The privacy-aware patient-controlled personal health record (P
3HR) system protects privacy even when the personal health records (PHR) are stored into untrusted third-party-managed databases. It differs from other pseudonym-based protection systems in term of the selection of attributes for using pseudonyms, the method of handling anamnesis data and the method of controlling secondary usage of data. The stored PHRs in P
3HR become anonymous to unauthorized entities but unanonymous to authorized entities. This paper first presents a novel method for graphically representing the overall privacy level of a system. Then, the performance evaluation of P
3HR system was carried out in terms of ‘privacy level’ and ‘scope for secondary use’ of the stored health records. The privacy level was assessed based on the level and number of (i) standard security threats handled, and (ii) legal and technical objectives achieved. The scope for secondary use was measured based upon the availability and accuracy of data for secondary use. Analytical results show the superiority of P
3HR system over other systems in both of the above metrics.
View full abstract