On XACML's adequacy to specify and to enforce HIPAA

  • Authors:
  • Omar Chowdhury;Haining Chen;Jianwei Niu;Ninghui Li;Elisa Bertino

  • Affiliations:
  • The University of Texas at San Antonio, San Antonio, TX;Purdue University, West Lafayette, IN;The University of Texas at San Antonio, San Antonio, TX;Purdue University, West Lafayette, IN;Purdue University, West Lafayette, IN

  • Venue:
  • HealthSec'12 Proceedings of the 3rd USENIX conference on Health Security and Privacy
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

In the medical sphere, personal and medical information is collected, stored, and transmitted for various purposes, such as, continuity of care, rapid formulation of diagnoses, and billing. Many of these operations must comply with federal regulations like the Health Insurance Portability and Accountability Act (HIPAA). To this end, we need a specification language that can precisely capture the requirements of HIPAA. We also need an enforcement engine that can enforce the privacy policies specified in the language. In the current work, we evaluate eXtensible Access Control Markup Language (XACML) as a candidate specification language for HIPAA privacy rules. We evaluate XACML based on the set of features required to sufficiently express HIPAA, proposed by a prior work. We also discuss which of the features necessary for expressing HIPAA are missing in XACML. We then present high level designs of how to enhance XACML's enforcement engine to support the missing features.