Blockchain-enabled EHR access auditing: Enhancing healthcare data security

被引:5
作者
Ullah, Faheem [1 ]
He, Jingsha [1 ]
Zhu, Nafei [1 ]
Nazir, Ahsan [1 ]
Qureshi, Sirajuddin [1 ]
Pathan, Muhammad Salman [2 ]
Dev, Soumyabrata [3 ]
机构
[1] Beijing Univ Technol, Fac Informat Technol, Beijing, Peoples R China
[2] Dublin City Univ, Sch Comp, Dublin, Ireland
[3] Univ Coll Dublin, Sch Comp Sci, Dublin, Ireland
基金
爱尔兰科学基金会; 北京市自然科学基金;
关键词
EHR audit trail; EHR access control policy verification; Smart contract; EHR audit logs; Access control pattern; Purpose-based access control; CHALLENGES; PRIVACY; RECORD;
D O I
10.1016/j.heliyon.2024.e34407
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
In the realm of modern healthcare, Electronic Health Records EHR serve as invaluable assets, yet they also pose significant security challenges. The absence of EHR access auditing mechanisms, which includes the EHR audit trails, results in accountability gaps and magnifies security vulnerabilities. This situation effectively paves the way for unauthorized data alterations to occur without detection or consequences. Inadequate EHR compliance auditing procedures, particularly in verifying and validating access control policies, expose healthcare organizations to risks such as data breaches, and unauthorized data usage. These vulnerabilities result from unchecked unauthorized access activities. Additionally, the absence of EHR audit logs complicates investigations, weakens proactive security measures, and raises concerns to put healthcare institutions at risk. This study addresses the pressing need for robust EHR auditing systems designed to scrutinize access to EHR data, encompassing who accesses it, when, and for what purpose. Our research delves into the complex field of EHR auditing, which includes establishing an immutable audit trail to enhance data security through blockchain technology. We also integrate Purpose-Based Access Control ( PBAC ) alongside smart contracts to strengthen compliance auditing by validating access legitimacy and reducing unauthorized entries. Our contributions encompass the creation of audit trail of EHR access, compliance auditing via PBAC policy verification, the generation of audit logs, and the derivation of data-driven insights, fortifying EHR access security.
引用
收藏
页数:26
相关论文
共 42 条
[1]  
Adlam Ryno, 2020, P 2 INT C INT INN CO, P1
[2]   Electronic Health Record Implementation: A Review of Resources and Tools [J].
Aguirre, Rohoam R. ;
Suarez, Orlando ;
Fuentes, Mailenys ;
Sanchez-Gonzalez, Marcos A. .
CUREUS JOURNAL OF MEDICAL SCIENCE, 2019, 11 (09)
[3]   Heterogeneous signcryption with proxy re-encryption and its application in EHR systems [J].
Ahene, Emmanuel ;
Walker, Joojo ;
Gyening, Rose-mary Owusuaa Mensah ;
Abdul-Salaam, Gaddafi ;
Ben Hayfron-Acquah, James .
TELECOMMUNICATION SYSTEMS, 2022, 80 (01) :59-75
[4]  
Al Baqari M, 2020, INT WIREL COMMUN, P2228, DOI 10.1109/IWCMC48107.2020.9148357
[5]  
Aldosari Bakheet, 2012, J. Health Inf. Dev. Ctries., V6
[6]  
Almaghrabi NS., 2022, Dr. Sulaiman Al Habib Med J, V4, P126, DOI DOI 10.1007/S44229-022-00016-9
[7]  
[Anonymous], 2009, U.S. Congress and Ways and Means Committee, Health information technology for economic and clinical health (hitech) act, Code of Federal Regulations
[8]   MedRec: Using Blockchain for Medical Data Access and Permission Management [J].
Azaria, Asaph ;
Ekblaw, Ariel ;
Vieira, Thiago ;
Lippman, Andrew .
PROCEEDINGS 2016 2ND INTERNATIONAL CONFERENCE ON OPEN AND BIG DATA - OBD 2016, 2016, :25-30
[9]  
Bakare S. S., 2024, Computer Science & IT Research Journal, V5, P528, DOI DOI 10.51594/CSITRJ.V5I3.859
[10]   Health Records Database and Inherent Security Concerns: A Review of the Literature [J].
Basil, Nduma N. ;
Ambe, Solomon ;
Ekhator, Chukwuyem ;
Fonkem, Ekokobe .
CUREUS JOURNAL OF MEDICAL SCIENCE, 2022, 14 (10)