Abstract
In the medical sphere, personal and medical information is collected, stored, and transmitted for various purposes, such as, continuity of care, rapid formulation of diagnoses, and billing. Many of these operations must comply with federal regulations like the Health Insurance Portability and Accountability Act (HIPAA). To this end, we need a specification language that can precisely capture the requirements of HIPAA. We also need an enforcement engine that can enforce the privacy policies specified in the language. In the current work, we evaluate eXtensible Access Control Markup Language (XACML) as a candidate specification language for HIPAA privacy rules. We evaluate XACML based on the set of features required to sufficiently express HIPAA, proposed by a prior work. We also discuss which of the features necessary for expressing HIPAA are missing in XACML. We then present high level designs of how to enhance XACML’s enforcement engine to support the missing features.
| Original language | English |
|---|---|
| State | Published - 2012 |
| Event | 3rd USENIX Workshop on Health Security and Privacy, HealthSec 2012, co-located with the 21st USENIX Security Symposium - Bellevue, United States Duration: Aug 6 2012 → Aug 7 2012 |
Conference
| Conference | 3rd USENIX Workshop on Health Security and Privacy, HealthSec 2012, co-located with the 21st USENIX Security Symposium |
|---|---|
| Country/Territory | United States |
| City | Bellevue |
| Period | 08/6/12 → 08/7/12 |
Fingerprint
Dive into the research topics of 'On XACML’s adequacy to specify and to enforce HIPAA'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver