MétaCan
Menu
Retour à la cohorte
Enregistrement W4390665355 · doi:10.3389/fpubh.2023.1270450

Enhancing public health research: a viewpoint report on the transition to secure, cloud-based systems

2024· article· en· W4390665355 sur OpenAlexaffabout
Plinio Pelegrini Morita, Jasleen Kaur, Pedro Augusto Da Silva E Souza Miranda

Notice bibliographique

RevueFrontiers in Public Health · 2024
Typearticle
Langueen
DomaineHealth Professions
ThématiqueMobile Health and mHealth Applications
Établissements canadiensPublic Health OntarioUniversity of TorontoUniversity of WaterlooResearch Institute for AgingUniversity Health Network
Organismes subventionnairesnon disponible
Mots-clésPublic healthCloud computingPublic opinionDigital healthFront (military)Public relationsPolitical scienceInternet privacyComputer securityMedicineComputer scienceHealth careEngineeringNursingPolitics

Résumé

récupéré en direct d'OpenAlex

The use of Personal Health Information (PHI) can revolutionize public health research. However, traditional data storage methods and security requirements present challenges to fully utilizing PHI. Cloud technology offers a solution: providing a secure, scalable, and compliant environment for storing and managing PHI. Here we share the experiences of the Ubiquitous health technology lab (University of Waterloo) in developing the new data governance framework, UbiSECE. Leveraging Microsoft's Azure cloud platform, UbiSECE centralizes data storage, integrates robust cybersecurity measures, and implements role-based access controls. The strengths, limitations, and future prospects of UbiSECE are discussed. This paper presents practical guidance for researchers and institutions aiming to adopt cloud technology to manage PHI.1 IntroductionFrom smart devices to smart home technologies, Personal Health Information (PHI) is being collected on a previously unprecedented level [1]–[8]. The individual and population metrics gathered can transform public health research, providing valuable insights into population health, disease trends, and effective interventions. Despite advancements in data availability, collection, and analysis [9]–[13], the use of PHI for research has been hindered by storage, cybersecurity, and data governance challenges [6]–[8], [14] [15]–[18]. PHI has traditionally been stored in local databases or filesystems which lack sufficient cybersecurity and data governance. This leaves sensitive health information vulnerable to unauthorized access and malicious attacks [3], [5], [19]–[28]. Local databases also lack scalability, making it difficult to accommodate large volumes of data and perform computationally intensive tasks [10], [29]–[32].Cloud-based solutions have emerged to address these challenges [33]. Our rapid literature review [34]–[39] identified several frameworks such as InfusedHeart [34], I-Health [38], and Blockchain-Based Personalized Federated Learning [39], which leverage cloud computing for public health applications. While these solutions offer insights into the potential of cloud services, it's crucial to note that their compliance with healthcare standards such as PIPEDA [17], HIPAA [18], and GDPR [15] varies. Some may partially meet these standards, addressing certain aspects of Personal Health Information (PHI) management, but there remains a lack of a comprehensive solution fully aligned with all these regulatory requirements. This gap underscores the need for a tailored approach, such as the UbiSECE framework, which is specifically designed to address the complex requirements of PHI in public health research, ensuring full compliance with these critical healthcare standards.Microsoft Azure [33], [40], a leading cloud platform, has gained popularity in public health research due to its robust infrastructure and compliance with industry standards [41]. The Ubiquitous health technology lab (UbiLab) at the University of Waterloo has faced and addressed the challenges associated with the use of PHI for public health research [42]. This paper aimed to share our experiences and insights gained in the adoption of UbiSECE, a cloud-based data governance framework. UbiSECE is based on Microsoft Azure's governance architecture guidelines and incorporates NIST 800-53 compliance with healthcare standards such as PIPEDA, HIPAA, and GDPR [15], [17], [18], [40], [41]. It also implements role-based access controls and centralizes data storage. The framework shared here serves as a blueprint for the field of public health research to create streamlined and efficient platforms for managing PHI.2 Phases2.1 Phase 1- Local SystemScenario and BenefitsIn this initial phase, each Ubilab researcher operated independently, using their own system for research data and resources. This approach resulted in a spread of data across individual computers with minimal centralized storage. Despite the challenges this posed, there were implicit benefits in this setup. Researchers experienced a certain level of comfort and familiarity with their own systems, which might have allowed for ease of use and adaptability to individual working styles. Furthermore, this decentralized approach could have been perceived as more cost-effective initially, as it relied on existing resources without additional investment in centralized infrastructure.ChallengesThe limited utilization of cloud resources and data sharing created a fragmented landscape of resources, often leading to a 'sandbox' effect between projects. This phase was marked by a lack of standardized data storage solutions, such as SQL or JSON databases, and an absence of unified data governance frameworks. Cybersecurity measures were not adequately established, leaving sensitive data potentially vulnerable. Additionally, the management of credentials was limited and primarily facilitated by the university's Information Systems & Technology (IST) department, indicating a reliance on external support for essential security processes. There was also a notable deficiency in the IT infrastructure necessary for effectively managing study participants' informed consent and re-consent, which are critical components of ethical research practices. Moreover, the detailed management of data processing costs was inefficient, leading to potential resource wastage and budgetary concerns.2.2 Phase 2- UbiLab Azure General EnvironmentScenario and BenefitsIn Phase 2, the Ubilab research team made a significant leap by upgrading to a unified cloud-based research environment utilizing Microsoft Azure. This strategic shift enabled the centralization of data storage and sharing within individual research project groups. Additionally, the team implemented enhanced data governance mechanisms, marking a pivotal change in the management and accessibility of research data.The transition to a cloud-based architecture brought about several key benefits. Firstly, it facilitated improved access to Personal Health Information (PHI) and the utilization of big data, which are crucial for advanced public health research. Secondly, the cloud environment simplified collaboration with third parties and industry partners, making the sharing and analysis of data more efficient. Another significant advantage was the reduction in sandbox sharing of resources and data, which streamlined the research process and reduced redundancies. Moreover, the ability to collect informed consent and PHI remotely and automatically through the development of scripts and Application Programming Interfaces (APIs) was a noteworthy advancement. This not only enhanced the efficiency of data collection but also aligned with the evolving needs of digital health research.ChallengesIn Phase 2, while the transition to Azure improved certain aspects, several significant challenges persisted. Obtaining or producing high-quality, ongoing, or real-time datasets from Personal Health Information (PHI) remained a complex task. The IT management responsibilities, such as the development of scripts, APIs, and cloud-based pipelines for data transfer, continued to pose substantial barriers for public health researchers.Furthermore, there were gaps in data governance frameworks, specifically in the alignment with standards like ISO/IEC 38500, as well as in cybersecurity standards and credential management. Another substantial challenge was the cost implications associated with each researcher establishing their resource group. This setup often involved unique virtual machines (VMs), storage accounts, Databricks instances, database servers, app services, and a variety of mostly underutilized resources. This not only led to inefficiencies but also contributed to increased costs.In addition, there was limited IT infrastructure support for managing study participants' informed consent and re-consent processes, which is a crucial aspect of public health research. The cost management for processing the research data also remained inefficient, further complicating the overall effectiveness of the transition to the cloud-based environment.2.3 Phase 3- UbiLab Secure NIST EnvironmentScenario and BenefitsIn Phase 3, the focus shifted to enhancing cybersecurity and data governance within the cloud environment to manage Personal Health Information (PHI) more effectively. This phase saw the incorporation of comprehensive security recommendations outlined in the National Institute of Standards and Technology (NIST) Special Publication 800-171. Additionally, it integrated compliance with multiple key regulatory frameworks, including Ontario's Freedom of Information and Protection of Privacy Act, the Personal Information Protection and Electronic Documents Act (PIPEDA), the General Data Protection Regulation (GDPR), the Personal Data Sovereignty Inter-Organizational Governance Framework for Public Health Research [43], and Azure's cloud governance framework. These integrations represented a significant advancement in the project’s approach to data security and governance.The introduction of these robust cybersecurity standards and data governance frameworks had a marked impact on enhancing the security and management of PHI. This development significantly improved trust with collaborators, as the enhanced security measures provided assurances for safer data exchanges. It also led to an increase in operational efficiency by effectively mitigating risks associated with unauthorized access. The alignment with international and regional data protection regulations further bolstered the framework's credibility and reliability, making it a more robust solution for managing sensitive health data.ChallengesIn Phase 3, as the use of Azure increased, several new challenges emerged. The implementation of a virtual private network (VPN) for resource access became necessary, which in turn required the installation of a firewall and various security and performance applications, including Azure's NIST 800-171 blueprint initiative. This shift led to a significant escalation in the costs and complexity of managing networks, controlling user access, and configuring resources.Additionally, public health researchers at UbiLab often lacked the necessary expertise to navigate these complex technical systems. This gap in knowledge necessitated one-on-one meetings to assist each researcher through the VPN setup process, as the existing documentation proved inadequate due to its technical jargon. The limited internet access from Azure resources further complicated matters, leading to stalled workflows and prolonged wait times for issue resolution.Another challenge was the complexity involved in configuring and maintaining the resources deployed in Azure. Each new resource required extensive documentation and security measures such as firewall protection, logging, tagging, and password management. These tasks were often inadequately performed due to a shortage of human resources, which added to the challenges of maintaining a secure and efficient cloud-based environment.2.4 Phase 4- Secure Ubilab Environment with a Centralized data ecosystemScenario and BenefitsIn Phase 4, the appointment of a dedicated cloud architect played a pivotal role. This specialist expedited the setup of VPNs and network configurations, significantly improving user support, resource configuration, and maintenance. Concurrently, there was a notable enhancement in cybersecurity measures. Additionally, a data governance program was established, featuring a committee composed of representative stakeholders. This committee was tasked with aligning Ubilab's data strategy with the internal objectives of stakeholders and developing a comprehensive data-sharing agreement. The implementation of these measures in Phase 4 led to the creation of a secure, centralized cloud environment that is specifically designed for managing Personal Health Information (PHI) in public health research. A notable achievement during this phase was the reduction in Azure resource costs by approx. 30-40%, which was primarily due to decreased data redundancy costs. Additionally, the establishment of the data governance program significantly streamlined the process of collecting data from data custodians, effectively reducing obstacles, and enhancing the efficiency of data management overall.ChallengesIn Phase 4, the team faced a range of barriers related to data governance in healthcare, including concerns over user privacy, meeting data security requirements, setting appropriate data standards, and managing the intricacies of cross-institutional data collection and aggregation. The challenge of managing study participants' informed consent and the related costs was also significant.To address these challenges, the team worked to establish semi-trusted relationships with stakeholders. This approach was supported by governance mechanisms such as clearly defined metrics, compliance monitoring, and auditing processes. These strategies were aimed at creating a robust and reliable framework for data governance, ensuring comprehensive management of all data aspects, from privacy to consent, in line with the broader objectives of the Ubilab project.3 UbiSECE FrameworkThe Ubilab Secure Cloud Environment (UbiSECE) was developed as the cumulative result of our experiential learning in PHI-based research (Phase 1-4). UbiSECE prioritizes data security; securely storing PHI data and providing controlled, role-based access defined by our cloud architect. Azure's governance functionalities enable us to define roles and responsibilities, monitor data usage and costs, and meet the traceability, accountability, auditability, and compliance needs of our stakeholders.UbiSECE's Azure Architecture comprises four main environments: Ubilab External, Ubilab Production, Ubilab Internal, and Ubilab Research (Figure 1). ubilab_external – This environment hosts resources, applications, APIs, or other services that are externally accessible without the need for a VPN and user account. It is designed with the highest degree of access flexibility in mind, allowing for wider data collection and interaction with external systems. However, given the open nature of this environment, no PHI is stored here. Any data collected in this environment via user interactions or APIs are transferred securely via Azure's private links to our secure data storage, thus maintaining the integrity and security of our data.ubilab_production – This domain hosts resources ready for production, serving as the active interface for deployed applications. It may include Python scripts collecting data from user sensors or a Jupyter notebook for a data science project shared with industry partners. This environment requires authentication and strict access control for any interaction. Only users with an Azure account, created and managed by our cloud administrator, can access these resources, ensuring that only authorized personnel can access these applications.ubilab_internal – This is a controlled environment where internal research projects are executed, hosted separately from the external and production domains. It's secluded from the Internet and does not involve industry partners. It offers collaborators controlled and cached access to portions of UbiLab's PHI data via virtual machines for research purposes. Direct access to centralized data storage is restricted, and any need for writing information into the central data storage requires specific privileges. As in the production environment, access requires passing through security layers and an Azure account created by our cloud administrator.ubilab_research – Dedicated to fostering academic research, this domain is exclusively reserved for UbiLab's Master’s and Ph.D. students to conduct their thesis research. Although it shares the same restricted access controls as the internal and production environments, the ubilab_research domain is distinct due to the nature of the work it hosts. It supports a wide range of academic activities, from experimental data science work to more structured, thesis-driven research projects. As in the other environments, access to resources in this domain is only possible through security layers and with an Azure account created by our cloud administrator.4 DiscussionStrengths and ScalabilityStoring and managing Personal Health Information (PHI) is a major challenge in public health research. Here we outlined the progress towards the development of UbiSECE: a private and secure cloud-based data governance framework. UbiSECE employs role-based access controls to centralized data storage to ensure the security of PHI while enabling public health research.One of the key strengths of our cloud-based solution is its scalability and accessibility. UbiSECE allows public health researchers to store and analyze large volumes of data efficiently and facilitates seamless collaboration among different teams. The UbiSECE framework also paves the way for future integration with PHR systems, enabling seamless sharing and utilization of medical records for research purposes. The scalability of the UbiSECE framework is twofold, encompassing both vertical and horizontal dimensions. Vertically, it can expand its capacity to accommodate larger datasets and more complex processing needs. Horizontally, the framework is designed to integrate emerging technologies and adapt to new research demands, ensuring its utility in the evolving landscape of public health research.Another strength lies in the framework's compliance with healthcare standards and regulations including NIST 800-53, PIPEDA, HIPAA, and GDPR. The framework ensures that PHI is handled according to established security protocols and sets a high standard for ethical and responsible data governance. Looking forward, UbiSECE is strategically positioned to evolve with the advancements in technology and the increasing demands for data in public health research. Its design and infrastructure are geared towards adaptability and scalability, ensuring its relevance and efficacy in the future.Challenges in Data Access and SecurityDespite these benefits, managing data access for new collaborators or researchers remains complex. Currently, access is granted by cloud administrators through registered user accounts with limited privileges. Streamlining and automating this process could enhance collaboration and expedite research activities. Furthermore, although the framework ensures data security, ongoing efforts are needed to refine governance programs and fully comply with NIST-800-171 and NIST-800-52 standards. Continuous improvement and regular audits are essential to mitigate emerging cybersecurity threats and maintain the integrity of the cloud infrastructure.Evaluation and FeedbackIn recognizing the importance of continuous improvement, our framework includes robust evaluation and feedback mechanisms. Weekly leadership meetings are conducted with researchers to discuss the functioning and efficacy of the UbiSECE framework. These meetings serve as a platform for researchers to provide feedback on their experiences, challenges faced, and suggestions for improvements. Adjustments to the system and processes are made as needed, based on this feedback. Additionally, monthly meetings are with stakeholders to ensure their and requirements are effectively integrated into the framework. This process of and feedback ensures that the UbiSECE framework remains to the needs of its users and to with the in public health and transition to the UbiSECE framework is supported by conducted by our dedicated cloud architect. These one-on-one researchers with the necessary to navigate and the cloud-based system effectively. These a range of from of the Azure cloud environment to advanced data management and security Additionally, comprehensive user to provide ongoing support and address technical were provided to the the of UbiLab's projects the UbiSECE framework is in a variety of research its and These include using for change and disease risks big data for public health on and smart home technologies for healthcare This range of effectiveness in enhancing both research efficiency and data security, its potential as a key in public health transition to cloud-based for managing Personal Health Information (PHI) a comprehensive of ethical that informed The adoption of cloud computing in healthcare to the critical data and the potential for data ensure within cloud environments, robust and access control mechanisms on data that and to standards. Moreover, the of data by or the implementation of governance frameworks and the of regular These are to compliance with ethical standards and requirements. these ethical is crucial to maintain trust in cloud-based healthcare and to the integrity of and research advanced data and learning within the cloud-based framework to valuable insights from healthcare Azure's learning could to and support for public health research. the and data standards between different cloud platforms and PHR could data sharing and continuous evaluation of the framework's performance and security measures and of emerging healthcare regulations and standards ensure its effectiveness and adaptability in an evolving healthcare Additionally, it's to note the aspects of the UbiSECE framework UbiLab costs for data and system setup in cloud However, these were effectively by including an approx. reduction in Azure resource costs, primarily due to decreased data redundancy and enhanced operational The scalability of cloud solutions also the need for substantial future in IT further the of this frameworks developed here can support research and knowledge while public health of that the research was conducted in the absence of any or relationships that could as a potential of – – – contributed to the and the computing services for data storage and Health health and healthcare data of A cloud computing by Microsoft for app services and data standards for information security in Data Protection for data protection and Access A system of managing user access based on and for medical information Information Protection and Electronic Documents data privacy for Programming for components A secure network over the guidelines for of data availability, and Protection of and from digital that to more data to and

Récupéré en direct depuis OpenAlex et désinversé. Les résumés ne sont pas conservés dans cette base de données : les index inversés représentent 8,6 Go des 9,3 Go de texte de la base, et le serveur dispose de 13 Go libres.

Comment cette classification a été obtenuedéplier

Prédiction machine sur la base complète

Imitation des enseignants

Ni prévalence calibrée, ni vérité terrain. Validation humaine à venir. Le volet Gemma est une étiquette directe du modèle pour chaque travail de la base, lue sur la notice réduite au titre. Le volet Codex est un classifieur appris des 10 348 étiquettes directes de Codex et calibré sur les taux pondérés de l'échantillon; les champs sans appui suffisant ne portent aucun appel Codex. Le mode candidate est l'union des deux volets; le consensus est leur intersection. Ces sorties portent le statut machine_predicted_unvalidated et ne sont pas des étiquettes humaines.

score de la tête « metaresearch » (Codex)0,063
score de la tête « metaresearch » (Gemma)0,054
Version: metacan-v3-hybrid-931329e0061cStatut de validation: machine_predicted_unvalidated
Catégories candidatesMétarecherche
Catégories consensuellesaucune
DomaineSignal candidat: Méthodes · Signal consensuel: aucune
Devis d'étudeSignal candidat: Sans objet · Signal consensuel: aucune
GenreSignal candidat: Commentaire · Signal consensuel: Commentaire
Score de désaccord entre enseignants0,937
Score d'incertitude au seuil0,331

Scores du classifieur distillé par catégorie (deux têtes)

CatégorieCodexGemma
Métarecherche0,0630,054
Méta-épidémiologie (sens strict)0,0010,001
Méta-épidémiologie (sens large)0,0010,001
Bibliométrie0,0040,005
Études des sciences et des technologies0,0050,011
Communication savante0,0210,028
Science ouverte0,0030,015
Intégrité de la recherche0,0130,015
Charge utile insuffisante (le modèle a refusé de juger)0,0080,002

Scores machine (provisoires)

Les deux têtes enseignantes du modèle étudiant, lues sur ce travail. Un score ordonne la base pour la relecture; il n'affirme jamais une catégorie, et le statut de validation accompagne chaque rangée tel quel.

Scores de référence d'un modèle non mature (critères de maturité non atteints, 7 itérations). Un score ordonne; il n'affirme jamais une catégorie.

Tête enseignante Opus0,253
Tête enseignante GPT0,477
Écart entre enseignants0,224 · la distance entre les deux têtes enseignantes sur ce seul travail
Statut de validationscore_only:v0-immature-baseline · tel quel depuis la passe de notation : score_only signifie que le nombre peut ordonner les travaux, et qu'aucune étiquette de catégorie n'en découle

Classification

machine, non validée

Prédiction automatique; un appel candidat d’une seule source (Gemma direct ou Codex distillé), pas un consensus.

Devis d'étudeSans objet
DomaineMéthodes
GenreCommentaire

Le détail, modèle par modèle et score par score, se trouve en fin de page sous « Comment cette classification a été obtenue ».

En bref

Citations3
Publié2024
Routes d'admission2
Résumé présentoui

Explorer davantage

Même revueFrontiers in Public HealthMême sujetMobile Health and mHealth ApplicationsTravaux en français237 207