Disclosures of health databases for secondary purposes is increasing rapidly. In this paper, we develop and evaluate a reidentification risk metric for the case where an intruder wishes to re-identify as many records as possible in a disclosed database. In this case, the intruder is concerned about the overall matching success rate. The metric is evaluated on public and health datasets and recommendations for its use are provided. Categories and Subject Descriptors K.4.1 [Computers and Society]: Public Policy Issues – Privacy. Keywords Identity disclosure, privacy, re-identification risk, disclosure control.