Title of article :
A Certificate Authority (CA)-based cryptographic solution for HIPAA privacy/security regulations
Author/Authors :
Ray, Sangram Indian School of Mines - Department of Computer Science Engineering, India , Biswas, G.P. Indian School of Mines - Department of Computer Science Engineering, India
From page :
170
To page :
180
Abstract :
The Health Insurance Portability and Accountability Act (HIPAA) passed by the US Congress establishes a number of privacy/security regulations for e-healthcare systems. These regulations support patients’ medical privacy and secure exchange of PHI (protected health information) among medical practitioners. Three existing HIPAA-based schemes have been studied but appear to be ineffective as patients’ PHI is stored in smartcards. Moreover, carrying a smartcard during a treatment session and accessing PHI from different locations results in restrictions. In addition, authentication of the smartcard presenter would not be possible if the PIN is compromised.In this context, we propose an MCS (medical center server) should be located at each hospital and accessed via the Internet for secure handling of patients’ PHI. All entities of the proposed e-health system register online with the MCS, and each entity negotiates a contributory registration key, where public-key certificates issued and maintained by CAs are used for authentication.Prior to a treatment session, a doctor negotiates a secret session key with MCS and uploads/retrieves patients’ PHI securely. The proposed scheme has five phases, which have been implemented in a secure manner for supporting HIPAA privacy/security regulations. Finally, the security aspects, computation and communication costs of the scheme are analyzed and compared with existing methods that display satisfactory performance.
Keywords :
Health Insurance Portability and Accountability Act(HIPAA) , Certificate Authority (CA) , Protected health information(PHI) , E , health security , Medical center server (MCS) , Public key infrastructure(PKI)
Journal title :
Journal Of King Saud University - Computer an‎d Information Sciences
Journal title :
Journal Of King Saud University - Computer an‎d Information Sciences
Record number :
2609780
Link To Document :
بازگشت