medicaid Info Technical Archive.
    • MITA Application Architecture, CMS Centres for Medicare Medicaid Services. May 8, 2006, Medicaid Info Technical Archive.
    • (2006)
  • 53
    • 84919401800 scopus 로고    scopus 로고
    • Purdue University, Computer & Information Technology, available at: (accessed 23.08.14).
    • IPS: Security services for healthcare applications, Purdue University, Computer & Information Technology, 2007, available at: (accessed 23.08.14). http://www.cs.purdue.edu/homes/bertino/IIS-eHealth/ehealth.shtml.
    • (2007)
  • 55
    • 84919343117 scopus 로고    scopus 로고
    • Data Sharing and Security Framework
    • available at: (accessed 23.08.14).
    • Cancer Biomedical Informatics Grid (caBIG): Data Sharing and Security Framework, available at: (accessed 23.08.14). https://wiki.nci.nih.gov/display/DSIC/Data+Sharing+and+Security+Framework.
  • 56
    • 84904118648 scopus 로고    scopus 로고
    • A human rights approach to an international code of conduct for genomic and clinical data sharing
    • Knoppers B.M., Harris J.R., Budin-Ljøsne I., Dove E.S. A human rights approach to an international code of conduct for genomic and clinical data sharing. Hum. Genet. 2014, 133:895-903.
    • (2014) Hum. Genet. , vol.133 , pp. 895-903
    • Knoppers, B.M.1    Harris, J.R.2    Budin-Ljøsne, I.3    Dove, E.S.4
  • 57
    • 84871882786 scopus 로고    scopus 로고
    • Methods and dimensions of electronic health record data quality assessment: enabling reuse for clinical research
    • Gray Weiskopf N., Weng C. Methods and dimensions of electronic health record data quality assessment: enabling reuse for clinical research. J. Am. Med. Inform. Assoc. 2013, 20:144-151.
    • (2013) J. Am. Med. Inform. Assoc. , vol.20 , pp. 144-151
    • Gray Weiskopf, N.1    Weng, C.2
  • 58
    • 84919401799 scopus 로고    scopus 로고
    • Incorporating security requirements from legal regulations into UMLsec model
    • Available at: (accessed 23.08.14).
    • Shareeful Islam, Jan Jürjens. Incorporating security requirements from legal regulations into UMLsec model. Available at: (accessed 23.08.14). http://www.secse.cs.tu-dortmund.de/jj/publications/papers/modsec08IJ.pdf.
    • Islam, S.1    Jürjens, J.2
  • 59
    • 77950516884 scopus 로고    scopus 로고
    • Eliciting security requirements and tracing them to design: an integration of Common Criteria, heuristics, and UMLsec
    • Houmb S.H., Islam S., Knauss E., Jurjens J., Schneider K. Eliciting security requirements and tracing them to design: an integration of Common Criteria, heuristics, and UMLsec. Requirements Eng. 2010, 15:63-93.
    • (2010) Requirements Eng. , vol.15 , pp. 63-93
    • Houmb, S.H.1    Islam, S.2    Knauss, E.3    Jurjens, J.4    Schneider, K.5
  • 60
    • 84919395950 scopus 로고    scopus 로고
    • Business Process Modeling Notation Specification. OMG Final Adopted Specification
    • February. Online available: (accessed: 23.08.14).
    • Business Process Modeling Notation Specification. OMG Final Adopted Specification. Object Management Group (February 2006). Online available: (accessed: 23.08.14). http://www.omg.org/bpmn/Documents/OMG_Final_Adopted_BPMN_1-0_Spec_06-02-01.pdf.
    • (2006) Object Management Group
  • 61
    • 34247151648 scopus 로고    scopus 로고
    • A BPMN extension for the modeling of security requirements in business processes
    • E90-D(4)
    • Rodrigez A., Fernandez-Medina E., Piattini M. A BPMN extension for the modeling of security requirements in business processes. IEICE Trans. Inf. Syst. 2007, E90-D(4).
    • (2007) IEICE Trans. Inf. Syst.
    • Rodrigez, A.1    Fernandez-Medina, E.2    Piattini, M.3
  • 63
    • 84872459720 scopus 로고    scopus 로고
    • Identifying personal genomes by surname inference
    • Gymrek M., McGuire A.L., Golan D., Halperin E., Erlich Y. Identifying personal genomes by surname inference. Science 2013, 339(6117):321-324.
    • (2013) Science , vol.339 , Issue.6117 , pp. 321-324
    • Gymrek, M.1    McGuire, A.L.2    Golan, D.3    Halperin, E.4    Erlich, Y.5
  • 64
    • 77957594024 scopus 로고    scopus 로고
    • Broken promises of privacy: Responding to the surprising failure of anonymization
    • Ohm P. Broken promises of privacy: Responding to the surprising failure of anonymization. UCLA Law Rev. 2010, 57:1701-1711.
    • (2010) UCLA Law Rev. , vol.57 , pp. 1701-1711
    • Ohm, P.1
  • 66
    • 77957204647 scopus 로고    scopus 로고
    • Privacy compliance and enforcement on European healthgrids: an approach through ontology
    • Rahmouni H.B., Solomonides T., Mont M.C., Shiu S. Privacy compliance and enforcement on European healthgrids: an approach through ontology. Philos. Trans. A Math. Phys. Eng. Sci. 2010, 368(1926):4057-4072.
    • (2010) Philos. Trans. A Math. Phys. Eng. Sci. , vol.368 , Issue.1926 , pp. 4057-4072
    • Rahmouni, H.B.1    Solomonides, T.2    Mont, M.C.3    Shiu, S.4
  • 69
    • 66149190569 scopus 로고    scopus 로고
    • A state-based approach to privacy and security for interoperable health information exchange
    • Dimitropoulos L., Rizk S. A state-based approach to privacy and security for interoperable health information exchange. Health Aff. (Millwood) 2009, 28(2):428-434.
    • (2009) Health Aff. (Millwood) , vol.28 , Issue.2 , pp. 428-434
    • Dimitropoulos, L.1    Rizk, S.2


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.