Designing Secure and Privacy-Aware IoT Services in the Health Sector
摘要
The chapter discusses the intricate challenges of privacy and data protection in eHealth/M-Health systems. These systems must adhere to specific demands from organizations and users, along with the diverse legal mandates set by the GDPR, which governs the rights of data subjects and the duties of data controllers. To tackle these challenges, the chapter introduces a Privacy and Data Protection Framework. This framework outlines necessary steps and measures—technical, organizational, and procedural—to be implemented. Unlike prior studies, it integrates privacy by design principles with the recent GDPR stipulations, facilitating a robust process for identifying essential technical security and privacy needs. Additionally, the framework suggests a method for verifying that these identified requirements meet the objectives outlined in the Data Protection Impact Assessment (DPIA), conducted in compliance with the GDPR.