Visible to the public Biblio

Filters: Keyword is personal health records  [Clear All Filters]
2019-01-31
Samet, Saeed, Ishraque, Mohd Tazim, Sharma, Anupam.  2018.  Privacy-Preserving Personal Health Record (P3HR): A Secure Android Application. Proceedings of the 7th International Conference on Software and Information Engineering. :22–26.

In contrast to the Electronic Medical Record (EMR) and Electronic Health Record (EHR) systems that are created to maintain and manage patient data by health professionals and organizations, Personal Health Record (PHR) systems are operated and managed by patients. Therefore, it necessitates increased attention to the importance of security and privacy challenges, as patients are most often unfamiliar with the potential security threats that can result from release of their health data. On the other hand, the use of PHR systems is increasingly becoming an important part of the healthcare system by sharing patient information among their circle of care. To have a system with a more favorable interface and a high level of security, it is crucial to provide a mobile application for PHR that fulfills six important features: (1) ease the usage for various patient demographics and their delegates, (2) security, (3) quickly transfer patient data to their health professionals, (4) give the ability of access revocation to the patient, (5) provide ease of interaction between patients and their circle of care, and (6) inform patients about any instances of access to their data by their circle of care. In this work, we propose an implementation of a Privacy-Preserving PHR system (P3HR) for Android devices to fulfill the above six characteristics, using a Ciphertext Policy Attribute Based Encryption to enhance security and privacy of the system, as well as providing access revocation in a hierarchical scheme of the health professionals and organizations involved. Using this application, patients can securely store their health data, share the records, and receive feedback and recommendations from their circle of care.

2018-09-05
Gardiyawasam Pussewalage, Harsha S., Oleshchuk, Vladimir A..  2017.  A Distributed Multi-Authority Attribute Based Encryption Scheme for Secure Sharing of Personal Health Records. Proceedings of the 22Nd ACM on Symposium on Access Control Models and Technologies. :255–262.
Personal health records (PHR) are an emerging health information exchange model, which facilitates PHR owners to efficiently manage their health data. Typically, PHRs are outsourced and stored in third-party cloud platforms. Although, outsourcing private health data to third-party platforms is an appealing solution for PHR owners, it may lead to significant privacy concerns, because there is a higher risk of leaking private data to unauthorized parties. As a way of ensuring PHR owners' control of their outsourced PHR data, attribute based encryption (ABE) mechanisms have been considered due to the fact that such schemes facilitate a mechanism of sharing encrypted data among a set of intended recipients. However, such existing PHR solutions suffer from inflexibility and scalability issues due to the limitations associated with the adopted ABE mechanisms. To address these issues, we propose a distributed multi-authority ABE scheme and thereby we show how a patient-centric, attribute based PHR sharing scheme which can provide flexible access for both professional users such as doctors as well as personal users such as family and friends is realized. We have shown that the proposed scheme supports on-demand user revocation as well as secure under standard security assumptions. In addition, the simulation results provide evidence for the fact that our scheme can function efficiently in practice. Furthermore, we have shown that the proposed scheme can cater the access requirements associated with distributed multiuser PHR sharing environments as well as more realistic and scalable compared with similar existing PHR sharing schemes.