# Privacy-preserving linkage tokens for every cancer data holder

Source: https://onco.cc/ideas/idea-data-privacy-preserving-linkage-tokens/  
OnCo record `idea-data-privacy-preserving-linkage-tokens` (Idea). Data CC BY-NC 4.0, attribute "Data from OnCo (onco.cc)"; commercial use needs a licence.

## TL;DR

Give each patient a scrambled code that is the same across hospitals, labs and registries, so records can be joined without anyone seeing names.

## Summary

Record linkage across holders fails without a shared identifier; where national IDs exist (Nordics) linkage is trivial, elsewhere it is probabilistic and lossy. Privacy-preserving record linkage using salted hashes of identifiers (as used by Datavant in the US and Bloom-filter approaches in Australia and Germany) allows joining without exposing identity. The proposal mandates a common tokenisation scheme, run by a public trusted third party, for all holders of cancer data.

## Fields

- Kind: Idea
- Last checked: 2026-09-08
- Hypothesis: A common token will raise linkage rates between registries, genomic labs and hospitals from below 70 percent (probabilistic) to above 97 percent, at no measurable privacy cost.
- Rationale: Where national identifiers exist, near-complete linkage has powered decades of registry research; tokens replicate the function without a national ID.
- Proposed test: Tokenise one registry, one genomic lab and one hospital system; measure linkage rate against a gold-standard manually linked subset.
- Maturity: early-clinical
- Actor: data

## Sources

- Bottleneck evidence (Data silos): AACR Project GENIE: https://www.aacr.org/professionals/research/aacr-project-genie/

## Connected records

- fronts: [AI & Computation](https://onco.cc/fronts/ai-computation/)
- bottlenecks: [Data silos](https://onco.cc/bottlenecks/b-data-silos/)

---
JSON: https://onco.cc/api/v1/entities/idea-data-privacy-preserving-linkage-tokens.json