Related Experiment Video
Updated: Jun 6, 2026

Inverse Probability of Treatment Weighting (Propensity Score) using the Military Health System Data Repository and National Death Index
Published on: January 8, 2020
A methodology for the pseudonymization of medical data
Thomas Neubauer1, Johannes Heurix
1Institute of Software Technology and Interactive Systems, Vienna University of Technology, Favoritenstrasse 9-11, 1040 Vienna, Austria. neubauer@ifs.tuwien.ac.at
This study introduces a novel pseudonymization method for electronic health records (EHRs), empowering patients to control data access and prevent misuse. This ensures privacy while enabling secure data sharing for healthcare and research.
Area of Science:
- Health Informatics
- Data Privacy
- Cybersecurity
Background:
- Electronic health records (EHRs) offer improved healthcare communication and efficiency but pose significant privacy risks due to sensitive patient data.
- Unauthorized access and misuse of health data by third parties, such as insurers and employers, create societal and political pressure for robust data protection.
- Existing privacy mechanisms like encryption, anonymization, and pseudonymization have limitations in fully protecting patient data while allowing necessary access.
Purpose of the Study:
- To develop and evaluate a methodology for protecting health records from unauthorized access.
- To empower patients as data owners, enabling them to control who accesses their sensitive health information.
- To prevent data disclosure that could negatively impact patients' lives, such as denial of insurance or employment.
Main Methods:
- A combination of conceptual-analytical, artifact-building, and artifact-evaluating research approaches was employed.
- Existing privacy-preserving techniques were explored, compared, and analyzed to identify shortcomings.
- A novel pseudonymization methodology was defined, evaluated through threat analysis, and validated via a prototype implementation.
Main Results:
- A new methodology for pseudonymizing medical data was developed, separating health information from patient identifiers.
- This approach facilitates privacy-preserving secondary use of health records for research without requiring additional anonymization.
- Patients retain control over re-identifying their data, rendering it useless for unauthorized parties like insurers or employers while enabling trusted access for primary care.
Conclusions:
- The proposed framework offers a unique solution for healthcare providers, ensuring data privacy compliance (e.g., HIPAA) and enabling simultaneous primary and secondary data use.
- Security analysis confirmed the methodology's robustness against common intruder scenarios.
- The system empowers patients by giving them control over their health data, enhancing trust and facilitating secure data exchange.
More Related Videos
Related Concept Videos
Ethical Standards II
Nurses are entrusted with upholding various ethical principles and standards. Nurses forge solid therapeutic relationships using trust, empathy, autonomy, confidentiality, and professional competence.
Confidentiality is crucial, embodying respect for individual privacy and...
Methods of Documentation II: POMR
Ethical Standards I
The Code of Ethics provisions outline the nurse's duty to the patient, the healthcare team, the profession, and society. The Code's fundamental principles include advocacy,...
Blinding
Legal Guidelines for Documentation
Blind Procedures

