• DocumentCode
    3668652
  • Title

    Formally expressing HIPAA privacy policies for web services

  • Author

    Tariq Alshugran;Julius Dichter;Miad Faezipour

  • Author_Institution
    Department of Computer Science and Engineering, University of Bridgeport, CT 06604, USA
  • fYear
    2015
  • fDate
    5/1/2015 12:00:00 AM
  • Firstpage
    295
  • Lastpage
    299
  • Abstract
    Healthcare software applications are designed to collect, store, and manage patients´ personal and medical information. Such applications are required to maintain the patients´ privacy and to comply with the privacy laws and regulations. In the United States, patients´ privacy is protected with federal regulations, more specifically the Health Insurance Portability and Accountability Act (HIPAA) of 1996 and its amendments. To guarantee compliance with HIPAA, the software application must have a decision engine which should be consulted before any operation is carried on the patients´ information to determine the operation validity and compliance. This decision engine will use HIPAA privacy rules in the decision making process, which triggers the need to formally express HIPAA privacy rules in the form of formal privacy policies. In this work, we evaluate the potential languages that can be used to formally express the extracted HIPAA privacy policies. Also, we expose any required extensions to the specification language features to support the decision engine logic.
  • Keywords
    "Privacy","Web services","Access control","Engines","XML","Specification languages","Standards"
  • Publisher
    ieee
  • Conference_Titel
    Electro/Information Technology (EIT), 2015 IEEE International Conference on
  • Electronic_ISBN
    2154-0373
  • Type

    conf

  • DOI
    10.1109/EIT.2015.7293356
  • Filename
    7293356