Securing EHRs via CPMA attribute-based encryption on cloud systems

Electronic Health Records (EHRs) are further driving the volume of data as patients' files, x-rays, lab results, and other sensitive medical records are transmitted across the network. Today, nearly one-third of healthcare providers use mobile devices to access EHRs from cloud systems. With the healthcare industry facing a new reality, healthcare applications are steadily impacting the mobility and security of how caregivers and hospitals are authorized to access vital information. However, mobile services are still not generally allowed to operate with highly sensitive and personal data, mainly due to the lack of a defined security standard, low protection of data transferred through the mobile and wireless network and no standard and widely accepted user authentication method that ensure confidentiality. In this paper, a proposed privacy-preserving EHR system using ciphertext-multi authority attribute-based encryption (CPMA-ABE) will be built. In this system, patients can encrypt their EHRs and store them on semi-trusted cloud servers such that servers do not have access to sensitive EHR contexts. Meanwhile patients maintain full control over access to their EHR files, by assigning fine-grained, attribute-based access privileges to selected data users, while different users can have access to different parts of their EHR. The system also provides extra features such as populating EHR from different EHR cloud systems using ABE.

[1]  Ruoyu Wu,et al.  Secure sharing of electronic health records in clouds , 2012, 8th International Conference on Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom).

[2]  S. Laxminarayan,et al.  Status of Mobile Computing in Health Care: An Evidence Study , 2004, The 26th Annual International Conference of the IEEE Engineering in Medicine and Biology Society.

[3]  M. Ries,et al.  Electronic Medical Records: Friends or Foes? , 2014, Clinical orthopaedics and related research.

[4]  José Luis Fernández Alemán,et al.  Security and privacy in electronic health records: A systematic literature review , 2013, J. Biomed. Informatics.

[5]  Matthew Green,et al.  Securing electronic medical records using attribute-based encryption on mobile devices , 2011, SPSM '11.

[6]  Ahmad-Reza Sadeghi,et al.  Securing the e-health cloud , 2010, IHI.

[7]  Ling Liu,et al.  Security Models and Requirements for Healthcare Application Clouds , 2010, 2010 IEEE 3rd International Conference on Cloud Computing.

[8]  Ling Liu,et al.  Role-based and time-bound access and management of EHR data , 2014, Secur. Commun. Networks.

[9]  P. Mell,et al.  The NIST Definition of Cloud Computing , 2011 .