問題文
A hospital network wants an analytics team to study how outcomes differ by treatment over several years. The team must be able to follow the same patient across visits, must not be able to learn who that patient is, and the clinical team must still be able to re-identify a single case if a safety signal appears. Which approach fits these requirements?
選択肢
- Strip and generalize the identifying attributes so that no case can ever be traced back, and give the analytics team a visit level extract that groups the years of treatment together.
- Replace the identifying attributes with a token that is consistent per patient, and keep the mapping from token to patient in a separately controlled store that only the clinical team can use.
- Encrypt the identifying fields in place and hand the records to the analytics team, since the analysts cannot read the encrypted values, and the clinical team decrypts a single case whenever a safety signal has to be followed up.
- Give the analytics team a copy of the full records and rely on a signed agreement plus an access log, so the identifying attributes stay available for the safety follow-up while misuse is deterred by the review of that log after the fact.