health data privacy

Designs, implements, and evaluates policies, technical controls, and operational processes to protect personal health information and ensure adherence to healthcare privacy and security requirements. Work includes developing data governance frameworks, access controls and authentication, de‑identification/pseudonymization, consent and data‑sharing mechanisms, audit and monitoring, risk assessments and incident response, and compliance programs for healthcare data handling.

healthdataprivacy

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
-0.26
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$178K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

TRUCE: TRUsted Compliance Enforcement Service for Secure Health Data Exchange

Dec 09, 2025
DK
Dae-young Kim
🏛️ University of Maryland, Baltimore County

To address regulatory conflicts—particularly between HIPAA and the 21st Century Cures Act—and associated PII leakage risks in health data sharing, this paper proposes a Trusted Compliance Enforcement Framework for real-time, automated governance of sensitive health data. Methodologically, it introduces a novel two-layer trust modeling mechanism that integrates static regulatory requirements with dynamic organizational policies, leveraging AI-based knowledge representation, ontological modeling, semantic rule engines, and adaptive trust scoring algorithms to enable cross-regulatory compliance reasoning and millisecond-scale decision-making. Evaluated on CDC’s million-record contact-tracing dataset, the framework fully satisfies HIPAA Data Use Agreement (DUA) requirements, achieves <10 ms compliance adjudication latency, reduces manual review effort by over 90%, and significantly enhances both privacy protection efficacy and regulatory adaptability.

Automates compliance procedures for sensitive health data exchangeEnhances trusted data management using AI and semantic technologiesResolves conflicts between regulations like HIPAA and Cures Act

Artificial Intelligent Implications on Health Data Privacy and Confidentiality

Jan 03, 2025
AK
Ahmad K. Momani
🏛️ University of Wisconsin-Milwaukee

This study addresses privacy and confidentiality risks to patient health information arising from AI applications in healthcare, focusing on the dynamic tension between innovation and privacy protection. Method: Employing regulatory compliance analysis, HIPAA mapping assessment, ethical risk modeling, and cross-domain data-sharing controversy analysis, the research develops a novel three-dimensional Privacy–Innovation Assessment Model encompassing regulatory adaptability, technical robustness, and patient trustworthiness. The model is validated through real-world case studies in diabetic retinopathy screening and oncology. Contribution/Results: Six high-risk AI deployment scenarios are identified, and actionable governance guidelines for AI-enabled health data are proposed. Implementation of these guidelines increased healthcare institutions’ privacy protection maturity by 40%. Key recommendations have been formally adopted by industry regulatory bodies as policy reference material.

Artificial IntelligenceHealth Information PrivacyPatient Confidentiality

This work addresses the privacy risks associated with the reuse of patient identifiers in healthcare systems by proposing a patient-centric identity management framework. The framework innovatively integrates anonymous pseudonyms with a conditional traceability mechanism and is grounded in a security architecture built upon a hardware-rooted trust anchor. Through rigorous evaluation—including MSRA architectural analysis, formal verification, and simulation-based assessment—the study demonstrates that the proposed approach is both feasible and secure under typical clinical workflow latency constraints. It effectively balances stringent privacy protection, regulatory compliance, and operational efficiency in real-world medical environments.

healthcare accesslinkabilitypatient identity management

HIPAAChecker: The Comprehensive Solution for HIPAA Compliance in Android mHealth Apps

Jun 01, 2023
BS
Bilash Saha
🏛️ Kennesaw State University | RightCodes Solutions

To address the lack of HIPAA compliance verification for mobile health (mHealth) applications, this paper introduces the first automated detection framework tailored for Android. Methodologically, it establishes the first formal model of HIPAA regulations and integrates static code analysis—including sensitive data flow tracking—with dynamic runtime monitoring. The framework delivers actionable feedback via an IDE plugin for developers and a web interface for end users, enabling end-to-end compliance assessment across development and distribution stages. Key contributions include: (1) filling the critical gap in end-to-end HIPAA compliance verification for mHealth apps; (2) enabling real-time identification and remediation of violations during coding; and (3) empowering users with privacy-aware decision-making prior to app installation. Evaluated on 52 real-world mHealth apps, the framework detected 187 HIPAA violations with a mean accuracy of 91.3%.

Addressing lack of developer awareness about health data securityDeveloping tools for secure PHI handling in mobile appsEnsuring HIPAA compliance in Android mHealth applications

Empower Healthcare through a Self-Sovereign Identity Infrastructure for Secure Electronic Health Data Access

Jan 21, 2025
AL
Antonio L'opez Mart'inez
🏛️ University of Murcia | Tél écom SudParis | Institut Polytechnique de Paris

To address security challenges in electronic health data—including data loss, dynamic access revocation, and emergency access—this paper proposes an open-source, patient-centric health data management framework grounded in Self-Sovereign Identity (SSI). Methodologically, it introduces a patient-controlled distributed storage architecture integrating fault-tolerant data recovery, dynamic fine-grained permission revocation, and a trusted emergency authorization protocol for unconscious patients. Innovatively, the framework unifies Decentralized Identifiers (DIDs), Verifiable Credentials (VCs), and blockchain to enable autonomous identity management, cryptographically verifiable operations, and end-to-end auditable provenance. A prototype system validates real-time access control, automated emergency authorization, and immutable audit logging in patient–physician interaction scenarios. Results demonstrate significant improvements in privacy protection and patient-controlled data sovereignty.

Authorization and Access ControlData Integrity and VerificationElectronic Health Information Security

Latest Papers

What's happening recently
View more

This study addresses the growing challenge of digital threats in healthcare by proposing an AI-integrated framework tailored to medical environments. The framework synergistically combines intelligent threat detection, automated response mechanisms, and privacy-enhancing technologies, all underpinned by design principles of transparency and regulatory compliance. Validated through real-world healthcare case studies, the approach demonstrably strengthens system security while ensuring adherence to stringent privacy regulations such as HIPAA and GDPR. The primary contribution lies in establishing a practical, deployable pathway for AI-driven security that balances robust protection, regulatory conformity, and operational transparency—offering healthcare institutions a technically sound and ethically responsible solution to contemporary cybersecurity and data privacy challenges.

Artificial IntelligenceData ProtectionHealthcare

This work addresses the challenges of secure electronic health record (EHR) sharing, including privacy preservation, system interoperability, and integration of heterogeneous data. The authors propose a novel architecture that combines a private blockchain with IPFS, uniquely positioning the patient as the sole authority for EHR access control. Fine-grained permission management is implemented through Hyperledger-based smart contracts, ensuring compliance with GDPR while enabling seamless cross-system integration. A prototype system was evaluated across multiple clinical scenarios, demonstrating the solution’s scalability, security, and practicality in real-world healthcare environments.

Access ControlData SharingElectronic Health Records

This study addresses the critical challenge of securely leveraging sensitive private-sector data—such as financial transactions—for public health decision-making, particularly in pandemic response, while preserving individual privacy. It introduces, for the first time, a systematic application of differentially private synthetic data generation to public health, producing high-fidelity synthetic financial transaction records that retain spatiotemporal characteristics. These synthetic data are integrated with mobility and epidemiological datasets to establish a reusable, privacy-preserving analytical framework. The authors develop a suite of six tools enabling tasks including hotspot detection, compliance monitoring, mobility analysis, and contact matrix estimation. Empirical validation demonstrates that privacy-preserving synthetic data can effectively and practically support pandemic surveillance and forecasting without compromising confidentiality.

Data SharingDifferential PrivacyPandemic Management

This work addresses the limitations of current healthcare data privacy compliance approaches, which rely heavily on manual processes and treat policy auditing and technical risk assessment in isolation, leading to inefficiency and error-proneness. To overcome these challenges, the authors propose PriEval-Protect, a two-stage framework that integrates legal large language models with data-level privacy metrics during the evaluation phase. By leveraging retrieval-augmented generation (RAG), cryptographic identification, and analytic hierarchy process (AHP) weighting, the framework produces an interpretable, composite risk score. In the protection phase, it dynamically recommends mitigation strategies—such as federated learning or differential privacy—based on this score. Validated on real-world hospital data, PriEval-Protect enables synergistic compliance with GDPR and HIPAA, delivers precise risk assessment, and offers explainable privacy safeguards, significantly enhancing the automation and consistency of privacy governance.

data privacyhealthcare systemsprivacy evaluation

This work addresses the underexplored risk of indirect patient privacy leakage through deployed clinical foundation models, a challenge inadequately mitigated by current legal and technical safeguards. It proposes, for the first time, a context-aware privacy risk assessment framework that systematically integrates technical and legal perspectives to evaluate indirect leakage risks across the model’s entire lifecycle. By combining privacy risk modeling, leakage scenario simulation, and compliance mapping with technical measures such as differential privacy and access control, the framework elucidates representative leakage mechanisms. It delivers an actionable risk assessment workflow and cross-jurisdictional compliance guidance, enabling robust privacy protection without compromising model utility.

clinical foundation modelsdata privacymodel-mediated leakage

Hot Scholars

SR

Soorya Ram Shimgekar

Student, University of Illinois at Urbana Champaign
Artificial Intelligence
SS

Simranjit Singh

Dr. B.R Ambedkar National Institute of Technology
Deep learningRemote SensingHyperspectral imagesSoil quantification
EK

Elmar Kotter

Professor für Radiologie, Universität Freiburg
RadiologyMedical ImagingComputer Aided DiagnosisArtificial Intelligence
VL

Vu Le

Microsoft
Program SynthesisMachine Learning
LT

Lynda Tamine

Professor in computer science, University of Toulouse, IRIT lab. , France
Information retrieval