| Literature DB >> 17942386 |
Khaled El Emam1, Emilio Neri, Elizabeth Jonker.
Abstract
BACKGROUND: The public is concerned about the privacy of their health information, especially as more of it is collected, stored, and exchanged electronically. But we do not know the extent of leakage of personal health information (PHI) from data custodians. One form of data leakage is through computer equipment that is sold, donated, lost, or stolen from health care facilities or individuals who work at these facilities. Previous studies have shown that it is possible to get sensitive personal information (PI) from second-hand disk drives. However, there have been no studies investigating the leakage of PHI in this way.Entities:
Mesh:
Year: 2007 PMID: 17942386 PMCID: PMC2047285 DOI: 10.2196/jmir.9.3.e24
Source DB: PubMed Journal: J Med Internet Res ISSN: 1438-8871 Impact factor: 5.428
Contingency table with marginal totals and percentages showing the status of purchased drives distributed by province of purchase*
| Province | Repartitioned | Formatted | DoD | Data | Blank | Total |
| Ontario | 19 | 11 | 5 | 4 | 3 | 42 (70%) |
| Quebec | 5 | 5 (8%) | ||||
| Alberta | 12 | 12 (20%) | ||||
| British Columbia | 1 | 1 (2%) | ||||
| Total | 19 (32%) | 16 (27%) | 17 (28%) | 5 (8%) | 3 (5%) | 60 (100%) |
*For store chains, we considered the location of the specific store that we purchased from. The actual owners of the disk drives may be located in a different province or country. Four of the drives bought from Ontario belonged to US-based entities: 2 of them were state government departments, 1 was a municipal department, and 1 belonged to an individual.
Claims made by the vendors of the drives from which we were able to extract data
| Vendor Statement About Wiping Drives | Count |
| “Like new condition” | 1 |
| Verbally stated that the drives were formatted | 1 |
| “Recertified to factory settings” | 1 |
| None | 5 |
Percentage of drives with recoverable files and percentage of total drives with available personal data
| Owner PI (A)* | Owner PI (B)* | Other PI | Owner PHI | Other PHI | |
| Percentage of Recovered | 72% (28/39) | 62% (24/39) | 56% (22/39) | 13% (5/39) | 15% (6/39) |
| Percentage of Total | 47% (28/60) | 40% (24/60) | 37% (22/60) | 8% (5/60) | 10% (6/60) |
| Kappa† | 0.8 | 0.6 | 0.78 | 0.76 | 0.795 |
*(A) indicates that work products were considered as PI, and (B) indicates that work products were not considered as PI.
†Interrater agreement Kappa scores and their 95% confidence intervals.
Summary of findings from an international data remnants study [26]
| UK and Australia (2005) | UK (2006) | Australia (2006) | Germany (2006) | North America (2006) | |
| Total Drives | 116 | 200 | 53 | 40 | 24 |
| Faulty Drives | 13 (11%) | 87 (43%) | 3 (6%) | 30 (75%) | 12 (50%) |
| Wiped* | 17 (16%) | 55 (49%) | 18 (36%) | 4 (40%) | 1 (8%) |
| Had PI* | 51 (49%) | 35 (31%) | 9 (18%) | 3 (30%) | 7 (60%) |
*The percentage of these disk drives that were not faulty.