Secure Data Linkage and Information Sharing with GRHANITE
Siaw‐Teng Liaw, Douglas IR Boyle · 2008
Objectives: To address and simplify the operational, ethics, consent and governance processes during the secure collection of individual identifiers and the accurate, reliable and confidential identification and re-identification of individuals to facilitate safety and quality of health care as well as accurate and rigorous evaluation research. Background: Linking accurate personal information to decision support systems can improve professional services e.g. health care or financial management. Linking professions will promote integrated services, avoiding costly duplication of infrastructure and services. However, where person-specific information is held, there are risks of identity theft or confidentiality breaches. The ethics and governance processes involved in routinely collecting data for service provision, research, evaluation, quality assurance, policy development and governance reporting need to be integrated yet simplified. Methods: Functional specifications for ethical, secure and accurate information sharing and management were established. A flexible decentralised design methodology was adopted to develop GRHANITE [TM] to manage informed consent, encrypt, extract, link and manipulate personal clinical data without collecting or exposing personal identifiers. Results: GRHANITE [TM] reduces risks of confidentiality breaches and identity theft by dispensing with the need to collect and store recognisable person identifiers and by forcing informed consent processes. GRHANITE [TM] has interfaced with disparate technologies in a generic manner to: (1) demonstrate the secure, de-identified linkage processes enable accurate and reliable identification; (2) de-identification mechanisms with security protocols can effectively guarantee privacy in the collection, linkage, aggregation and analysis system; and (3) Secure re-identification of individuals is still possible in source systems. Large-scale de-identified data repositories which hold no identifiable person-identifiers BUT are able to perform automated data linkage and acquisition can be developed and maintained in a viable manner. Implications: The GRHANITE [TM] research and development program will provide the knowledge to underpin the next generation of encrypted data repositories and their implementation in service organisations, delivering innovations in personal identification, information protection and integrity of national security systems.