PHeDHA: Protecting Healthcare Data in Health Information Exchanges with Active Data Bundles
Wesam Fadheel, Raed Mahdi Salih, Leszek T. Lilien · 2018
Health Information Exchanges (HIEs) collect and disseminate electronic patient healthcare data (EHRs/EMRs) among different healthcare providers to improve the quality and reduce the cost of healthcare services. However, the dissemination of patient data raises privacy and security concerns due to ease of copying and unauthorized dissemination of electronic data. This paper proposes a HIE system called PHeDHA (Protecting Healthcare Data in HIEs with Active Data Bundles), which provides privacy and security protection for patient data during their transmission via an HIE among different healthcare providers. PHeDHA uses as its basis the scheme named Active Data Bundles with Trusted Third Party (ADB-TTP). As the name suggests, ADB-TTP is based on an integration of a trusted third party (TTP) with Active Data Bundles (ADBs). An ADB is a software object that keeps patient healthcare data as sensitive data; includes metadata describing these sensitive data and prescribing their use (via data access and privacy policies specified within metadata); and encompasses a policy enforcement engine (called a virtual machine or VM), which controls and manages how the ADB behaves. In particular, the VM assures ADB's data integrity and enforces its policies specified as a part of metadata. We describe and discuss the conceptual model for PHeDHA, based on ADB-TTP. We are currently evaluating PHeDHA via simulation experiments.