HIPAA and GDPR Compliance in IoT Healthcare Systems
摘要
Data privacy in the Internet of Things (IoT) remains a challenging topic in all industries, including healthcare services. The introduction of new data privacy regulations: the Health Insurance Portability and Accountability Act (HIPAA) and the European General Data Protection Regulation (GDPR) enables users to control how their data is accessed and processed, requiring consent from users before any data collection from smart devices or sensors. Consequently, the implementation of these regulations in IoT infrastructures is still a major concern for all researchers. Since these laws don’t only apply to doctors and nurses, IT personnel must comply too. In this work, a novel IoT architecture is proposed to protect users’ privacy and comply with both regulations using edge computing and encryption techniques for healthcare infrastructure.