PubMed Health⌕ Search

Biomedical subjects

H Bouzelat

Publications and source records attributed to H Bouzelat.

10 recordsLinked to original sources

[Security services: an overview of the French legislation on cryptography].

This paper deals with the main security services of data protection: integrity, authentication, nonrepudiation and confidentiality. It describes the different tools which may be used to achieve these security objectives: encryption, digital signature, access controls, integrity control, audit and certification. The French legislation concerning encryption has been recently updated in order to simplify the use of encryption techniques for personal data security. This legislation describes different authorization or reporting procedures according to the type of the request (application, equipment, import or export of encryption techniques) and the security level required.

Algorithms↗

[Security of healthcare data networks used for epidemiological studies].

Record linkage, for compiling sameperson records from various source files, can improve the feasibility of epidemiological research using populationbased studies. The question is comply with the European legislation on data privacy and data security. For example, a computerized record hash coding and linkage procedure is described to link medical information within the framework of epidemiological followup. Before their extraction, files are rendered anonymous using a oneway hash coding based on the standard hash algorithm (SHA) function. Once rendered anonymous using the software ANONYMAT, the linkage of patient information can be accomplished by means of a mixture model, taking into account several identification variables. An application of this anonymous record linkage procedure was carried out in order to link medical files on cancer, from 3 hospitals of the French RhôneAlpes region. This application stresses how the use of the ANONYMAT software allows compliance with the legislation on data confidentiality without entailing problems on data availability.

Computer Communication Networks↗

How to ensure data security of an epidemiological follow-up: quality assessment of an anonymous record linkage procedure.

A computerised record hash coding and linkage procedure is proposed to allow the chaining of medical information within the framework of epidemiological follow-up. Before their extraction, files are rendered anonymous using a one-way hash coding based on the standard hash algorithm (SHA) function, in order to respect the legislation on data privacy and security. To avoid dictionary attacks. two keys have been added to SHA coding. Once rendered anonymous, the linkage of patient information can be accomplished by means of a statistical model, taking into account several identification variables. Quality assessment of this anonymous record linkage procedure shows a specificity of 100% and a sensitivity of 95%.

Algorithms↗

Security aspects of medical file regrouping for the epidemiological follow-up.

To carry out epidemiological studies at a regional level, one may need to link information collected by medical doctors working either in hospitals or in private offices or laboratories. The first problem is to respect the European legislation on nominal data processing, which does not allow the linkage of nominal files. As a consequence, we have developed an anonymous record linkage procedure, which ensures an irreversible transformation of identity and allows the linkage of rendered anonymous files. The second problem is to ensure data security during the transmission and we discuss the advantages of different methods of communication such as the norms X400 and Internet protocols.

Computer Communication Networks↗

Automatic record hash coding and linkage for epidemiological follow-up data confidentiality.

A protocol is proposed to allow linkage of anonymous medical information within the framework of epidemiological follow-up studies. The protocol is composed of two steps; the first concerns the irreversible transformation of identification data, using a one-way hash function which is used after spelling processing. To avoid dictionary attacks, two large random files of keys, called pads, are introduced. The second step consists in the linkage of files rendered anonymous. The weight given to each linkage field is estimated by a mixture model, the likelihood of which being maximized with the Expectation and Maximization (EM) algorithm. The performance of this method has been assessed by comparing record linkage, based on exclusive use of the automatic procedure, with a manual linkage, obtained by the Burgundy Registry of Digestive Cancers. The result of the linkage of a file of 2,847 cancers with a file of 388,614 hospitalization stays in the Dijon university hospital showed a sensitivity of 97% and a specificity of 93%.

Algorithms↗

A computerized record hash coding and linkage procedure to warrant epidemiological follow-up data security.

A computerized record hash coding and linkage procedure is proposed to allow the chaining of medical information within the framework of epidemiological follow-up. Before their extraction, files are rendered anonymous using a one-way hash coding based on the SHA function, in order to respect the legislation on data privacy and security. To avoid dictionary attacks, two keys have been added to SHA coding. Once rendered anonymous, the linkage of patient information can be accomplished by the means of a statistical model, taking into account several identification variables.

Confidentiality↗

[Modelling of length of stay and costs in 2 homogeneous groups of hematological and pneumological patients: clinical characterization of patients with long-stay and high costs].

After the implementation of the Medicare Prospective Payment System (PPS) in the USA, many European countries like France have introduced DRGs to curb hospital overspending. However, there has been some reluctance from hospital actors, especially because of the heterogeneous nature of DRG's. To analyse this situation, we propose a method based on distribution modelization of length of stays and costs within DRGs. For each DRG, the model is based on a mixture of Poisson and Weibull distributions identified as subgroups. The subgroups are characterized by their means and their proportions which are estimated by maximization of data likelihood. For a particular DRG, the proportion of long stay or high-cost patients can be explained by the introduction of clinical variables in the model. First the model was applied to the DRG "leukemia and lymphoma" (HCFA V.3), using 133 discharge abstract files from the Dijon public teaching hospital which were classified into this DRG in 1993. Among the studies parameters only acute leukemia, neutropenia < 500 PNN/mm3, high dose aplastic chemotherapy, central venous catheterization, parenteral nutrition, use of protected or laminar air flow room, septicemia, large spectrum intravenous antibiotherapy, and blood transfusion had a significant influence on the distribution of the patients in the long stay or costly subgroup. Second, for DRG "chronic bronchopneumopathies" (n = 220) the significant parameters were mechanical ventilation, antibiotherapy, post hospitalization medicalized care.

Adolescent↗

Extraction and anonymity protocol of medical file.

To carry out the epidemiological study of patients suffering from a given cancer, the Department of Medical Informatics (DIM) has to link information coming from different hospitals and medical laboratories in the Burgundy region. Demands from the French department for computerized information security (Commission Nationale de l'Informatique et des Libertés: CNIL), in regard to abiding by the law of January 6, 1978, completed by the law of July 1st, 1994 on nominal data processing in the framework of medical research have to be taken into account. Notably, the CNIL advised to render anonymous patient identities before the extraction of each establishment file. This paper describes a recently implemented protocol, registered with the French department for computerized information security (Service Central de la Sécurité des Systèmes d'information : SCSSI) whose purpose is to render anonymous medical files in view of their extraction. Once rendered anonymous, these files will be exportable so as to be merged with other files and used in a framework of epidemiological studies. Therefore, this protocol uses the Standard Hash Algorithm (SHA) which allows the replacement of identities by their imprints while ensuring a minimal collision rate in order to allow a correct linkage of the different information concerning the same patient. A first evaluation of the extraction and anonymity software with regard to the purpose of an epidemiological survey is described here. In this paper, we also show how it would be possible to implement this system by means of the Internet communication network.

Computer Communication Networks↗

A one way public key cryptosystem for the linkage of nominal files in epidemiological studies.

An encryption method is proposed for nominal files to allow their linkage while respecting confidentiality rules. In contrast to most encryption algorithms, this encryption method must be non-reversible. The method is based on congruence, like the SAN MARCO algorithm, and satisfies the two following conditions. 1) Non-reversible enciphering, which implies the possibility of collisions. 2) The collision rate must be minimized, to allow file linkage. The security of this method is, in addition, guaranteed by a key, which is destroyed after enciphering and is not given to the recipient of the coded file.

Algorithms↗

Irreversible encryption method by generation of polynomials.

Patient follow up, within the framework of epidemiological studies, poses the problem of linking nominal files. An encryption method of identity is proposed to allow the linkage of medical information on the same patient while respecting the confidentiality of medical data. In contrast with most encryption algorithms, the proposed method is mathematically irreversible in response to the requirement of the French National Commission of Computerized Information Security which demands that the cryptosystem must not be decipherable even by the legitimate recipient. In order to prevent deciphering by frequency analysis, the proposed method introduces polynomial operations so that neither indication concerning the length of the string nor a possible repetition of characters can be obtained by code disclosure. The security of the system is reinforced by the use of two keys, the first one to be defined by the producers of information and the second one by the recipient so that nobody can decrypt the enciphered text.

Algorithms↗