Skip to main content
Advertisement
Browse Subject Areas
?

Click through the PLOS taxonomy to find articles in your field.

For more information about PLOS Subject Areas, click here.

< Back to Article

Table 1.

The attributes removed, or generalized, to satisfy the HIPAA Safe Harbor policy.

More »

Table 1 Expand

Table 2.

A summary of the notation used in this work.

More »

Table 2 Expand

Table 3.

Payoff functions for the publisher and adversary for a fixed data sharing strategy g.

More »

Table 3 Expand

Fig 1.

An illustrative example.

An illustrative example of the re-identification game with four data sharing strategies.

More »

Fig 1 Expand

Table 4.

Algorithm 1: Backward Induction Search (BIS) Algorithm.

More »

Table 4 Expand

Fig 2.

DGH for Age.

The Domain Generation Hierarchy (DGH) for the attribute Age in the case study.

More »

Fig 2 Expand

Fig 3.

DGH for Race.

The Domain Generation Hierarchy (DGH) for the attribute Race in the case study.

More »

Fig 3 Expand

Fig 4.

Lattice for two attributes.

The illustrative lattice for a database with two attributes Race and Age.

More »

Fig 4 Expand

Table 5.

Algorithm 2: Lattice-Based Search (LBS) Algorithm.

More »

Table 5 Expand

Table 6.

Recent notable HIPAA breach violation cases as reported by the U.S. Department of Health and Human Services.

More »

Table 6 Expand

Fig 5.

Payoff across strategies.

Payoffs for the record ⟨48, Asian, Female, 38363⟩ across all strategies.

More »

Fig 5 Expand

Table 7.

A comparison of four de-identification policies for the case study on performance measures.

More »

Table 7 Expand

Fig 6.

Histogram of Payoff Differences.

Distributions of the publisher’s payoff differences (left) and the adversary’s payoff differences (right) between games and HIPAA Safe Harbor (SH).

More »

Fig 6 Expand

Fig 7.

Scatter-plot of Payoff Differences.

Detailed distributions of the publisher’s payoff differences (left) and the adversary’s payoff differences (right) between games and HIPAA Safe Harbor (SH).

More »

Fig 7 Expand

Fig 8.

Example solution 1 in Basic Game.

Resulting strategies and payoffs for ⟨19, Black or African American, Male, 37208⟩ in the Basic Game. GI stands for the generalization intensity. V corresponds to the benefit that the publisher receives by sharing the record in its original form. L corresponds to the publisher’s loss for one record due to a successful re-identification.

More »

Fig 8 Expand

Fig 9.

Example solution 2 in Basic Game.

Resulting strategies and payoffs for ⟨62, White, Female, 37014⟩ in the Basic Game. GI stands for the generalization intensity. V corresponds to the benefit that the publisher receives by sharing the record in its original form. L corresponds to the publisher’s loss for one record due to a successful re-identification.

More »

Fig 9 Expand

Fig 10.

Sensitivity of Basic Game to Benefit and Loss.

Sensitivity of the average payoffs and strategies over the dataset to the changes of the publisher’s benefit and the publisher’s loss in the Basic Game. GI stands for the generalization intensity. V corresponds to the benefit that the publisher receives by sharing the record in its original form. L corresponds to the publisher’s loss for one record due to a successful re-identification.

More »

Fig 10 Expand

Fig 11.

Sensitivities of different scenarios to Benefit or Loss.

Sensitivity of the average payoffs over the dataset to the change of the publisher’s benefit, the publisher’s loss, or the adversary’s cost in different de-identification scenarios. V corresponds to the benefit that the publisher receives by sharing the record in its original form. L corresponds to the publisher’s loss for one record due to a successful re-identification. c corresponds to the adversary’s cost to launch a re-identification attack towards one record.

More »

Fig 11 Expand

Table 8.

A performance comparison of the de-identification game solving approaches.

More »

Table 8 Expand

Fig 12.

Accuracy of Lattice-based Search.

A comparison of the accuracy of the LBS game solving heuristic. V corresponds to the benefit that the publisher receives by sharing the record in its original form. L corresponds to the publisher’s loss for one record due to a successful re-identification. c corresponds to the adversary’s cost to launch a re-identification attack towards one record.

More »

Fig 12 Expand