It's certainly possible to do, whether or not the controls are in place to prevent re-identification is a different matter...
The document I linked says they do have these controls in place but having done my fair slog in the NHS I'm doubtful.
The document I linked says they do have these controls in place but having done my fair slog in the NHS I'm doubtful.
Does something similar apply here? Can it be formally proven that there's no way to de-anonymise the data?