Privacy Policy Specification and Audit in a Fixed-Point Logic - How to Enforce HIPAA, GLBA and All That

Abstract

Organizations such as hospitals and banks that collect and use personal information are required to comply with privacy regulations like the Health Insurance Portability and Accountability Act (HIPAA) and the Gramm-Leach-Bliley Act (GLBA). With the goal of speci cation and enforcement of such prac- tical policies, we develop the logic PrivacyLFP, whose syntax is an extension of the xed point logic LFP with operators of linear temporal logic. We model organizational processes by assigning role-based responsibilities to agents that are also expressed in the same logic. To aid in designing such processes we develop a semantic locality criterion to characterize responsibilities that agents (or groups of agents) have a strategy to discharge, and easily checkable, sound syntactic characterizations of responsibilities that meet this criterion. Policy enforcement is achieved through a combination of techniques: (a) a design-time analysis of the organizational process to show that the privacy policy is respected if all agents act responsibly, using a sound proof system we develop for PrivacyLFP; and (b) a posthoc audit of logs of organizational activity that identi es agents who did not live up to their responsibilities, using a model checking procedure we develop for PrivacyLFP. We illustrate these enforcement techniques using a representative example of an organizational process.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
May 11, 2010
Accession Number
ADA571959

Entities

People

  • Anupam Datta
  • Deepak Garg
  • Dilsun Kırlı Kaynar
  • Henry Deyoung
  • Limin Jia

Organizations

  • Carnegie Mellon University

Tags

Communities of Interest

  • Biomedical
  • C4I

DTIC Thesaurus Topics

  • Accountability
  • Auditing
  • Business Administration
  • Case Studies
  • Computer Science
  • Health Care
  • Health Services
  • Hospitals
  • Insurance
  • Language
  • Law
  • Regulations
  • Set Theory
  • Specifications
  • Standards
  • Symbols
  • Theoretical Computer Science

Readers

  • Distributed Systems and Data Platform Development
  • Government and Public Administration Law.
  • Mathematical Modeling and Probability Theory.