Rahmouni Hanene Boussi, Solomonides Tony, Mont Marco Casassa, Shiu Simon
Bristol Institute of Technology, UWE, Bristol/BS16 1QY.
Stud Health Technol Inform. 2010;159:14-27.
To be processed within a healthgrid environment, medical data goes through a complete lifecycle and several stages until it is finally used for the primary reason it has been collected for. This stage is not always the final occurrence of when the data would have been manipulated. The data could rather continue to be needed for secondary purposes of legitimate or non legitimate nature. Although other privacy issues are related to the processing of patient data while it is residing on a healthgrid environment, the control of data disclosure is our primary interest. When sharing medical data between different Healthcare and biomedical research organizations in Europe, it is important that the different parties involved in the sharing handle the data in the same way indicated by the legislation of the member state where the data was originally collected as the requirements might differ from one state to another. Privacy requirements, such as patient consent, may be subject to conflicting conditions between different national frameworks as well as between different legal and ethical frameworks within a single member state. These circumstances have made the compliance management process in European healthgrid very challenging. In this paper we are presenting an approach to tackle these issues by relying on several technologies contained in the semantic web stack. Our work suggests a direct mapping from high level legislation on privacy and data protection to operational level privacy aware controls. Additionally we suggest an architecture for the enforcement of these controls on access control models adopted by healthgrids security infrastructures.
为了在健康网格环境中进行处理,医疗数据要经历完整的生命周期和多个阶段,直到最终用于其最初收集的主要目的。这个阶段并不总是数据被操纵的最终情况。数据可能会因合法或非法的次要目的而继续被需要。虽然其他隐私问题与患者数据在健康网格环境中的处理有关,但数据披露的控制是我们的主要关注点。当在欧洲不同的医疗保健和生物医学研究组织之间共享医疗数据时,重要的是,参与共享的不同方要按照数据最初收集所在成员国的立法所指示的相同方式处理数据,因为不同国家的要求可能不同。隐私要求,如患者同意,可能在不同国家框架之间以及单个成员国的不同法律和道德框架之间存在冲突的情况。这些情况使得欧洲健康网格中的合规管理过程极具挑战性。在本文中,我们提出一种依靠语义网堆栈中包含的多种技术来解决这些问题的方法。我们的工作建议从隐私和数据保护的高级立法直接映射到操作层面的隐私感知控制。此外,我们建议一种架构,用于在健康网格安全基础设施采用的访问控制模型上实施这些控制。