File-Sharing Software Potential Threat to Health Privacy – Study

Wednesday, March 03, 2010

Cross-Posted from: http://www.databreaches.net/?p=10367

A research report on file-sharing risks that compares risks for personal financial information to personal health information:

Khaled El Emam, Emilio Neri, Elizabeth Jonker, Marina Sokolova, Liam Peyton, Angelica Neisa, Teresa Scassa. The inadvertent disclosure of personal health information through peer-to-peer file sharing programs. Journal of the American Medical Informatics Association, 2010; 17: 148-158.

ABSTRACT

Objective There has been a consistent concern about the inadvertent disclosure of personal information through peer-to-peer file sharing applications, such as Limewire and Morpheus. Examples of personal health and financial information being exposed have been published. We wanted to estimate the extent to which personal health information (PHI) is being disclosed in this way, compare that to the extent of disclosure of personal financial information (PFI).

Design After careful review and approval of our protocol by our institutional research ethics board, files were downloaded from peer-to-peer file sharing networks and manually analyzed for the presence of PHI and PFI. The geographic region of the IP addresses was determined, and classified as either USA or Canada.

Measurement We estimated the proportion of files that contain personal health and financial information for each region. We also estimated the proportion of search terms that return files with personal health and financial information. We ascertained and discuss the ethical issues related to this study.

Results Approximately 0.4% of Canadian IP addresses had PHI, as did 0.5% of US IP addresses. There was more disclosure of financial information, at 1.7% of Canadian IP addresses and 4.7% of US IP addresses. An analysis of search terms used in these file sharing networks showed that a small percentage of the terms would return PHI and PFI files (ie, there are people successfully searching for PFI and PHI on the peer-to-peer file sharing networks).

Conclusion There is a real risk of inadvertent disclosure of PHI through peer-to-peer file sharing networks, although the risk is not as large as for PFI. Anyone keeping PHI on their computers should avoid installing file sharing applications on their computers, or if they have to use such tools, actively manage the risks of inadvertent disclosure of their, their family’s, their clients’, or patients’ PHI.

Possibly Related Articles:
3725
HIPAA Viruses & Malware
Bio/Pharma Healthcare Provider
HIPAA Privacy PHI P2P
Post Rating I Like this!
Default-avatar
Espie Q We all know that file sharing isn't that much secured. I mean, you don't know how secured your information is. A courtroom ruling against peer-to-peer file-sharing has pulled the plug on LimeWire downloads. Tuesday's courtroom rule ends a four-year courtroom battle between LimeWire and the Recording Industry Association of The United States, which finally won its case . LimeWire said it's preparing to launch a legal subscription-based music service as its users migrated to other p2p online websites such as FrostWire.
1288416272