{"title":"Applying a Threshold Scheme to the Pseudonymization of Health Data","authors":"Bernhard Riedl, V. Grascher, T. Neubauer","doi":"10.1109/PRDC.2007.24","DOIUrl":null,"url":null,"abstract":"Due to the cost pressure on the health care system an increase in the need for electronic healthcare records (EHR) could be observed in the last decade because EHRs promise massive savings by digitizing and centrally providing medical data. As highly sensitive patient information is exchanged and stored within such a system, legitimate concerns about the privacy of the stored data occur, as the lifelong storage of medical data is a promising target for attackers. These concerns and the lack of existing approaches that provide a sufficient level of security raise the need for a system that guarantees data privacy and keeps the access to health data under strict control of the patient. This paper introduces PIPE (Pseudonymization of Information for Privacy in e-Health), a new EHR architecture for primary and secondary usage of health data. PIPE's security model is based on pseudonymization instead of encryption.","PeriodicalId":183540,"journal":{"name":"13th Pacific Rim International Symposium on Dependable Computing (PRDC 2007)","volume":"14 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2007-12-17","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"67","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"13th Pacific Rim International Symposium on Dependable Computing (PRDC 2007)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/PRDC.2007.24","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 67
Abstract
Due to the cost pressure on the health care system an increase in the need for electronic healthcare records (EHR) could be observed in the last decade because EHRs promise massive savings by digitizing and centrally providing medical data. As highly sensitive patient information is exchanged and stored within such a system, legitimate concerns about the privacy of the stored data occur, as the lifelong storage of medical data is a promising target for attackers. These concerns and the lack of existing approaches that provide a sufficient level of security raise the need for a system that guarantees data privacy and keeps the access to health data under strict control of the patient. This paper introduces PIPE (Pseudonymization of Information for Privacy in e-Health), a new EHR architecture for primary and secondary usage of health data. PIPE's security model is based on pseudonymization instead of encryption.
由于医疗保健系统的成本压力,在过去十年中可以观察到对电子医疗记录(EHR)的需求增加,因为电子医疗记录承诺通过数字化和集中提供医疗数据来节省大量费用。由于高度敏感的患者信息在这样的系统中交换和存储,因此对存储数据的隐私产生了合理的担忧,因为医疗数据的终身存储是攻击者很有希望的目标。这些问题以及缺乏提供足够安全级别的现有方法,使人们需要一个系统来保证数据隐私,并使对健康数据的访问处于患者的严格控制之下。本文介绍了PIPE (Pseudonymization of Information for Privacy in e-Health),这是一种新的电子病历体系结构,用于医疗数据的主要和次要使用。PIPE的安全模型基于假名而不是加密。