Patient-Controlled Attribute-Based Encryption for Secure Electronic Health Records System.

In recent years, many countries have been trying to integrate electronic health data managed by each hospital to offer more efficient healthcare services. Since health data contain sensitive information of patients, there have been much research that present privacy preserving mechanisms. However, e...

Descripción completa

Detalles Bibliográficos
Publicado en:Journal of Medical Systems Vol. 40; no. 12; pp. 1 - 17
Autores principales: Eom, Jieun, Lee, Dong, Lee, Kwangsu
Formato: equations & formulas tables/charts Journal Article
Publicado: Springer Nature Dec2016
Acceso en línea:Ver este registro en EBSCOhost
Descripción
Sumario:In recent years, many countries have been trying to integrate electronic health data managed by each hospital to offer more efficient healthcare services. Since health data contain sensitive information of patients, there have been much research that present privacy preserving mechanisms. However, existing studies either require a patient to perform various steps to secure the data or restrict the patient to exerting control over the data. In this paper, we propose patient-controlled attribute-based encryption, which enables a patient (a data owner) to control access to the health data and reduces the operational burden for the patient, simultaneously. With our method, the patient has powerful control capability of his/her own health data in that he/she has the final say on the access with time limitation. In addition, our scheme provides emergency medical services which allow the emergency staffs to access the health data without the patient's permission only in the case of emergencies. We prove that our scheme is secure under cryptographic assumptions and analyze its efficiency from the patient's perspective.