HEALTH-DP: a framework for health data de-anonymization risk assessment and mitigation with differential privacy
Loading...
Files
Published Version
Date
2026
Authors
Aguelal, Hamza
Shafiq, Akasha
Palmieri, Paolo
Journal Title
Journal ISSN
Volume Title
Publisher
SCITEPRESS
Published Version
Abstract
Privacy protection is a significant challenge in the computation of personal data, especially when data (e.g. health-related) is considered sensitive under relevant regulations. Although anonymization is widely applied, adversaries can still de-anonymize data through sophisticated attacks. Risks are particularly severe for health datasets, such as genomics or physiological data, due to their inherent uniqueness. Differential privacy (DP) has emerged as a strong privacy-preservation technique. However, current approaches to its implementation remain theoretical (and thus not directly linked to actual risks) or specific to a single context, and lack inclusive pathways for different stakeholders in the medical environment. This paper presents a comprehensive framework to address these limitations, combining a systematic study of re-identification attacks and practical risk assessment with DP implementation. The framework incorporates the parties’ roles, threat pre-assessment, known attacks and DP integration. An adaptive mitigation strategy within a structured flow and logical process ensures wide coverage of different requirements. Furthermore, we validate the framework by applying central DP (CDP) to a heart-attack prediction dataset as an initial case study for a future broader end-to-end implementation. The framework provides a roadmap for implementing DP based on evaluating re-identification risks and data governance requirements, and gives stakeholders actionable guidance for safer data use.
Description
Keywords
De-anonymization , Differential privacy , Anonymization , Risk assessment , Health data , Privacy enhancement technologies
Citation
Aguelal, H., Shafiq, A. and Palmieri, P. (2026) 'HEALTH-DP: a framework for health data de-anonymization risk assessment and mitigation with differential privacy', Proceedings of the 12th International Conference on Information Systems Security and Privacy (ICISSP 2026), Marbella, Spain, 4-6 March, Volume 1, pp. 201-212.
