{"title":"Addressing Privacy in a Federated Identity Management Network for EHealth","authors":"L. Peyton, Jun Hu, Chintan Doshi, P. Seguin","doi":"10.1109/WCMEB.2007.34","DOIUrl":null,"url":null,"abstract":"E-health networks can provide integrated services to patients and health care workers that are more broadly accessible by leveraging Internet technology and electronic health records. However, issues of security and privacy must be addressed. In particular, compliance with relevant privacy legislation must be established. Federated identity management can enable users and service providers to securely and systematically manage identities and user profiles in a single sign on framework that controls access to personal information. In this paper, we use a simple ePrescription scenario to analyze the business and technical issues that need to be addressed in a Liberty Alliance federated identity management framework. We look at the potential impact of privacy compliance on three existing components of the framework (Discovery Service, Identity Mapping Service, Interaction Service) as well as a fourth component (Audit Service) that has been proposed to address potential privacy breeches in Liberty Alliance.","PeriodicalId":140908,"journal":{"name":"Eighth World Congress on the Management of eBusiness (WCMeB 2007)","volume":"85 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2007-07-11","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"26","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Eighth World Congress on the Management of eBusiness (WCMeB 2007)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/WCMEB.2007.34","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 26
Abstract
E-health networks can provide integrated services to patients and health care workers that are more broadly accessible by leveraging Internet technology and electronic health records. However, issues of security and privacy must be addressed. In particular, compliance with relevant privacy legislation must be established. Federated identity management can enable users and service providers to securely and systematically manage identities and user profiles in a single sign on framework that controls access to personal information. In this paper, we use a simple ePrescription scenario to analyze the business and technical issues that need to be addressed in a Liberty Alliance federated identity management framework. We look at the potential impact of privacy compliance on three existing components of the framework (Discovery Service, Identity Mapping Service, Interaction Service) as well as a fourth component (Audit Service) that has been proposed to address potential privacy breeches in Liberty Alliance.