medical data

Researchers: Your ‘Anonymous Data’ May Not Be As Anonymous After All

Americans could be signing over the keys to their identity when filling out medical forms that promise to “anonymize” their information, according to a new algorithm developed by scientists.

When most Americans sign agreements allowing their medical records or personal information to be used for research, they are told that their data will be “anonymized” — in other words, it cannot be traced back to them. Residents who fill out Census Bureau forms, providing data that determines how government funds are distributed and may become public, are told the same thing.

But, according to research published in the journal Nature Tuesday, your data may not be as anonymous as you thought. Scientists at the Imperial College London and Université Catholique de Louvain in Belgium have come up with a computer algorithm that can identify 99.98 percent of Americans from “almost any available data set with as few as 15 attributes,” including gender, ZIP code or marital status, The New York Times reported.

In making the algorithm public, the researchers made a difficult choice in alerting the world to the massive amount of personal information already available via data sets that are bought and sold without regulation in many parts of the globe. Usually, the flaw is reported to a country or company, but the data privacy problem is so prevalent that the authors decided to publish it widely.

Read more: Healthcare Industry at Highest Risk of Cybersecurity Breaches, Study Finds

“It’s always a dilemma,” Yaniv Erlich, chief scientific officer at MyHeritage, a consumer genealogy service, told the Times. “Should we publish or not? The consensus so far is to disclose. That is how you advance the field: Publish the code, publish the finding.”

The finding poses a major issue for security experts tasked with protecting consumer data, particularly when it comes to medical and health data sets. Usually, researchers “de-identify” individuals by removing attributes, substituting fake values or by releasing only parts of anonymized data.

But this isn’t enough to protect people from being identified, either as individuals or part of a household data set, according to the study’s authors.

“We need to move beyond de-identification,” Alexandre de Montjoye, a computer and lead author of the paper, told the Times. “Anonymity is not a property of a data set, but is a property of how you use it.”

The balance between encouraging scientific research and potentially exposing the personal information of hundreds of millions of people to cybercriminals is extremely tricky, and the data gathered about individuals is never completely private, according to the researchers.

“You cannot reduce risk to zero,” Erlich said.

de Montjoye told the Times that medical professionals are now asking patients to sign forms letting them know that their medical data could be shared with other hospitals and a system that might give his information to universities, government agencies and private companies. One form he saw as a patient even said that he could be identified through the data he signed over.

“We are at a point where we know a risk exists and count on people saying they don’t care about privacy,” he said. “It’s insane.”

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • Report: 47 Percent of Security Service Providers Are Not Yet Using AI or Automation Tools

    Trackforce, a provider of security workforce management platforms, today announced the launch of its 2025 Physical Security Operations Benchmark Report, an industry-first study that benchmarks both private security service providers and corporate security teams side by side. Based on a survey of over 300 security professionals across the globe, the report provides a comprehensive look at the state of physical security operations. Read Now

    • Guard Services
  • Identity Governance at the Crossroads of Complexity and Scale

    Modern enterprises are grappling with an increasing number of identities, both human and machine, across an ever-growing number of systems. They must also deal with increased operational demands, including faster onboarding, more scalable models, and tighter security enforcement. Navigating these ever-growing challenges with speed and accuracy requires a new approach to identity governance that is built for the future enterprise. Read Now

  • Eagle Eye Networks Launches AI Camera Gun Detection

    Eagle Eye Networks, a provider of cloud video surveillance, recently introduced Eagle Eye Gun Detection, a new layer of protection for schools and businesses that works with existing security cameras and infrastructure. Eagle Eye Networks is the first to build gun detection into its platform. Read Now

  • Report: AI is Supercharging Old-School Cybercriminal Tactics

    AI isn’t just transforming how we work. It’s reshaping how cybercriminals attack, with threat actors exploiting AI to mass produce malicious code loaders, steal browser credentials and accelerate cloud attacks, according to a new report from Elastic. Read Now

  • Pragmatism, Productivity, and the Push for Accountability in 2025-2026

    Every year, the security industry debates whether artificial intelligence is a disruption, an enabler, or a distraction. By 2025, that conversation matured, where AI became a working dimension in physical identity and access management (PIAM) programs. Observations from 2025 highlight this turning point in AI’s role in access control and define how security leaders are being distinguished based on how they apply it. Read Now

New Products

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings.

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities