Disclosure Limitation Review

Guidelines for Maintaining Respondent Privacy and Anonymity

A contractual obligation of researches who qualify for access to restricted data from the Health and Retirement Study is to maintain respondent anonymity. Disclosure limitation review is the method by which HRS can prevent disclosure of confidential information, reduce the likelihood of respondent re-identification, provide useful data to researchers, and ensure the results of the review process are acceptable to both the researcher and the provider(s) of the restricted data.

Methods Used to Protect Confidentiality in HRS Data Products

  • All HRS public and restricted files are directly or indirectly based on sample survey methodology
  • Public file variables containing indirect identifiers such as industry, occupation, and geographic information have been collapsed
  • Microdata files derived from SSA administrative data (e.g., Earnings, Benefits, and SSI records) have been subjected to rounding and top-coding in accordance with the governing Memorandum of Understanding
  • Direct respondent identifiers such as name, address, SSN, Medicare/Medicaid identifier, place of birth, etc. have been removed from all public microdata products, and limitations have been placed on access to geographic detail information
  • Data items at the respondent level related to sample design, such as PSU, segment, and line, are not distributed to the public

Protecting Confidentiality During Analysis

  • Researchers should only publish statistical summary values (frequency tabulations, magnitude tabulations, means, variances, regression coefficients, and correlation coefficients) that do not permit the identification of any individual person, family, household, employer, or benefit provider
  • File(s) that result from any merge process which includes restricted data input should be treated as restricted
  • Researchers should not publish the results of any analysis that can potentially identify respondents, either directly or inferentially
  • Researchers are prohibited from publishing results that identify geographic areas below the level of Census Region/Division. Under certain circumstances restricted data users with access to state-level geographic information may wish to report state-level summary information. In such cases, analysis results must be submitted to the HRS Data Confidentiality Committee for review and approval prior to presentation or publication
  • When producing tabulations for distribution, the following guidelines should be employed:
    • Magnitude Data: Ensure that no cells/strata with n < 3 are produced
    • Frequency Data: Apply a marginal threshold of n >= 5 and cell threshold of n >= 3 to all tabulations
  • Certain types of cross-category merges (e.g., State-level geographic data with Social Security Administrative data) are not allowed under traditional restricted licensing agreements (see Merge Rule Cross-Reference Table, below). Geographic information may only be used in conjunction with files derived from Social Security administrative data (1) after executing a MiCDA Data Enclave data use agreement and (2) obtaining written permission from the HRS Project Director
  • Analysis results containing merged area data based on geographic information may be reported if there is no direct identification of geographic areas, if geographic areas are reported using the same grouping characteristics as public files, or if special approval has been granted by the HRS Data Confidentiality Committee. When using geocodes to link respondent information to area data, make sure that respondent privacy is not inadvertently compromised by reporting unique area data values (e.g., including census tracts with unusual environmental characteristics in data analysis reports)
  • Researchers may wish to recode or collapse certain high visibility variables such as Cause of Death or Medical Condition before reporting analysis results using such variables
  • All published research resulting from restricted data analysis should be reviewed according to the terms of the Agreement For Use of Restricted Data From the Health and Retirement Study