PRIA AS: Redefining Individual Privacy in the Era of Digital Healthcare

Privacy as a Service: Protecting the Individual in Healthcare Data Processing

2016-11-01
Xiang Su, Jarkko Hyysalo, Mika Rautiainen, Jukka Riekki, Jaakko J. Sauvola, Altti Ilari Maarala, Harri Hirvonsalo, Pingjiang Li, Harri Honko
Summary
Problem
Method
Results
Takeaways
Abstract

The paper introduces PRIA AS, a privacy-centered architecture that provides "user consent as a service" within the MyData infrastructure. It integrates data security and semantic descriptions into a trust-query framework to handle multi-provider healthcare data while ensuring compliance with GDPR.

TL;DR

With the rise of digital healthcare, personal data is often siloed or used without transparent consent. This paper presents PRIA AS, a privacy-centered architecture built on the MyData principles and GDPR mandates. It shifts the paradigm by treating user consent as a managed service, allowing individuals to control how their data moves between sources and sinks without the service provider acting as a gatekeeper.

The Core Problem: The Failure of Static Consent

Modern healthcare involves a myriad of organizations—hospitals, wearable manufacturers, and insurance companies. Historically, consent has been a "paper-and-ink" process or a static checkbox on a website. These methods are:

  • Inflexible: They cannot be easily revoked or updated across different platforms.
  • Siloed: Every provider has their own silo, creating a "lock-in" effect for the patient.
  • Non-Interoperable: Data cannot flow securely between services to provide holistic health insights.

The authors argue that for digital healthcare to fulfill its promise, trust must be built into the technology itself via transparency and user-centered control.

Methodology: Privacy-as-a-Service (PRIA AS)

The researchers developed PRIA AS to operate as a middleware layer in the MyData infrastructure. The architecture is driven by five guiding principles: Control, Access, Translation, Interoperability, and Provisioning.

1. The MyData Operator

Unlike traditional models where the service provider holds both the data and the consent, PRIA AS introduces a MyData Operator. This operator acts as a "consent manager." It stores the user's permissions but never touches the actual personal health data.

2. Trust-Query Framework

The system uses two key standards:

  • UMA (User Managed Access): Based on OAuth 2.0, it allows users to manage access policies in one place.
  • MVCR (Minimum Viable Consent Record): A machine-readable format for "consent receipts" that ensures everyone—humans and machines—understands what was agreed upon.

Model Architecture Figure 1: Conceptual view of the privacy-centered architecture integrated into the MyData ecosystem.

3. The Consent Flow vs. Data Flow

The innovation lies in the separation of concerns. (1) The User authorizes a Service via the Operator. (2) The Operator issues a cryptographic token. (3) The Sink (Data Consumer) presents this token to the Source (Data Provider) to get the data. The data flows directly between Source and Sink, keeping the process lightweight and secure.

Experimental Validation: Semantic Health Reasoning

The authors validated their architecture with a proof-of-concept that generates health recommendations based on data from diverse sources (like Fitbit or hospital records).

A Semantic Reasoner was used to process raw data into actionable insights (e.g., "Very High Type 2 Diabetes Risk"). By using PRIA AS, the reasoner could access data from non-compliant third-party sources through a proxy, all while the user maintained full control via their MyData account interface.

Experimental Results Table 1: Sample rules used by the Semantic Reasoning service to infer health conditions securely.

Critical Insight & Conclusion

PRIA AS demonstrates that privacy does not have to be a barrier to innovation. By standardizing the "Consent Record," the architecture provides significant benefits:

  • Efficiency: Reduces the administrative burden of handling paper consent.
  • Cost Savings: Interoperability in US health systems alone is estimated to save $77.8 billion annually.
  • Empowerment: It places the individual back at the center of their digital life.

Limitations: While the framework is robust, its success depends on the widespread adoption of MyData-compliant APIs by major tech and healthcare giants. Without a critical mass of "Sources" and "Sinks," the ecosystem remains limited.

Future Outlook: The PRIA AS model is domain-agnostic. While tested in healthcare, its logic could easily be applied to finance (Open Banking) or smart city infrastructures, making it a blueprint for the future of human-centric data management.

Find Similar Papers

Try Our Examples

  • Search for recent papers that extend the MyData framework or PRIA AS architecture specifically for decentralized clinical trial management.
  • Which 2012 European Commission documents or early GDPR drafts served as the primary regulatory foundation for the "Privacy-as-a-Service" concept described here?
  • Are there existing studies that have applied the UMA 2.0 protocol and semantic reasoning to secure data sharing in the Internet of Things (IoT) or edge computing domains outside of healthcare?
Contents
PRIA AS: Redefining Individual Privacy in the Era of Digital Healthcare
1. TL;DR
2. The Core Problem: The Failure of Static Consent
3. Methodology: Privacy-as-a-Service (PRIA AS)
3.1. 1. The MyData Operator
3.2. 2. Trust-Query Framework
3.3. 3. The Consent Flow vs. Data Flow
4. Experimental Validation: Semantic Health Reasoning
5. Critical Insight & Conclusion