PubMed Health⌕ Search

SEARCH · PubMed Health

Results for “Privacy”

Explore indexed PubMed citations for clinical trials, systematic reviews and public health research. Read source abstracts and follow each citation to its original PubMed record.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5Linked to original sources

Will the new Australian health privacy law provide adequate protection?

Amendments to the original Privacy Act (1988) come at a key point in time, as a national medical record system looms on the Australian horizon. Changes to The Privacy Act have the potential to define a level of information privacy prior to the implementation of such a system. We have therefore collected expert opinions on the ability of the Health Privacy Guidelines (enacted in December 2001 under The Privacy Act and hereafter more specifically known as Health Privacy Legislation) to ensure the privacy and security of patient information. We conclude that the legislation is flawed in its capacity to withstand an increasingly corporatised health sector. Deficiencies in consent requirements, together with feeble enforcement capabilities, mean The Legislation cannot effectively ensure that personally identifiable information will not end up in corporate third party hands. To significantly bolster the new legislation, we argue that it should be supplemented with explicit health data legislation and privacy auditing.

Access to Information↗

The HIPAA privacy rule and bioterrorism planning, prevention, and response.

Effective bioterrorism planning, prevention, and response require information sharing between various entities, ranging from public health authorities and health-care workers to national security and law enforcement officials. While the source of much information exchanged may be nonidentifiable, many entities legitimately need access to personally identifiable health information (or "protected health information" [PHI]) in planning for and responding to a bioterrorism event. The HIPAA Privacy Rule allows for essential exchanges of health data during a public health emergency while protecting against unnecessary disclosures of PHI. In the event of a bioterrorist attack, the Privacy Rule allows covered entities to disclose PHI without individual authorization in the following instances: (1) for treatment by health-care providers, (2) to avert a serious threat to health or safety, (3) to public health authorities for public health purposes, (4) to protect national security, (5) to law enforcement under certain conditions, and (6) for judicial or administrative proceedings. Despite these favorable disclosure provisions, some privacy challenges remain. The flow of PHI may be slowed by misunderstandings of the Privacy Rule's accounting requirement. In addition, in a bioterrorism scenario, nontraditional entities may find themselves acting as health-care providers, triggering Privacy Rule provisions. Finally, the potential for de facto disclosures of individuals' disease or exposure status increases where conspicuous treatment methods, isolation, or quarantine are implemented without additional measures to protect privacy. Understanding the Privacy Rule's impact on bioterrorism planning and response ensures that various entities can conduct their activities with needed information while still protecting individual privacy.

Bioterrorism↗

Changing parental opinions about teen privacy through education.

OBJECTIVE: Confidentiality for adolescent patients is the standard of care. However, some parents object to this practice. We determined the prevalence of parents who have negative opinions regarding adolescent privacy policies and education's effect on that prevalence. METHODS: All parents who sought care for their teen at 2 adolescent medicine clinics were asked to complete a computer survey about teen privacy and risk-taking behavior. Parents who did not know the clinic's privacy policy or had never been to the clinic were asked to participate in an educational study. Study participants were randomly selected to receive education by a handout or a scripted face-to-face encounter. They were surveyed again the same day. For evaluating long-term retention, a follow-up survey was conducted at least 30 days after the education. RESULTS: A total of 563 parents were surveyed. Of 281 eligible parents, 130 (46%) completed the postintervention survey and 52 (19%) completed the follow-up survey. Repeated measures analysis of variance showed that both education types were equally effective in teaching parents chosen privacy facts. The average number of correct test questions increased from 58.6% to 89.1%. More than 30 days later, the parents' score was 86.9%. Before education, 35% disagreed or strongly disagreed with teens' having private information, compared with 13.8% immediately after education and 15.4% at follow-up. The percentage of parents who disagreed or strongly disagreed with providers' seeing the patient alone was 30.5%, which decreased to 14.5% after education and 17.3% with the follow-up survey. Chi2 tests showed no statistically significant differences between face-to-face and written education in changing parental opinions regarding privacy. When an adolescent wanted to speak with a provider alone, 93% of the parents agreed with that choice, regardless of intervention. CONCLUSIONS: This study identifies that almost one third of the parents who presented to these adolescent medicine clinics had negative opinions about some privacy practices. The 2 main issues were teens' seeing a provider alone and providers' keeping information confidential. Education was effective in teaching parents about privacy issues and produced a significant improvement in parental opinion about confidentiality. Simultaneously, an overwhelming majority of parents support the idea that teens should speak with a provider alone if the teen so desires, suggesting that parents acknowledge a need for independence. Providing confidential services is an essential part of adolescent health care that works best with the alliance of parents. This study supports the continued need to assess parental attitudes about privacy issues and to provide parents with education.

Adolescent↗

Privacy-preserving framework for genomic computations via multi-key homomorphic encryption.

MOTIVATION: The affordability of genome sequencing and the widespread availability of genomic data have opened up new medical possibilities. Nevertheless, they also raise significant concerns regarding privacy due to the sensitive information they encompass. These privacy implications act as barriers to medical research and data availability. Researchers have proposed privacy-preserving techniques to address this, with cryptography-based methods showing the most promise. However, existing cryptography-based designs lack (i) interoperability, (ii) scalability, (iii) a high degree of privacy (i.e. compromise one to have the other), or (iv) multiparty analyses support (as most existing schemes process genomic information of each party individually). Overcoming these limitations is essential to unlocking the full potential of genomic data while ensuring privacy and data utility. Further research and development are needed to advance privacy-preserving techniques in genomics, focusing on achieving interoperability and scalability, preserving data utility, and enabling secure multiparty computation. RESULTS: This study aims to overcome the limitations of current cryptography-based techniques by employing a multi-key homomorphic encryption scheme. By utilizing this scheme, we have developed a comprehensive protocol capable of conducting diverse genomic analyses. Our protocol facilitates interoperability among individual genome processing and enables multiparty tests, analyses of genomic databases, and operations involving multiple databases. Consequently, our approach represents an innovative advancement in secure genomic data processing, offering enhanced protection and privacy measures. AVAILABILITY AND IMPLEMENTATION: All associated code and documentation are available at https://github.com/farahpoor/smkhe.

Computer Security↗

Safeguarding biomedical AI: a critical scoping review of privacy-enhancing technologies, hybrid approaches, and deployment models.

BACKGROUND: Biomedical artificial intelligence (AI) requires the integration of privacy-enhancing technologies (PETs) to safeguard sensitive clinical, imaging, and genomic data while preserving analytical utility. OBJECTIVES: This review critically and systematically maps applications of PETs across the biomedical AI lifecycle in accordance with PRISMA-ScR guidelines and evaluates their technical trade-offs, deployment feasibility, and residual risks. METHODS: We systematically searched PubMed, IEEE Xplore, ACM Digital Library, and Scopus for studies published between 2015 and 2025. Eligible studies addressed differential privacy, federated learning, secure multiparty computation, homomorphic encryption, or hybrid approaches in biomedical AI. Data were charted on PET type, modality, lifecycle stage, utility metrics, privacy parameters, and deployment considerations. A critical appraisal rubric assessed threat-model adequacy, methodological clarity, reproducibility, privacy-utility transparency, and deployment realism. Additionally, we hand-searched major venues (USENIX Security, NeurIPS, AAAI) and screened Google Scholar for grey literature, applying de-duplication across sources. RESULTS: We identified 87 studies spanning clinical decision support, genomics, and medical imaging. From 25,761 initial records, 3,754 underwent title/abstract screening and 1,968 underwent full-text assessment. PETs demonstrated distinct strengths and limitations: differential privacy provided provable guarantees but reduced performance on imbalanced data; federated learning improved data access but remained vulnerable to gradient leakage; and cryptographic methods ensured confidentiality at high computational cost. Synthetic data generation supported privacy-conscious data sharing and benchmarking but remained sensitive to disclosure risk, fidelity loss, and subgroup representation. Hybrid and emerging approaches, including trusted execution environments, zero-knowledge proofs, and privacy-preserving transformer architectures, mitigated composability gaps yet lacked full end-to-end assurance. Case studies at hospital and biobank scale illustrated practical feasibility and infrastructure demands. CONCLUSIONS: Situating PETs within technical and operational contexts clarifies their capabilities, limitations, and deployment challenges. Residual risks persist, including fairness concerns, inference-time leakage, and overreliance on PETs as compliance proxies. Sustained technical innovation and institutional governance remain essential for the trustworthy integration of PETs in biomedical AI.

biomedical AI↗

Legal issues concerning electronic health information: privacy, quality, and liability.

Personally identifiable health information about individuals and general medical information is increasingly available in electronic form in health databases and through online networks. The proliferation of electronic data within the modern health information infrastructure presents significant benefits for medical providers and patients, including enhanced patient autonomy, improved clinical treatment, advances in health research and public health surveillance, and modern security techniques. However, it also presents new legal challenges in 3 interconnected areas: privacy of identifiable health information, reliability and quality of health data, and tortbased liability. Protecting health information privacy (by giving individuals control over health data without severely restricting warranted communal uses) directly improves the quality and reliability of health data (by encouraging individual uses of health services and communal uses of data), which diminishes tort-based liabilities (by reducing instances of medical malpractice or privacy invasions through improvements in the delivery of health care services resulting in part from better quality and reliability of clinical and research data). Following an analysis of the interconnectivity of these 3 areas and discussing existing and proposed health information privacy laws, recommendations for legal reform concerning health information privacy are presented. These include (1) recognizing identifiable health information as highly sensitive, (2) providing privacy safeguards based on fair information practices, (3) empowering patients with information and rights to consent to disclosure (4) limiting disclosures of health data absent consent, (5) incorporating industry-wide security protections, (6) establishing a national data protection authority, and (7) providing a national minimal level of privacy protections.

Computer Communication Networks↗

Comparison of the auditory and visual privacy of emergency department treatment areas with curtains versus those with solid walls.

STUDY OBJECTIVE: The design and function of emergency departments may allow breaches of privacy that could adversely affect patient satisfaction and medical care. We sought to determine whether patients perceive less privacy in ED treatment areas with curtains than in rooms with solid walls. METHODS: Patients 18 years and older at a university hospital ED who received care in a room with solid walls and a door, a curtained area next to the nurses' station, or a curtained area away from the nurses' station were surveyed. Patients responded on a 5-point Likert scale to 11 questions regarding privacy. Differences between areas were determined by using the Kruskal-Wallis and Mann-Whitney tests and were considered significant at P values of less than.05. RESULTS: Structured interviews were conducted with 108 ED patients. Responses from those in the curtained areas were similar. Compared with those in the rooms with walls, these patients more often believed that they could overhear others and that others could hear them, view them, hear personal information, and view personal parts of their bodies (P < or =.04 for all). They also perceived a lower overall sense of privacy (P <.01). Of all those surveyed, 85.2% reported "a lot of" or "complete" respect for privacy by the staff, and 92.6% experienced at least as much privacy as they expected, with no difference between areas. CONCLUSION: Patients perceive significantly less auditory and visual privacy in ED treatment areas with curtains compared with a room with solid walls. Consideration of these findings in current practice and in future ED design and construction is suggested.

Adult↗

Update on HIPAA privacy: are you ready?

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) created new requirements for health care providers to protect the privacy and security of individually identifiable health information. Regulations to implement HIPAA's privacy provisions were published by the Department of Health and Human Services (HHS) in "final" form in December 2000 (the Privacy Rules). In March, 2002, HHS proposed modifications to the Privacy Rules, which were published on August 14, 2002. The modified final regulations differed from the 2000 regulations in a number of important respects. Most recently, on December 4, 2002, the Office of Civil Rights (OCR), which is charged with enforcement of HIPAA, published "Guidance Explaining Significant Aspects of the Privacy Rule." The Privacy Rules went into effect on April 14, 2003. This article provides a summary of the modified Privacy Rules, discusses some interesting aspects of OCR's "guidance," and highlights the requirements that are most likely to impact the practice of medical genetics.

Confidentiality↗

Privacy of genetic information: a review of the laws in the United States.

This paper examines the privacy of genetic information and the laws in the United States designed to protect genetic privacy. While all 50 states have laws protecting the privacy of health information, there are many states that have additional laws that carve out additional protections specifically for genetic information. The majority of the individual states have enacted legislation to protect individuals from discrimination on the basis of genetic information, and most of this legislation also has provisions to protect the privacy of genetic information. On the Federal level, there has been no antidiscrimination or genetic privacy legislation. Secretary Donna Shalala of the Department of Health and Human Services has issued proposed regulations to protect the privacy of individually identifiable health information. These regulations encompass individually identifiable health information and do not make specific provisions for genetic information. The variety of laws regarding genetic privacy, some found in statutes to protect health information and some found in statutes to prevent genetic discrimination, presents challenges to those charged with administering and executing these laws.

Confidentiality↗

Privacy and research involving humans.

Human research ethics committees in Australia are required to consider compliance with privacy law as an element of the ethics of research. Recent legislation has introduced federal private sector privacy protection, as well as privacy protection at State and Territory levels. In Victoria, which is used as an example in this article, State privacy legislation covers public sector information and health records. This article considers the implications for research involving human participants and for ethics committees of the new privacy regimes. Although privacy law is a potential barrier to research about humans, the need for exceptions has been dealt with effectively in the context of medical or health research. However, privacy law and its chilling effect could potentially be a serious impediment to some forms of non-health-related research, such as social and socio-legal research.

Australia↗

Designing solutions for securing patient privacy--meeting the demands of health care in the 21st century.

OBJECTIVES: To define the issues surrounding patient privacy, examine the political context in which debate is taking place, and present a novel technology model for addressing privacy, confidentiality, and security in 21st century health care. SUMMARY: The discussion of privacy addresses one of the basic issues in health care today--the tension between the needs of the individual patient for privacy and confidentiality and the needs of society to effectively manage health care practices and control health care costs. Patient concerns for privacy, confidentiality, and security are legitimate, and can usually be reduced to issues that potentially affect an individual's employment, ability to get and maintain health coverage, and have control over his or her records and care. These concerns, combined with several precipitating events, are forcing the issue of privacy into the political arena, where new health policy decisions will be made. The debate must be framed within a principle-centered approach that focuses on boundaries, security, consumer control, accountability, and public responsibility. A global, distributed electronic health record management model that provides location-independent, secured, authenticated access to relevant patient care records by qualified health care professionals on a need-to-know basis provides solutions. Information asset considerations should be designed to equitably represent the ownership needs of corporate entities, society, and the individual. CONCLUSION: A secure electronic health record structure that systematically ensures a high level of accountability combined with thoughtful dialogue among key stakeholders in the public policy development process can offer the privacy outcomes we seek.

Delivery of Health Care↗

HIPAA privacy regulations.

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) impacts all health-care professionals, including speech-language pathologists (SLPs). The administration simplification section of HIPAA includes specific regulations designed to protect the privacy of an individual's health records. These privacy regulations are not designed to impede upon essential health-care practices, but do require that covered providers take reasonable steps to limit the use and disclosure of protected health information. Important aspects of the privacy regulations include the development of facility- or practice-specific privacy policies, the development of a privacy manual, staff training on privacy policies and procedures, and the drafting and posting of a notice of privacy practices. In addition, authorization forms are mandated for instances of use and disclosure of public health information not related to treatment, payment, or health-care operations.

Confidentiality↗

Employee privacy: legal and research developments and implications for personnel administration.

The contemporary emphasis on privacy has created a myriad of complex personnel problems and associated approaches to handle them. These privacy-oriented problems generally involve social, ethical, legal, managerial, and even political considerations. Personnel administrators are constantly confronted with the privacy issue. This article attempts to synthesize privacy information relevant to personnel administration, and to provide personnel administrators with managerial guidance for handling employee privacy problems in the work environment. It places particular emphasis on differentiating between ethical and legal aspects of privacy in our society, and, accordingly, on clarifying existing confusion over the impact of so-called "privacy laws" on personnel administration.

Civil Rights↗

Privacy, confidentiality, and security in information systems of state health agencies.

OBJECTIVES: To assess the employment and status of privacy, confidentiality, security and fair information practices in electronic information systems of U.S. state health agencies. METHODS: A survey instrument was developed and administered to key contacts within the state health agencies of each of the 50 U.S. states, Puerto Rico and the District of Columbia. RESULTS: About a third of U.S. state health agencies have no written policies in place regarding privacy and confidentiality in electronic information systems. The doctrines of fair information practice often seemed to be ignored. One quarter of the agencies reported at least one security breach during the past two years, and 16% experienced a privacy and confidentiality related transgression. Most of the breaches were committed by personnel from within the agencies. CONCLUSIONS: These results raise questions about the integrity of existing privacy, confidentiality and security measures in the information systems of U.S. state health agencies. Recommendations include the development and vigorous enforcement of written privacy and confidentiality policies, increased personnel training, and expanded implementation of security measures such as encryption and system firewalls. A discussion of the current status of U.S. privacy, confidentiality and security issues is offered.

Computer Security↗

Privacy concerns of patients and nurse practitioners in primary care--an APRNet study.

PURPOSE: This study explores and compares the privacy concerns of primary care nurse practitioners (NPs) and their patients. DATA SOURCES: Privacy concerns were identified in separate focus groups of NPs and patients, and then parallel survey instruments were designed and administered to 27 NPs and 185 of their patients. All subjects were recruited through APRNet, a regional practice-based research network of NPs in southern New England encompassing 58 practices. CONCLUSIONS: Both groups demonstrated high levels of concern regarding privacy. While NPs and patients had similar levels of concern about most issues, there were some notable differences regarding breeches because of carelessness, disclosures for research, and which disorders require the most care in maintaining privacy. IMPLICATIONS FOR PRACTICE: These results allow NPs to anticipate patient privacy concerns and to enhance trust in the clinical relationship. These results also indicate the need to educate patients regarding privacy rights and expectations.

Adult↗

Privacy and patient-clergy access: perspectives of patients admitted to hospital.

BACKGROUND: For patients admitted to hospital both pastoral care and privacy or confidentiality are important. Rules related to each have come into conflict recently in the US. Federal laws and other rules protect confidentiality in ways that countermand hospitals' methods for facilitating access to pastoral care. This leads to conflicts and poses an unusual type of dilemma-one of conflicting values and rights. As interests are elements necessary for establishing rights, it is important to explore patients' interests in privacy compared with their desire for attention from a cleric. AIM: To assess the willingness of patients to have their names and rooms included on a list by religion, having that information given to clergy without their consent, their sense of privacy violation if that were done and their views about patients' privacy rights. METHODS AND PARTICIPANTS: 179 patients, aged 18-92 years, admitted to hospital in an acute care setting, were interviewed and asked about their preferences for confidentiality and pastoral support. RESULTS: Most (57%) patients did not want to be listed by religion; 58% did not think hospitals should give lists to clergy without their consent and 84% welcomed a visit by their own clergy even if triggered from a hospital list. CONCLUSIONS: Values related to confidentiality or privacy and pastoral care were found to be inconsistent and more complicated than expected. Balancing the right to privacy and the value of religious support continue to present a challenge for hospitals. Patients' preferences support the importance of providing balance in a way that protects rights while offering comprehensive services.

Adolescent↗

Perceptions of privacy in the care of elderly people in five European countries.

The focus of this article is on elderly patients' and nursing staff perceptions of privacy in the care of elderly patients/residents in five European countries. Privacy includes physical, social and informational elements. The results show that perceptions of privacy were strongest in the UK (Scotland) and weakest in Greece. Country comparisons revealed statistically significant differences between the perceptions of elderly patients and also between those of nurses working in the same ward or long-term care facility. Perceptions of privacy by patients and their nursing staff were quite similar in Finland, Germany and the UK. In contrast, in Greece and Spain these perceptions were different: nurses believed that they took account of their patients' privacy needs more often than the patients themselves felt this was the case. Among Spanish and UK patients, an association was found between lower levels of independence and comparatively less positive perceptions of privacy. No associations were established between nurses' perceptions and their demographic factors. This is the third of a set of five articles published together in this issue of Nursing Ethics in which the results of this comparative research project are presented.

Activities of Daily Living↗

Patients' privacy of the person and human rights.

The UK Government published various circulars to indicate the importance of respecting the privacy and dignity of NHS patients following the implementation of the Human Rights Act, 1998. This research used an ethnographic method to determine the extent to which health professionals had in fact upheld the philosophy of these documents. Fieldwork using nonparticipant observation, and unstructured and semistructured interviews with patients and staff, took place over six months in three acute care wards in a large district NHS trust hospital. Applying the principles of phenomenology and grounded theory, the data were analysed and the contents organized into 11 key categories, leading to the formulation of a privacy model. The level of intrusion into patients' privacy by health professionals was measured against the benchmarking of the 'dignity and privacy' factors contained in the Department of Health's The essence of care document and Article 8(2) of the Human Rights Act. The findings established that patients had little privacy in the wards, and that the terms 'privacy of the person' and 'dignity' are interrelated.

Benchmarking↗