PubMed Health⌕ Search

PubMed · 17074532

Comparing approaches for advanced e-health security infrastructures.

Abstract

OBJECTIVES: The healthcare systems of all developed countries face the challenge for improving quality, efficiency and safety of patients' care. For meeting this challenge, health is moving from being organisation-centred to process-based care. This process will continue in the future turning health towards person-centred architectures. This system transformation is combined with extended and advanced communication and collaboration supported and enabled by appropriate information and communication technologies (ICT), also called e-health. The resulting solutions have to be trustworthy. METHODS: There is a set of security services needed for realising trustworthy e-health solutions. Those security services must be comprehensively integrated in the e-health application. Furthermore, a set of infrastructure services has to be specified and implemented. For keeping the solutions future-proof, they have to comply with architectural principles and paradigms. RESULTS: After shortly introducing meanwhile internationally acknowledged architectural paradigms for applications, means and infrastructures providing security services, existing, or specified advanced solutions are described and compared. In that context, the Electronic Health Record as e-health core application has been especially considered. Based on published work as well as on explored solutions, the security services needed are summarised and evaluated. The pros and cons of investigated examples are collected and interpreted. In that context, especially the German health telematics framework architecture and security infrastructure and the corresponding implementable solutions on the one hand and the USA Veterans Health Administration approach to security have been carefully considered. CONCLUSION: Processes and systems are determined by policies, which define and distinguish constraints for communication and collaboration. Therefore, formally modelling policies and performing policy bridging are the main challenges to be met. As result of investigations, recommendations have been derived for establishing the trustworthiness required for any e-health solution at different level from regional to national, European, and even global scale, which are included in the conference summary.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Bernd Blobel. 2006-10-30. Comparing approaches for advanced e-health security infrastructures.. https://doi.org/10.1016/j.ijmedinf.2006.09.012

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related citations

PRISM: privacy-preserving rare disease analysis using fully homomorphic encryption.

MOTIVATION: Rare diseases affect millions of people worldwide, yet their genomic foundations remain poorly understood due to limited patient data and strict privacy regulations, such as the General Data Protection Regulation (GDPR) (https://gdpr.eu/tag/gdpr/) in March 2025. These restrictions can hinder the collaborative analysis of genomic data necessary for uncovering disease-causing variants. RESULTS: We present PRISM, a novel privacy-preserving framework based on fully homomorphic encryption (FHE) that facilitates rare disease variant analysis across multiple institutions without exposing sensitive genomic information. To address the challenges of centralized trust, PRISM is built upon a Threshold FHE scheme. This approach decentralizes key management across participating institutions and ensures no single entity can unilaterally decrypt sensitive data. Our method filters disease-causing variants under recessive, dominant, and de novo inheritance models entirely on encrypted data. We propose two algorithmic variants: a multiplication-intensive (MUL-IN) approach and an addition-intensive (ADD-IN) approach. The ADD-IN algorithms minimize the number of costly multiplication operations, enabling up to a 17× improvement in runtime for recessive/dominant filtering and 22× for de novo filtering, compared to MUL-IN methods. While ADD-IN produces larger ciphertexts, efficient parallelization via SIMD and multithreading allows it to handle millions of variants in reasonable time. To the best of our knowledge, this is the first study that utilizes FHE for privacy-preserving rare disease analysis across multiple inheritance models, demonstrating its practicality and scalability in a single-cloud setting. AVAILABILITY AND IMPLEMENTATION: The source code and the data used in this work can be found in https://github.com/mdppml/PRISM.git.

Computer Security↗

Privacy-preserving framework for genomic computations via multi-key homomorphic encryption.

MOTIVATION: The affordability of genome sequencing and the widespread availability of genomic data have opened up new medical possibilities. Nevertheless, they also raise significant concerns regarding privacy due to the sensitive information they encompass. These privacy implications act as barriers to medical research and data availability. Researchers have proposed privacy-preserving techniques to address this, with cryptography-based methods showing the most promise. However, existing cryptography-based designs lack (i) interoperability, (ii) scalability, (iii) a high degree of privacy (i.e. compromise one to have the other), or (iv) multiparty analyses support (as most existing schemes process genomic information of each party individually). Overcoming these limitations is essential to unlocking the full potential of genomic data while ensuring privacy and data utility. Further research and development are needed to advance privacy-preserving techniques in genomics, focusing on achieving interoperability and scalability, preserving data utility, and enabling secure multiparty computation. RESULTS: This study aims to overcome the limitations of current cryptography-based techniques by employing a multi-key homomorphic encryption scheme. By utilizing this scheme, we have developed a comprehensive protocol capable of conducting diverse genomic analyses. Our protocol facilitates interoperability among individual genome processing and enables multiparty tests, analyses of genomic databases, and operations involving multiple databases. Consequently, our approach represents an innovative advancement in secure genomic data processing, offering enhanced protection and privacy measures. AVAILABILITY AND IMPLEMENTATION: All associated code and documentation are available at https://github.com/farahpoor/smkhe.

Computer Security↗

Data protection in biomaterial banks for Parkinson's disease research: the model of GEPARD (Gene Bank Parkinson's Disease Germany).

Parkinson's disease (PD) is the second most common neurodegenerative disease. Although 10 gene loci have been identified to cause a Parkinsonian syndrome, these loci account only for a minority of PD patients. Large, systematic research programs are required to collect, store, and analyze DNA samples and clinical information to support further discovery of additional genetic components of PD or other movement disorders. Such programs facilitate research into the relationship between genotype and phenotype. The German Competence Network on Parkinson's disease (CNP) initiated the Gene Bank Parkinson's Disease Germany (GEPARD), providing an administrative and scientific infrastructure for the storage of DNA and clinical data that are electronically accessible and protective of patient rights. In this article, we offer guidance on how to establish a framework for a clinical genetic data and DNA bank, and describe GEPARD as a model that may be useful to other local, national, and international research groups developing similar programs.

Computer Security↗