An architecture for secure data management in medical research and aided diagnosis

  1. Pedrosa, Micael Cardoso Gonçalves
Supervised by:
  1. Julián Dorado Co-director
  2. Carlos Manuel Azevedo Costa Co-director

Defence university: Universidade da Coruña

Fecha de defensa: 26 September 2022

Committee:
  1. María Jesús Taboada Iglesias Chair
  2. Marcos Gestal Pose Secretary
  3. José María Barreiro Sorrivas Committee member

Type: Thesis

Teseo: 745998 DIALNET lock_openRUC editor

Abstract

The General Data Protection Regulation (GDPR) was implemented on 25 May 2018 and is considered the most important development in data privacy regulation in the last 20 years. Heavy fines are defined for violating those rules and is not something that healthcare centers can afford to ignore. The main goal of this thesis is to study and propose a secure/integration layer for healthcare data curators, where: connectivity between isolated systems (locations), unification of records in a patientcentric view and data sharing with consent approval are the cornerstones of the proposed architecture. This proposal empowers the data subject with a central role, which allows to control their identity, privacy profiles and access grants. It aims to minimize the fear of legal liability when sharing medical records by using anonymisation and making patients responsible for securing their own medical records, yet preserving the patient’s quality of treatment. Our main hypothesis is: are the Distributed Ledger and Self-Sovereign Identity concepts a natural symbiosis to solve the GDPR challenges in the context of healthcare? Solutions are required so that clinicians and researchers can maintain their collaboration workflows without compromising regulations. The proposed architecture accomplishes those objectives in a decentralized environment by adopting isolated data privacy profiles.