International Journal of Medical Informatics
Volume 76, Issue 5 , Pages 471-479, May 2007

Securing electronic health records without impeding the flow of information

  • Rakesh Agrawal

      Affiliations

    • Microsoft Search Labs, 1065 La Avenida, Mountain View, CA 94043, United States
    • Work done while the author was at IBM Almaden Research Center.
    • Corresponding Author InformationCorresponding author.
  • ,
  • Christopher Johnson

      Affiliations

    • IBM Almaden Research Center, 650 Harry Road, San Jose, CA 95120, United States

Abstract 

Objective

We present an integrated set of technologies, known as the Hippocratic Database, that enable healthcare enterprises to comply with privacy and security laws without impeding the legitimate management, sharing, and analysis of personal health information.

Approach

The Hippocratic Database approach to securing electronic health records involves (1) active enforcement of fine-grained data disclosure policies using query modification techniques, (2) efficient auditing of past database access to verify compliance with policies and track security breaches, (3) data mining algorithms that preserve privacy by randomizing information at the individual level, (4) de-identification of personal health data using an optimal method of k-anonymization, and (5) information sharing across autonomous data sources using cryptographic protocols.

Conclusions

Our research confirms that policies concerning the disclosure of electronic health records can be reliably and efficiently enforced and audited at the database level. We further demonstrate that advanced data mining and anonymization techniques can be employed to analyze aggregate health records without revealing individual patient identities. Finally, we show that web services and commutative encryption can be used to share sensitive information selectively among autonomous entities without compromising security or privacy.

Keywords: Security, Privacy, Electronic health record, Auditing, Anonymization, Data mining

To access this article, please choose from the options below

Login to an existing account or Register a new account.

  • Purchase this article for 31.50 USD (You must login/register to purchase this article)

    Online access for 24 hours. The PDF version can be downloaded as your permanent record.

  • Subscribe to this title

    Get unlimited online access to this article and all other articles in this title 24/7 for one year.

  • Claim access now

    For current subscribers with Society Membership or Account Number.

  • Visit SciVerse ScienceDirect to see if you have access via your institution.
 

PII: S1386-5056(06)00220-6

doi:10.1016/j.ijmedinf.2006.09.015

International Journal of Medical Informatics
Volume 76, Issue 5 , Pages 471-479, May 2007