MedShare: Breaking EHR Silos via Hybrid Cloud and Two-Way Authorization

Medshare: A Novel Hybrid Cloud for Medical Resource Sharing Among Autonomous Healthcare Providers

2018-01-01
Yilong Yang, Xiaoshan Li, Nafees Qamar, Peng Liu, Wei Ke, Bingqing Shen, Zhiming Liu
Summary
Problem
Method
Results
Takeaways
Abstract

MedShare is a novel hybrid cloud architecture designed for Health Information Exchange (HIE) across autonomous healthcare providers. It features a decentralized storage model that utilizes private clouds for sensitive medical records and a public cloud for de-identified patient indexing, successfully implemented across three hemodialysis centers in Macau.

TL;DR

MedShare is a hybrid cloud framework that resolves the "Interoperability Paradox" in healthcare. By keeping sensitive Electronic Health Records (EHRs) in hospital private clouds and only storing hashed pointers in a public index, it satisfies the strict privacy demands of autonomous hospitals while enabling seamless data exchange. In a study involving three Macau hospitals, it proved capable of handling 5,000 concurrent requests with sub-second latency.

Problem & Motivation: The "Information Silo" Paradox

Modern healthcare faces a frustrating contradiction: while medical data is more digital than ever, it is trapped in Legacy EHR Systems that were never designed to talk to each other.

The barriers to sharing are not just technical, but political and economic:

  1. Economic Silos: Large hospitals view patient data as a competitive asset and are reluctant to "upload" it to a central authority.
  2. Standardization Gaps: Different hospitals use different terms (e.g., card_id vs identity_id) for the same patient attributes.
  3. Security Risks: Centralized databases represent a "honeypot" for cyberattacks; a single breach could expose millions of records.

The authors' insight was to stop trying to force everyone into a single central database and instead build a Mediated Hybrid Architecture.

Methodology: The Hybrid Cloud Architecture

The core philosophy of MedShare is "Data Control at the Source." The architecture is split into two distinct views.

1. Unified Data Mapping

To solve terminology conflicts, MedShare employs a "Negotiated Common Data Model." Each hospital uses a internal Data Extractor to map legacy fields into a unified format. Unified Data Format Table

2. The Hybrid Cloud Workflow

  • Private Cloud: Stores the actual medical resources (Lab reports, CT scans, medications).
  • Public Cloud: Functions as a "Global Index." It stores a de-identified HashMap of where patient records are located.

MedShare Internal Architecture

3. Two-Way Authorization

Security is handled through a double-gate mechanism:

  1. Doctor Authorization: Validated via Role-Based Access Control (RBAC).
  2. Patient Consent: The patient must physically swipe their ID card, which is authenticated via the Resident Identification Authority (RIA).

Experiments: Performance at Scale

The researchers stress-tested MedShare using Apache JMeter to simulate high-concurrency clinical environments.

Concurrency and Throughput

The system remained stable under intense loads. Even with 5,000 concurrent clients, the query timeout rate was kept below 0.5%. The average throughput reached roughly 1,782 queries per second.

Performance Results

The Power of Scaling

Because the system is built using Docker Containers, it can auto-scale. When increasing from 1 to 3 CPU units/replicas, the response time dropped by over 70% (from 3,051ms to 831ms), demonstrating that MedShare can grow alongside a city's healthcare infrastructure.

Critical Analysis & Conclusion

Takeaway: MedShare’s brilliance lies in its respect for the autonomy of healthcare providers. By allowing hospitals to maintain their own private clouds, the system removes the "fear of data loss" that usually stymies HIE initiatives.

Limitations:

  • Public Cloud Dependency: If the public indexing server (the "map") goes down, the records (the "treasure") cannot be found, even though they are safe in the private clouds.
  • Manual Mapping: Currently, setting up the "Data Extractor" for a new hospital requires manual negotiation of data fields.

Future Outlook: The integration of Blockchain for a tamper-proof audit trail and NLP for automated data translation across languages (like the English/Chinese mix in Macau) are the logical next steps for making MedShare a global standard for medical interoperability.

Find Similar Papers

Try Our Examples

  • Search for recent papers that combine Blockchain technology with Hybrid Cloud architectures for medical data sharing to improve auditability and trust.
  • Which research first proposed the use of HashMap-based indexing for distributed medical records, and how does it compare to modern Decentralized Identifiers (DIDs)?
  • Explore how Natural Language Processing (NLP) is currently being used to automate the "Unified Data Format" conversion process from multi-lingual legacy clinical notes.
Contents
MedShare: Breaking EHR Silos via Hybrid Cloud and Two-Way Authorization
1. TL;DR
2. Problem & Motivation: The "Information Silo" Paradox
3. Methodology: The Hybrid Cloud Architecture
3.1. 1. Unified Data Mapping
3.2. 2. The Hybrid Cloud Workflow
3.3. 3. Two-Way Authorization
4. Experiments: Performance at Scale
4.1. Concurrency and Throughput
4.2. The Power of Scaling
5. Critical Analysis & Conclusion