SlideShare a Scribd company logo
Navigating data-driven medical researchers
through the IT privacy/security landscape
Jeff Christiansen, Jared Winton and Kathy Dallest
med.data.edu.au
NCRIS-funded project
A national facility for petabyte
scale research data storage
and high-speed networked
computational services to
Australian Health and Medical
Research organisations
med.data.edu.au
4 RDS nodes:
Intersect, VicNode, eRSA, QCIF
Health/medical research data:
4 states
7 Universities
12 Medical Research Institutes
2.2PB (91 data collections)
Human genomic data ~85%
Human 3D imaging ~10%
Other health datasets <5%
med.data.edu.au
FIND DATA
USE DATA
STORE DATA
med.data.edu.au
FIND DATA
med.data.edu.au
FIND DATA
Dataset descriptions listed
Tools and processes to publish
dataset descriptions
Leverages institutional
and national infrastructure
(ANDS)
med.data.edu.au
USE DATA
med.data.edu.au
USE DATA
Generally, users requiring large
data storage and associated
HPC or cloud (Nectar)
compute, or
Collaborative research
across Institutions
BYO software
med.data.edu.au
STORE DATA
med.data.edu.au
STORE DATA
Data is managed using various
platforms
(Mediaflux, Aspera, MyTardis)
Human-derived data is
subject to a higher level
of protection than other data
Health and Medical information
Health and Medical information
Collected for healthcare provision
Held by health service providers
Derived from or relating to human individuals
It is personal* info: i.e. about an identified or reasonably identifiable individual
It is sensitive* info: i.e. about an individual’s Health; or Genetic or Biometric info.
* As defined by The Privacy Act 1988 (Cth)
Health and Medical information
Collected for healthcare provision
Held by health service providers
Derived from or relating to human individuals
It is personal* info: i.e. about an identified or reasonably identifiable individual
It is sensitive* info: i.e. about an individual’s Health; or Genetic or Biometric info.
Must be protected (Privacy Act (Cth) and various state health privacy legislation)
Health and Medical information in research
Health and Medical information in research
Collected for healthcare provision OR specifically collected for use in research
studies
Held by researchers
Derived from or relating to human individuals (i.e. is personal and sensitive)
Health and Medical information in research
Collected for healthcare provision OR specifically collected for use in research
studies
Held by researchers
Derived from or relating to human individuals (i.e. is personal and sensitive)
Must be protected from misuse, interference and loss,
and from unauthorised access, modification or disclosure.
Health and Medical information in research
POINTS FOR CONSIDERATION
Privacy Protection Legislation
Privacy Protection Legislation
Protecting an individual’s privacy (and health privacy) is enshrined in
Commonwealth and State Legislation:
Commonwealth
• Privacy Act (1988)
NSW
• Privacy and Personal information Protection Act 1998
• Health Records and Information Privacy Act 2002 (HRIPA)
VIC
• Information Privacy Act 2000 (Vic)
• Privacy and Data Protection Act 2014
• Health Records Act 2001 (Vic)
• Charter of Human Rights and Responsibilities Act 2006 (Vic)
QLD
• Information Privacy Act 2009 (Qld)
• Health Services Act 1991 (Qld)
• Information Standards 42 (general) & 42A (health)
• Public Health Act 2005 Chapter 6, Part 4, Division 2, s281
SA
• Department of the Premier and Cabinet IPPs
WA
• Information Privacy Bill 2007
TAS
• No health specific privacy legislation.
• Personal Information and Protection Act 2004
ACT
• Information Privacy Act 2014 (ACT) (ACT Public Sector Agencies)
• Health Records (Privacy and Access) Act 1997
NT
• No health specific privacy legislation.
Ethics
Ethics
When health data is collected for research purposes, Human Research Ethics
Committee (HREC) approval is required first.
HREC approval is also required for its use (usually only approved for use in a
specific research study).
Must not be shared in an identifiable form with those outside the HREC-
approved research project(s).
Consent
Consent
The guiding principle for researchers is that a person’s decision to participate in
research is to be voluntary, and based on sufficient information and adequate
understanding of both the proposed research and the implications of participation
in it.
“Informed consent”
As defined in the National Statement on Ethical Conduct in Human Research (NHMRC, ARC, Universities Australia)
Consent
When consent has not been given to use personal health data in research, the
use of health data use may still be permitted for research purposes:
Cth Privacy Act Section 95 – allows Commonwealth managed health data to be used for research in an
identifiable form if the proposed research has been approved by a HREC.
Cth Privacy Act Section 95A – allows private sector data to be used for research where gaining consent is
not practical, and the research has been approved by a HREC.
Note – neither are applicable for data from State Health Departments - however some states e.g. NSW
have comparable legislation (e.g. NSW – HRIPA)
Identifiability of data
Identifiability of data
Individually identifiable data – where the identity of a specific individual can
reasonably be ascertained (e.g. a name, image, date of birth or address).
Re-identifiable data - where identifiers have been removed and replaced by a
code, but it remains possible to re-identify a specific individual by, for example,
using the code or linking different data sets.
Non-identifiable data - has never been labelled with individual identifiers or from
which identifiers have been permanently removed, and by means of which no
specific individual can be identified.
As defined in the National Statement on Ethical Conduct in Human Research (NHMRC, ARC, Universities Australia)
Identifiability of data
Individually identifiable data – where the identity of a specific individual can
reasonably be ascertained (e.g. a name, image, date of birth or address).
Re-identifiable data - where identifiers have been removed and replaced by a
code, but it remains possible to re-identify a specific individual by, for example,
using the code or linking different data sets.
Non-identifiable data - has never been labelled with individual identifiers or from
which identifiers have been permanently removed, and by means of which no
specific individual can be identified.
As defined in the National Statement on Ethical Conduct in Human Research (NHMRC, ARC, Universities Australia)
Identifiability of data
Individually identifiable data – where the identity of a specific individual can
reasonably be ascertained (e.g. a name, image, date of birth or address).
Re-identifiable data - where identifiers have been removed and replaced by a
code, but it remains possible to re-identify a specific individual by, for example,
using the code or linking different data sets.
Non-identifiable data - has never been labelled with individual identifiers or from
which identifiers have been permanently removed, and by means of which no
specific individual can be identified.
As defined in the National Statement on Ethical Conduct in Human Research (NHMRC, ARC, Universities Australia)
Identifiability of data
Making data non-identifiable, decreases risks associated with inadvertent release
Removal of overt identifying information or identifiers - e.g. name, image,
date of birth, address, medicare/patient numbers.
Statistical methods - applied by an expert and the methods must be
documented
As defined in the Guidelines for the disclosure of Secondary Use Health Information for Statistical Reporting, Research and
Analysis 2015 (National Health Information Standards and Statistics Committee)
Legislation affecting trans-border dataflow
Legislation affecting trans-border dataflow
Commonwealth – Privacy Act (1988) Australian Privacy Principle (APP)-8 cross-jurisdictional
transfer of personal information out of Australia.
NSW – NSW Health Records and Information Privacy Act 2002 Health Privacy Principle (HPP)-14
Trans-border data flows and data flow to Commonwealth agencies.
VIC – Health Records Act 2001 (Vic) Health Privacy Principle (HPP)-9 Transborder Data Flows
WA – Information Privacy Bill 2007 (WA) Information Privacy Principle 8: Transborder data flows
TAS – Personal Information Protection Act 2004
NT – Information Act: Information Privacy Principle (IPP)-9 Transborder data flows
So… what controls are needed to protect HM data in
research?
So… what controls are needed to protect HM data in
research?
National eHealth Transition Authority
(now Australian Digital Health Agency)
Health Informatics Society
of Australia
Australian Standards
Australian Signals Directorate
There IS no definitive checklist - it’s about risk management
So… what controls are needed to protect HM data in
research?
Discussion paper
Legislative framework
(Commonwealth, State
and International)
Best Practice (Ethics,
Research etc)
IT Security requirements for
Health (Human-derived) data
Roles and Responsibilities
(Data Custodians, Users, Nodes)
41 pages and heavy going
Need something simpler
Discussion paper
Use Guide
On-line wizard
Navigates the user
through relevant info
Use Guide
On-line wizard
Navigates the user
through relevant info
Simple questions
Use Guide
Info when requested
Authoritative references
Use Guide
Option to be contacted for
Node Specific Information
End
Use Guide
Node Specific Security Info
How do each Node’s Storage, HPC
and Cloud compute stack up against…
• National Standards for Protected or
Sensitive Info (ASD ISM)?
• Common other standards (e.g. NIH Best Practices
for storage of Human Genomic Sequence)?
Required for an informed conversation about
risk with each Data Custodian
• Node set-up, Roles and Responsibilities of Data
Custodians, Data Users and Node Operators).
Available Now
Use Guide
Acknowledgements
THANK YOU
jeff@intersect.org.au

More Related Content

PPTX
The data sharing landscape and planning to publish
PPTX
Ethics and consent for data sharing
PPT
Licensing health and sensitive data
PPTX
ANDS health and medical data webinar 16 May. Storing and Publishing Health an...
PPTX
Data Sharing and Release Legislation
PPTX
International perspective for sharing publicly funded medical research data
PPTX
Publishing your data smyth
PPTX
Architecture and Standards
The data sharing landscape and planning to publish
Ethics and consent for data sharing
Licensing health and sensitive data
ANDS health and medical data webinar 16 May. Storing and Publishing Health an...
Data Sharing and Release Legislation
International perspective for sharing publicly funded medical research data
Publishing your data smyth
Architecture and Standards

What's hot (20)

PPTX
Med.data.edu.au project
PPTX
Introduction to vision and scope
PPTX
Clinical trials data sharing
PPTX
Up2013 hie cloud_kamran_ghane
PPTX
Investigator-initiated clinical trials: a community perspective
PDF
End-to-End Research Data Management for the Responsible Conduct of Research
PPTX
Data curation
PPTX
20160523 23 Research Data Things
PPTX
20160719 23 Research Data Things
PDF
MLA 2022 My Favorite Tool: Airtable
PDF
Research data and the ANDS agenda in Australia
PDF
Brisbane Health-y Data: Supplementary materials on consent forms
PPTX
Managing your data paget
PPTX
Data management profiles workshop
PDF
Brisbane Health-y Data: Licensing health and sensitive data
PPTX
Use of data in safe havens: ethics and reproducibility issues
PPTX
Data Management, Research Integrity and Ethics
PDF
Brisbane Health-y Data: Queensland Data Linkage Framework
PPTX
Hybrid Architecture with Ike & Data Libraries
PDF
How FAIR is your data? Copyright, licensing and reuse of data
Med.data.edu.au project
Introduction to vision and scope
Clinical trials data sharing
Up2013 hie cloud_kamran_ghane
Investigator-initiated clinical trials: a community perspective
End-to-End Research Data Management for the Responsible Conduct of Research
Data curation
20160523 23 Research Data Things
20160719 23 Research Data Things
MLA 2022 My Favorite Tool: Airtable
Research data and the ANDS agenda in Australia
Brisbane Health-y Data: Supplementary materials on consent forms
Managing your data paget
Data management profiles workshop
Brisbane Health-y Data: Licensing health and sensitive data
Use of data in safe havens: ethics and reproducibility issues
Data Management, Research Integrity and Ethics
Brisbane Health-y Data: Queensland Data Linkage Framework
Hybrid Architecture with Ike & Data Libraries
How FAIR is your data? Copyright, licensing and reuse of data
Ad

Viewers also liked (17)

PPTX
TG_tema VII
PPTX
Las conjunciones. practica
PPT
Acreditação Sael
DOCX
الجهات المهتمة بالتعليم - أسبوع العمل العالمى للتعليم
PDF
PPTX
Tayrona national park
PPTX
Dai tics-1
PDF
Weekly Report Inspiral - 01 A 08 Dez
PDF
08242015143710
PDF
Weekly report inspiral_19a26fev11
DOC
INTRODUCTION LETTER
PDF
Weekly Report 28 Mar 04 Abr 11
PPSX
Cosmos
PDF
أسعار مواد البناء
PDF
PDF
Resume (Dominic Chandran)
TG_tema VII
Las conjunciones. practica
Acreditação Sael
الجهات المهتمة بالتعليم - أسبوع العمل العالمى للتعليم
Tayrona national park
Dai tics-1
Weekly Report Inspiral - 01 A 08 Dez
08242015143710
Weekly report inspiral_19a26fev11
INTRODUCTION LETTER
Weekly Report 28 Mar 04 Abr 11
Cosmos
أسعار مواد البناء
Resume (Dominic Chandran)
Ad

Similar to Med.data.edu.au Online Interactive Use Guide (20)

PPTX
Ethical Conduct of Human Research
PPT
Data Quality: Missing Data (PPT slides)
PPTX
An Introduction to Health Informatics
PPTX
Medical device data protection and security
PPT
Preserving the Privacy of Genetic Information
PPTX
Key Recommendations for Health Information Privacy Reform
PDF
HIPAA
DOCX
PLEASE POST EACH DISCUSSION SEPARATELYEach healthcare organi
PDF
Nicolas Terry, "Big Data, Regulatory Disruption, and Arbitrage in Health Care"
PPT
eHealth Governance, Security and Privacy a UK Perspective
PPTX
A Stocktake of New Zealand’s Healthcare Datasets
PPTX
Accessing and using linked health data
PPT
The Challenging and Changing Face of NHS Information Governance - Paper Deliv...
PDF
Workshop 3 - "Presentation of the concept, definitions and terminology"
PDF
Regulations, privacy and security requirements - Legal interoperability for d...
PPTX
Confidentiality manager training mha 690
PPTX
ELECTRONIC HEALTH RECORD SYSTEMS:
PPT
Health Technology And Information Standards - Peter Lennon
PPTX
Universal Unique Patient Information Identifier UUPII
PPTX
iHT2 Health IT Summit in Austin 2012 – Deborah C. Peel, MD, Founder and Chai...
Ethical Conduct of Human Research
Data Quality: Missing Data (PPT slides)
An Introduction to Health Informatics
Medical device data protection and security
Preserving the Privacy of Genetic Information
Key Recommendations for Health Information Privacy Reform
HIPAA
PLEASE POST EACH DISCUSSION SEPARATELYEach healthcare organi
Nicolas Terry, "Big Data, Regulatory Disruption, and Arbitrage in Health Care"
eHealth Governance, Security and Privacy a UK Perspective
A Stocktake of New Zealand’s Healthcare Datasets
Accessing and using linked health data
The Challenging and Changing Face of NHS Information Governance - Paper Deliv...
Workshop 3 - "Presentation of the concept, definitions and terminology"
Regulations, privacy and security requirements - Legal interoperability for d...
Confidentiality manager training mha 690
ELECTRONIC HEALTH RECORD SYSTEMS:
Health Technology And Information Standards - Peter Lennon
Universal Unique Patient Information Identifier UUPII
iHT2 Health IT Summit in Austin 2012 – Deborah C. Peel, MD, Founder and Chai...

More from ARDC (20)

PPTX
Introduction to ADA
PPT
Australian Dementia Network (ADNet)
PPTX
NCRIS and the health domain
PPTX
Clinical trials and cohort studies
PPTX
FAIR for the future: embracing all things data
PDF
ARDC 2018 state engagements - Nov-Dec 2018 - Slides - Ian Duncan
PDF
Skilling-up-in-research-data-management-20181128
PDF
Research data management and sharing of medical data
PPTX
Findable, Accessible, Interoperable and Reusable (FAIR) data
PPTX
Applying FAIR principles to linked datasets: Opportunities and Challenges
PDF
How to make your data count webinar, 26 Nov 2018
PDF
Ready, Set, Go! Join the Top 10 FAIR Data Things Global Sprint
PDF
Peter neish DMPs BoF eResearch 2018
PPTX
Connected DMPs at UoA - we have a dream
PPTX
ReDBox and rdmps bof
PPTX
DMPs BoF eResearch 2018 - organiser's deck
PDF
DashR dashboard for research Andrew Janke
PDF
Resources for making your data fair - poster
PDF
How to get the most out of the rda - poster
PPTX
Coordinated identifier infrastructure enabling Geoscience researchers to meet...
Introduction to ADA
Australian Dementia Network (ADNet)
NCRIS and the health domain
Clinical trials and cohort studies
FAIR for the future: embracing all things data
ARDC 2018 state engagements - Nov-Dec 2018 - Slides - Ian Duncan
Skilling-up-in-research-data-management-20181128
Research data management and sharing of medical data
Findable, Accessible, Interoperable and Reusable (FAIR) data
Applying FAIR principles to linked datasets: Opportunities and Challenges
How to make your data count webinar, 26 Nov 2018
Ready, Set, Go! Join the Top 10 FAIR Data Things Global Sprint
Peter neish DMPs BoF eResearch 2018
Connected DMPs at UoA - we have a dream
ReDBox and rdmps bof
DMPs BoF eResearch 2018 - organiser's deck
DashR dashboard for research Andrew Janke
Resources for making your data fair - poster
How to get the most out of the rda - poster
Coordinated identifier infrastructure enabling Geoscience researchers to meet...

Recently uploaded (20)

PDF
Human Health And Disease hggyutgghg .pdf
PPT
Management of Acute Kidney Injury at LAUTECH
PDF
Intl J Gynecology Obste - 2021 - Melamed - FIGO International Federation o...
PPT
Breast Cancer management for medicsl student.ppt
PPTX
History and examination of abdomen, & pelvis .pptx
PPTX
Cardiovascular - antihypertensive medical backgrounds
PPTX
Important Obstetric Emergency that must be recognised
PPT
STD NOTES INTRODUCTION TO COMMUNITY HEALT STRATEGY.ppt
PDF
Handout_ NURS 220 Topic 10-Abnormal Pregnancy.pdf
PDF
NEET PG 2025 | 200 High-Yield Recall Topics Across All Subjects
PPTX
CEREBROVASCULAR DISORDER.POWERPOINT PRESENTATIONx
PPTX
anal canal anatomy with illustrations...
PDF
Oral Aspect of Metabolic Disease_20250717_192438_0000.pdf
PPTX
POLYCYSTIC OVARIAN SYNDROME.pptx by Dr( med) Charles Amoateng
PPT
OPIOID ANALGESICS AND THEIR IMPLICATIONS
PPTX
ca esophagus molecula biology detailaed molecular biology of tumors of esophagus
PPTX
Imaging of parasitic D. Case Discussions.pptx
PPTX
Acid Base Disorders educational power point.pptx
PPTX
DENTAL CARIES FOR DENTISTRY STUDENT.pptx
PPTX
ACID BASE management, base deficit correction
Human Health And Disease hggyutgghg .pdf
Management of Acute Kidney Injury at LAUTECH
Intl J Gynecology Obste - 2021 - Melamed - FIGO International Federation o...
Breast Cancer management for medicsl student.ppt
History and examination of abdomen, & pelvis .pptx
Cardiovascular - antihypertensive medical backgrounds
Important Obstetric Emergency that must be recognised
STD NOTES INTRODUCTION TO COMMUNITY HEALT STRATEGY.ppt
Handout_ NURS 220 Topic 10-Abnormal Pregnancy.pdf
NEET PG 2025 | 200 High-Yield Recall Topics Across All Subjects
CEREBROVASCULAR DISORDER.POWERPOINT PRESENTATIONx
anal canal anatomy with illustrations...
Oral Aspect of Metabolic Disease_20250717_192438_0000.pdf
POLYCYSTIC OVARIAN SYNDROME.pptx by Dr( med) Charles Amoateng
OPIOID ANALGESICS AND THEIR IMPLICATIONS
ca esophagus molecula biology detailaed molecular biology of tumors of esophagus
Imaging of parasitic D. Case Discussions.pptx
Acid Base Disorders educational power point.pptx
DENTAL CARIES FOR DENTISTRY STUDENT.pptx
ACID BASE management, base deficit correction

Med.data.edu.au Online Interactive Use Guide

  • 1. Navigating data-driven medical researchers through the IT privacy/security landscape Jeff Christiansen, Jared Winton and Kathy Dallest
  • 2. med.data.edu.au NCRIS-funded project A national facility for petabyte scale research data storage and high-speed networked computational services to Australian Health and Medical Research organisations
  • 3. med.data.edu.au 4 RDS nodes: Intersect, VicNode, eRSA, QCIF Health/medical research data: 4 states 7 Universities 12 Medical Research Institutes 2.2PB (91 data collections) Human genomic data ~85% Human 3D imaging ~10% Other health datasets <5%
  • 6. med.data.edu.au FIND DATA Dataset descriptions listed Tools and processes to publish dataset descriptions Leverages institutional and national infrastructure (ANDS)
  • 8. med.data.edu.au USE DATA Generally, users requiring large data storage and associated HPC or cloud (Nectar) compute, or Collaborative research across Institutions BYO software
  • 10. med.data.edu.au STORE DATA Data is managed using various platforms (Mediaflux, Aspera, MyTardis) Human-derived data is subject to a higher level of protection than other data
  • 11. Health and Medical information
  • 12. Health and Medical information Collected for healthcare provision Held by health service providers Derived from or relating to human individuals It is personal* info: i.e. about an identified or reasonably identifiable individual It is sensitive* info: i.e. about an individual’s Health; or Genetic or Biometric info. * As defined by The Privacy Act 1988 (Cth)
  • 13. Health and Medical information Collected for healthcare provision Held by health service providers Derived from or relating to human individuals It is personal* info: i.e. about an identified or reasonably identifiable individual It is sensitive* info: i.e. about an individual’s Health; or Genetic or Biometric info. Must be protected (Privacy Act (Cth) and various state health privacy legislation)
  • 14. Health and Medical information in research
  • 15. Health and Medical information in research Collected for healthcare provision OR specifically collected for use in research studies Held by researchers Derived from or relating to human individuals (i.e. is personal and sensitive)
  • 16. Health and Medical information in research Collected for healthcare provision OR specifically collected for use in research studies Held by researchers Derived from or relating to human individuals (i.e. is personal and sensitive) Must be protected from misuse, interference and loss, and from unauthorised access, modification or disclosure.
  • 17. Health and Medical information in research POINTS FOR CONSIDERATION
  • 19. Privacy Protection Legislation Protecting an individual’s privacy (and health privacy) is enshrined in Commonwealth and State Legislation: Commonwealth • Privacy Act (1988) NSW • Privacy and Personal information Protection Act 1998 • Health Records and Information Privacy Act 2002 (HRIPA) VIC • Information Privacy Act 2000 (Vic) • Privacy and Data Protection Act 2014 • Health Records Act 2001 (Vic) • Charter of Human Rights and Responsibilities Act 2006 (Vic) QLD • Information Privacy Act 2009 (Qld) • Health Services Act 1991 (Qld) • Information Standards 42 (general) & 42A (health) • Public Health Act 2005 Chapter 6, Part 4, Division 2, s281 SA • Department of the Premier and Cabinet IPPs WA • Information Privacy Bill 2007 TAS • No health specific privacy legislation. • Personal Information and Protection Act 2004 ACT • Information Privacy Act 2014 (ACT) (ACT Public Sector Agencies) • Health Records (Privacy and Access) Act 1997 NT • No health specific privacy legislation.
  • 21. Ethics When health data is collected for research purposes, Human Research Ethics Committee (HREC) approval is required first. HREC approval is also required for its use (usually only approved for use in a specific research study). Must not be shared in an identifiable form with those outside the HREC- approved research project(s).
  • 23. Consent The guiding principle for researchers is that a person’s decision to participate in research is to be voluntary, and based on sufficient information and adequate understanding of both the proposed research and the implications of participation in it. “Informed consent” As defined in the National Statement on Ethical Conduct in Human Research (NHMRC, ARC, Universities Australia)
  • 24. Consent When consent has not been given to use personal health data in research, the use of health data use may still be permitted for research purposes: Cth Privacy Act Section 95 – allows Commonwealth managed health data to be used for research in an identifiable form if the proposed research has been approved by a HREC. Cth Privacy Act Section 95A – allows private sector data to be used for research where gaining consent is not practical, and the research has been approved by a HREC. Note – neither are applicable for data from State Health Departments - however some states e.g. NSW have comparable legislation (e.g. NSW – HRIPA)
  • 26. Identifiability of data Individually identifiable data – where the identity of a specific individual can reasonably be ascertained (e.g. a name, image, date of birth or address). Re-identifiable data - where identifiers have been removed and replaced by a code, but it remains possible to re-identify a specific individual by, for example, using the code or linking different data sets. Non-identifiable data - has never been labelled with individual identifiers or from which identifiers have been permanently removed, and by means of which no specific individual can be identified. As defined in the National Statement on Ethical Conduct in Human Research (NHMRC, ARC, Universities Australia)
  • 27. Identifiability of data Individually identifiable data – where the identity of a specific individual can reasonably be ascertained (e.g. a name, image, date of birth or address). Re-identifiable data - where identifiers have been removed and replaced by a code, but it remains possible to re-identify a specific individual by, for example, using the code or linking different data sets. Non-identifiable data - has never been labelled with individual identifiers or from which identifiers have been permanently removed, and by means of which no specific individual can be identified. As defined in the National Statement on Ethical Conduct in Human Research (NHMRC, ARC, Universities Australia)
  • 28. Identifiability of data Individually identifiable data – where the identity of a specific individual can reasonably be ascertained (e.g. a name, image, date of birth or address). Re-identifiable data - where identifiers have been removed and replaced by a code, but it remains possible to re-identify a specific individual by, for example, using the code or linking different data sets. Non-identifiable data - has never been labelled with individual identifiers or from which identifiers have been permanently removed, and by means of which no specific individual can be identified. As defined in the National Statement on Ethical Conduct in Human Research (NHMRC, ARC, Universities Australia)
  • 29. Identifiability of data Making data non-identifiable, decreases risks associated with inadvertent release Removal of overt identifying information or identifiers - e.g. name, image, date of birth, address, medicare/patient numbers. Statistical methods - applied by an expert and the methods must be documented As defined in the Guidelines for the disclosure of Secondary Use Health Information for Statistical Reporting, Research and Analysis 2015 (National Health Information Standards and Statistics Committee)
  • 31. Legislation affecting trans-border dataflow Commonwealth – Privacy Act (1988) Australian Privacy Principle (APP)-8 cross-jurisdictional transfer of personal information out of Australia. NSW – NSW Health Records and Information Privacy Act 2002 Health Privacy Principle (HPP)-14 Trans-border data flows and data flow to Commonwealth agencies. VIC – Health Records Act 2001 (Vic) Health Privacy Principle (HPP)-9 Transborder Data Flows WA – Information Privacy Bill 2007 (WA) Information Privacy Principle 8: Transborder data flows TAS – Personal Information Protection Act 2004 NT – Information Act: Information Privacy Principle (IPP)-9 Transborder data flows
  • 32. So… what controls are needed to protect HM data in research?
  • 33. So… what controls are needed to protect HM data in research? National eHealth Transition Authority (now Australian Digital Health Agency) Health Informatics Society of Australia Australian Standards Australian Signals Directorate
  • 34. There IS no definitive checklist - it’s about risk management So… what controls are needed to protect HM data in research?
  • 35. Discussion paper Legislative framework (Commonwealth, State and International) Best Practice (Ethics, Research etc) IT Security requirements for Health (Human-derived) data Roles and Responsibilities (Data Custodians, Users, Nodes)
  • 36. 41 pages and heavy going Need something simpler Discussion paper
  • 37. Use Guide On-line wizard Navigates the user through relevant info
  • 38. Use Guide On-line wizard Navigates the user through relevant info
  • 40. Info when requested Authoritative references Use Guide
  • 41. Option to be contacted for Node Specific Information End Use Guide
  • 42. Node Specific Security Info How do each Node’s Storage, HPC and Cloud compute stack up against… • National Standards for Protected or Sensitive Info (ASD ISM)? • Common other standards (e.g. NIH Best Practices for storage of Human Genomic Sequence)? Required for an informed conversation about risk with each Data Custodian • Node set-up, Roles and Responsibilities of Data Custodians, Data Users and Node Operators).