TOWARDS AN ECOSYSTEM FOR
PRIVACY RESPECTING ANALYSIS
OF DISTRIBUTED HEALTH DATA
Wessel Kraaij (TNO and Leiden University) and Marc van Lieshout (TNO)
OVERVIEW
Introduction: big data in health applications, privacy risks
The right to privacy
Personal data: interests of researchers vs. data subjects
FAIR & RESPECT4U
Project outlines
PIME – a privacy respecting data platform with transparency features
PRANA – privacy respecting data analytics in health care settings
07 June 20162 | Privacy respecting approach in health care applications
Respo
nsible
Empo
wering
Sec
ure
Proac
tive
Ethi
cal
Contr
olled
Transp
arent
BIG DATA IN HEALTH CARE
07 June 20163 | Privacy respecting approach in health care applications
http://www-03.ibm.com/press/us/en/photo/40728.wss
QUANTIFIED SELF
4
bron: MIT
Quantified Self
A DIY movement aiming for
improved self knowledge by
using tracking technology
(sensors and apps).
Gary Wolf (Wired): “Almost
everything we do generates
data”.
bron: RescueTime
FROM POPULATION AVERAGES
TOWARDS INDIVIDUAL TREATMENT
5
Van ‘big’ naar ik
Bron: cbw.ge en wikimedia.org
Contributing towards
Reference population
Interpretation of
QS data needs
contrasting peer
data.
07 June 20166 | Privacy respecting approach in health care applications
BMC (October 2015)
66% of tested health apps (#79) which all were accredited
according to the UK NHS accreditation scheme did not use data
encryption
90% of apps tested transmit data to the cloud
20% of apps did not have a privacy policy
78% of those with a privacy policy did not adequately describe the
nature of personal information that was transmitted
Serious risk for unforeseen and unwanted dissemination of data to
third party services without clear notification to and consent by the
end user.
APPS FOR HEALTHY LIVING
SO WHAT?
Distrust in EHR systems is high.
Data protection regulation in EU has been strengthened.
It is more difficult to do studies that aggregate patients across different
hospitals or countries.
The development of precision medicine and personalized health meets a
serious technical and legal barrier.
A possibility for more efficient and more effective health care is delayed
07 June 20167 | Privacy respecting approach in health care applications
WE NEED INNOVATIONS IN DATA
MANAGEMENT AND GOVERNANCE
#1: FAIR DATA: FINDABLE, ACCESSIBLE,
INTEROPERABLE, REUSABLE
Solution to increase the impact of public research.
Data should be accessible, to reproduce results
How about patient data?
07 June 20168 | Privacy respecting approach in health care applications
BUT PRIVACY IS A FUNDAMENTAL RIGHT
07 June 20169 | Privacy respecting approach in health care applications
EU Charter of Fundamental Rights (2009)
Article 7: Respect for private and family life: Everyone has the right to
respect for his or her private and family life, home and
communications.
Article 8: Protection of personal data: Everyone has the right to the
protection of personal data concerning him or her.
The Dutch Constitution:
Safeguards in article 10 (private life), article 11 (the body), article
12 (the home), article 13 (communications)
#2: RESPECT4U
Responsible
Empowering
Secure
ProactiveEthical
Controlled
Transparent
4
U
10 | Privacy respecting approach in health care applications 07 June 2016
MOVING TO PRACTICE: PIME AND PRANA
Two technology valorization programmes (EIT Digital and COMMIT/) funding
two separate streams of research
PIME (Personal Information Management Ecosystems)
Focus on patient self management
Dedicated middleware platform with several privacy and security features
Privacy and transparency dashboard to help patients keeping control over
their data
PRANA (Privacy Respecting ANAlysis of health data)
Focus on analysis of aggregated distributed health data
Looking for ways to enhance privacy respecting analysis of patient data
07 June 201611 | Privacy respecting approach in health care applications
07 June 201612 | Privacy respecting approach in health care applications
PIME
PERSONAL DATA STORE WITH ACCESS
CONTROL POLICIES
07 June 201613 | Privacy respecting approach in health care applications
 A set of permissions (permit or deny) or obligations based on
conditions
 Conditions use comparisons on attributes and their specified values
 Traditional AC applications are in the computer networks firewalls and
building security and are usually ROLE-based
 New access control applications are in controlled credit cards,
controlled cell phones and access to structured documents
 There is a shift underway to ABAC (attribute based access control)
 With our PDS we’re talking about Cell-Based Access Control (CBAC)*
PROOF OF THE PUDDING
PIME pilot
Middleware platform with privacy dashboard for integrated birth control
Province of Noord Holland; small pilot (few tens of patients)
TNO/Synergetics for organising patient consent (and control!)
07 June 201614 | Privacy respecting approach in health care applications
ONATAL
PRANA DATA
07 June 201615 | Privacy respecting approach in health care applications
RESEARCH QUESTION
How to perform privacy respecting analysis on sensitive data
that is distributed and should not be disclosed to the parties that perform the analysis?
Data protection and processing by design
Informed consent based transparency
Privacy respecting analysis of distributed data repositories
Provide proof of principles in 2 use cases:
Research setting: MUMC and UMCG development of distributed learning technology
focused on lung cancer prediction models
Patient setting: relate individual health data to the best matching patient profiles, while
respecting data protection rules, informed consent settings and data location
Privacy respecting analyses on
patient data without revealing data
2 Proof of Principles:
Research Setting
Patient setting
16 | Privacy respecting approach in health care applications 07 June 2016
PERSONAL HEALTH TRAIN
If it is impossible to bring the data to the learner / model (a centralized
approach)
 just bring the learner to the data ( a distributed approach)
07 June 201617 | Privacy respecting approach in health care applications
http://www.dtls.nl/fair-data/personal-health-train/
Andre Dekker, MUMC
Bram Peter ‘t Hoen,
LUMC
DTL
https://vimeo.com/138977162
CONCLUSIONS
Increasing need for sophisticated solutions that bring together:
Patients’ need for privacy respecting approaches
Patients’ need for transparency
Health care providers’ need for advanced data analytics
Working –with various stakeholders- on solutions that meet
FAIR principles (Findable – Accessible – Interoperable – Reusable)
RESPECT4U principles (Responsible – Empowering – Secure – Pro-active
– Ethical – Controlled – Transparent)
Experimentation with
Real patients – health care providers
Technology
07 June 201618 | Privacy respecting approach in health care applications
THANK YOU FOR YOUR ATTENTION
Wessel.kraaij@tno.nl marc.vanlieshout@tno.nl

More Related Content

PDF
Kraaij infrastructures for secure data analytics def brussel 2017
PDF
From personal health data to a personalized advice
PDF
Enabling Analytics on Sensitive Medical Data with Secure Multiparty Computation
PPTX
BDE SC1 Workshop 3 - iASiS (Guillermo Palma)
PPTX
Methodologies for Addressing Privacy and Social Issues in Health Data: A Case...
PDF
An Introduction to Clinical Informatics
PPTX
Data Sharing and Release Legislation
PPTX
Legal and regulatory challenges to data sharing for clinical genetics and ge...
Kraaij infrastructures for secure data analytics def brussel 2017
From personal health data to a personalized advice
Enabling Analytics on Sensitive Medical Data with Secure Multiparty Computation
BDE SC1 Workshop 3 - iASiS (Guillermo Palma)
Methodologies for Addressing Privacy and Social Issues in Health Data: A Case...
An Introduction to Clinical Informatics
Data Sharing and Release Legislation
Legal and regulatory challenges to data sharing for clinical genetics and ge...

What's hot (20)

PPTX
Group project slides of informatics infrastructure (1)
PPTX
Infrastructure of an informatics department4
PPTX
International perspective for sharing publicly funded medical research data
PPT
Health Information Strategy for New Zealand Sharing personal health information
PPTX
Clinical Informatics: some lessons learned
PPTX
Clinical trials data sharing
PPTX
Architecture and Standards
PPTX
Investigator-initiated clinical trials: a community perspective
PDF
Laurila presentation VTT SmartHealth Ecosystem Event 12.6.2019
PPTX
Hospital Cloud Forum - thoughts for panel
PPTX
Analytics in Action - Health
PPTX
Introduction to vision and scope
PPTX
The application of new technologies and IT in Health: standards as infrastruc...
PPTX
AMIA 2015 Registries in Accountable Care poster
PDF
Building a National Data Infrastructure to Advance Patient-Centered Comparati...
PPTX
BDE SC1 Workshop 3 - MIDAS (Michaela Black)
PDF
Brisbane Health-y Data: What are health and sensitive data and why are they t...
PPT
BioSHaRE: The DataSHIELD Legal Analysis Template - Susan Wallace - University...
PPTX
Interoperability in health care information systems
PPTX
Does Greece have an eHealth strategy plan?
Group project slides of informatics infrastructure (1)
Infrastructure of an informatics department4
International perspective for sharing publicly funded medical research data
Health Information Strategy for New Zealand Sharing personal health information
Clinical Informatics: some lessons learned
Clinical trials data sharing
Architecture and Standards
Investigator-initiated clinical trials: a community perspective
Laurila presentation VTT SmartHealth Ecosystem Event 12.6.2019
Hospital Cloud Forum - thoughts for panel
Analytics in Action - Health
Introduction to vision and scope
The application of new technologies and IT in Health: standards as infrastruc...
AMIA 2015 Registries in Accountable Care poster
Building a National Data Infrastructure to Advance Patient-Centered Comparati...
BDE SC1 Workshop 3 - MIDAS (Michaela Black)
Brisbane Health-y Data: What are health and sensitive data and why are they t...
BioSHaRE: The DataSHIELD Legal Analysis Template - Susan Wallace - University...
Interoperability in health care information systems
Does Greece have an eHealth strategy plan?
Ad

Similar to Towards an ecosystem for privacy respecting analysis of distributed health data (20)

PDF
Towards Privacy by Design in Personal e-Health Systems
PDF
Privacy Issues in Data-Driven Health Care
PPTX
Ethical Consideration for Patient Data Privacy in Digital Health System
PPTX
iHT2 Health IT Summit in Austin 2012 – Deborah C. Peel, MD, Founder and Chai...
DOCX
ScienceDirectAvailable online at www.sciencedirect.com
PDF
Privacy 2020 (Participants) EINS summer school
PPTX
Digital Revolution in Healthcare System
PDF
The shared value of personal and population data
PPT
Privacy Preserving DB Systems
PDF
Secondary Use of Electronic Health Information – the Way to Guard Patient Sec...
PPTX
Knowing me, knowing you, knowing your disease
PPTX
Governance And Data Protection In The Health Sector - Billy Hawkes
PPTX
Extracting Intention from Web Queries– Application in eHealth Personalization
PDF
It's time for open source design in healthcare
PPT
From Lip-Service to Action: Improving Healthcare Privacy Practices
PDF
HIM-I 6-1 Stanzer Ed
PDF
[AIIM18] GDPR: whose job is it now? - Paul Lanois
PPT
Information Security & Compliance in Healthcare: Beyond HIPAA and HITECH
PPTX
Privacy of patient data versus patient safety. HIMSS Europe, Nov 6, 2014
PPTX
secured storage of Personal health record in cloude
Towards Privacy by Design in Personal e-Health Systems
Privacy Issues in Data-Driven Health Care
Ethical Consideration for Patient Data Privacy in Digital Health System
iHT2 Health IT Summit in Austin 2012 – Deborah C. Peel, MD, Founder and Chai...
ScienceDirectAvailable online at www.sciencedirect.com
Privacy 2020 (Participants) EINS summer school
Digital Revolution in Healthcare System
The shared value of personal and population data
Privacy Preserving DB Systems
Secondary Use of Electronic Health Information – the Way to Guard Patient Sec...
Knowing me, knowing you, knowing your disease
Governance And Data Protection In The Health Sector - Billy Hawkes
Extracting Intention from Web Queries– Application in eHealth Personalization
It's time for open source design in healthcare
From Lip-Service to Action: Improving Healthcare Privacy Practices
HIM-I 6-1 Stanzer Ed
[AIIM18] GDPR: whose job is it now? - Paul Lanois
Information Security & Compliance in Healthcare: Beyond HIPAA and HITECH
Privacy of patient data versus patient safety. HIMSS Europe, Nov 6, 2014
secured storage of Personal health record in cloude
Ad

Recently uploaded (20)

PPTX
Manage HIV exposed child and a child with HIV infection.pptx
PPTX
HYPERSENSITIVITY REACTIONS - Pathophysiology Notes for Second Year Pharm D St...
PPTX
CARDIOVASCULAR AND RENAL DRUGS.pptx for health study
PPTX
Hearthhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh
PDF
SEMEN PREPARATION TECHNIGUES FOR INTRAUTERINE INSEMINATION.pdf
PDF
B C German Homoeopathy Medicineby Dr Brij Mohan Prasad
PPTX
Neoplasia III.pptxjhghgjhfj fjfhgfgdfdfsrbvhv
PPT
Rheumatology Member of Royal College of Physicians.ppt
PPT
Infections Member of Royal College of Physicians.ppt
PPT
nephrology MRCP - Member of Royal College of Physicians ppt
PPTX
Electrolyte Disturbance in Paediatric - Nitthi.pptx
PPTX
Neonate anatomy and physiology presentation
PPTX
NUCLEAR-MEDICINE-Copy.pptxbabaabahahahaahha
PPTX
Wheat allergies and Disease in gastroenterology
PDF
Transcultural that can help you someday.
PPTX
NRP and care of Newborn.pptx- APPT presentation about neonatal resuscitation ...
PDF
OSCE SERIES ( Questions & Answers ) - Set 3.pdf
PPTX
Effects of lipid metabolism 22 asfelagi.pptx
PDF
OSCE SERIES ( Questions & Answers ) - Set 5.pdf
PDF
The_EHRA_Book_of_Interventional Electrophysiology.pdf
Manage HIV exposed child and a child with HIV infection.pptx
HYPERSENSITIVITY REACTIONS - Pathophysiology Notes for Second Year Pharm D St...
CARDIOVASCULAR AND RENAL DRUGS.pptx for health study
Hearthhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh
SEMEN PREPARATION TECHNIGUES FOR INTRAUTERINE INSEMINATION.pdf
B C German Homoeopathy Medicineby Dr Brij Mohan Prasad
Neoplasia III.pptxjhghgjhfj fjfhgfgdfdfsrbvhv
Rheumatology Member of Royal College of Physicians.ppt
Infections Member of Royal College of Physicians.ppt
nephrology MRCP - Member of Royal College of Physicians ppt
Electrolyte Disturbance in Paediatric - Nitthi.pptx
Neonate anatomy and physiology presentation
NUCLEAR-MEDICINE-Copy.pptxbabaabahahahaahha
Wheat allergies and Disease in gastroenterology
Transcultural that can help you someday.
NRP and care of Newborn.pptx- APPT presentation about neonatal resuscitation ...
OSCE SERIES ( Questions & Answers ) - Set 3.pdf
Effects of lipid metabolism 22 asfelagi.pptx
OSCE SERIES ( Questions & Answers ) - Set 5.pdf
The_EHRA_Book_of_Interventional Electrophysiology.pdf

Towards an ecosystem for privacy respecting analysis of distributed health data

  • 1. TOWARDS AN ECOSYSTEM FOR PRIVACY RESPECTING ANALYSIS OF DISTRIBUTED HEALTH DATA Wessel Kraaij (TNO and Leiden University) and Marc van Lieshout (TNO)
  • 2. OVERVIEW Introduction: big data in health applications, privacy risks The right to privacy Personal data: interests of researchers vs. data subjects FAIR & RESPECT4U Project outlines PIME – a privacy respecting data platform with transparency features PRANA – privacy respecting data analytics in health care settings 07 June 20162 | Privacy respecting approach in health care applications Respo nsible Empo wering Sec ure Proac tive Ethi cal Contr olled Transp arent
  • 3. BIG DATA IN HEALTH CARE 07 June 20163 | Privacy respecting approach in health care applications http://www-03.ibm.com/press/us/en/photo/40728.wss
  • 4. QUANTIFIED SELF 4 bron: MIT Quantified Self A DIY movement aiming for improved self knowledge by using tracking technology (sensors and apps). Gary Wolf (Wired): “Almost everything we do generates data”. bron: RescueTime
  • 5. FROM POPULATION AVERAGES TOWARDS INDIVIDUAL TREATMENT 5 Van ‘big’ naar ik Bron: cbw.ge en wikimedia.org Contributing towards Reference population Interpretation of QS data needs contrasting peer data.
  • 6. 07 June 20166 | Privacy respecting approach in health care applications BMC (October 2015) 66% of tested health apps (#79) which all were accredited according to the UK NHS accreditation scheme did not use data encryption 90% of apps tested transmit data to the cloud 20% of apps did not have a privacy policy 78% of those with a privacy policy did not adequately describe the nature of personal information that was transmitted Serious risk for unforeseen and unwanted dissemination of data to third party services without clear notification to and consent by the end user. APPS FOR HEALTHY LIVING
  • 7. SO WHAT? Distrust in EHR systems is high. Data protection regulation in EU has been strengthened. It is more difficult to do studies that aggregate patients across different hospitals or countries. The development of precision medicine and personalized health meets a serious technical and legal barrier. A possibility for more efficient and more effective health care is delayed 07 June 20167 | Privacy respecting approach in health care applications WE NEED INNOVATIONS IN DATA MANAGEMENT AND GOVERNANCE
  • 8. #1: FAIR DATA: FINDABLE, ACCESSIBLE, INTEROPERABLE, REUSABLE Solution to increase the impact of public research. Data should be accessible, to reproduce results How about patient data? 07 June 20168 | Privacy respecting approach in health care applications
  • 9. BUT PRIVACY IS A FUNDAMENTAL RIGHT 07 June 20169 | Privacy respecting approach in health care applications EU Charter of Fundamental Rights (2009) Article 7: Respect for private and family life: Everyone has the right to respect for his or her private and family life, home and communications. Article 8: Protection of personal data: Everyone has the right to the protection of personal data concerning him or her. The Dutch Constitution: Safeguards in article 10 (private life), article 11 (the body), article 12 (the home), article 13 (communications)
  • 10. #2: RESPECT4U Responsible Empowering Secure ProactiveEthical Controlled Transparent 4 U 10 | Privacy respecting approach in health care applications 07 June 2016
  • 11. MOVING TO PRACTICE: PIME AND PRANA Two technology valorization programmes (EIT Digital and COMMIT/) funding two separate streams of research PIME (Personal Information Management Ecosystems) Focus on patient self management Dedicated middleware platform with several privacy and security features Privacy and transparency dashboard to help patients keeping control over their data PRANA (Privacy Respecting ANAlysis of health data) Focus on analysis of aggregated distributed health data Looking for ways to enhance privacy respecting analysis of patient data 07 June 201611 | Privacy respecting approach in health care applications
  • 12. 07 June 201612 | Privacy respecting approach in health care applications PIME
  • 13. PERSONAL DATA STORE WITH ACCESS CONTROL POLICIES 07 June 201613 | Privacy respecting approach in health care applications  A set of permissions (permit or deny) or obligations based on conditions  Conditions use comparisons on attributes and their specified values  Traditional AC applications are in the computer networks firewalls and building security and are usually ROLE-based  New access control applications are in controlled credit cards, controlled cell phones and access to structured documents  There is a shift underway to ABAC (attribute based access control)  With our PDS we’re talking about Cell-Based Access Control (CBAC)*
  • 14. PROOF OF THE PUDDING PIME pilot Middleware platform with privacy dashboard for integrated birth control Province of Noord Holland; small pilot (few tens of patients) TNO/Synergetics for organising patient consent (and control!) 07 June 201614 | Privacy respecting approach in health care applications ONATAL
  • 15. PRANA DATA 07 June 201615 | Privacy respecting approach in health care applications
  • 16. RESEARCH QUESTION How to perform privacy respecting analysis on sensitive data that is distributed and should not be disclosed to the parties that perform the analysis? Data protection and processing by design Informed consent based transparency Privacy respecting analysis of distributed data repositories Provide proof of principles in 2 use cases: Research setting: MUMC and UMCG development of distributed learning technology focused on lung cancer prediction models Patient setting: relate individual health data to the best matching patient profiles, while respecting data protection rules, informed consent settings and data location Privacy respecting analyses on patient data without revealing data 2 Proof of Principles: Research Setting Patient setting 16 | Privacy respecting approach in health care applications 07 June 2016
  • 17. PERSONAL HEALTH TRAIN If it is impossible to bring the data to the learner / model (a centralized approach)  just bring the learner to the data ( a distributed approach) 07 June 201617 | Privacy respecting approach in health care applications http://www.dtls.nl/fair-data/personal-health-train/ Andre Dekker, MUMC Bram Peter ‘t Hoen, LUMC DTL https://vimeo.com/138977162
  • 18. CONCLUSIONS Increasing need for sophisticated solutions that bring together: Patients’ need for privacy respecting approaches Patients’ need for transparency Health care providers’ need for advanced data analytics Working –with various stakeholders- on solutions that meet FAIR principles (Findable – Accessible – Interoperable – Reusable) RESPECT4U principles (Responsible – Empowering – Secure – Pro-active – Ethical – Controlled – Transparent) Experimentation with Real patients – health care providers Technology 07 June 201618 | Privacy respecting approach in health care applications
  • 19. THANK YOU FOR YOUR ATTENTION Wessel.kraaij@tno.nl marc.vanlieshout@tno.nl