CompTIA Data+ (DA0-002)Data Governance, Quality and ControlsHard
A healthcare organization replaces patient names in a research dataset with randomly generated unique codes. The organization retains a separately secured mapping table linking each code back to the original patient identity for authorized re-identification if needed later. Which de-identification technique does this represent?
- AAggregation
- BPseudonymization
- CAnonymization
- DData masking
Show answer & explanationAnswer & explanation
Correct answer: B. Pseudonymization
Pseudonymization replaces identifying fields with artificial identifiers (codes) while retaining a separate, securely stored mapping table that allows re-identification, unlike true anonymization, which permanently removes the ability to re-identify individuals.
Why the other options are wrong
- A. Aggregation combines data into summary groups, not individual-level code substitution.
- C. Anonymization irreversibly removes identifying information so re-identification is not possible.
- D. Data masking obscures values (e.g., partial characters) typically for display, not full replacement with a reversible code.
Pseudonymization
A reversible de-identification technique that replaces identifying data fields with artificial identifiers (pseudonyms), while a separately secured mapping table allows authorized re-identification.
- Reversible, unlike anonymization
- Mapping table must be securely stored separately
- Still considered personal data under regulations like GDPR
Memory trick: Pseudonymization wears a 'mask' that can be removed with the right key.