UNAIDS 2019 | GUIDANCE
The Privacy,
Confidentiality and
Security Assessment Tool
Protecting personal health information
,
,Contents
Foreword 2
Summary 4
Main points: how to use the assessment tool 6
The privacy, Confidentiality and Security Assessment Tool 8
Data warehouse-level assessment tool 40
Policy-level assessment tool 68
References 83
, Foreword
With the scale-up of HIV and other health services
in low- and middle-income countries, an increasing
amount of personally identifiable health information
is being collected at health facilities and in data
repositories at the regional and national levels.
Countries need to protect the confidentiality and
security of identifiable and de-identified personal
health information, and this can be accomplished in
part through the existence and implementation of
relevant privacy laws.
A UNAIDS and United States President’s Emergency
Plan for AIDS Relief (PEPFAR) workshop with
multi-stakeholder input that was held in Geneva,
Switzerland, in 2006 led to the development of
country guidelines to protect the confidentiality
and security of HIV information. Those Guidelines
on protecting the confidentiality and security of
HIV information: proceedings from a workshop (1)
(interim guidelines) can be used by countries to
adapt, adopit and implement their own guidelines
In 2008, 96 low- and middle-income countries
were surveyed to determine whether or not they
had developed and implemented their own
guidelines (2). The findings indicated that very few
countries had developed comprehensive guidelines
on protecting the confidentiality and security of HIV
information.
2
The Privacy,
Confidentiality and
Security Assessment Tool
Protecting personal health information
,
,Contents
Foreword 2
Summary 4
Main points: how to use the assessment tool 6
The privacy, Confidentiality and Security Assessment Tool 8
Data warehouse-level assessment tool 40
Policy-level assessment tool 68
References 83
, Foreword
With the scale-up of HIV and other health services
in low- and middle-income countries, an increasing
amount of personally identifiable health information
is being collected at health facilities and in data
repositories at the regional and national levels.
Countries need to protect the confidentiality and
security of identifiable and de-identified personal
health information, and this can be accomplished in
part through the existence and implementation of
relevant privacy laws.
A UNAIDS and United States President’s Emergency
Plan for AIDS Relief (PEPFAR) workshop with
multi-stakeholder input that was held in Geneva,
Switzerland, in 2006 led to the development of
country guidelines to protect the confidentiality
and security of HIV information. Those Guidelines
on protecting the confidentiality and security of
HIV information: proceedings from a workshop (1)
(interim guidelines) can be used by countries to
adapt, adopit and implement their own guidelines
In 2008, 96 low- and middle-income countries
were surveyed to determine whether or not they
had developed and implemented their own
guidelines (2). The findings indicated that very few
countries had developed comprehensive guidelines
on protecting the confidentiality and security of HIV
information.
2