<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Patient-Centric Secure-and-Privacy-Preserving Service-Oriented Architecture for Health Information Integration and Exchange</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Mahmoud Awad</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Larry Kerschberg</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Center for Health Information Technology, George Mason University</institution>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2010</year>
      </pub-date>
      <abstract>
        <p>In this paper, we propose a secure and privacy-preserving Service Oriented Architecture (SOA) for health information integration and exchange in which patients are “part owners” of their medical records, have complete ownership of their integrated health information and decide when and how data is modified or exchanged between healthcare providers or insurance companies. This architecture is different from integrated Personal Health Record (PHR) such as Google Health and Microsoft HealthVault in that electronic health records are not stored in online databases but instead are aggregated on-demand using web service requests. Web service providers working on behalf of the patients do not keep copies of the complete EHR but instead provide a passthrough service, and would require PKI-based security certificates to initiate health information exchange.</p>
      </abstract>
      <kwd-group>
        <kwd>Privacy Ontology</kwd>
        <kwd>Electronic Health Record</kwd>
        <kwd>Service Oriented Architecture</kwd>
        <kwd>Health Information Exchange</kwd>
        <kwd>HER</kwd>
        <kwd>SOA</kwd>
        <kwd>HIE</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1 Introduction</title>
      <p>Patient health records (in electronic or paper form) such as medications, lab results
and family history are owned by the healthcare establishment that requested or
created such records. Even though patients can request copies of their medical
records, the process of getting such records is neither streamlined nor convenient.
Photocopies of large medical files are costly and in most cases unreadable, and, in the
case of electronic systems, these records are usually in proprietary format that are
hard to integrate with each other. As more healthcare providers switch to Electronic
Health Records (EHR), most of these issues will be overcome but the security,
privacy and ownership of these medical records remain hard-pressed issues.
The Health Insurance Portability and Accountability Act (HIPAA), which was
enacted in 1996, includes provisions that govern certain privacy aspects related to
patients health records. These provisions apply to healthcare providers such as
hospitals, physicians and laboratories, but do not apply to companies that aggregate
these health records in electronic format such as Google Health, Microsoft
HealthVault and Indivo. Most people consider the state of their health to be very
confidential and, therefore, security and privacy concerns may drive people away
from such integrated systems in spite of all the strict online privacy policies
established by Google and Microsoft. People would rather deal with a healthcare
entity that is covered under an enforceable federal law than deal with unenforceable
privacy policies established by corporations that have objectives that overshadow and
eclipse the confidentiality of an individual’s lab results or family medical history.
In this paper, we propose a secure and privacy-preserving Service Oriented
Architecture (SOA) for health information integration and exchange. The proposed
architecture is different from integrated EHR systems such as Google Health and
Microsoft HealtVault in that electronic health records are not stored in online
databases but instead are aggregated on demand using web service requests. All
health information exchanges have to be approved by the patient and would require
one-time use secure tokens for authentication, privacy policies to control data
elements exchanged and fine-grained security policies to control data element values
exchanged. As a proof of concept, we developed a prototype showing how privacy
and security policies are created and how they are applied as part of an EHR
exchange.</p>
    </sec>
    <sec id="sec-2">
      <title>2 Proposed Architecture</title>
      <p>In our proposed architecture, shown in Figure 1, the patient is represented by an
application server that communicates with healthcare providers using a set of web
services. This application server contains a set of privacy policies and security
policies that govern all data exchange requests, and does not have the capability to
store the patient’s complete health record.
The server representing the patient consists of the following components:
1.
2.</p>
      <p>Database contains fine-grained historical audit trail of all data exchange
requests among healthcare providers, which includes additions,
modifications and deletions of health record structure or data. The
patient’s medical history can be reconstructed using this audit trail but
only the patient has privileges to initiate such request.</p>
      <p>Privacy Policy Generator (PPG) generates privacy policies by defining
which data structure elements are allowed to be exchanged between
healthcare entities. The policy itself is represented using HL7 CDA syntax
and acts as a filter between a web service and its data store. Privacy
policies can be generated manually or via templates such as Continuity of
Care Record (CCR) which is an HL7 constraint.</p>
      <p>Security Policy Generator (SPG) generates security policies that restrict
records retrieved by a database in response to an EHR query. These
security policies enforce fine-grained access and are modeled similar to
relational database fine-grained security access control. In order to
generate new security policies or modify existing policies, the SPG
receives a request from the PPG with a privacy policy identifier, a
healthcare provider identifier and the data elements that need to be
secured by the new security policy.</p>
      <p>The architecture offers a clear separation between privacy policies and security
policies in order to provide better flexibility in producing and applying the filters and
predicates produced by the PPG and SPG respectively. Privacy filters are applied first
to restrict data elements in an XML response (or columns in case of relational tables),
then security policies are applied to limit the data element values. Implementation
details depend on the architecture of the medical record system implemented
internally at the healthcare providers or health insurance companies. Systems that use
relational database can use fine-grained access control to implement security policies
and systems that use XML databases can use XML schemas to validate the XML
document produced.</p>
      <p>1. Secure Token Generator (STG), Requests for EHR exchange are initiated
but not executed until secure tokens are generated by the STG. The tokens
are generated using PKI and use a random number to ensure they are used
only once.
2.</p>
      <p>Privacy Ontology; helps the PPG determine relationships among
healthcare providers and between EHR data elements and provides a
mapping between the healthcare providers and EHR data elements.
Default privacy policy templates are generated using this privacy
ontology. An example of relationships between healthcare providers is all
the hospitals and medical practices that use Quest Diagnostics as their
diagnostic laboratory testing facility. This knowledge simplifies the
process of generating security policies that would allow lab results to be
exchanged between these medical facilities and Quest Diagnostics. Also,
knowing that the patient’s primary family physician is a registered
practitioner at particular hospital helps establish the level of trust in data
exchanges between the physician and various offices within the hospital.
Applications are used to: a) Monitor data exchange requests and help the
users decide whether to approve or reject a request; b) Produce privacy
policies and security policies; c) Query an individual component of the
EHR or produce a complete EHR by issuing EHR integration web service
requests to all the registered healthcare providers; and d) Review and
correct individual components of the EHR by issuing correction requests
to the system holding the affected record.</p>
      <p>ThePrivacy Ontology is an important component of our architecture and a subject of
active research. We are motivated by the HL7 Security and Privacy Ontology (See:
http://wiki.hl7.org/index.php?title=Security_and_Privacy_Ontology ). The ontology
was developed using their methology and use cases dealing with access control based
on category of action, of object, of structural role, of functional role, and on multiple
role values. Additional use cases deal with facilitating an automatic decision function
and the design of an access control system.</p>
      <p>The HL7 Security and Privacy Ontology is specified in the Web Ontology Language
(OWL) and is implemented in the Protege Ontology Editor from Stanford University.
We are presently investigating how to incorporate patient-centric privacy and security
authorization constructs into the Privacy Ontology so as to strike a balance between
patient privacy, the secure exchange of health information, and mechanisms to ensure
the chain-of-custody of electronic health records.</p>
    </sec>
    <sec id="sec-3">
      <title>4 Discussion</title>
      <p>Any comprehensive solution for EHR integration and exchange has to be
technologically feasible but also politically acceptable. Healthcare providers will
always claim ownership of all medical records in their possession, and as long they
are HIPAA-compliant, we have to assume that they have developed adequate internal
security and privacy policies to protect these medical records. Our proposed solution
only requires a web services layer around existing systems while giving patients an
active role in the EHR exchange instead of the current practice of providing their
healthcare providers with a blank authorization to exchange their EHR with anybody.
Also, fully centralized EHR integration solutions are prone to privacy and security
lapses and disruptive hacker attacks such as Denial Of Service (DOS). Fully
distributed solutions, on the other hand, are prone to data loss if they do not offer
proper data redundancy and backup strategies. Our proposed solution maintains the
existing distributed network of systems represented by the healthcare providers but
offers a secure method for data integration on demand.
5</p>
    </sec>
    <sec id="sec-4">
      <title>Conclusion</title>
      <p>In this paper, we propose a secure and privacy-preserving SOA for health information
integration and exchange in which patients are “part owners” of their medical records,
have complete ownership of their integrated health information and decide when and
how data is modified or exchanged between healthcare providers or insurance
companies. This architecture is different from integrated Electronic Health Record
(EHR) such as Google Health and Microsoft HealtVault in that electronic health
records are not stored in online databases but instead are aggregated on demand using
web service requests. Web service providers working on behalf of the patients do not
keep copies of the complete EHR but instead provide a pass-through service, and
would require PKI-based security certificates to initiate health information exchange.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <string-name>
            <given-names>Vagelis</given-names>
            <surname>Hristidis</surname>
          </string-name>
          ,
          <string-name>
            <surname>Peter J. Clarke</surname>
            , Nagarajan Prabakar, Yi Deng,
            <given-names>Jeffrey A.</given-names>
          </string-name>
          <string-name>
            <surname>White</surname>
          </string-name>
          , Redmond P.
          <article-title>Burke: A Flexible Approach For Electronic Medical Records Exchange</article-title>
          .
          <source>In: Proceedings of the international workshop on Healthcare information and knowledge management, Conference on Information and Knowledge Management</source>
          , Arlington, Virginia, USA, Pages:
          <fpage>33</fpage>
          -
          <lpage>40</lpage>
          . (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <string-name>
            <surname>Au</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ; Croll,
          <string-name>
            <given-names>P.</given-names>
            :
            <surname>Consumer-Centric And</surname>
          </string-name>
          Privacy
          <string-name>
            <surname>-Preserving Identity Management For Distributed E-Health Systems</surname>
          </string-name>
          .
          <source>In: Proceedings of the 41st Annual Hawaii International Conference on System Sciences</source>
          , vol., no., pp.
          <fpage>234</fpage>
          -
          <issue>234</issue>
          ,
          <fpage>7</fpage>
          -
          <lpage>10</lpage>
          . (
          <year>2008</year>
          )
          <article-title>Rakesh Agrawal</article-title>
          , Jerry Kiernan, Ramakrishnan Srikant, Yirong Xu:
          <article-title>Hippocratic Databases</article-title>
          .
          <source>In: Proceedings of the 28th international conference on Very Large Data Bases</source>
          , Hong Kong, China, Pages:
          <fpage>143</fpage>
          -
          <lpage>154</lpage>
          .(
          <year>2002</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          <string-name>
            <given-names>Deepthi</given-names>
            <surname>Rajeev</surname>
          </string-name>
          ,
          <string-name>
            <surname>Catherine J Staes</surname>
            ,
            <given-names>R Scott</given-names>
          </string-name>
          <string-name>
            <surname>Evans</surname>
          </string-name>
          , Susan Mottice, Robert Rolfs, Matthew H Samore, Jon Whitney, Richard Kurzban, Stanley M Huff,
          <year>2010</year>
          .
          <source>Development Of An Electronic Public Health Case Report Using HL7 V2</source>
          .
          <article-title>5 To Meet Public Health Needs</article-title>
          .
          <source>In: The Journal of the American Medical Informatics Association</source>
          , JAMIA;
          <volume>17</volume>
          :
          <fpage>34</fpage>
          -
          <lpage>41</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          5. Song Han, Geoff Skinner, Vidyasagar Potdar,
          <string-name>
            <surname>Elizabeth Chang</surname>
            :
            <given-names>A Framework</given-names>
          </string-name>
          <string-name>
            <surname>Of Authentication And Authorization For E-Health Services</surname>
          </string-name>
          .
          <source>In: Proceedings of the 3rd ACM workshop on Secure web services</source>
          . (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          6.
          <string-name>
            <surname>Janos L. Mathe</surname>
          </string-name>
          , Sean Duncavage, Jan Werner, Bradley A.
          <string-name>
            <surname>Malin</surname>
          </string-name>
          , Akos Ledeczi,
          <source>Janos Sztipanovits: Towards The Security And Privacy Analysis Of Patient Portals. ACM SIGBED Review</source>
          , Volume
          <volume>4</volume>
          ,
          <string-name>
            <surname>Issue</surname>
            <given-names>2</given-names>
          </string-name>
          , Pages:
          <fpage>5</fpage>
          -
          <lpage>9</lpage>
          . (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          7.
          <string-name>
            <given-names>Jing</given-names>
            <surname>Jin</surname>
          </string-name>
          ,
          <string-name>
            <surname>Gail-Joon</surname>
            <given-names>Ahn</given-names>
          </string-name>
          , Hongxin Hu,
          <string-name>
            <given-names>Michael J.</given-names>
            <surname>Covington</surname>
          </string-name>
          , Xinwen Zhang:
          <article-title>PatientCentric Authorization Framework For Sharing Electronic Health Records</article-title>
          .
          <source>In Proceedings of the 14th ACM symposium on Access control models and technologies</source>
          , Pages:
          <fpage>125</fpage>
          -
          <lpage>134</lpage>
          . (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          8.
          <string-name>
            <surname>Daglish</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ;
          <string-name>
            <surname>Archer</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          :
          <article-title>Electronic Personal Health Record Systems: A Brief Review of Privacy, Security, and Architectural Issues</article-title>
          .
          <source>In: World Congress on Privacy, Security, Trust and the Management of e-Business</source>
          ,
          <year>2009</year>
          . CONGRESS '
          <volume>09</volume>
          , vol., no., pp.
          <fpage>110</fpage>
          -
          <lpage>120</lpage>
          ,
          <fpage>25</fpage>
          -
          <lpage>27</lpage>
          . (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          9.
          <string-name>
            <surname>Sloane</surname>
            , Elliot; Leroy, Gondy; And Sheetz,
            <given-names>Steven:</given-names>
          </string-name>
          <article-title>An Integrated Social Actor and Service Oriented Architecture (SOA) Approach for Improved Electronic Health Record (EHR) Privacy and Confidentiality in the US National Healthcare Information Network (NHIN)</article-title>
          .
          <source>In Americas Conference on Information Systems (AMCIS)</source>
          ,
          <source>AMCIS 2007 Proceedings. Paper 366</source>
          . (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          10.
          <string-name>
            <given-names>Ajit</given-names>
            <surname>Appari And M. Eric</surname>
          </string-name>
          <article-title>Johnson: Information Security and Privacy in Healthcare: Current State of Research</article-title>
          . In:
          <source>International Journal of Internet and Enterprise Management</source>
          . (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          11.
          <string-name>
            <surname>Vicky</surname>
            <given-names>Liu</given-names>
          </string-name>
          , Lauren May,
          <string-name>
            <given-names>William</given-names>
            <surname>Caelli</surname>
          </string-name>
          , Peter Croll:
          <article-title>Strengthening Legal Compliance For Privacy In Electronic Health Information Systems: A Review And Analysis</article-title>
          .
          <source>In: Electronic Journal of Health Informatics</source>
          , Vol
          <volume>3</volume>
          (
          <issue>1</issue>
          ):
          <fpage>e3</fpage>
          . (
          <year>2008</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          12.
          <string-name>
            <surname>Taylor</surname>
          </string-name>
          , K.L.
          <string-name>
            <surname>; O'keefe</surname>
          </string-name>
          , C.M.;
          <string-name>
            <surname>Colton</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ; Baxter,
          <string-name>
            <surname>R.</surname>
          </string-name>
          ; Sparks,
          <string-name>
            <surname>R.</surname>
          </string-name>
          ; Srinivasan,
          <string-name>
            <given-names>U.</given-names>
            ;
            <surname>Cameron</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.A.</given-names>
            ;
            <surname>Lefort</surname>
          </string-name>
          ,
          <string-name>
            <surname>L.</surname>
          </string-name>
          :
          <article-title>A Service Oriented Architecture For A Health Research Data Network</article-title>
          .
          <source>In: Proceedings. 16th International Conference on Scientific and Statistical Database Management</source>
          , vol., no., pp.
          <fpage>443</fpage>
          -
          <lpage>444</lpage>
          ,
          <fpage>21</fpage>
          -
          <lpage>23</lpage>
          . (
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>