1 of 21

Data Privacy

1

Data 6 Summer 2025

DISCUSSION 04

​

Looking at how data privacy has changed through a case analysis of Latanya Sweeney.

Edwin Vargas Navarro | jedwin321@berkeley.edu

Office Hours: Tuesdays 6-8 PM

​

Created by Edwin Vargas Navarro

2 of 21

Week 2

Announcements!

  • Announcements

2

3 of 21

Ice breaker

🧊🥶

​

3

Would you rather...

​

  • Have all your texts leaked to your family?

​

  • Have your medical records posted publicly?

​

Talk to the people around you and explain why.

4 of 21

Today’s Roadmap

Discussion 04, Data 6 Summer 2025

  1. Public, Anonymized, Personally Identifiable Data
  2. Case Study: Latanya Sweeney and HIPPA
  3. Discussion Worksheet

4

5 of 21

Public, Anonymized, Personally Identifiable Data

5

1. Public, Anonymized, Personally Identifiable Data

2. Case Study: Latanya Sweeney and HIPPA

3. Discussion Worksheet

​

➤

6 of 21

Public vs. Anonymized vs. Personally Identifiable Data

Public Data: Freely available to anyone (e.g., census, weather).

​

Anonymized Data: Identifying info removed or masked.

​

Personally Identifiable Data (PID): Data that can be traced back to a person (e.g., name, SSN, birthday).

6

7 of 21

Case Study: Latanya Sweeney and HIPPA

7

1. Public, Anonymized, Personally Identifiable Data

2. Case Study: Latanya Sweeney and HIPPA

3. Discussion Worksheet

​

➤

8 of 21

Who is Latnaya Sweeney?

  • Known for groundbreaking work in data privacy and re-identification

​

  • In 1997, re-identified the medical record of Massachusetts Governor William Weld using “anonymized” hospital data. She then mailed his medical records to his home.

8

Latnaya is a computer scientist and privacy researcher at Harvard, but why is she relevant to us?

9 of 21

The Massachusetts "Anonymized" Dataset

In the 1990s, the state of Massachusetts released anonymized hospital records for research through the Group Insurance Commission (GIC) government agency.

​

  • Removed all names and direct identifiers

​

  • Included fields like:
    • ZIP code
    • Gender
    • Date of birth
    • Diagnosis, procedures, prescriptions

9

10 of 21

The Voter Roll Linkage

At the same time, voter registration data was publicly available. Latnaya purchased the voter registration list for $20.

​

Voter data included:

  • Name
  • Address (including ZIP)
  • Gender
  • Date of birth

​

These were not anonymized

10

11 of 21

Joining the two

11

Ethnicity

​

Visit Date

​

Diagnosis

​

Procedure

​

Medication

​

Total Charge

Name

​

Address

​

Date Registered

​

Party Affiliation

​

Date Last Voted

ZIP

​

Birthday

​

Gender

Medical Data

Voter List

12 of 21

Re-identifying Governor William Weld

William Weld was Governor of Massachusetts at the time

  • He lived in Cambridge, MA
  • His medical records were included in the anonymized GIC dataset

​

​

12

According to the Cambridge voter list:

  • 6 people shared his birthdate
  • Only 3 of them were men
  • Only 1 man lived in his 5-digit ZIP code

​

That 1 person was uniquely identifiable: Governor Weld

13 of 21

HIPAA & the Risk of Re-Identification

What is HIPAA?

Health Insurance Portability and Accountability Act (1996)

  • Designed to protect the privacy of medical records

​

  • Allows “anonymized” data sharing by removing direct identifiers

​

But... Is That Enough?

​

13

14 of 21

Sweeney’s Findings

Latanya Sweeney showed that even HIPAA compliant data could be vulnerable.

​

87% of Americans could be uniquely identified using just:

  • ZIP code
  • Birth date
  • Gender

​

These quasi-identifiers are not considered protected under HIPAA

Anonymized ≠ Anonymous

14

15 of 21

Questions?

15

16 of 21

Discussion Worksheet

16

1. Public, Anonymized, Personally Identifiable Data

2. Case Study: Latanya Sweeney and HIPPA

3. Discussion Worksheet

​

➤

17 of 21

Privacy

Q1.1 Use the shared fields ZIP, Birthday, and Gender to join these two tables. Based on this data, which voter could be re-identified in the anonymized medical dataset?

Person C

Q1.2 Use the shared fields ZIP, Birthday, and Gender to join these two tables. Based on this data, which voter could be re-identified in the anonymized medical dataset?

Option C:

While the medical dataset was anonymized, it still contained quasi-identifiers such as ZIP code, birthdate, and sex. These identifiers that uniquely identified many individuals. When these were joined with publicly available voter registration data that also had those same fields (plus names), Sweeney was able to re-identify individuals.... including the governor.

17

18 of 21

Table Function Visualizer

Q2.1 cones.group("Flavor")

Chocolate

Strawberry

3

2

18

19 of 21

Table Function Visualizer

Q2.2 chocolates.group("Color", max)

Dark

Milk

White

Round

Round

Rectangular

7

9

12

1.75

1.4

2

19

20 of 21

Table Function Visualizer

Q2.3 chocolates.pivot("Color", "Shape", "Amount", np.mean)

Rectangular

Round

0

5.5

7.5

2

12

0

20

21 of 21

Table Function Visualizer

Q2.4 Edwin has this table, but he needs your help finding the correct code. Select the option

that yields the following table:

Option D: chocolates.pivot("Shape", "Color", "Price", sum)

21