CompTIA DataSys+ (DS0-001)Data and Database SecurityHard

A research institution is sharing a dataset containing patient health information with external collaborators for statistical analysis. To comply with privacy regulations like HIPAA, the institution needs to ensure that individual patients cannot be identified from the shared dataset, even by combining information from multiple sources. However, the statistical integrity of the data must be preserved. Which data privacy technique is most suitable for this scenario?

  1. AData masking
  2. BPseudonymization
  3. CData encryption
  4. DAnonymization
Show answer & explanation

Correct answer: D. Anonymization

Anonymization involves permanently removing or irreversibly transforming personal identifiers so that the data subject cannot be re-identified, even with additional information. This is crucial for sharing data for statistical analysis while complying with strict privacy regulations like HIPAA and preserving statistical integrity.

Why the other options are wrong

  • A. Data masking replaces sensitive data with fictitious values, often for testing, but doesn't guarantee irreversible de-identification against linking attacks.
  • B. Pseudonymization replaces direct identifiers with artificial ones but maintains a link to the original data, meaning re-identification is possible (though restricted). The scenario requires *cannot be identified* even with *combining information*.
  • C. Data encryption protects confidentiality but the data is still identifiable once decrypted.

Anonymization

The process of irreversibly removing or modifying personally identifiable information (PII) from a dataset so that individuals cannot be re-identified.

  • Aims for permanent and irreversible de-identification.
  • Different from pseudonymization, where re-identification is still technically possible with a key.
  • Essential for sharing datasets for research or public use while protecting privacy.

Memory trick: Anonymity means no one knows your name, ever.

More Data and Database Security questions