This paper addresses the critical challenge of ensuring healthcare policy compliance in the context of Electronic Health Records (EHRs). Despite stringent regulations like HIPAA, significant gaps in policy compliance often remain undetected until a data breach occurs. To bridge this gap, we propose a novel blockchain-powered, smart contract-based access control model. This model is specifically designed to enforce patient-provider agreements (PPAs) and other relevant policies, thereby ensuring both policy compliance and provenance. Our approach integrates components of informed consent into PPAs, employing blockchain smart contracts to automate and secure policy enforcement. The authorization module utilizes these contracts to make informed access decisions, recording all actions in a transparent, immutable blockchain ledger. This system not only ensures that policies are rigorously applied but also maintains a verifiable record of all actions taken, thus facilitating an easy audit and proving compliance. We implement this model in a private Ethereum blockchain setup, focusing on maintaining the integrity and lineage of policies and ensuring that audit trails are accurately and securely recorded. The Proof of Compliance (PoC) consensus mechanism enables decentralized, independent auditor nodes to verify compliance status based on the audit trails recorded. Experimental evaluation demonstrates the effectiveness of the proposed model in a simulated healthcare environment. The results show that our approach not only strengthens policy compliance and provenance but also enhances the transparency and accountability of the entire process. In summary, this paper presents a comprehensive, blockchain-based solution to a longstanding problem in healthcare data management, offering a robust framework for ensuring policy compliance and provenance through smart contracts and blockchain technology.
翻译:本文针对电子健康记录(EHR)背景下确保医疗政策合规的关键挑战展开研究。尽管存在HIPAA等严格法规,但政策合规的重大漏洞往往在数据泄露事件发生后才被发现。为弥合这一鸿沟,我们提出了一种新型的基于区块链的智能合约访问控制模型。该模型专为强制执行患者-提供者协议(PPA)及其他相关政策而设计,从而确保政策合规性与可追溯性。本方法将知情同意的要素整合至PPA中,利用区块链智能合约自动执行并保障政策实施的安全性。授权模块运用这些合约做出知情访问决策,并将所有操作记录在透明且不可篡改的区块链账本中。该系统不仅确保政策得到严格实施,还维护所有操作的可验证记录,便于审计并证明合规性。我们在私有以太坊区块链环境中实现了该模型,重点保持政策完整性与来源追溯,确保审计轨迹被准确安全地记录。合规证明(PoC)共识机制使去中心化的独立审计节点能够依据记录的审计轨迹验证合规状态。实验评估展示了该模型在模拟医疗环境中的有效性。结果表明,我们的方法不仅强化了政策合规性与可追溯性,还提升了整个流程的透明度与问责性。综上,本文为医疗数据管理中一个长期存在的难题提供了基于区块链的综合解决方案,通过智能合约与区块链技术构建了确保政策合规性与可追溯性的稳健框架。