I’m not sure how to defend against this as it seems based on HIPAA and what it allows. Since de-identified data can be legally sold, I think it will.
The theoretical defense I’ve thought up is a class action lawsuit for synthetic breaches. Since these data are deemed de-identified by expert determination [0] and that’s hazy, if I could reidentify myself after de-id, and I didn’t authorize it, then I could be eligible for breach damages for HIPAA violations up to $50k per person [1].
Since these sets have millions of people, likely everyone in the country. And since expert determination can possibly classify an acceptable re-id risk as less than 1%, this could be a million or two people. So a big enough pool to attract big legal investments.
That would increase the cost and risk of doing this to outweigh the benefits. But currently it’s “free money” for any healthcare system that’s kind of impossible for me as a patient to opt out.
[0] https://www.hhs.gov/hipaa/for-professionals/privacy/special-... [1] https://www.injuryclaimcoach.com/hipaa-violations.html