CSTE Spatial Analysis Workgroup

👏 Spatial Data Security

Hey everyone,

As mentioned on the call; I wanted to provide some links below that have been helpful in our department in regards to Spatial Analysis and Information/Data Security. Before utilizing these steps, always be aware of your protocols for data and population. It is important to not apply these techniques if you have a geographical area that is too rural, or if certain conditions like HIV/STD/TB have stricter requirements.
-----

At the forefront is HHS' HIPAA and De-identification of PHI. This includes both the Expert Determination and Safe Harbor methods. These are two very important concepts to become familiar with, and pretty much focus on either utilizing expert de-identification review for "very small" risk, or utilizing safe harbor's definition. Quoted and linked below:

"The De-identification Standard
Section 164.514(a) of the HIPAA Privacy Rule provides the standard for de-identification of protected health information.  Under this standard, health information is not individually identifiable if it does not identify an individual and if the covered entity has no reasonable basis to believe it can be used to identify an individual.

§ 164.514 Other requirements relating to uses and disclosures of protected health information.
(a) Standard: de-identification of protected health information. Health information that does not identify an individual and with respect to which there is no reasonable basis to believe that the information can be used to identify an individual is not individually identifiable health information.

Sections 164.514(b) and(c) of the Privacy Rule contain the implementation specifications that a covered entity must follow to meet the de-identification standard. As summarized in Figure 1, the Privacy Rule provides two methods by which health information can be designated as de-identified."

Additional info here: https://www.hhs.gov/hipaa/for-professionals/privacy/special-topics/de-identification/index.html#_ednref1
-----

Here is a blog that provides a good intro/overview and geo-spatial data and HIPAA:
https://bigdatamedsci.com/2014/02/18/geospatial-data-and-hipaa/

This article provides a good focus on data security and methods:
http://www.pnas.org/content/pnas/105/46/17608.full.pdf

For dot density, we like to use random point generation shown in the ArcGIS guide below. Step 9 depicts how to assign a random point within that polygon, which changes every time the map is refreshed or changed: 
http://desktop.arcgis.com/en/arcmap/10.3/map/working-with-layers/using-dot-density-layers.htm

Here is a YouTube video on creating a random number in Excel. Depending on your geographical size, depends on the calculation (in my case I usually multiple by 0.001 or so): 
https://www.youtube.com/watch?v=q8fU001P2lI

Some additional resources discussing spatial epidemiology and data security: 
https://healthitsecurity.com/news/de-identifcation-of-data-breaking-down-hipaa-rules
https://bmcinfectdis.biomedcentral.com/articles/10.1186/1471-2334-11-29
https://www.taylorfrancis.com/books/9780849384332
https://www.geospatialhealth.net/index.php/gh/article/view/182/182



Best,
Steven

Comments & Events

Scott Troppy, Surveillance Epidemiologist at MA DPH
Thanks for sharing this! Scott
Jennifer Kret turned on public link sharing for this message on