Abstract
Confidentiality is the professional and ethical obligation to protect information a person discloses within a trusted relationship, releasing it only with consent or under a recognized exception. In clinical psychology and medicine it is both a duty owed to the patient and a precondition of effective care, because people disclose sensitive information only when they trust it will be held. This article examines what confidentiality is, the principles that ground it, the narrow circumstances that override it, and the evidence that assurances change what patients are willing to reveal. It then turns to the modern problem of protecting privacy in shared data, where formal models such as k-anonymity quantify re-identification risk. Three interactive demonstrations let the reader balance disclosure against a duty to protect, vary confidentiality assurances, and generalize a dataset until re-identification becomes unlikely.
Keywords: confidentiality, privacy, duty to protect, k-anonymity
Confidentiality is the obligation to safeguard information entrusted to a professional within a relationship of trust, disclosing it only with the discloser’s consent or under a narrowly defined exception recognized by ethics or law. It is one of the oldest commitments in the helping professions, articulated in the Hippocratic oath and carried into every modern code of psychological and medical ethics, and it is distinct from the broader idea of privacy from which it descends. Privacy, in the classic formulation of Samuel Warren and Louis Brandeis, is a person’s right “to be let alone,” a general interest in controlling access to oneself (Warren & Brandeis, 1890). Confidentiality is the narrower, relational duty that arises once private information has already been shared with a professional: it governs what the recipient may then do with it. That duty is not absolute. It is, in the language of moral philosophy, a prima facie obligation, one that binds strongly but can be outweighed by a competing duty of sufficient weight, such as the protection of an endangered third party (Beauchamp & Childress, 2019). Understanding confidentiality therefore means understanding both why it matters and when, exactly, it yields.
- Confidentiality is the relational duty to protect information disclosed in trust; it descends from, but is narrower than, the general right to privacy.
- It is a prima facie obligation, binding strongly yet capable of being overridden by a weightier duty such as protecting an identifiable person from serious harm.
- The duty to protect, established by the Tarasoff litigation, requires both a serious threat and an identifiable victim before confidentiality yields, and then only to the minimum extent needed.
- Assurances of confidentiality measurably increase what patients, especially adolescents, are willing to disclose, so confidentiality is instrumental to care and not merely a courtesy.
- Protecting privacy in shared data is a formal problem: removing names is not enough, because combinations of quasi-identifiers can re-identify people, which models such as k-anonymity are designed to quantify and prevent.
What Confidentiality Is
Confidentiality is best understood as a rule governing the flow of information across the boundary of a trusted relationship. When a patient tells a psychologist something, that information does not become the professional’s to use freely; it remains, in an important sense, the patient’s, and the professional holds it under an obligation of nondisclosure. Sissela Bok, in her philosophical study of secrecy, located this obligation in the ethics of concealment and revelation more generally, arguing that a promise of confidentiality creates a genuine moral claim precisely because the discloser has surrendered control over information in reliance on it (Bok, 1983). The duty rests on several distinct justifications that a well-known analysis in professional psychology has separated out: respect for the patient’s autonomy and privacy, the fidelity owed within a professional relationship, and the consequentialist argument that confidentiality produces better outcomes because it enables candor (Fisher, 2008). These justifications usually point the same way, but they can diverge, and when they do the professional must decide which consideration governs, which is why confidentiality is treated as a duty to be weighed rather than a rule to be applied mechanically (Donner et al., 2008).
It is worth distinguishing three terms that are often conflated. Privacy is the underlying interest in controlling access to oneself and one’s information. Confidentiality is the professional’s corresponding duty not to re-disclose what was shared in trust. Privilege is the narrower legal rule that protects certain confidential communications, such as those between a patient and a psychotherapist, from being compelled as evidence in court. A single conversation can therefore be private in interest, confidential in ethics, and privileged in law all at once, and a professional may find that the three concepts do not align in a given case.
Because the term covers several related but separate obligations, it is useful to see the kinds distinguished by formal indexing side by side before taking the topic further. Table 1 lays them out.
Types of Confidentiality
The Medical Subject Headings (MeSH) thesaurus, which the U.S. National Library of Medicine uses to index the biomedical literature, files Confidentiality beneath three broader headings at once, a reflection of the concept’s several homes: Forensic Psychiatry, Patient Rights, and Jurisprudence. This multiple placement is an artifact of indexing rather than a claim about the concept’s essence; MeSH is a classification built to retrieve documents, not a metaphysical taxonomy, and a heading can sit under several parents because articles about it are shelved in several literatures. Beneath Confidentiality, MeSH distinguishes five narrower descriptors, summarized in Table 1. They are largely orthogonal: a given case may involve one, several, or none of them, and they carve up the territory along different axes, some concerning the kind of information, others the act of releasing or withholding it. Only the descriptors are listed here; none currently has its own article on this site.
| Descriptor | What it concerns |
|---|---|
| Data Anonymization | Removing or masking identifiers so that a record can no longer be traced to the individual it describes. |
| Disclosure | The release of confidential information to a third party, whether authorized by consent or compelled by law. |
| Duty to Warn | A clinician’s obligation to breach confidentiality in order to warn or protect a third party endangered by a patient. |
| Genetic Privacy | Protection of an individual’s genetic information, which uniquely implicates biological relatives as well as the person tested. |
| Personally Identifiable Information | Any data element that alone, or combined with others, can single out a specific person. |
Note. Descriptors and their placement are drawn from the 2026 MeSH release. The kinds are orthogonal, not mutually exclusive; a single case can engage several at once, and MeSH placement reflects how the literature is indexed rather than a strict conceptual hierarchy.
The Ethical Foundations
Why does confidentiality bind so strongly? The most influential framework in biomedical ethics grounds it in the four principles of respect for autonomy, beneficence, nonmaleficence, and justice, and treats confidentiality as an obligation derived chiefly from autonomy and fidelity (Beauchamp & Childress, 2019). On this view, to disclose what a person told me in confidence is to override their control over their own information and to break an implicit promise, both of which are wrongs even when no tangible harm results. A second, consequentialist justification runs alongside the first: confidentiality is protected because the practice of medicine and psychotherapy depends on it. A patient who fears exposure will withhold the very information a clinician needs, so a regime of confidentiality is defended not only as a right but as an instrument that makes candor, and therefore effective care, possible (Fisher, 2008). These strands are usually mutually reinforcing, but the professional literature stresses that they can conflict, and that resolving such conflicts is a matter of judgment rather than rule-following, requiring the clinician to weigh privacy against protection case by case (Donner et al., 2008).
That confidentiality dilemmas are not rare edge cases was established empirically by a national survey of psychologists, who reported that questions about confidentiality, and especially about when to break it, were among the most frequent and troubling ethical problems they encountered in practice (Pope & Vetter, 1992). The survey helped move confidentiality from an abstract principle to a recognized site of routine professional difficulty, and it motivated much of the later work on how the duty should be structured and taught.
Limits and the Duty to Protect
Confidentiality yields most clearly when a patient poses a serious danger to an identifiable other person. The doctrine took its modern shape from the California litigation in Tarasoff v. Regents of the University of California, in which a therapist’s patient killed a young woman he had earlier told the therapist he intended to harm. The court held that the protective privilege ends where the public peril begins, imposing on clinicians a duty to take reasonable steps to protect a foreseeable victim, which may include warning the intended target or notifying the police. The clinical and legal literature has since worked out how this duty should be applied, stressing that it is triggered narrowly and that a clinician confronting a threat must assess both its seriousness and the identifiability of the person at risk before overriding confidentiality (Appelbaum, 1985). The two conditions are jointly necessary: a vague threat against no one in particular does not trigger the duty, and neither does a named person who is under no genuine threat. Only when a serious risk and an identifiable victim coincide does the seal give way, and even then the clinician is expected to disclose no more than the situation requires. The demonstration below makes that joint condition concrete.
The duty to protect: two conditions, not one
Beyond the duty to protect, every jurisdiction recognizes a set of standing exceptions in which disclosure is permitted or mandated: the reporting of suspected child abuse, responses to certain court orders, and situations in which a patient is at imminent risk of self-harm. What unites these exceptions is that each represents a competing duty judged, by legislatures or courts, to be weighty enough to override the presumption in favor of confidentiality. The default, however, remains nondisclosure, and the burden always falls on the reason to breach, never on the reason to keep faith.
Confidentiality and What Patients Disclose
The consequentialist defense of confidentiality makes an empirical prediction: if people disclose more when they trust that information will be held, then varying the assurance of confidentiality should change what they are willing to reveal. That prediction has been tested directly, most influentially in adolescent health care, where the stakes are high because young people may avoid care altogether if they fear their parents will be told. In a randomized study, adolescents who were assured of confidentiality reported greater willingness to disclose sensitive information and to seek future health care than those told their parents might be informed, and the effect was concentrated in the most sensitive domains (Ford et al., 1997). Complementary work found the same pattern in the general logic of the therapeutic relationship: when confidentiality is qualified rather than absolute, people report that they would disclose less, particularly about the topics that matter most (Nowell & Spruill, 1993). Qualitative research with patients has added texture, showing that people hold nuanced and sometimes conditional views about medical confidentiality, valuing it highly while accepting that it has limits (Jenkins et al., 2005). The interactive figure below illustrates the central finding: assurance moves the sensitive topics most and leaves routine care largely untouched.
Confidentiality assurance and willingness to disclose
This body of evidence reframes confidentiality as something more than an ethical nicety. It is a working part of the clinical machinery: the assurance that information will be held is one of the conditions that make disclosure, diagnosis, and treatment possible, and weakening it has measurable costs in the care people are willing to seek and the truths they are willing to tell. Practical guidance for psychotherapists accordingly treats the management of confidentiality, including how its limits are explained to a patient at the outset, as a core clinical skill rather than a bureaucratic formality (Younggren & Harris, 2008).
Protecting Privacy in Shared Data
Confidentiality in the era of large datasets raises a problem that the clinical duty alone does not address: how to share information for research and public benefit without exposing the individuals in it. The naive solution, simply deleting names and other obvious identifiers, is not enough, and the reason is one of the foundational results of data privacy. Latanya Sweeney showed that combinations of seemingly innocuous attributes, called quasi-identifiers, can single a person out even after direct identifiers are removed. In a famous demonstration, she estimated that the combination of five-digit ZIP code, date of birth, and sex was unique for a large majority of the United States population, so that a de-identified medical record could be re-linked to a named individual by joining it, on those quasi-identifiers, to a publicly available record such as a voter roll (Sweeney, 2002). Figure 1 sketches that re-identification attack.
Figure 1
Re-identification by Linking on Quasi-Identifiers
Sweeney’s response was the model of k-anonymity: a release satisfies k-anonymity if every record is indistinguishable, on its quasi-identifiers, from at least k minus one others, so that each person hides in a crowd of at least k look-alikes and the worst-case chance of pinpointing anyone is at most one in k (Sweeney, 2002). The crowd is enlarged by generalization, coarsening precise values into ranges, and by suppression, deleting the most stubborn fields. The demonstration below lets the reader raise the generalization level on a small table of synthetic records and watch the smallest crowd, and hence the re-identification risk, change; the Worked Example that follows traces the arithmetic by hand.
k-anonymity: hiding in a crowd of look-alikes
| Age | ZIP | Sex | Crowd size |
|---|---|---|---|
| 25 | 47906 | F | 1 |
| 27 | 47907 | F | 1 |
| 29 | 47901 | F | 1 |
| 33 | 47902 | M | 1 |
| 35 | 47905 | M | 1 |
| 22 | 47301 | F | 1 |
| 24 | 47304 | F | 1 |
| 38 | 47306 | M | 1 |
Worked Example
Consider the eight synthetic records in the interactive table above, each carrying an age, a five-digit ZIP code, and a sex alongside a (hidden) diagnosis. At generalization level 0 the quasi-identifiers are left raw. Every one of the eight rows is then unique, so the smallest equivalence class has size one, k equals 1, and the worst-case re-identification risk is 100 divided by 1, or 100 percent: an attacker who knows a target’s exact age, ZIP, and sex can pick them out with certainty. This is the situation Sweeney warned of, and it holds even though no names appear in the table.
Now raise the generalization to level 3. Age is coarsened into twenty-year bands, so every record falls into the single band 20 to 39; the ZIP is truncated to its first two digits, so all eight become 47 followed by three asterisks; and sex is still shown. The records now differ only by sex. Five of the eight are female and three are male, so there are just two equivalence classes, of sizes five and three. The smallest is the male class, giving k equals 3 and a worst-case risk of 100 divided by 3, or about 33.3 percent: the best an attacker can now do, knowing only the generalized quasi-identifiers, is narrow a target to one of three people.
Push one step further, to level 4. Age is suppressed to an asterisk, the ZIP is cut to a single leading digit, and sex too is suppressed. Every record now reads identically on its quasi-identifiers, so all eight collapse into one equivalence class. The smallest crowd is the whole dataset, k equals 8, and the worst-case risk falls to 100 divided by 8, or 12.5 percent. The progression from 100 percent to 33.3 percent to 12.5 percent shows the fundamental trade-off of anonymization exactly: each increase in k buys privacy by destroying detail, and because sex was the last quasi-identifier to be suppressed, the risk held steady at the level-3 value until that final field fell away. Choosing k is therefore choosing a point on the curve between privacy and usefulness, not finding a setting that gives both at once.
Discussion
Confidentiality is a rare instance in which an ancient ethical commitment, a body of case law, an empirical research program, and a branch of computer science all converge on a single object. The ethical tradition supplies the reason the duty binds: it protects autonomy and fidelity, and it is a prima facie obligation that yields only to a weightier one. The law, through the Tarasoff line and the statutory exceptions, specifies the narrow conditions of that yielding and insists they be met before the seal is broken. The empirical literature shows why the stakes are practical as well as moral, because confidentiality demonstrably shapes what patients will disclose and whether they will seek care at all. And the data-privacy literature shows that keeping confidence in a world of linked databases is a technical problem with technical solutions and technical limits, since removing names protects no one when quasi-identifiers remain. What these strands share is a recognition that confidentiality is not a single bright line but a structured judgment: a strong default in favor of nondisclosure, a small set of principled exceptions, and, increasingly, a quantitative account of how much protection a given release actually provides. The open problems are correspondingly varied, from the perennial difficulty of teaching clinicians to reason about exceptions rather than to memorize them, to the harder question of what confidentiality can mean when sensitive information flows through devices and platforms that were never bound by a professional oath.
Current Directions
The most active work on confidentiality concerns the migration of sensitive disclosure out of the consulting room and into digital systems. Mental-health care increasingly happens through apps, teletherapy platforms, and wearable sensors, and a growing literature warns that these channels raise privacy risks with no clear counterpart in traditional practice, from data brokers to breaches to secondary uses that patients never contemplated (Lustgarten et al., 2020). Direct-to-consumer digital psychotherapy applications sharpen the concern, because they often operate outside the professional-ethics framework that governs licensed clinicians, so that questions of accountability, data protection, and meaningful consent must be rebuilt for a commercial context (Martinez-Martin & Kreitmair, 2018). In adolescent medicine, where confidentiality is most consequential, the spread of electronic health records and patient portals has created a concrete tension between a young person’s confidentiality and a parent’s access, forcing a rethinking of how longstanding confidentiality protections are implemented in shared record systems (Maslyanskaya & Alderman, 2019). Running beneath these applied questions is a continuing theoretical effort to understand confidentiality as the management of information boundaries between people; communication privacy management theory treats private information as jointly owned once it is shared, with negotiated rules about who may re-disclose it, and recent work has refined how that framework is defined and measured (Petronio & Child, 2020). The common thread is that the principle is settled while its implementation is not: the duty to hold what is disclosed in trust is being renegotiated for systems in which information moves further, faster, and to more parties than any oath anticipated.
Common Misconceptions
- Confidentiality is absolute; a professional can never disclose what a patient says.
- It is a prima facie duty, strong but not unconditional, and it yields to a weightier obligation such as protecting an identifiable person from serious harm (Beauchamp & Childress, 2019). The duty to protect established by the Tarasoff litigation is the clearest such limit (Appelbaum, 1985).
- Confidentiality, privacy, and privilege all mean the same thing.
- Privacy is the general interest in controlling access to oneself (Warren & Brandeis, 1890); confidentiality is the professional’s duty not to re-disclose what was shared in trust (Fisher, 2008); privilege is the narrower legal rule shielding certain communications from being compelled in court. A single disclosure can engage all three, and they need not align.
- Confidentiality is a courtesy, not something that affects outcomes.
- Assurances of confidentiality measurably increase what patients disclose and whether they seek care, an effect demonstrated in a randomized trial with adolescents (Ford et al., 1997) and echoed in analog research on the therapeutic relationship (Nowell & Spruill, 1993).
- Deleting names makes health data anonymous.
- Combinations of quasi-identifiers such as ZIP code, birth date, and sex can re-identify most people even after names are removed, by linkage to public records (Sweeney, 2002). Genuine anonymization requires generalization or suppression sufficient to satisfy a model such as k-anonymity.
Glossary
- Anonymization.
- The process of removing or altering identifiers in a dataset so that records can no longer be traced to the individuals they describe.
- Beneficence.
- The ethical principle of acting for the benefit of others; one of the four principles of biomedical ethics that bear on confidentiality.
- Confidentiality.
- The professional and ethical obligation to protect information disclosed within a trusted relationship, releasing it only with consent or under a recognized exception.
- Disclosure.
- The release of confidential information to a third party, whether authorized by the discloser’s consent or compelled by law.
- Duty to protect.
- A clinician’s obligation to take reasonable steps, which may include breaching confidentiality, to protect an identifiable person threatened by a patient.
- Equivalence class.
- In k-anonymity, the set of records that share identical values on all quasi-identifiers and are therefore indistinguishable from one another.
- Generalization.
- Coarsening precise data values into broader categories or ranges to enlarge equivalence classes and reduce re-identification risk.
- Genetic privacy.
- The protection of an individual’s genetic information, which is distinctive because it also implicates biological relatives.
- k-anonymity.
- A privacy model under which every record is indistinguishable, on its quasi-identifiers, from at least k minus one others, capping worst-case re-identification risk at one in k.
- Prima facie duty.
- An obligation that binds unless it is outweighed by a stronger competing obligation; the standard characterization of confidentiality in ethics.
- Privacy.
- The general interest in controlling access to oneself and one’s information; the broader concept from which confidentiality descends.
- Privilege.
- The legal rule protecting certain confidential communications, such as those in psychotherapy, from being compelled as evidence in court.
- Quasi-identifier.
- An attribute, such as ZIP code, birth date, or sex, that is not identifying on its own but can single out a person in combination with others.
- Re-identification.
- The re-attaching of a person’s identity to a supposedly anonymous record, typically by linking it to another dataset on shared quasi-identifiers.
- Suppression.
- Deleting or masking a data value entirely, the most aggressive anonymization step, used when generalization alone cannot enlarge a crowd.
- Tarasoff.
- The California litigation that established the clinician’s duty to protect a foreseeable victim, the paradigmatic limit on confidentiality.
Key Researchers
Paul S. Appelbaum (b. 1951). Professor of psychiatry, medicine, and law at Columbia University; a leading authority on the legal regulation of psychiatry whose analyses of the duty to protect clarified how clinicians should apply the Tarasoff ruling in practice. ORCID - Google Scholar - Faculty Page - Wikipedia
Thomas L. Beauchamp (1939-2025). Philosopher at Georgetown University’s Kennedy Institute of Ethics; with James Childress he authored Principles of Biomedical Ethics, the framework that grounds confidentiality in respect for autonomy and fidelity. Faculty Page - Wikipedia
Sissela Bok (b. 1934). Philosopher affiliated with the Harvard Center for Population and Development Studies; her book Secrets gave the ethics of concealment and revelation, including the moral force of a promise of confidentiality, its most influential modern treatment. Faculty Page - Wikipedia
Louis D. Brandeis (1856-1941). Later a U.S. Supreme Court justice; with Samuel Warren he wrote “The Right to Privacy,” the 1890 law-review article that first articulated privacy as a legal right to be let alone. Wikipedia - Wikidata
James F. Childress (b. 1940). Professor of religious studies and ethics at the University of Virginia; co-author of Principles of Biomedical Ethics and a central figure in the principlist tradition that structures how confidentiality is weighed against competing duties. Faculty Page - Wikipedia
Carol A. Ford. Adolescent-medicine physician at the University of Pennsylvania and the Children’s Hospital of Philadelphia; her randomized research demonstrated that assurances of confidentiality increase adolescents’ willingness to disclose and to seek care. Faculty Page
Sandra Petronio (1949-2024). Communication scholar at Indiana University–Purdue University Indianapolis; she developed communication privacy management theory, which models private information as jointly owned and governed by negotiated rules of disclosure. Google Scholar - Wikidata
Latanya Sweeney. Professor of the practice of government and technology at Harvard University; her work on re-identification and the k-anonymity model founded the modern computer science of data privacy and showed that removing names does not make data anonymous. Faculty Page - Wikipedia - Wikidata
Frequently Asked Questions
What is confidentiality? Confidentiality is the professional and ethical obligation to protect information a person discloses within a trusted relationship, releasing it only with the person’s consent or under a recognized exception. It is a cornerstone of psychology and medicine because effective care depends on candid disclosure (Fisher, 2008).
How is confidentiality different from privacy? Privacy is the broad interest in controlling access to oneself and one’s information, famously described as the right to be let alone (Warren & Brandeis, 1890). Confidentiality is the narrower, relational duty that arises after private information has been shared with a professional, governing what that professional may then do with it.
Is confidentiality ever allowed to be broken? Yes. Confidentiality is a prima facie duty, meaning it binds strongly but can be outweighed by a weightier obligation (Beauchamp & Childress, 2019). Recognized exceptions include the duty to protect an identifiable person from serious harm, the mandatory reporting of child abuse, and certain court orders.
What is the duty to protect? It is the clinician’s obligation, established by the Tarasoff litigation, to take reasonable steps to protect a foreseeable victim when a patient poses a serious threat to an identifiable person (Appelbaum, 1985). Both a serious threat and an identifiable target are required before confidentiality yields, and then only to the minimum extent necessary.
Does confidentiality actually change what patients tell their clinicians? It does. In a randomized study, adolescents assured of confidentiality reported greater willingness to disclose sensitive information and to seek future care than those told their parents might be informed (Ford et al., 1997). The effect is largest for the most sensitive topics.
Why is removing names not enough to anonymize data? Because combinations of quasi-identifiers such as ZIP code, birth date, and sex can single out most individuals, allowing a de-identified record to be re-linked to a named person through public data (Sweeney, 2002). Real anonymization requires further steps such as generalization and suppression.
What is k-anonymity? It is a privacy model requiring that every record be indistinguishable, on its quasi-identifiers, from at least k minus one others, so each person hides in a crowd of at least k look-alikes and the worst-case chance of re-identifying anyone is at most one in k (Sweeney, 2002). Larger values of k give more privacy at the cost of detail.
How is confidentiality changing in the digital age? Sensitive information increasingly flows through apps, teletherapy platforms, and electronic records that were never bound by a professional oath, raising new risks around data protection, consent, and secondary use (Lustgarten et al., 2020; Martinez-Martin & Kreitmair, 2018). The underlying duty is unchanged, but its implementation is being renegotiated for these systems.
References
Appelbaum, P. S. (1985). Tarasoff and the clinician: Problems in fulfilling the duty to protect. American Journal of Psychiatry, 142(4), 425-429. https://doi.org/10.1176/ajp.142.4.425
Beauchamp, T. L., & Childress, J. F. (2019). Principles of biomedical ethics (8th ed.). Oxford University Press.
Bok, S. (1983). Secrets: On the ethics of concealment and revelation. Pantheon Books.
Donner, M. B., VandeCreek, L., Gonsiorek, J. C., & Fisher, C. B. (2008). Balancing confidentiality: Protecting privacy and protecting the public. Professional Psychology: Research and Practice, 39(3), 369-376. https://doi.org/10.1037/0735-7028.39.3.369
Fisher, M. A. (2008). Protecting confidentiality rights: The need for an ethical practice model. American Psychologist, 63(1), 1-13. https://doi.org/10.1037/0003-066X.63.1.1
Ford, C. A., Millstein, S. G., Halpern-Felsher, B. L., & Irwin, C. E. (1997). Influence of physician confidentiality assurances on adolescents’ willingness to disclose information and seek future health care: A randomized controlled trial. JAMA, 278(12), 1029-1034. https://doi.org/10.1001/jama.1997.03550120089044
Jenkins, G., Merz, J. F., & Sankar, P. (2005). A qualitative study of women’s views on medical confidentiality. Journal of Medical Ethics, 31(9), 499-504. https://doi.org/10.1136/jme.2004.010280
Lustgarten, S. D., Garrison, Y. L., Sinnard, M. T., & Flynn, A. W. P. (2020). Digital privacy in mental healthcare: Current issues and recommendations for technology use. Current Opinion in Psychology, 36, 25-31. https://doi.org/10.1016/j.copsyc.2020.03.012
Martinez-Martin, N., & Kreitmair, K. (2018). Ethical issues for direct-to-consumer digital psychotherapy apps: Addressing accountability, data protection, and consent. JMIR Mental Health, 5(2), e32. https://doi.org/10.2196/mental.9423
Maslyanskaya, S., & Alderman, E. M. (2019). Confidentiality and consent in the care of the adolescent patient. Pediatrics in Review, 40(10), 508-516. https://doi.org/10.1542/pir.2018-0040
Nowell, D., & Spruill, J. (1993). If it’s not absolutely confidential, will information be disclosed? Professional Psychology: Research and Practice, 24(3), 367-369. https://doi.org/10.1037/0735-7028.24.3.367
Petronio, S., & Child, J. T. (2020). Conceptualization and operationalization: Utility of communication privacy management theory. Current Opinion in Psychology, 31, 76-82. https://doi.org/10.1016/j.copsyc.2019.08.009
Pope, K. S., & Vetter, V. A. (1992). Ethical dilemmas encountered by members of the American Psychological Association: A national survey. American Psychologist, 47(3), 397-411. https://doi.org/10.1037/0003-066X.47.3.397
Sweeney, L. (2002). k-anonymity: A model for protecting privacy. International Journal of Uncertainty, Fuzziness and Knowledge-Based Systems, 10(5), 557-570. https://doi.org/10.1142/S0218488502001648
Warren, S. D., & Brandeis, L. D. (1890). The right to privacy. Harvard Law Review, 4(5), 193-220. https://doi.org/10.2307/1321160
Younggren, J. N., & Harris, E. A. (2008). Can you keep a secret? Confidentiality in psychotherapy. Journal of Clinical Psychology, 64(5), 589-600. https://doi.org/10.1002/jclp.20480