De-identification is in the eye of the data steward and their legal folks.
So it’s the definition of de-id that doesn’t actually “work” in that it’s possible to reidentify small amounts from de-id data, and that adds up over time.
For example, HIPAA considers data de-id if you remove 19 fields or expert determine that it’s de-id. [0]
What’s expert determination, who’s an export? That’s up to me to decide and my lawyers to accept.
The bug is that if half a percent of people each de-id datasets can be reidentified, likely acceptable in HIPAA, then each data released adds up for reidentified people. And more datasets allow for triangulation and linking to reidentify.
The article calls this out as a risk, not a certainty as it’s unclear if anyone is doing this. But the process would be something like:
1) buy HIPAA de-identified data since it doesn’t require patient consent
2) reidentify patients using other data publicly for sale (marketing data, voter registration, etc)
3) new data is not longer HIPAA restricted and fully identified health records can be sold for whatever you like (eg, super targeted drug marketing)
[0] https://www.hhs.gov/hipaa/for-professionals/privacy/special-...