Engineering a policy-based system for federated healthcare databases

被引:16
作者
Bhatti, Rafae
Samuel, Arjmand
Eltabakh, Mohamed Y.
Amjad, Haseeb
Ghafoor, Arif
机构
[1] IBM Corp, Almaden Res Ctr, San Jose, CA 95120 USA
[2] Purdue Univ, Sch Elect & Comp Engn, W Lafayette, IN 47907 USA
关键词
federated database security; healthcare engineering; policy-based management; role-based access control;
D O I
10.1109/TKDE.2007.1050
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Policy-based management for federated healthcare systems has recently gained increasing attention due to strict privacy and disclosure rules. Although the work on privacy languages and enforcement mechanisms, such as Hippocratic databases, has advanced our understanding of designing privacy-preserving policies for healthcare databases, the need to integrate these policies in a practical healthcare framework is becoming acute. Additionally, although most work in this area has been organization oriented, dealing with the exchange of information between healthcare organizations (such as referrals), the requirements for the emerging area of personal healthcare information management have so far not been adequately addressed. These shortcomings arise from the lack of a sophisticated policy specification language and enforcement architecture that can capture the requirement for 1) the integration of privacy and disclosure policies with well-known healthcare standards used in the industry in order to specify the precise requirements of a practical healthcare system and 2) the provision of ubiquitous healthcare services to patients using the same infrastructure that enables federated healthcare management for organizations. In this paper, we have designed a policy-based system to mitigate these concerns. First, we have designed our disclosure and privacy policies by using a requirements specification based on a set of use cases for the Clinical Document Architecture (CDA) standard proposed by the community. Second, we present a context-aware policy specification language, which allows encoding of CDA-based requirements use cases into privacy and disclosure policy rules. We have shown that our policy specification language is effective in terms of handling a variety of expressive constraints on CDA-encoded document contents. Our language enables specification of privacy-aware access control for federated healthcare information across organizational boundaries, whereas the use of contextual constraints allows the incorporation of user and environment context in the access control mechanism for personal healthcare information management. Moreover, the declarative syntax of the policy rules makes the policy adaptable to changes in privacy regulations or patient preferences. We also present an enforcement architecture for the federated healthcare framework proposed in this paper.
引用
收藏
页码:1288 / 1304
页数:17
相关论文
共 29 条
[1]  
Abowd GD, 1999, LECT NOTES COMPUT SC, V1707, P304
[2]  
Agrawal R, 2005, PROC INT CONF DATA, P1013
[3]  
AGRAWAL R, 2005, MANAGING DISCLOSURE
[4]  
AGRAWAL R, 2006, P INT MED INF ASS WO
[5]  
ALSCHULER L, 2002, XML
[6]  
[Anonymous], 2005, P 10 ACM S ACC CONTR
[7]  
[Anonymous], IEEE COMPUTER
[8]  
[Anonymous], PLATF PRIV PREF P3P
[9]  
[Anonymous], 2002, P VLDB 02
[10]  
Bhatti R., 2005, ACM Transactions on Information and Systems Security, V8, P388, DOI 10.1145/1108906.1108909