Privacy aware access controls for medical data disclosure on European healthgrids
- PMID: 20543423
Privacy aware access controls for medical data disclosure on European healthgrids
Abstract
To be processed within a healthgrid environment, medical data goes through a complete lifecycle and several stages until it is finally used for the primary reason it has been collected for. This stage is not always the final occurrence of when the data would have been manipulated. The data could rather continue to be needed for secondary purposes of legitimate or non legitimate nature. Although other privacy issues are related to the processing of patient data while it is residing on a healthgrid environment, the control of data disclosure is our primary interest. When sharing medical data between different Healthcare and biomedical research organizations in Europe, it is important that the different parties involved in the sharing handle the data in the same way indicated by the legislation of the member state where the data was originally collected as the requirements might differ from one state to another. Privacy requirements, such as patient consent, may be subject to conflicting conditions between different national frameworks as well as between different legal and ethical frameworks within a single member state. These circumstances have made the compliance management process in European healthgrid very challenging. In this paper we are presenting an approach to tackle these issues by relying on several technologies contained in the semantic web stack. Our work suggests a direct mapping from high level legislation on privacy and data protection to operational level privacy aware controls. Additionally we suggest an architecture for the enforcement of these controls on access control models adopted by healthgrids security infrastructures.
Similar articles
-
Privacy compliance and enforcement on European healthgrids: an approach through ontology.Philos Trans A Math Phys Eng Sci. 2010 Sep 13;368(1926):4057-72. doi: 10.1098/rsta.2010.0169. Philos Trans A Math Phys Eng Sci. 2010. PMID: 20679122
-
Modelling and enforcing privacy for medical data disclosure across Europe.Stud Health Technol Inform. 2009;150:695-9. Stud Health Technol Inform. 2009. PMID: 19745400
-
Ontology-based privacy compliance on European healthgrid domains.Stud Health Technol Inform. 2009;147:183-9. Stud Health Technol Inform. 2009. PMID: 19593056
-
Securing electronic health records without impeding the flow of information.Int J Med Inform. 2007 May-Jun;76(5-6):471-9. doi: 10.1016/j.ijmedinf.2006.09.015. Epub 2007 Jan 3. Int J Med Inform. 2007. PMID: 17204451 Review.
-
Recommendations for European health data protection legislation.Stud Health Technol Inform. 1996;27:23-52. Stud Health Technol Inform. 1996. PMID: 10172820 Review.
MeSH terms
LinkOut - more resources
Full Text Sources