DocumentCode
3668652
Title
Formally expressing HIPAA privacy policies for web services
Author
Tariq Alshugran;Julius Dichter;Miad Faezipour
Author_Institution
Department of Computer Science and Engineering, University of Bridgeport, CT 06604, USA
fYear
2015
fDate
5/1/2015 12:00:00 AM
Firstpage
295
Lastpage
299
Abstract
Healthcare software applications are designed to collect, store, and manage patients´ personal and medical information. Such applications are required to maintain the patients´ privacy and to comply with the privacy laws and regulations. In the United States, patients´ privacy is protected with federal regulations, more specifically the Health Insurance Portability and Accountability Act (HIPAA) of 1996 and its amendments. To guarantee compliance with HIPAA, the software application must have a decision engine which should be consulted before any operation is carried on the patients´ information to determine the operation validity and compliance. This decision engine will use HIPAA privacy rules in the decision making process, which triggers the need to formally express HIPAA privacy rules in the form of formal privacy policies. In this work, we evaluate the potential languages that can be used to formally express the extracted HIPAA privacy policies. Also, we expose any required extensions to the specification language features to support the decision engine logic.
Keywords
"Privacy","Web services","Access control","Engines","XML","Specification languages","Standards"
Publisher
ieee
Conference_Titel
Electro/Information Technology (EIT), 2015 IEEE International Conference on
Electronic_ISBN
2154-0373
Type
conf
DOI
10.1109/EIT.2015.7293356
Filename
7293356
Link To Document