Corvus Medical Press
JMIDH

Patient Privacy, De-identification & Security Research Policy

Informatics research often uses large amounts of personal health data and describes systems that hold such data. JMIDH requires authors to protect the privacy of patients and users, and to handle security research responsibly.

No identifiable patient information

•     Articles, figures, supplementary files, code and shared datasets must not contain names, initials, hospital or record numbers, health ID numbers (such as ABHA numbers), phone numbers, addresses, exact dates of birth, or other direct identifiers.

•     Screenshots of electronic health records, dashboards, apps or messaging platforms must use synthetic or test data, or be fully masked. Screenshots of real records are not accepted.

•     Medical images must have identifiers removed from both the image and the file metadata (for example DICOM headers).

•     Free-text clinical notes quoted in articles or released with datasets must be de-identified using a documented method, with its performance reported where possible.

•     Small subgroups, rare conditions and linked datasets can allow re-identification; authors should aggregate results or suppress small counts where necessary.

Individual patients

JMIDH does not publish individual patient case reports. If an article describes an individual in a way that could identify them — for example a patient’s experience of a telemedicine service or an error caused by a digital system — written informed consent for publication must be obtained from the person (or a parent, guardian or next of kin, as appropriate). The consent must cover free online publication. The consent form is retained by the authors and provided to the editors on request, and the article must state that consent was obtained.

Reporting of errors and system failures

Reports of safety incidents involving health IT (for example, wrong-patient orders or alert failures) are welcome when written for learning. They must be de-identified, must not identify the staff involved, should take a systems-based approach, and require institutional permission.

Security and vulnerability research

Research that identifies security vulnerabilities in health software, medical devices, apps or networks must follow responsible disclosure. Authors must confirm that the vendor or system owner was notified and given reasonable time to fix the problem (normally at least 90 days) before submission, and must not publish information that would allow attackers to exploit unpatched systems. Testing must have been carried out lawfully and with permission, without accessing real patient data. Editors may ask to see disclosure correspondence and may require technical details to be removed or delayed.

Data protection

Authors must handle personal data in line with India’s Digital Personal Data Protection Act, 2023, and other applicable laws such as the EU GDPR and US HIPAA.