论文标题

医疗保健区块链申请的GDPR合规性

GDPR Compliance for Blockchain Applications in Healthcare

论文作者

Hasselgren, Anton, Wan, Paul Kengfai, Horn, Margareth, Kralevska, Katina, Gligoroski, Danilo, Faxvaag, Arild

论文摘要

当应用于医疗保健用例时,与区块链相关的透明和分散特征既有吸引力又有问题。由于健康数据非常敏感,因此它也受到高度调节以确保患者的隐私。同时,访问健康数据和互操作性的需求量很高。在其他目标中,诸如GDPR和HIPAA等监管框架是为了减轻健康数据侵犯隐私的风险的其他目标。区块链特征可能可以改善互操作性和对健康数据的访问控制,同时,保留甚至增加患者的隐私。区块链应用程序应解决符合当前的监管框架,以提高现实世界的可行性。这项探索性工作表明,在卫生领域中发布的概念证明在一定程度上符合GDRP。区块链开发人员需要使设计选择符合GDPR,因为目前没有一个可用的区块链平台可以显示出合规性。

The transparent and decentralized characteristics associated with blockchain can be both appealing and problematic when applied to a healthcare use-case. As health data is highly sensitive, it is also highly regulated to ensure the privacy of patients. At the same time, access to health data and interoperability is in high demand. Regulatory frameworks such as GDPR and HIPAA are, amongst other objectives, meant to contribute to mitigating the risk of privacy violations in health data. Blockchain features can likely improve interoperability and access control to health data, and at the same time, preserve or even increase, the privacy of patients. Blockchain applications should address compliance with the current regulatory framework to increase real-world feasibility. This exploratory work indicates that published proof-of-concepts in the health domain comply with GDRP, to an extent. Blockchain developers need to make design choices to be compliant with GDPR since currently, none available blockchain platform can show compliance out of the box.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源