Earlier quoted context omitted.
Why don't you include a step where you ask patients if they're ok with their medical history being put in a public s3 bucket ? I'm fully supportive of the right to pseudonymous speech, but it strikes me that you are in an awfully awkward position of speaking anonymously while demanding that you should have access a trove of patient history without signing any sort of data use agreement and without even the most basic…
Ok, why not, this is what I propose: Asking the user: "This record is going to be shared publicly, do you agree to share this information (without revealing your name and address) ? > [...] This information can help researchers, doctors and people interested into science to discover new information about drugs and diseases interaction."
That is WAY harder that it sounds. When you add public disclosure of mismatch between results on public data and private (full) data things are even harder.
Specifically: suppose an independent researcher determines X is true via statistical test Y on the public dataset. Officials must respond, and say "True" or "False".
A small number of queries via this process can be used to infer data that makes re-identification possible. And there will be many more than a small number of queries, including from adversarial agents specifically designing queries to maximize information gain based on previous (public) revelations.
This is a game, in the game theory sense, in which the goal is to exploit the mathematical properties of statistical tests and social dynamics to force public revelations of binary assessments that yield information about individual cells or sets of cells and make re-id possible.
Have you actually studied this stuff, designed de-anonymization protocols, developed re-id threat models, thought about privacy budgets in public disclosure mandates, and at last put your reputation and your customer's privacy on the line when asserting that your statistical methods are resilient against attacks? Or are you just a jawboning know-it-all anonymous coward without any actual experience balancing privacy against public disclosure?
To be honest, all of your posts read like "just stop writing vulnerable software and then there will be no more hackers mmmkay?"