Health data privacy through homomorphic encryption and distributed ledger computing: an ethical-legal qualitative expert assessment study.

Background: Increasingly, hospitals and research institutes are developing technical solutions for sharing patient data in a privacy preserving manner. Two of these technical solutions are homomorphic encryption and distributed ledger technology. Homomorphic encryption allows computations to be perf...

Descripción completa

Detalles Bibliográficos
Publicado en:BMC Medical Ethics Vol. 23; no. 1; pp. 1 - 14
Autores principales: Scheibner, James, Ienca, Marcello, Vayena, Effy
Formato: Journal Article
Publicado: BioMed Central 12/1/2022
Acceso en línea:Ver este registro en EBSCOhost
fields @attributes:
  recordID: 1
pdfLink:
plink: https://search.ebscohost.com/login.aspx?direct=true&db=ccm&AN=160503796&site=ehost-live
header:
  @attributes:
    shortDbName: ccm
    uiTerm: 160503796
    longDbName: CINAHL Complete
    uiTag: AN
  controlInfo:
    bkinfo:
    dissinfo:
    jinfo:
      jid:
        14726939
        1CHX
      jtl: BMC Medical Ethics
      issn: 14726939
      maglogo: N
    pubinfo:
      dt: 12/1/2022
      vid: 23
      iid: 1
      pid: 24147
      pub: BioMed Central
    artinfo:
      ui:
        160503796
        160503796
        NLM36451210
        10.1186/s12910-022-00852-2
        NLM36451210
        160503796
      ppf: 1
      ppct: 13
      formats:
      tig:
        atl: Health data privacy through homomorphic encryption and distributed ledger computing: an ethical-legal qualitative expert assessment study.
      aug:
        au:
          Scheibner, James
          Ienca, Marcello
          Vayena, Effy
        affil: Health Ethics and Policy Laboratory, Department of Health Sciences and Technology (D-HEST), ETH Zürich, Zurich, Switzerland
      sug:
        subj:
          Privacy and Confidentiality
          Technology
          Dissent and Disputes
          Research Ethics
          Qualitative Studies
          Scales
      ab: Background: Increasingly, hospitals and research institutes are developing technical solutions for sharing patient data in a privacy preserving manner. Two of these technical solutions are homomorphic encryption and distributed ledger technology. Homomorphic encryption allows computations to be performed on data without this data ever being decrypted. Therefore, homomorphic encryption represents a potential solution for conducting feasibility studies on cohorts of sensitive patient data stored in distributed locations. Distributed ledger technology provides a permanent record on all transfers and processing of patient data, allowing data custodians to audit access. A significant portion of the current literature has examined how these technologies might comply with data protection and research ethics frameworks. In the Swiss context, these instruments include the Federal Act on Data Protection and the Human Research Act. There are also institutional frameworks that govern the processing of health related and genetic data at different universities and hospitals. Given Switzerland's geographical proximity to European Union (EU) member states, the General Data Protection Regulation (GDPR) may impose additional obligations.Methods: To conduct this assessment, we carried out a series of qualitative interviews with key stakeholders at Swiss hospitals and research institutions. These included legal and clinical data management staff, as well as clinical and research ethics experts. These interviews were carried out with two series of vignettes that focused on data discovery using homomorphic encryption and data erasure from a distributed ledger platform.Results: For our first set of vignettes, interviewees were prepared to allow data discovery requests if patients had provided general consent or ethics committee approval, depending on the types of data made available. Our interviewees highlighted the importance of protecting against the risk of reidentification given different types of data. For our second set, there was disagreement amongst interviewees on whether they would delete patient data locally, or delete data linked to a ledger with cryptographic hashes. Our interviewees were also willing to delete data locally or on the ledger, subject to local legislation.Conclusion: Our findings can help guide the deployment of these technologies, as well as determine ethics and legal requirements for such technologies.
      pubtype: Academic Journal
      doctype: Journal Article
      ougenre: Article
    language: English
    refInfo:
    holdings:
      @attributes:
        islocal: N