Skip to main navigation Skip to search Skip to main content

On XACML’s adequacy to specify and to enforce HIPAA

  • Purdue University
  • University of Texas at San Antonio

Research output: Contribution to conferencePaperpeer-review

10 Scopus citations

Abstract

In the medical sphere, personal and medical information is collected, stored, and transmitted for various purposes, such as, continuity of care, rapid formulation of diagnoses, and billing. Many of these operations must comply with federal regulations like the Health Insurance Portability and Accountability Act (HIPAA). To this end, we need a specification language that can precisely capture the requirements of HIPAA. We also need an enforcement engine that can enforce the privacy policies specified in the language. In the current work, we evaluate eXtensible Access Control Markup Language (XACML) as a candidate specification language for HIPAA privacy rules. We evaluate XACML based on the set of features required to sufficiently express HIPAA, proposed by a prior work. We also discuss which of the features necessary for expressing HIPAA are missing in XACML. We then present high level designs of how to enhance XACML’s enforcement engine to support the missing features.

Original languageEnglish
StatePublished - 2012
Event3rd USENIX Workshop on Health Security and Privacy, HealthSec 2012, co-located with the 21st USENIX Security Symposium - Bellevue, United States
Duration: Aug 6 2012Aug 7 2012

Conference

Conference3rd USENIX Workshop on Health Security and Privacy, HealthSec 2012, co-located with the 21st USENIX Security Symposium
Country/TerritoryUnited States
CityBellevue
Period08/6/1208/7/12

Fingerprint

Dive into the research topics of 'On XACML’s adequacy to specify and to enforce HIPAA'. Together they form a unique fingerprint.

Cite this