Abstract

Cloud computing is rapidly evolving due to its effi cient characteristics such as cost-effectiveness, availability and elasticity. Healthcare organizatio ns and consumers lose control when they outsource t heir sensitive data and computing resources to a third p arty Cloud Service Provider (CSP), which may raise security and privacy concerns related to data loss and misuse appealing threats. Lack of consumers’ knowledge about their data storage location may lea d to violating rules and regulations of Health Insu rance Portability and Accountability Act (HIPAA) that can cost them huge penalty. Fear of data breach by int ernal or external hackers may decrease consumers’ trust i n adopting cloud computing and benefiting from its promising features. We designed a HealthcareTrusted Cloud Computing (HTCC) framework that maintains security, privacy and considers HIPAA regulations. HTCC framework deploys Trusted Computing Group (TCG) technologies such as Trusted Platform Module (TPM), Trusted Software Stack (TSS), virtual Trusted Platform Module (vTPM), Trusted Network Connect (TNC) and Self Encrypting Drives (SEDs). We emphasize on using strong multi-factor authentic ation access control mechanisms and strict security controls, as well as encryption for data at storage , in-transit and while process. We contributed in customizing a cloud Service Level Agreement (SLA) by considering healthcare requirements. HTCC was evaluated by comparing with previous researchers’ work and conducting survey from experts. Results wer e satisfactory and showed acceptance of the framework. We aim that our proposed framework will assist in optimizing trust on cloud computing to be adopted i n healthcare sector.

Highlights

  • Healthcare users are demanding higher level of IT interaction such as instant online access to are several obstacles related to security, privacy and trust that restricts its full adoption (Servos, 2012), (Mori, 2011), information, products and services through their mobile (Khatua et al, 2011)

  • HealthcareTrusted Cloud Computing (HTCC) framework was evaluated by conducting a survey from experts in information security for cloud computing and healthcare as shown in Fig. 5. 75% of experts agreed on the usage of Trusted Platform Module (TPM), Trusted Network Connect (TNC) and Self Encrypting Drives (SEDs) for securing the physical layer

  • 81% of respondents have agreed on the usage of security controls such as firewall, Anti-Malware, Anti-Virus and Intrusion Detection and Prevention Systems (IDPS) and virtual Trusted Platform Module (vTPM) for securing the virtualization layer

Read more

Summary

Introduction

Healthcare users are demanding higher level of IT interaction such as instant online access to are several obstacles related to security, privacy and trust that restricts its full adoption (Servos, 2012), (Mori, 2011), information, products and services through their mobile (Khatua et al, 2011). Healthcare organizations are struggling to outsource their data and computing resources to cloud with manage the complexity, cost and effort when upgrading their IT infrastructure, purchasing new hardware and no knowledge of data storage location and accessing person from the CSP side which may alternatively lead to HIPAA software, as well as licencing and maintenance of their violation (Popovic and Hocenski, 2010). Cloud has high potential to server as their competitors. This requires strong isolation techniques beside robust authentication and authorization maximize the efficiency and quality of healthcare services through its various service delivery and deployment models methods to preserve privacy and prevent any illegal access to their data (Takahashi et al, 2012)

Objectives
Results
Discussion
Conclusion
Full Text
Paper version not known

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call

Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.