<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Identifying Materialized Privacy Claims of Clinical-Care Metadata Share using Process-Mining and REA ontology</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Syeda Amna Sohail</string-name>
          <email>s.a.sohail@utwente.nl</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Faiza Allah Bukhsh</string-name>
          <email>f.a.bukhsh@utwente.nl</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Medische Spectrum Twente</institution>
          ,
          <addr-line>Medlon BV, 7500 KA Enschede</addr-line>
          ,
          <country>The Netherlands mst.nl</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>University of Twente</institution>
          ,
          <addr-line>7522NB Enschede</addr-line>
          ,
          <country country="NL">The Netherlands</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>Metadata formation, maintenance, and interoperability are crucial for long-term, e ective usage of valuable digital information across domains. Metadata interoperability especially triggers privacy concerns regarding personally identi able information of data subjects when sensitive clinical-care metadata is shared amongst multiple caregivers. The problem intensi es when the care metadata share across caregivers is considered essentially signi cant for an e cient care system. Patients' un-anonymized care metadata share across caregivers is validated using a real-world Sepsis dataset with Process Mining discovery techniques. Findings are further evaluated, for both horizontally and vertically distributed caregivers, by an IT expert from a Dutch hospital. The Resource, Event, Agent (REA) ontology-based `Insurance Model' is used to identify the underlying economic factors behind the un-anonymized patients' metadata share amongst caregivers. The model discovers the key economic agents, their prime interactions (from contract signing to the exchange of resources) for mutual economic gain/loss in the care metadata share landscape. Lastly, we explicate that the privacy concerns of patient's metadata share emerge as `Materialized Privacy Claim'. The privacy claim only emerges if either the patient or any other potent (involved) authority nds an imbalance between the materialization and settlement of the patient's exchanged resources. The `Materialized Privacy Claim' illustrates concretely with money claims for unlawful disclosure of a patient's personal information from caregivers and insurers.</p>
      </abstract>
      <kwd-group>
        <kwd>metadata share • REA ontology • Process Mining • clinicalcare • privacy</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        In the contemporary digital information landscape, the formation and
maintenance of metadata are vital steps to avoid information loss across domains
over time. Metadata adds context to the raw data and facilitates the extraction
of knowledgeable value [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. The metadata formation (record formulation in the
repository using consistent identi ers and publication) to its maintenance (for
e cient reusability) is a shared duty of the concerned authorities [
        <xref ref-type="bibr" rid="ref23">23</xref>
        ].
Additionally, metadata interoperability is the successful reuse and exchange of data
sources within and across organizations Information Systems (ISs) [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ].
Therefore, a collective need is felt by policymakers, regulators, and enterprises alike
for metadata formation, maintenance, and interoperability within and across
domains for collective cost and time-e cient growth [
        <xref ref-type="bibr" rid="ref18 ref23 ref3">3, 18, 23</xref>
        ]. Moreover,
domainspeci c pressure groups play a signi cant role in ensuring metadata share across
domains [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. Simultaneously, the local and pan-European authorities legally
constrain the concerned authorities for privacy-preservation/privacy of Personally
Identi able Information (PII) of EU citizens to avoid information harm/misuse
[
        <xref ref-type="bibr" rid="ref10 ref6 ref8">6, 8, 10</xref>
        ]. Privacy (literally) implies an individual's right to autonomous decision
making (about what to share and with whom) and direct or indirect control over
the extended personal information share [
        <xref ref-type="bibr" rid="ref30">30</xref>
        ]. With privacy-preserving measures,
the legislative and regulatory authorities aim to protect the EU citizen's PII to
avoid discriminatory or harmful treatment [
        <xref ref-type="bibr" rid="ref10 ref6 ref8">6, 8, 10</xref>
        ]. In this regard, special
attention is given to the sensitive healthcare metadata share [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ].
      </p>
      <p>
        This research work concerns the privacy-preservation of clinical-care
metadata share amongst Dutch caregivers. Here, the clinical-care is the
immediate healthcare (treatment and testing) of patients [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. (Clinical) care metadata
is presumably shared un-anonymized amongst horizontally and vertically
distributed caregivers in the Netherlands. Horizontally distributed caregivers are
intra-organizational, internally-located caregivers (i.e. the caregivers within
General Practitioners (GPs) clinic, diagnostic lab, or between various departments
within a hospital) sharing care metadata. Vertically distributed caregivers are the
inter-organizational, remotely located caregivers (i.e. multiple outpatient
caregivers such as GPs, diagnostic labs, pharmacies, dentists, and hospitals) sharing
care metadata. All these care metadata interactions involve the metadata
sharing in the 'as is' condition. This implies that the data is either un-anonymized or
recorded as pseudonymized data. In `pseudonymization' the pseudo identi ers
are allocated to the patients and caregivers with reversible one-way
cryptography. Unlike `anonymization', where identi ers are permanently removed for the
sake of privacy [
        <xref ref-type="bibr" rid="ref20">20</xref>
        ]. In this research work, the term `un-anonymized metadata
share' is used because the patients' identities are retractable in caregivers' ISs
for an e cient clinical care system [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ].
      </p>
      <p>The objective and contribution of this research work are:</p>
      <p>- To validate the patients' un-anonymized care metadata share amongst
Dutch caregivers using Process Mining (PM) discovery techniques on a
realworld Sepsis dataset.</p>
      <p>- To conceptualize the Dutch care metadata share landscape from a patient's
perspective using REA ontology to highlight: the key economic agents, their
prime interactions, and collective economic value gain or loss.</p>
      <p>- To explicate privacy as a `Materialized Privacy Claim (MPC)' using REA
ontology elicited from real-world events.</p>
      <p>
        To validate the patients' un-anonymized care metadata share, a real-world
Sepsis dataset (extracted from a Dutch Hospital Information System (HIS) [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]) is
analyzed using PM `discovery' techniques [
        <xref ref-type="bibr" rid="ref14 ref5">5,14</xref>
        ]. PM is business process analytics
on event logs (extracted directly from an organization's IS) for process discovery
and compliance checking for an organization's operational improvements [31{33].
The PM results are further evaluated by an Information Technology (IT) expert
working in a Dutch hospital. The Resource, Event, Agent (REA) ontology is
used to locate the underlying economic factors behind patients' un-anonymized
care metadata share amongst Dutch caregivers [
        <xref ref-type="bibr" rid="ref24">24</xref>
        ]. Mainly because the
fundamental REA concepts are domain-independent and do not require architectural
changes [
        <xref ref-type="bibr" rid="ref24">24</xref>
        ].
      </p>
      <p>This paper is structured in a way that the introduction is in Section 1.
Related work is given in Section 2. Section 3 contains two subsections. In subsection
3.1, the conceptual validation using a real-world Sepsis dataset with PM
discovery techniques and an evaluation by an IT expert working in a Dutch hospital is
given. In subsection 3.2, the REA ontology's Insurance Model (IM) is used to
discover the underlying economic factors behind the current Dutch care metadata
share landscape. The conclusion is in Section 4.
2</p>
    </sec>
    <sec id="sec-2">
      <title>Related Work</title>
      <p>
        In the Dutch care system, the hub and spoke model essentially facilitates care
metadata formation, maintenance, and interoperability by contributing to the
Electronic Health Record (EHR) from the grass-root level. Collective EHR from
Dutch caregivers is publicly regulated for an uninterrupted care metadata share
at the national and international level [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]. Interestingly, Dutch clinical care is
appraised as the best in the EU for more than a decade till 2017 [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. Generally,
a hub, central IS, is the central point of information access for the smaller
distinct reporting spokes, ISs. Hub leads the spokes to make well informed, timely,
and evidence-based decisions regarding patients' treatments. The hub and spoke
model ensures an e cient, patient-friendly care system with satis ed and
cognitively connected caregivers [
        <xref ref-type="bibr" rid="ref16 ref25 ref27">16, 25, 27</xref>
        ]. Hub and spoke model works in both:
horizontally and vertically distributed caregivers in the Netherlands for patients'
primary and secondary care [
        <xref ref-type="bibr" rid="ref16 ref22 ref25 ref27">16, 22, 25, 27</xref>
        ].
      </p>
      <p>
        Reidenti cation concerns of pseudonymized care metadata are already well
known in academia and industry alike [
        <xref ref-type="bibr" rid="ref15 ref30">15, 30</xref>
        ]. A bigger point of concern is
the lop-sided advancement of digital health technologies than their
privacypreserving measures [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ]. A similar imbalance is visible in care metadata sharing
e orts in comparison to their privacy-preserving measures implications [
        <xref ref-type="bibr" rid="ref15 ref17 ref26 ref9">9,15,17,
26</xref>
        ]. A leading point of concern is the open accessibility of patients' PII to
numerous caregivers who are not directly involved with the patients' care [
        <xref ref-type="bibr" rid="ref17 ref9">9, 17</xref>
        ].
Such access points are principal threats to patient's sense of physical,
informational, and decisional security (i.e privacy [
        <xref ref-type="bibr" rid="ref19 ref28">19, 28</xref>
        ]) [
        <xref ref-type="bibr" rid="ref11 ref12">11, 12</xref>
        ]. In addition to a
patient's physical security, informational security is patients' PII's protection
from potential information harm. Decisional security is the protection of his/her
autonomous decision-making regarding his/her extended PII share.
Privacypreserving measures ensure patient's informational, decisional, and physical
security by the concerned authorities [
        <xref ref-type="bibr" rid="ref19 ref28">19, 28</xref>
        ]. This research work addresses patients'
this sense of security during the patients' clinical care.
3
      </p>
      <p>
        Patients' Metadata Share and Privacy-Preservation:
Conceptual Validation and REA Ontology
To validate the patients' un-anonymized metadata share amongst Dutch
caregivers, the Sepsis dataset is analyzed using PM tools: Disco and ProM Lite [
        <xref ref-type="bibr" rid="ref14 ref5">5,14</xref>
        ].
Later, the PM experiments are validated by an IT expert from a Dutch
hospital. Afterward, the REA's Insurance Model (IM) [
        <xref ref-type="bibr" rid="ref24">24</xref>
        ] is used to conceptualize
our proposed model. The model discovered that primarily who, how, and what
leads to patients' un-anonymized metadata-share amongst Dutch caregivers and
in explicating privacy as a materialized claim.
3.1
`Sepsis' Dataset Analysis using Process Mining and Expert's
Opinion
The dataset/event log comprises Sepsis patients as `cases', treatments as
`activities' in the `events' with initiating and ending timestamps [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. The event log
also provides the activities' link to sub-hospital organizations/departments
(horizontally distributed caregivers). The goal of PM experiments was to look-out
for evidence of patients' un-anonymized data sharing. The aim was to uncover
the pairs of subsequent un-anonymized activities as indications of the lack of
privacy-preserving actions.
      </p>
      <p>PM experiments ndings and discussion: The commercial tool Disco
(fuzzy minor algorithm) discovered that there are 16 activities for 1,050 cases and
15,214 events/instances. The sub-hospital departments (with pseudo-identi ers)
are shown with activities share (in percentage) in the top left box and the process
model (with sharing time stamps) is given underneath see Fig. 1. The periods
(with activities' median and least time stamps) of care data share amongst
horizontally distributed caregivers, and activity frequency is noted. The succeeding
data sharing was done either instantly or after a short period (see on arrows)
from one sub-organization/department to the other. PM experiments explained
that no privacy-preserving actions could practically have occurred in such brief
time frames see Fig. 1.</p>
      <p>ProM Lite with the social network algorithm discovers information regarding
working (medical/administrative) sta in an event log. The absence of a social
network suggested that either the sta disagreed to publicly share their PII or
it was intentionally withheld for privacy's sake. However, the `Dotted Chart'
substantiated that the maximum succeeding activities are performed either
instantly or within 2 days (48 hours) between horizontally distributed caregivers.
Thus, the chart further validated our PM experiments goal see Fig. 2.
Expert Opinion: IT expert working in a Dutch local hospital was shown
the PM results and was asked whether caregivers share un-anonymized (and
pseudonymized) care data amongst horizontally distributed caregivers. And do
they remove the PII of medical and administrative sta ? We also asked to
conrm whether the results are generalizable to the vertically distributed Dutch
caregivers or not. The IT expert validated all our ndings.</p>
      <p>The REA ontology is used to conceptualize the underlying economic factors
behind patients' un-anonymized metadata share amongst Dutch caregivers.
3.2</p>
      <p>
        Underlying Conceptual Framework using REA Ontology
Dutch caregivers are privately run and partially publicly funded enterprises. Our
goal behind using REA ontology was to discover the underlying nancial
priorities of care enterprises for patients' un-anonymized metadata share [
        <xref ref-type="bibr" rid="ref24">24</xref>
        ]. REA's
Insurance model (IM) is an extended application model because it includes
contract and commitment levels to the increment and decrement events between
economic agents for mutual value gain or loss.
      </p>
      <p>
        Before Fig. 3 conceptualization fundamentals, it is vital to emphasize that
the PM experiments in Fig. 1 and Fig. 2 validated our assumptions regarding
patients' un-anonymized metadata share amongst Dutch caregivers. Whereas
Fig. 3 is about the proposed REA model which relates to real-life events where
privacy is used as a `Materialized Claim' against caregivers/health insurers in the
Netherlands. Fig. 3 is explained from top to bottom, describing the concepts and
relations of the model. The `economic agents' are legal entities who lose or gain
control over the economic resources through economic events/interactions. An
`economic resource' is a thing or service to be planned, monitored, and controlled
by the concerned authorities/economic agents. Here, resources like cash,
metadata, and care services are exchanged as increment and/or decrement events.
The increment is the in ow of resources, while the decrement is the out ow of
resources from a patient's perspective. Contracts are legal commitments that
involve each agent as a `party'. Initially, the contract is signed between two active
`party' agents. There can be passive `party' agents who activate (like caregivers
with respective registrations/contracts) later with further increment/decrement
events. Initially, the patients and health insurers perform the increment and
decrement events by exchanging cash with and for one another respectively. With
an insurance contract, the PII of the insured is also stored in insurers IS. This
information intake (economic resource) leaves the insured with less control over
his/her PII (for physical, decisional, and informational security). The insurance
contract clauses commit the (party) agents for future increment and decrement
events (including the privacy preservation of the insured). From the patient's
perspective, the increments include the timely cash payments from the insurer
to caregivers, clinical care to the patient, and patient's PII security assurance
from insurer and caregivers alike. The decrement events are monthly insurance
payments from the patient to the insurer and the out ow of patients' PII (as
an input to metadata) to the insurer and caregivers. After the increment and
decrement events' execution, the involved agents evaluate if there are any
imbalances between the materialization and the settlements of the patient's resources.
Patients usually evaluate their physical security/recovery in comparison to their
cash payments to the insurer. `Materialized Privacy Claim (MPC)' surfaces only
when either the patient or any other involved potent authority (such as Data
Protection O cer [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]) claims for the assurance of the patient's informational
and decisional security in addition to his/her physical security/recovery. For
instance, recently the Dutch Data Protection O cer (DPO) ned Haga hospital
Euros 460,000 for a Dutch celebrity's privacy breach [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ] and charged Menzis
(health insurer) Euros 50K for care data mishandling [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ].
      </p>
      <p>Privacy and metadata in REA ontology: In REA ontology the metadata
formation, maintenance, and interoperability is part of an organization's
`posting and dimension aspect of nancial disbursement' instead of its application
&lt;&lt;Economic agent&gt;&gt;</p>
      <p>Health Insurer
&lt;&lt;party&gt;&gt;</p>
      <p>&lt;&lt;Provide&gt;&gt;
Insurer
&lt;&lt;receive&gt;&gt;
&lt;&lt;Economic agent&gt;&gt;
Clinical Caregiver
(when registered)
&lt;&lt;party&gt;&gt;</p>
      <p>&lt;&lt;party&gt;&gt;
&lt;&lt;decrement&gt;&gt;
Insurance Contract,
Personally Identifiable
Information (PII) share</p>
      <p>Insured
&lt;&lt;Economic agent&gt;&gt;</p>
      <p>Patient
&lt;&lt;Clause&gt;&gt;
&lt;&lt;Increment term&gt;&gt;
Insurance Policy
(PII privacy)
&lt;&lt;receive&gt;&gt;
&lt;&lt;Provide&gt;&gt;
&lt;&lt;outflow &lt;&lt;outflow&gt;&gt;
reservation&gt;&gt;
&lt;&lt;Economic
Resource&gt;&gt;
Cash, input to
metadata
&lt;&lt;Clause&gt;&gt;
&lt;&lt;Clause&gt;&gt;</p>
      <p>Instantiate
&lt;&lt;fulfilment&gt;&gt;
comd&lt;mi&lt;sdPbiteIumIcrsesrheneamtm&gt;ree&gt;ennCtt,ash exchange Cc&lt;oa&lt;msihnmcRirteemcmeeenipnt&gt;tt,&gt;
(input to metadata) reciprocity Clinical-Care/care
&lt;&lt;fulfilment&gt;&gt;</p>
      <p>&lt;&lt;inflow
reservation&gt;&gt;
&lt;&lt;decrement&gt;&gt;
Cash disbursement,
PII share (input to
metadata)
exchange
duality
&lt;&lt;increment&gt;&gt;
Cash Receipt,</p>
      <p>care
&lt;&lt;Materialization&gt;&gt;
&lt;&lt;Settlement&gt;&gt;
&lt;&lt;Inflow&gt;&gt;
&lt;&lt;Economic
Resource&gt;&gt;
Cash, care
&lt;&lt;Claim&gt;&gt;</p>
      <p>Unbalanced Value,
agent and resource info,</p>
      <p>Unit of Measure
with Date and Time</p>
      <p>&lt;&lt;Claim Type&gt;&gt;
&lt;&lt;Materialized Privacy</p>
      <p>
        Claim&gt;&gt;
unbalanced value:
&lt;&lt;Instance Privacy-Preservation
of&gt;&gt;
model [
        <xref ref-type="bibr" rid="ref24">24</xref>
        ]. Earlier (in 2006), metadata handling was considered dependent upon
the behavioral pattern of the respective organization [
        <xref ref-type="bibr" rid="ref24">24</xref>
        ]. Although the metadata
entries are always stored using the identity strings (ID strings with PII) in
organizations' ISs. Still, they lacked standardized information security management
systems [
        <xref ref-type="bibr" rid="ref29">29</xref>
        ]. Nowadays, metadata privacy is protected by the national and
European regulations and involves legal commitments by the concerned authorities to
avoid hefty money claims [
        <xref ref-type="bibr" rid="ref10 ref6 ref8">6,8,10</xref>
        ]. The legal and administrative requirements for
privacy include privacy by policy, privacy by design, and patients' informed
consent measures [
        <xref ref-type="bibr" rid="ref10 ref29 ref6 ref8">6, 8, 10, 29</xref>
        ]. Therefore, the privacy-preservation of care metadata
share does not rely on the behavioral patterns of health insurers/caregivers
anymore. Rather, legal benchmarks constrain the concerned authorities for shaping
the respective organizational/services contracts accordingly. Consequently, the
patients' privacy concerns now appear as Materialized Privacy Claims (MPCs)
in the Dutch care metadata share landscape.
      </p>
      <p>Another approach (for a better generalizable REA model) was to incorporate
privacy-breach as a condition in the insurance policy. Furthermore, it could have
added granularity regarding the levels of severity and respective cash
disbursements. Nevertheless, the proposed REA model signi es the scenarios involving
privacy claims by patients (or for patients by any other potent authority i.e.
DPO) against caregivers and insurers. In this regard, it is emphasized that the
possibilities of these privacy claims getting compensated with hefty cash
payments by the concerned authorities (caregivers/insurers) are high.
4</p>
    </sec>
    <sec id="sec-3">
      <title>Conclusion</title>
      <p>A real-world Sepsis dataset has been analyzed with Process Mining (PM)
discovery techniques using Disco and ProM Lite to validate the un-anonymized
clinical care metadata share amongst Dutch caregivers. The experiments' results
veri ed that the horizontally distributed Dutch caregivers share un-anonymized
(and pseudonymized/retractable) patients' metadata. An IT expert (working in
a Dutch hospital) further evaluated the PM results and their generalizability for
the vertically distributed Dutch caregivers. Furthermore, The PM results and
the IT expert also con rmed that the PII of the administrative and medical
sta is intentionally removed during the metadata share across caregivers from
di erent domains. In this regard, the REA model helped us to discover: who,
how, and what leads to an un-anonymized metadata-share amongst vertically
and horizontally distributed Dutch caregivers.</p>
      <p>REA's Insurence Model (IM) uncovered the key economic agents, their prime
economic interactions in the Dutch care metadata share landscape from the
patient's perspective. The health insurer and patient are key (active) economic
(party) agents who sign the contract of health insurance where caregivers are
initially the passive (party) agents. The (party) agents become committed to
the contract clauses for the increment (in ow) and decrement (out ow) of
economic resources. As an increment, the patient receives the cash in ow from the
insurer to the caregivers (who activate with respective contracts registration by
the patient) on each medical checkup visit, the care services from caregivers, and
preservation of PII (via contracts). As a decrement, the patient pays monthly
payments to the insurer and his/her PII as an input to the metadata of the
insurer and caregivers. The decremented resources become valuable to the receiver
and let him/her evaluate the imbalance (if there is any) between the
materialization of economic resources (provided care for the physical, informational, and
decisional security) and their prior settlements (cash payments, contract clauses
ensuring privacy). An important result of our conceptualization is that the
privacy concerns take the form of a Materialized Privacy Claim (MPC) when an
economic agent (either the patient or any other potent authority) nds the
imbalance in patients' exchanged resources. This modeling approach explains the
who, how, and why of money claims for illegal information disclosures as MPC.</p>
      <p>The future work includes the breaking down of the proposed REA model into
two sub-models with further speci cations and detailed descriptions of mutual
transactions between patients, health insurers, and caregivers in binary format.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1. aalep, http://www.aalep.eu/lobbying-landscape
          <source>-netherlands, 7 Jan</source>
          , 2021
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2. Collinsdictionary, https://www.collinsdictionary.com/dictionary/english/ clinical-care,
          <issue>11</issue>
          <year>Nov</year>
          ,
          <year>2020</year>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3. Ctis, https://www.ema.europa.eu/en/documents/newsletter/clinicaltrials
          <article-title>-information-system-ctis-</article-title>
          <string-name>
            <surname>highlights-</surname>
          </string-name>
          june-2020_.pdf,
          <issue>20</issue>
          <year>Dec</year>
          ,
          <year>2020</year>
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4. data.4tu, https://data.4tu.nl/, 11 Nov,
          <year>2020</year>
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5. Disco, https://fluxicon.com/disco, 11 Nov,
          <year>2020</year>
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6. Dpo, https://www.itgovernance.
          <article-title>eu/nl-nl/data-protection-officer-dpounder-the-gdpr-</article-title>
          <string-name>
            <surname>nl</surname>
          </string-name>
          ,
          <issue>11</issue>
          <year>Nov</year>
          ,
          <year>2020</year>
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7. Echi-2017, https://healthpowerhouse.com/media/EHCI-2016/EHCI-2016
          <string-name>
            <surname>-</surname>
          </string-name>
          launch-presentation.
          <source>pdf, 11 Nov</source>
          ,
          <year>2020</year>
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8. Edpb, https://edpb.europa.eu/, 11 Nov,
          <year>2020</year>
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9. Euctregister, https://www.clinicaltrialsregister.eu/ctr-search/trial/ 2017-002976-24/NL, 11 Nov,
          <year>2020</year>
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Gdpr</surname>
          </string-name>
          , https://gdpr-info.eu/, 11 Nov,
          <year>2020</year>
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Hagahospital</surname>
          </string-name>
          , https://www.cordemeyerslager.nl/fine-of-e-
          <volume>460</volume>
          -000-imposed
          <string-name>
            <surname>-</surname>
          </string-name>
          on
          <article-title>-dutch-haga-hospital-by-dutch-data-protection-officer-the-firstdutch-fine-under-gdpr-</article-title>
          <string-name>
            <surname>july-</surname>
          </string-name>
          19-2019/, 30 Dec,
          <year>2020</year>
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12. insurer ne, https://www.iapp.org/news/a/dutch
          <article-title>-dpa-hits-medical-insurerwith-50k-euro-gdpr-fine/#:~:text=</article-title>
          <source>The%20Dutch%20data%20protection% 20authority,its%20processing%20of%20personal%20data., 30 Dec</source>
          ,
          <year>2020</year>
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Nictiz</surname>
          </string-name>
          , https://www.nictiz.nl/english/exchange
          <article-title>-of-electronic-patientdata-in-the-netherlands/the-infrastructure-for-central-</article-title>
          <source>exchange/ #section1, 30 Dec</source>
          ,
          <year>2020</year>
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14. promtool, https://www.promtools.org/doku.php,
          <issue>11</issue>
          <year>Nov</year>
          ,
          <year>2020</year>
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15. Wiley, https://www.wiley.com/en-us/Medical+Information+Systems+Ethicsp-
          <volume>9781848218598</volume>
          , 11 Nov,
          <year>2020</year>
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <surname>Albarello</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Prati</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sangiorgi</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tremosini</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Menegatti</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Depolo</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rubini</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Does hub-and-spoke organization of healthcare system promote workers' satisfaction?</article-title>
          <source>Journal of Applied Social Psychology</source>
          <volume>49</volume>
          (
          <issue>10</issue>
          ),
          <volume>634</volume>
          {
          <fpage>646</fpage>
          (
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <string-name>
            <surname>Badawy</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hameed</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bataille</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Little</surname>
            ,
            <given-names>M.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Claes</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Saria</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cedarbaum</surname>
            ,
            <given-names>J.M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Stephenson</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Neville</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Maetzler</surname>
            ,
            <given-names>W.</given-names>
          </string-name>
          , et al.:
          <article-title>Metadata concepts for advancing the use of digital health technologies in clinical research</article-title>
          .
          <source>Digital biomarkers 3(3)</source>
          ,
          <volume>116</volume>
          {
          <fpage>132</fpage>
          (
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          18.
          <string-name>
            <surname>Bountouri</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Papatheodorou</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Soulikias</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Stratis</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Metadata interoperability in public sector information</article-title>
          .
          <source>Journal of Information Science</source>
          <volume>35</volume>
          (
          <issue>2</issue>
          ),
          <volume>204</volume>
          {
          <fpage>231</fpage>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          19.
          <string-name>
            <surname>Chassie</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          :
          <article-title>A private matter [privacy in society]</article-title>
          .
          <source>IEEE Potentials</source>
          <volume>20</volume>
          (
          <issue>4</issue>
          ),
          <volume>26</volume>
          (
          <year>2001</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          20.
          <string-name>
            <surname>Critselis</surname>
          </string-name>
          , E.:
          <article-title>Impact of the general data protection regulation on clinical proteomics research</article-title>
          .
          <source>PROTEOMICS{Clinical Applications</source>
          <volume>13</volume>
          (
          <issue>2</issue>
          ),
          <volume>1800199</volume>
          (
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          21.
          <string-name>
            <surname>Davis</surname>
            ,
            <given-names>J.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Osoba</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          :
          <article-title>Improving privacy preservation policy in the modern information age</article-title>
          .
          <source>Health and Technology</source>
          <volume>9</volume>
          (
          <issue>1</issue>
          ),
          <volume>65</volume>
          {
          <fpage>75</fpage>
          (
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          22.
          <string-name>
            <surname>Garattini</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ra</surname>
            <given-names>e</given-names>
          </string-name>
          , J.,
          <string-name>
            <surname>Aisyah</surname>
            ,
            <given-names>D.N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sartain</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kozlakidis</surname>
            ,
            <given-names>Z.</given-names>
          </string-name>
          :
          <article-title>Big data analytics, infectious diseases and associated ethical impacts</article-title>
          .
          <source>Philosophy &amp; technology 32(1)</source>
          ,
          <volume>69</volume>
          {
          <fpage>85</fpage>
          (
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          23.
          <string-name>
            <surname>Habermann</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>Metadata and reuse: Antidotes to information entropy</article-title>
          .
          <source>Patterns</source>
          <volume>1</volume>
          (
          <issue>1</issue>
          ),
          <volume>100004</volume>
          (
          <year>2020</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          24.
          <string-name>
            <surname>Hruby</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          :
          <article-title>Model-driven design using business patterns</article-title>
          . Springer Science &amp; Business
          <string-name>
            <surname>Media</surname>
          </string-name>
          (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          25.
          <string-name>
            <surname>Joseph</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          :
          <article-title>Eliminating disparities and implicit bias in health care delivery by utilizing a hub-and-spoke model</article-title>
          .
          <source>Research Ideas and Outcomes</source>
          <volume>4</volume>
          ,
          <issue>e26370</issue>
          (
          <year>2018</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          26.
          <string-name>
            <surname>Mannhardt</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Koschmider</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Baracaldo</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Weidlich</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Michael</surname>
          </string-name>
          , J.:
          <article-title>Privacypreserving process mining</article-title>
          .
          <source>Business &amp; Information Systems Engineering</source>
          <volume>61</volume>
          (
          <issue>5</issue>
          ),
          <volume>595</volume>
          {
          <fpage>614</fpage>
          (
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          27.
          <string-name>
            <surname>Nocera</surname>
          </string-name>
          , N.:
          <article-title>Hubs, spokes and trauma nurse coordinators: New south wales' model of optimal trauma care|part i</article-title>
          .
          <source>Australian Emergency Nursing Journal</source>
          <volume>6</volume>
          (
          <issue>1</issue>
          ), 5{
          <issue>9</issue>
          (
          <year>2003</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          28.
          <string-name>
            <surname>Serour</surname>
          </string-name>
          , G.:
          <article-title>Con dentiality, privacy and security of patients' health care information</article-title>
          .
          <source>International Journal of Gynecology and Obstetrics</source>
          <volume>2</volume>
          (
          <issue>93</issue>
          ),
          <volume>184</volume>
          {
          <fpage>186</fpage>
          (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          29.
          <string-name>
            <surname>Sohail</surname>
            ,
            <given-names>S.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Krabbe</surname>
            , J., de Alencar Silva,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bukhsh</surname>
            ,
            <given-names>F.A.</given-names>
          </string-name>
          :
          <article-title>Privacy value modeling: A gateway to ethical big data handling</article-title>
          .
          <source>In: 14th International Workshop on Value Modelling and Business Ontologies</source>
          ,
          <string-name>
            <surname>VMBO</surname>
          </string-name>
          <year>2020</year>
          . pp.
          <volume>5</volume>
          {
          <fpage>15</fpage>
          .
          <string-name>
            <surname>CEUR</surname>
          </string-name>
          (
          <year>2020</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          30. Van Den Hoven, J.:
          <article-title>Information technology, privacy, and the protection of personal data</article-title>
          .
          <source>Information technology and moral</source>
          philosophy pp.
          <volume>301</volume>
          {
          <issue>322</issue>
          (
          <year>2008</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          31.
          <string-name>
            <surname>Van Der Aalst</surname>
          </string-name>
          , W.:
          <article-title>Process mining: Overview and opportunities</article-title>
          .
          <source>ACM Transactions on Management Information Systems (TMIS) 3</source>
          (
          <issue>2</issue>
          ),
          <volume>1</volume>
          {
          <fpage>17</fpage>
          (
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          32.
          <string-name>
            <surname>Van Der Aalst</surname>
            ,
            <given-names>W.</given-names>
          </string-name>
          :
          <article-title>Data science in action</article-title>
          . In: Process mining, pp.
          <volume>3</volume>
          {
          <fpage>23</fpage>
          . Springer (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          33.
          <string-name>
            <surname>Vanderfeesten</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cardoso</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mendling</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Reijers</surname>
          </string-name>
          , H.A.,
          <string-name>
            <surname>van der Aalst</surname>
          </string-name>
          , W.M.:
          <article-title>Quality metrics for business process models</article-title>
          .
          <source>BPM and Work ow handbook 144</source>
          ,
          <volume>179</volume>
          {
          <fpage>190</fpage>
          (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>