Ασφάλεια και προστασία της ιδιωτικότητας σε επιχειρησιακό περιβάλλον
View/ Open
Keywords
GDPR ; Ιδιωτικότητα δεδομένων ; Ευαίσθητα δεδομένα ; Καταγραφή δεδομένων ; Ροή δεδομένων ; Ανάλυση αποκλίσεων ; Αξιολόγηση αντικτύπου δεδομένων προσωπικού χαρακτήραAbstract
Digital health services are disrupting the healthcare sector by injecting huge innovation, improving the quality of care and strengthening the doctor-patient relationship. However, by their very nature, such services collect and manage extremely sensitive data and therefore need to comply with security and privacy requirements defined by data protection laws. To develop the technology for managing collected data in accordance with laws and especially for the new introduced regulation for the data privacy represents a painful, costly, and potentially extremely risky activity due to the possibility of data loss, thefts and penalties. Moreover, the EU legal framework is very fragmented and rapidly evolving. This makes it very difficult to understand, not to mention extracting and implementing data protection requirements to ensure compliance.
In the scope of this study was to define, present and analyze the first steps a digital health services provider might be follow in order to be prepared under the new requirements and commitments introduced from the GDPR. This study also sought to produce a detailed approach and methodology for (1) Data Inventorying - Flows (2) Data Protection Impact Assessment and (3) Gap Analysis. For the purpose of modeling and visualizing the theoretical models on to practical and better understanding outputs with countable results, I am using a case study scenario based on a startup company operates on the healthcare services by developing mobile applications for helping chronic patients and seniors .