with Guidance here:
https://media.defense.gov/2021/Jan/05/2002560140/-1/-1/0/ELIMINATING_OBSOLETE_TLS_UOO197443-20.PDF
[protecting people by good design, solid security, efficient processes and trusted services]
“The latest Sandbox report is from medicines company Novartis, which uses innovative science and digital technologies to help transform patient care and improve their experiences and outcomes.
When Novartis entered the Sandbox in July 2019 the original vision was for a voice-enabled web portal allowing patients to fill in health questionnaires from home – retaining a high standard of care but reducing unnecessary face to face appointments.
The ‘Digital Solution’ was designed to allow clinicians to draw upon the data provided online by patients, examine any changes to their patient’s condition and allow prioritisation of patients who need to be seen more urgently in clinic. Engaging with patients from their perspective remotely, allows for better clinical decision-making and less footfall in clinics.” [..]
Report
https://ico.org.uk/media/for-organisations/documents/2619244/novartis-sandbox-report.pdf
Advanced encryption schemes
Ring signatures and group pseudonyms; chaining mode; pseudonyms based on multiple identifiers or attributes; pseudonyms with prooof of ownership; secure multiparty computation; secret sharing schemes
Pseudonymization use cases in healthcare
patient record comparison use case; medical research institution use-case; distributed storage use-case;
Advanced pseudonymisation scenario: the data custodianship
Notion of data custodianship; Personal Information Management System (PIMS) as data custodian; Data custodian as a part of the hospital; Data custodian as an independent organisation; Interconnected data custodian network
Pseudonymisation use cases in cybersecurity
Entities and roles; File Reputation; URL Reputation; Security Operations Centers; Consumer customer support; Protection gap and real-time protection
Rahmenbedingungen Cloud-basierter Krankenhausinformationssysteme
https://kh-digitalisierung.de/files/downloads/Haas_Schneider_Cloud-KIS-Gutachten.pdf
Informationen zur Zulässigkeit der Datenverarbeitung außerhalb Deutschlands im Zusammenhang mit dem Prüfverfahren des BfArM gemäß § 139e FünftesBuch Sozialgesetzbuch (SGB V)
https://www.bfarm.de/SharedDocs/Downloads/DE/Medizinprodukte/Datenverarbeitung_au%C3%9Ferhalb_Deutschlands_FAQ.pdf?__blob=publicationFile&v=3
References:
The authors actually reached out to the DPAs and polled them for the following questions. (written below as they were sent to the DPAs):
https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final