Bristol Institute of Technology, UWE, Frenchay Campus, Coldharbour Lane, Bristol BS16 1QY, UK.
Philos Trans A Math Phys Eng Sci. 2010 Sep 13;368(1926):4057-72. doi: 10.1098/rsta.2010.0169.
The sharing of medical data between different healthcare organizations in Europe must comply with the legislation of the Member State where the data were originally collected. These legal requirements may differ from one state to another. Privacy requirements such as patient consent may be subject to conflicting conditions between different national frameworks as well as between different legal and ethical frameworks within a single Member State. These circumstances have made the compliance management process in European healthgrids very challenging. In this paper, we present an approach to tackle these issues by relying on several technologies in the semantic Web stack. Our work suggests a direct mapping from high-level legislation on privacy and data protection to operational-level privacy-aware controls. Additionally, we suggest an architecture for the enforcement of these controls on access control models adopted in healthgrid security infrastructures.
在欧洲,不同医疗机构之间共享医疗数据必须符合原始数据收集所在成员国的立法。这些法律要求可能因国家而异。隐私要求(如患者同意)可能受到不同国家框架以及同一成员国内不同法律和道德框架之间相互冲突条件的限制。这些情况使得欧洲健康网格中的合规管理过程极具挑战性。在本文中,我们提出了一种通过语义 Web 堆栈中的几种技术来解决这些问题的方法。我们的工作建议将高级别的隐私和数据保护立法直接映射到操作级别的隐私感知控制。此外,我们还建议了一种架构,用于在健康网格安全基础架构中采用的访问控制模型上执行这些控制。