Electronic health records are being adopted at a rapid rate due to increased funding from the US federal government. Health data provide the opportunity to identify possible improvements in health care delivery by applying data mining and statistical methods to the data and will also enable a wide variety of new applications that will be meaningful to patients and medical professionals. Researchers are often granted access to health care data to assist in the data mining process, but HIPAA regulations mandate comprehensive safeguards to protect the data. Often universities (and presumably other research organizations) have an enterprise information technology infrastructure and a research infrastructure. Unfortunately, both of these infrastructures are generally not appropriate for sensitive research data such as HIPAA, as they require special accommodations on the part of the enterprise information technology (or increased security on the part of the research computing environment). Cloud computing, which is a concept that allows organizations to build complex infrastructures on leased resources, is rapidly evolving to the point that it is possible to build sophisticated network architectures with advanced security capabilities. We present a prototype infrastructure in Amazon’s Virtual Private Cloud to allow researchers and practitioners to utilize the data in a HIPAA-compliant environment.
[1]
Hovav Shacham,et al.
Hey, you, get off of my cloud: exploring information leakage in third-party compute clouds
,
2009,
CCS.
[2]
Xiaowei Yang,et al.
CloudCmp: comparing public cloud providers
,
2010,
IMC '10.
[3]
Dawn Xiaodong Song,et al.
Timing Analysis of Keystrokes and Timing Attacks on SSH
,
2001,
USENIX Security Symposium.
[4]
Prashant J. Shenoy,et al.
The Case for Enterprise-Ready Virtual Private Clouds
,
2009,
HotCloud.
[5]
Tim Wafa.
How the Lack of Prescriptive Technical Granularity in HIPAA Has Compromised Patient Privacy (HIPAA EHR (Electronic Health Record) Systems Security Recommendations)
,
2010
.
[6]
Micki Krause,et al.
HIPAA201: A Framework Approach to HIPAA Security Readiness
,
2019,
Information Security Management.
[7]
Kevin B. Johnson,et al.
Two Complementary Personal Medication Management Applications Developed on a Common Platform: Case Report
,
2011,
Journal of medical Internet research.
[8]
Ian Lumb,et al.
A Taxonomy and Survey of Cloud Computing Systems
,
2009,
2009 Fifth International Joint Conference on INC, IMS and IDC.