A Security Mediator for Health Care Information

Wiederhold, Gio, Michel Bilello, Vatsala Sarathy, and XioaLei "Qian

Proceedings of the 1996 AMIA Conference, Washington DC, Oct. 1996, pp.120-124. Paper (ps).

The TIHI (Trusted Interoperation of Healthcare Information) project addresses a security issue that arises when some information is being shared among collaborating enterprises, although not all enterprise information is sharable. It assumes that protection exists to prevent intrusion by adversaries through secure transmission and firewalls. The TIHI system design provides a gateway, owned by the enterprise security officer, to mediate queries and responses. The latter are typically transmitted via the Internet. The enterprise policy is determined by rules provided to the mediator. We show examples of typical rules. The problem and our solution, although developed in a healthcare context, is equally valid among collaborating enterprises.