AudaciousInquiry / fhir-saner

Situation Awareness for Novel Epidemic Response (COVID-19 driven project to track resource availability)
17 stars 0 forks source link

What threats to businesses might this data present #45

Closed JohnMoehrke closed 4 years ago

JohnMoehrke commented 4 years ago

as requested by Keith, the Security Considerations should include a description of some of the threats to a business with respect to public release of the data in the IG. How is the information Business Sensitive? How might it be used maliciously? These threats might drive for more strict release of the data only for Public Health reporting, vs a modification of the data such that public release has less threat.

JohnMoehrke commented 4 years ago

example news: Coronavirus fallout: Massachusetts won’t release town-specific COVID-19 data, citing ‘stigma’ and privacy; some towns doing it on their own https://www.masslive.com/coronavirus/2020/04/coronavirus-fallout-massachusetts-wont-release-town-specific-covid-19-data-citing-stigma-and-privacy-some-towns-doing-it-on-their-own.html

JohnMoehrke commented 4 years ago

Risks identified from that news and general musings

JohnMoehrke commented 4 years ago
JohnMoehrke commented 4 years ago
JohnMoehrke commented 4 years ago
JohnMoehrke commented 4 years ago
JohnMoehrke commented 4 years ago

IG Design Mitigation

JohnMoehrke commented 4 years ago

Operational Mitigation

JohnMoehrke commented 4 years ago

See IHE Handbook on De-Identification that includes element analysis and mitigation methods https://wiki.ihe.net/index.php/Healthcare_De-Identification_Handbook

JohnMoehrke commented 4 years ago

Provided text in commit to fhir-saner https://github.com/HL7/fhir-saner/commit/e5b2b39a8d0c0a6b2492d855ecf682dae51a9cb3#diff-4e396ddf4872ae6d43c86dbd3400ff19