Privacy-Preserving Personal Health Record (P3HR): A Secure Android Application

Saeed Samet, Mohd Tazim Ishraque, Anupam Sharma
{"title":"Privacy-Preserving Personal Health Record (P3HR): A Secure Android Application","authors":"Saeed Samet, Mohd Tazim Ishraque, Anupam Sharma","doi":"10.1145/3220267.3220271","DOIUrl":null,"url":null,"abstract":"In contrast to the Electronic Medical Record (EMR) and Electronic Health Record (EHR) systems that are created to maintain and manage patient data by health professionals and organizations, Personal Health Record (PHR) systems are operated and managed by patients. Therefore, it necessitates increased attention to the importance of security and privacy challenges, as patients are most often unfamiliar with the potential security threats that can result from release of their health data. On the other hand, the use of PHR systems is increasingly becoming an important part of the healthcare system by sharing patient information among their circle of care. To have a system with a more favorable interface and a high level of security, it is crucial to provide a mobile application for PHR that fulfills six important features: (1) ease the usage for various patient demographics and their delegates, (2) security, (3) quickly transfer patient data to their health professionals, (4) give the ability of access revocation to the patient, (5) provide ease of interaction between patients and their circle of care, and (6) inform patients about any instances of access to their data by their circle of care. In this work, we propose an implementation of a Privacy-Preserving PHR system (P3HR) for Android devices to fulfill the above six characteristics, using a Ciphertext Policy Attribute Based Encryption to enhance security and privacy of the system, as well as providing access revocation in a hierarchical scheme of the health professionals and organizations involved. Using this application, patients can securely store their health data, share the records, and receive feedback and recommendations from their circle of care.","PeriodicalId":177522,"journal":{"name":"International Conference on Software and Information Engineering","volume":"57 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-05-02","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Conference on Software and Information Engineering","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3220267.3220271","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

In contrast to the Electronic Medical Record (EMR) and Electronic Health Record (EHR) systems that are created to maintain and manage patient data by health professionals and organizations, Personal Health Record (PHR) systems are operated and managed by patients. Therefore, it necessitates increased attention to the importance of security and privacy challenges, as patients are most often unfamiliar with the potential security threats that can result from release of their health data. On the other hand, the use of PHR systems is increasingly becoming an important part of the healthcare system by sharing patient information among their circle of care. To have a system with a more favorable interface and a high level of security, it is crucial to provide a mobile application for PHR that fulfills six important features: (1) ease the usage for various patient demographics and their delegates, (2) security, (3) quickly transfer patient data to their health professionals, (4) give the ability of access revocation to the patient, (5) provide ease of interaction between patients and their circle of care, and (6) inform patients about any instances of access to their data by their circle of care. In this work, we propose an implementation of a Privacy-Preserving PHR system (P3HR) for Android devices to fulfill the above six characteristics, using a Ciphertext Policy Attribute Based Encryption to enhance security and privacy of the system, as well as providing access revocation in a hierarchical scheme of the health professionals and organizations involved. Using this application, patients can securely store their health data, share the records, and receive feedback and recommendations from their circle of care.
保护隐私的个人健康记录(P3HR):一个安全的Android应用程序
电子医疗记录(EMR)和电子健康记录(EHR)系统是由卫生专业人员和组织创建的,用于维护和管理患者数据,与之相反,个人健康记录(PHR)系统由患者操作和管理。因此,有必要更多地关注安全和隐私挑战的重要性,因为患者通常不熟悉发布其健康数据可能导致的潜在安全威胁。另一方面,PHR系统的使用正日益成为医疗保健系统的重要组成部分,通过在他们的护理圈中共享患者信息。为了使系统具有更有利的界面和高水平的安全性,提供一个满足以下六个重要特征的PHR移动应用程序至关重要:(1)简化各种患者人口统计数据及其代表的使用,(2)安全性,(3)快速将患者数据转移给他们的卫生专业人员,(4)赋予患者撤销访问权限的能力,(5)提供患者与其护理圈之间交互的便利性,以及(6)告知患者其护理圈访问其数据的任何实例。在这项工作中,我们提出了一种用于Android设备的隐私保护PHR系统(P3HR)的实现,以满足上述六个特征,使用基于密文策略属性的加密来增强系统的安全性和隐私性,并在涉及的卫生专业人员和组织的分层方案中提供访问撤销。使用此应用程序,患者可以安全地存储他们的健康数据,共享记录,并从他们的护理圈接收反馈和建议。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信