Privacy-preserving storage and access of medical data through pseudonymization and encryption

  • Authors:
  • Johannes Heurix;Thomas Neubauer

  • Affiliations:
  • SBA Research, Austria;Vienna University of Technology, Institute of Software Technology and Interactive Systems, Austria

  • Venue:
  • TrustBus'11 Proceedings of the 8th international conference on Trust, privacy and security in digital business
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

E-health allows better communication between health care providers and higher availability of medical data. However, the downside of interconnected systems is the increased probability of unauthorized access to highly sensitive records that could result in serious discrimination against the patient. This article provides an overview of actual privacy threats and presents a pseudonymization approach that preserves the patient's privacy and data confidentiality. It allows (direct care) primary use of medical records by authorized health care providers and privacypreserving (non-direct care) secondary use by researchers. The solution also addresses the identifying nature of genetic data by extending the basic pseudonymization approach with queryable encryption.