Abstract
This paper proposes embedding risk-based anonymisation directly into data access control, so that individual-level health data can be released at a protection level matched to each requester and use case. Instead of producing a single, maximally protected dataset for everyone, the design adjusts anonymisation to the risk profile of each access scenario, balancing privacy against analytical value case by case. This lets secure environments serve data more flexibly without compromising on protection. Presented in Studies in Health Technology and Informatics, it addresses the practical governance of sensitive health-data access.
anonymization disclosure risk data access control health data