A Comprehensive Survey on Data Utility and Privacy: Taking Indian Healthcare System as a Potential Case Study
Abstract
The authors would like to thank the anonymous reviewers and editors who have been involved in examining this manuscript.
Full text
inventions Review A Comprehensive Survey on Data Utility and Privacy: Taking Indian Healthcare System as a Potential Case Study Prathamesh Churi 1,2 , Ambika Pawar 1and Antonio-JoséMoreno-Guerrero 3,* Citation: Churi, P.; Pawar, A.; Moreno-Guerrero, A.-J. A Comprehensive Survey on Data Utility and Privacy: Taking Indian Healthcare System as a Potential Case Study. Inventions 2021,6, 45. https:// doi.org/10.3390/inventions6030045 Academic Editors: Majeed Abdul and Chien-Hung Liu Received: 13 May 2021 Accepted: 17 June 2021 Published: 23 June 2021 Publisher’s Note: MDPI stays neutral with regard to jurisdictional claims in published maps and institutional affiliations. Copyright: © 2021 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https:// creativecommons.org/licenses/by/ 4.0/). 1Symbiosis Institute of Technology, Symbiosis International Deemed University, Pune 412115, India; [email protected] (P.C.); [email protected] (A.P.) 2School of Technology Management and Engineering, NMIMS University, Mumbai 400056, India 3Department of Didactics and School Organization, University of Granada, 51001 Ceuta, Spain *Correspondence: [email protected] Abstract: Background: According to the renowned and Oscar award-winning American actor and film director Marlon Brando, “privacy is not something that I am merely entitled to, it is an absolute prerequisite.” Privacy threats and data breaches occur daily, and countries are mitigating the consequences caused by privacy and data breaches. The Indian healthcare industry is one of the largest and rapidly developing industry. Overall, healthcare management is changing from disease-centric into patient-centric systems. Healthcare data analysis also plays a crucial role in healthcare management, and the privacy of patient records must receive equal attention. Purpose: This paper mainly presents the utility and privacy factors of the Indian healthcare data and discusses the utility aspect and privacy problems concerning Indian healthcare systems. It defines policies that reform Indian healthcare systems. The case study of the NITI Aayog report is presented to explain how reformation occurs in Indian healthcare systems. Findings: It is found that there have been numerous research studies conducted on Indian healthcare data across all dimensions; however, privacy problems in healthcare, specifically in India, are caused by prevalent complacency, culture, politics, budget limitations, large population, and existing infrastructures. This paper reviews the Indian healthcare system and the applications that drive it. Additionally, the paper also maps that how privacy issues are happening in every healthcare sector in India. Originality/Value: To understand these factors and gain insights, understanding Indian healthcare systems first is crucial. To the best of our knowledge, we found no recent papers that thoroughly reviewed the Indian healthcare system and its privacy issues. The paper is original in terms of its overview of the healthcare system and privacy issues. Social Implications: Privacy has been the most ignored part of the Indian healthcare system. With India being a country with a population of 130 billion, much healthcare data are generated every day. The chances of data breaches and other privacy violations on such sensitive data cannot be avoided as they cause severe concerns for individuals. This paper segregates the healthcare system’s advances and lists the privacy that needs to be addressed first. Keywords: healthcare; utility; privacy; Indian healthcare; hospitals; EHR; KPI; PDP bill; data breach; attacks 1. Introduction The healthcare industry is an emerging industry. In recent years, the healthcare industry in developing countries has grown rapidly. In the last few decades, considerable efforts have been taken to integrate information and communication technologies (ICT) into healthcare practices [ 1 , 2 ]. In E-healthcare, the latest technologies are integrated with medical infrastructures, including continuous monitoring and transfer of health-related problems from the patient-centric environment to respective services providers [ 2 – 4 ]. The volume of the data generated in the healthcare industry is rapidly escalating. In healthcare, for highly accurate prediction and early diagnosis of diseases, we must increase healthcare Inventions 2021,6, 45. https://doi.org/10.3390/inventions6030045 https://www.mdpi.com/journal/inventions
Inventions 2021,6, 45 2 of 30 data utility with the help of various technologies such as machine learning, artificial intelligence (AI), and data analysis. According to IBM global business services’ executive report in 2012, the entire healthcare system is being moved from a disease-centric to a patient-centric environment [ 4 , 5 ]. Disease-centric healthcare systems have the following features (Figure 1): 1. The health data are centrally stored according to diseases (type, symptoms, and remedial medicines). 2. Electronic health records (EHRs) are assessments and analyses conducted according to diseases. For example, we can analyze the patient data of the past ten years in a hospital with diabetes, malaria, or another joint disease. 3. Disease-centric databases present less scope for data analysis because they do not focus on individual traits and symptoms. Some diseases are related to a person’s behavior, lifestyle, and geographical location. For example, suppose a person is treated for two or three similar diseases from different hospitals in the past ten years. In that case, we must analyze his treatment records, family records, and habits, which are unavailable in the disease-centric database or may be available in heterogeneous databases, wherein a combined analysis is complex. Some data values are spread across multiple datasets maintained separately by hospitals or may have incomplete values, resulting in inappropriate/wrong prediction. The data quality is questionable to be used for analysis. Figure 1. Diseaseand patient-centric healthcare systems. By contrast, patient-centric databases have the following features: 1. The data volume generated is considerably larger and stored according to the individual patient; hence, the data quality and utility are highly satisfactory in appropriate decision making. 2. In E-healthcare, the latest technologies are integrated with medical infrastructures, including continuous monitoring and transfer of health-related problems from the patient-centric environment to respective service providers [2,3,6–9]. 3. Because an individual’s data are collected from multiple devices and sensors or through sources, maintaining the individual’s privacy is challenging. Security and privacy concerns regarding any type of data are significant problems in the current technology-driven world. With substantial healthcare data for analyses and studies, maintaining privacy is another field that requires further improvement. The data are kept anonymous from users or servers to prevent its misuse. Such health data are processed and stored dynamically at different dynamic locations with various transparencies in the distributed environment. In such a scenario, maintaining data privacy is crucial. Some privacy techniques, namely anonymization, generalization, perturbation,
Inventions 2021,6, 45 3 of 30 role-based access control, and encryption, are used to hide data. According to [ 4 ], data undergo different phases during its lifecycle: Data storage, transition, transfer, and processing. Existing privacy-preserving techniques remain in the developing stages, and strong privacy protection is still an open study topic. With the advent of the technologies mentioned above presenting the problems of maintaining data privacy, central questions that remain unaddressed in the healthcare industry field are as follows [10]: 1. Can one pursue high data utility while maintaining acceptable privacy? 2. Because privacy concerns are different for different healthcare organizations, how is the trade-off between privacy protection and data utility balanced for computing? Figure 2illustrates the trade-off between data utility and privacy. In the past years, the focus was on maintaining patient privacy and maximizing utility by considering patient privacy [11–13]. Figure 2. Trade-off between privacy and utility. With the advent of technology, the number of healthcare markets and assets in India has been increasing every year. India will have a potential healthcare market shortly. Many medical institutes are emerging because of a change in government policies. The Indian government is motivating and encouraging medical colleges to be equipped. Because the Indian healthcare structure is complex and interdependent, technology implementation and addressing privacy problems has always been a big question. Therefore, the contributions of this paper are as follows: • Provide insights into Indian healthcare systems with applications, trends, and advantages. •Describe policies that drive Indian healthcare systems •Specify technological inventions used in Indian healthcare systems. • List the various privacy issues concerning the Indian healthcare system that needs to be addressed first. Structure of Paper The paper mainly presents the utility and privacy of the healthcare data and discusses the utility aspect and privacy problems of Indian healthcare systems (Figure 3). To understand these factors and gain insights, understanding Indian healthcare systems first is
Inventions 2021,6, 45 4 of 30 crucial. Section 2presents overall Indian healthcare systems and world health organization (WHO) indicators that classify sound healthcare systems. Section 3defines policies that reform Indian healthcare systems. The case study of the NITI Aayog report is presented to explain how reformation occurs in Indian healthcare systems. Section 4describes healthcare applications in India, wherein the advantages of the healthcare system, trends in healthcare systems, and healthcare startups originated in India are explained. Section 5 presents technologies available for healthcare analytics and Indian papers based on new machine learning and AI strategies. Section 6addresses the various privacy problems discussed in the literature. Section 7concludes the study. Figure 3. Structure and contribution of the paper. 2. Indian Healthcare Systems: Overview Indian healthcare systems are divided into two sectors: Public and private. The public sector healthcare is handled by the government and opens for all people. This sector includes super-specialty hospitals equipped with medicines and instruments, which are majorly located in tier I and tier II cities. Additionally, districtand taluka-level hospitals provide healthcare services to the people [ 11 – 13 ]. Primary healthcare centers and village hospitals with low costs are available, which provide affordable services to the people. The private sector has a similar structure and is generally used by the upper-middle class and upper-class population. The overall cost of healthcare services included in the private sector is higher than that in the public sector. Technological interventions are also more diverse in the private sector than in the public sector. Figure 4illustrates the detailed structure of the Indian healthcare system. Table 1presents the difference between the public and private sectors [ 14 ]. The differentiation factor is adopted from the WHO
Inventions 2021,6, 45 5 of 30 health system themes [ 14 ]. WHO presents some descriptive indicators to define a suitable healthcare system. Figure 4. Indian healthcare system. Table 1. WHO indicators for suitable healthcare systems and Indian context. Category Sub-Category Description and Indicators The Public Sector in India The Private Sector in India Access and response Availability 24 ×seven healthcare service availability to people without any hesitation Moderate Good Timeliness of service Less waiting time to initial screening and subsequent testing, providing results, and follow-up Moderate Excellent Hospitality Highly responsive feedback system, facility, and maintenance of healthcare system Moderate Good Quality The comprehensiveness of healthcare services Availability of all the components of WHO service packages Poor Good Diagnostic Accurate diagnosis of retrospective review Moderate Excellent Management standards Rate of conformity to international disease-specific management standards Poor Good Client retention Rate of failure to follow-up or rate of appropriate patient return Moderate Moderate Outcomes Treatment success rates Rate of therapy success, controlling of population characteristics, and delayed presentation Moderate Good Population coverage The proportion of the catchment population reached through dedicated campaigns (e.g., vaccination rates) Excellent Moderate Morbidity Rate of disability to patients and controlling of population characteristics Moderate Less Mortality Rate of patient death and controlling of population characteristics Moderate Less
Inventions 2021,6, 45 6 of 30 Table 1. Cont. Category Sub-Category Description and Indicators The Public Sector in India The Private Sector in India Accountability, transparency, and regulation. Data accessibility and quality Availability of data and appropriate use of indicators and statistics Poor Good Public health functions Contribution of healthcare systems to core public health system functions (e.g., reporting of critical diseases and preventative care) Good Good Reform capacity Results of quality improvement initiatives Poor Good Fairness and equity Financial barriers to care User fees, bribes, and pharmaceutical costs Very less High Distributive justice Healthcare availability commensurate with requirements Moderate Good Efficiency Cost Absolute dollars spent for a given indication Very less High Redundancy Repetition of diagnostic time, testing, supply chains, and therapy delivery Moderate Good Fragmentation Separation of core healthcare system functions and generating sluggish management Poor Poor Delays The time between the ordering of tests or therapies and their execution Poor Good 3. Healthcare in India: Reformation in Policies Case Study: Healthcare Sector in India: NITI Aayog Report The Indian government is highly proactive in the healthcare sector and encourages outside investors to invest in the Indian healthcare industry. According to the NITI Aayog statistics [ 1 ], the Indian government will increase the public expenditure of Healthcare from 1.1% to 2.5% GDP in the next four years. This finding shows that India is set on the path of progressive Healthcare for each individual. The Indian (union and states) government spends 1.13% of the total asset from its current GDP [ 1 ]. According to the NITI Aayog report, India has inadequate and fragmented delivery of healthcare services, perhaps because of cultural and religious diversity or inadequate implementation of health policies . According to a previous report [ 1 ], NITI Aayog has reported the following reasons for challenges, opportunities, benefits, and options for improving India’s health sectors: √Strong economic foundation and policy implementation for transforming the healthcare industry, which is currently underperforming. The Indian economy is growing at a high rate. For a decade, India has controlled inflation, increased its GDP, and encouraged states to become policy-driven. The health factor of Indians has increased in the decade because of a solid economic background. The use of EHRs, medical health analysis, competent and expert health advice through machines, and data analysis through wearable devices is adopted in India. The “make in India” [ 2 ] policy helped investors invest more assets in the healthcare industry, resulting from the quality improvisation of health and healthcare industries in India. Table 2[ 3 ] summarizes Indian health systems with key performance indicators such as GDP, PPP, and global healthcare rank. The source was obtained from the Lancet journal.
Inventions 2021,6, 45 7 of 30 Table 2. Key performance indicators and source: Lancet Journal. India China Sri Lanka Indonesia Egypt Philippines Total health expenditures as % GDP 4.0% 5.5% 4% 3% 5% 4% Fiscal health expenditures as % GDP 0.9% 3.2% 2% 1% 1% 1.3% Per-capita health expenditures (PPP) 239 761 491 363 516 342 Level of out-of-pocket (% Total health expenditures) 64% 36% 50% 60% 62% 54% Neo-natal mortality 1980 60 65 24 41 53 27 Neo-natal mortality 2016 25 5 7 13 12 13 Global healthcare rank 145 92 71 138 111 124 The burden of disease (DALYs per 100,000 population) 34,000 26,300 24,000 28,900 28,000 31,000 √Healthcare system improvisation can decrease mortality and poverty rates and accelerate economic growth. Implementing critical, intelligent, and automated health systems can help Indian people improve health and reduce mortality and poverty rates. The use of AI and machine learning algorithms in digital Indian healthcare data can enable the early prediction of diseases and provide remote-level advice from medical experts. Centralization of medical healthcare records can help rapidly access patient information and increase healthcare record utility. √Unnecessary and non-uniform health sector fragmentation is the main problem of healthcare industries in India. Data fragmentation at any level and its granularity are the significant reasons for the underperformance of India’s healthcare systems. Fragmentation, a myriad of organizations, institutions (formal and informal rules), management, and administrative arrangements and entitlements that do not coordinate harmoniously and are often subjected to contradictory incentives, severely hampers the continuity of care and portability benefits [ 1 ]. In other countries, healthcare system fragmentation occurs with uniform policies and rules and has the same set of roles to access it. Uniform and limited fragmentation of the healthcare data and users helps: •Protect the healthcare data from a third-party unauthorized entity; •Have uniformity in centralized health systems. Indian healthcare policies are growing and are adaptive and structured. Several problems of healthcare systems required to secure the systems are addressed. 4. Healthcare Industry and Applications in India India is emerging in terms of revenue and employment in the healthcare field. The advances of ICT help the healthcare sector streamline data structure, access, and health analytics [ 14 – 16 ]. The healthcare sector in India is growing relatively slower due to its extensive coverage, strengthening services, and increasing expenditure by public and private players. In India, the healthcare industry is divided into public and private industries. The public healthcare industry (operated by the Indian government) is responsible for providing primary health services and treatments primarily to people in rural areas. The private sector provides amenities and services to the middle-class and upper-class people in India. 4.1. Segments of Indian Healthcare Industry The Indian healthcare system is divided into six major segments: Hospitals, pharmaceuticals, diagnostics, medical equipment and supplies, medical insurance, and telemedicine,
Inventions 2021,6, 45 8 of 30 according to the IBEF report [ 15 ]. The Infographics (Figure 5) describe each segment involved in the Indian healthcare system. Figure 5. Segments of the Indian healthcare industry [15]. 4.2. Advantages of the New Indian Healthcare Industry Make in India is the fundamental initiative taken by the Indian government. Under this flagship campaign, the healthcare sector comprising hospitals, diagnostic centers, drugs and pharmaceuticals, and medical devices is identified as a part of the initiative [ 17 , 18 ]. Because of this initiative, the healthcare industry is transforming, and Figure 6presents its benefits as infographics. Figure 6. Advantages of the Indian healthcare industry [18].
Inventions 2021,6, 45 9 of 30 4.3. Rise in Healthcare Infrastructure in India With the advent of technology, the number of healthcare markets and assets in India has been increasing each year. India will have potential healthcare markets shortly. Many medical institutes are emerging because of the changes in government policies. The Indian government is motivating and encouraging medical colleges to be equipped. According to the national health profile in 2018–19 [ 17 ], the number of medical educational infrastructures in India has increased rapidly in the past 26 years. The total number of medical colleges in FY 2019 was 529, with 1,154,686 doctors with recognized medical qualifications. The presented demographics indicate increased medical colleges and doctors with recognized medical degrees in India (Figures 7and 8). Figure 7. Number of doctors in India [17]. Figure 8. Number of medical colleges in India [17].
Inventions 2021,6, 45 16 of 30 Table 7. Existing research in the Indian healthcare industry. Types of Disease Type of Data Data Mining Technique References Data Mining of Indian Health Data Conventional pathology data Structured Support vector machine classification [32–34] Heart disease Structured and unstructured Naïve Bayes, decision tree, and K-nearest neighbor [35] Lymphoma disease and lung cancer Unstructured (image dataset) Support vector machine [36,37] Psychiatric diseases Structured and semi-structured Random forest, support vector machine (SVM), K-nearest neighbor [38,39] Liver diseases Structured k-means (KM) clustering algorithm, agglomerative nesting (AGNES), clustering algorithm, density-based spatial clustering of applications with a noise clustering algorithm, ordering points to identify the clustering structure, clustering algorithm, and exception maximization clustering algorithm [40–42] Skin disease No paper found on the Indian dataset [43] Diabetes Structured Improved K-means algorithm and logistic regression [44] Chest disease Unstructured (image dataset) Risk factor identification through correlation-based feature subset selection with particle swarm optimization search method and K-means clustering algorithms. Supervised learning algorithms such as multilayer perceptron, multinomial logistic regression, fuzzy unordered rule induction algorithm, and C4.5 classification algorithm [45] Chronic disease Structured Naïve Bayes, K-nearest neighbor, and decision tree [46,47] Breast cancer No paper found on the Indian dataset [48] Cardiovascular diseases No paper found on the Indian dataset [49] Parkinson disease No paper found on the Indian dataset [50] AI/machine learning/deep learning in the Indian health data Conventional pathology data Unstructured (image data) Convolutional neural network on pathological myopia disease for vision blindness. Classification-based glottal closure instants detection from pathological acoustic speech signals [51–56] Heart disease Structured Naïve Bayes. Decision tree and random forest [57] Lymphoma disease and lung cancer No paper found on the Indian dataset Psychiatric diseases No paper was found on the Indian dataset. Liver diseases Structured Multilayer perceptron neural network algorithm based on various decision trees algorithms such as See5 (C5.0), chi-square automatic interaction detector, and classification and regression tree with boosting technique [58] Skin disease Unstructured (image dataset) Deep learning algorithms: (inception_ v3, MobileNet, resnet, exception [59] Diabetes Structured Linear kernel SVM, radial basis function kernel SVM, k-nearest neighbor, artificial neural network, and multifactor dimensionality reduction [60] Chest disease Unstructured (image dataset) Random forest [61] Chronic disease No paper found on the Indian dataset Breast cancer Unstructured Thermolytic risk score framework [62–64] Cardiovascular diseases No paper found on the Indian dataset - Parkinson disease No paper was found on the Indian dataset. - Data visualization of the Indian health data Covid 19 dataset (open research dataset of India) Structured - [65–67] Covid 19 dataset (open research dataset of India) Unstructured (X-ray image dataset) - [68–70] Tuberculosis screening Unstructured (X-ray image dataset) - [71–73] Augmented and virtual reality in Indian Healthcare Automated data capturing from medical devices Unstructured - [74]
Inventions 2021,6, 45 17 of 30 6. Healthcare Data Privacy in India Patient privacy is the most crucial aspect and jurisdiction of all countries worldwide, and all countries have accepted that the privacy of the people must be respected under any consequences. Privacy is a fundamental right of humans [ 75 – 77 ]. Some countries (primarily Europe and the USA) strictly prioritize privacy policies. Famous laws such as HIPPA [ 78 ] and GDPR [ 79 ] provide strength to people about their privacy concerns and help them build trust. However, to date, no universal definition of privacy is available. Some definitions are perception-centric and change with countries [ 80 ]. Various definitions of privacy are as follows. Definition 1. “The state of being alone or the right to keep one’s matters and relationships secret”— definition obtained from the Cambridge dictionary [81]. Definition 2. “No one shall be subjected to arbitrary interference of their privacy, family, home, or correspondence or attacks upon their honor and reputation. Everyone has the right to the protection of the law against such interference or attacks”—article 12 universal declaration of human rights. Definition 3. “privacy can be divided into several separate, but related, concepts:” - Information privacy involves establishing rules governing collecting and handling personal data such as credit information and medical and government records. It is also known as data protection; - Bodily privacy concerns the protection of people’s physical selves against invasive procedures such as genetic tests, drug testing, and cavity searches; - Privacy of communications covers the security and privacy of mail, telephones, e-mails, and other forms of communication; and - Territorial privacy concerns the setting of limits on intrusion into the domestic and other environments such as the workplace or public space. This includes searches, video surveillance, and ID checks—Australian law reform commission. Definition 4. “Privacy is the right to be let alone or freedom from interference or intrusion. Information privacy is the right to have some control over how your personal information is collected and used”—the international association of privacy professionals. Privacy plays a vital role in the healthcare field because healthcare data contain sensitive information about patients and related stakeholders. As stated in the introduction, most healthcare fields have changed their operations from disease to patient-centric. The records of people are stored according to their characteristics, personal and emotional behavior, and geographic information. Central storage of electronic medical data across highly configured servers is one of the most suitable options for data analysis [ 82 , 83 ]. It prevents the use of duplicated or redundant data because of its central storage and maintenance. The amount of healthcare data is significant, and in India, the data are also unstructured. Furthermore, this can lead to privacy and data breaching because of its storageand transformation-related concerns. In India, Privacy is not treated as a serious concern. Privacy issues in healthcare, specific to India, are caused by prevalent complacency, culture, politics, budget limitations, large population, and infrastructures. Due to these factors, data security requires a backseat that allows easy access to confidential information. Furthermore, the prevalent culture affects healthcare disclosure in India. In many cultures, disclosing sensitive personal healthcare data is considered ill-mannered. This leads to discrepancies in the recorded healthcare data and a decrease in the level of treatment meted out. The results and statistics of treatments given do not match the records due to inaccurate data reporting. India is a democratic country with a large population, and maintaining a standard infrastructure is a problem for implementing privacy models in India. The cost required to implement a privacy model is substantial and requires funding from the government
Inventions 2021,6, 45 18 of 30 and people. Making the privacy model a success involves the work of specialists in the Privacy and healthcare fields. Budget constraints may cause an ineffective model to be implemented, which cannot be secure and safe from attacks. According to the recent news, the Indian health ministry has proposed a law to govern data security (personal data protection bill) that would provide people complete ownership of their data. People can access, share, and deny sharing the records available at the server. The health ministry proposed digital information security in the healthcare act on March 11, 2018. The committee suggested the following key points and developed a privacy framework: •The law must be flexible and adhere to changing technologies. •Law must be applied to public and private sector entities. •Entities controlling the data should be accountable for data processing. •Consent must be structured and genuine. •Data processing and analysis must be minimal. •A high-powered statutory authority should enforce the data protection framework. The Indian healthcare data are considerably diverse and collected from different heterogeneous sources (public and private sector hospitals and health insurance). No regulations are enforced over the health data authorship, due to which any third party can access the sensitive data and misuse the data for its benefit. The proposed law has guidelines and technological aspects for preserving healthcare data privacy. Privacy Issues in the Indian Healthcare System From the literature survey, this paper presents 14 privacy issues (10 Primary issues) specific to the Indian healthcare system. Figure 9illustrates the privacy problems. Each privacy issue is described with an appropriate example obtained from the available resources [84]. Figure 9. Privacy issues in the Indian Healthcare system.
Inventions 2021,6, 45 19 of 30 A. Lack of Technology and Infrastructure Healthcare technology is changing, and the paper-based records of the patient are not used anymore. The records are being converted into EHRs for easy digital access through the Internet [ 85 ]. The use of wearable technologies, patient monitoring through sensor networks, and data analysis of patient records for early disease prediction are being implemented to ease and improve the lifestyle. Despite numerous advancements in this field, India has not successfully implemented technologies at the ground level of the healthcare system. According to the Indian healthcare system (Figure 4), the village/taluka and district hospitals still lack technologies. Another viewpoint is that patient records are primarily stored using paper-based technology rather than centralized electronic technology. In India, >60% of the area are villages, which indicates that the healthcare sector is majorly based in villages. Currently, rural areas face problems such as lack of electricity, high-speed Internet, and high-technology medical equipment facilities in hospitals and dispensaries. The lack of technological interventions directly affects patient privacy. Most villagers must physically visit healthcare centers and hospitals for their treatment with prescriptions, and health advice is provided on papers. Because records are paper-based, there is no control over who is having access at what level. Consent management, storage guidelines, and access control are no longer applicable to paper-based medical records. B. Doctor–Patient Relationship Another threat to Privacy in India is the trust between doctors and patients. Most people from tier II and III cities do not trust their doctors and hospital staff for their data security. Most hospitals share data with a third party without acquiring patient consent [ 85 , 86 ]. No law covers such actions because no uniform policy regarding such fraud is defined in the constitution. According to the literature, many factors lead to the doctor–patient relationship being compromised. 1. Poor government health systems. 2. A poor ratio of doctors to patients. 3. Easy accessibility of information and privacy concerns [86]. 4. Lack of a role of the patient in the decision-making process. 5. Corruption [87]. C. Data Storage and Management With the large population of India, storing electronic medical records in the cloud is crucial. A survey [ 88 ] revealed that most Indians store their health records on the cloud for easy access; however, considerably few are concerned about their privacy. Most Indians store sensitive data on the cloud, relying on the fact that the cloud provides security. Additionally, data management makes design most optimal for information, centralized or distributed storage, and data confidentiality and demand. D. Cyber Attacks and Hacking A dynamic EHR is maintained and regulated by a third party for suitable data storage and management. When such data are shared either for analysis, research, or marketing purposes, maintaining patient privacy is the responsibility of the third party. Moreover, the third party is responsible for providing sufficient mechanism security for data storage to prevent cyberattacks. Most Indian healthcare data are either stored in outdated systems, or no security mechanism is applied to the data. A suitable and secure system must not allow access to the data to unauthorized users. Table 8presents cyberattacks presented in the Indian data [89].
Inventions 2021,6, 45 20 of 30 Table 8. Cyberattacks presented in the Indian healthcare data. Cyber Attacks on Data Gathering Phase Cyber Attacks at Network Phase Cyber Attacks at Storage Phase Phishing attack Eavesdropping of health record Cross-site scripting attack Log access attack Man-in-the-middle attack Weak authentication attack Social engineering attack Data tampering SQL injection attack. Brute force attack (on passwords) Denial of the service attack Data interception Spoofing and sniffing attack E. Data Sharing Trust in the Third Party Most Indian healthcare systems lack consent; no consent is acquired while sharing data with a third party. Most private organizations share the data of their employees with a third party without applying any rules or policies to it. Sharing data for research and analysis purposes presents no harm; however, such information is shared with personal identification information. Alternatively, the information is the responsibility of organizations, which are not regulated by any statutory body for misuse. Most public sector hospitals share their data without patient consent [90]. Sharing data with a third party always presents doubts in the trust parameter. The privacy model is divided into two types: Trusted and untrusted models. In the trusted model, the data owner trusts the third party and shares the health data, and an untrusted party does not gain the owner’s trust. The use of a third party questions the confidentiality and integrity of the data and makes dealing with the party during the development of a highly reliable health architecture a vital issue. F. Lack of Policy and Constitutional Limitations Privacy is always ignored; private organizations especially give less importance to privacy. In Indian healthcare systems, privacy policies remain inadequate. Several case studies on the Indian healthcare domain have indicated that we are far from privacy implementation and applying privacy rules through design principles. A cohesive privacy policy must be implemented in India. The following questions remain unanswered and must be addressed when the data are used, shared, and published by a third party or organization [91]: 1. Who owns and accesses patient records and why? 2. What type of data with what granularity level must be collected? 3. Where must the data be stored (central warehouse or hospital)? 4. Who can view medical records? 5. Who is responsible for disclosing medical records? 6. Which consent must be acquired while deleting patient records? G. Data Breaching Despite taking data security measures, data breaching is one of the significant privacy problems in India. In healthcare, the main reasons behind data breaching are as follows [ 90 ]: 1. Brocken access and authentication. 2. Flawed service level agreements by organizations. 3. Poor backup and recovery plans in case of data loss. 4. Reverse engineering methods. A cross-sectional data sharing system is the most suitable technique for lowand middle-income countries like India. India’s Aadhaar personal identification program is promising. It is responsible for generating and monitoring health and social data, including EHRs, through a unique identification number. A unique card is distributed to all Indian citizens for identification. In 2017, the supreme court of India addressed privacy concerns,
Inventions 2021,6, 45 21 of 30 including breaching the Indian health data stating that because the Aadhaar card contains sensitive information, it cannot be used as a mandatory document in fields such as banking, the insurance sector, and mobile servicing [92]. H. Culture Cultural interventions are other challenges faced by the Indian healthcare industry. Most cultural communities do not allow people to share or disclose their personal information due to predefined cultural restrictions, resulting in the recording of false information. The discrepancy in health records results in inaccurate analyses and an inaccurate treatment that is meted out [93]. I. Prevalent Complacency Complacency is widespread in Indian healthcare. A large amount of work, planning, cooperation, and communication among multiple departments is required to make the privacy and security of healthcare in India a success. However, due to slackness, the probability of the privacy model implemented in India is poor [94]. J. Cost Implementation of the privacy model with suitable infrastructure is costly. The Indian government faces other problems such as poverty and corruption that are given high priority, and privacy model implementation is given the least priority. Small organizations do not have enough assets to protect their employees. Table 9presents the privacy problems of the healthcare system of India as mentioned above. Table 10 explains how each privacy problem is being addressed in different healthcare structures in India. Table 9. Privacy issues stated in the Indian healthcare system. Type of Healthcare Privacy Issues Stated in the Indian Healthcare System. Type of Sector Lack of Technology Doctor-Patient Relationship Data Storage and Management Cyberattacks Data Sharing Trust in the Third Party Super specialty hospital Public Very good Trustworthy Very good Minimal risk Drafted Policies for consent Strict Medical institutes/colleges Public Adequate Trustworthy Good Minimal risk With good consent Easy District and taluka hospitals Public Adequate Bit trustworthy Adequate High risk Minimal consent Easy Primary healthcare centers Public Poor Bit trustworthy Poor High risk Without consent Easy Village hospitals Public Poor Not trustworthy Poor High risk Without consent Easy Super and multispecialty hospitals Private Excellent Most Trustworthy Very good Minimal risk Drafted Policies for consent Strict Tier II and III city hospitals Private Very good Most Trustworthy Very good Minimal risk Drafted Policies for consent Strict Private clinics Private Very good Trustworthy Very good Minimal risk Drafted Policies for consent Strict Non-profit organizations Private good Trustworthy Very good Minimal risk Minimal consent Strict Pharmaceutical industry Private Excellent - Very good Minimal risk Drafted Policies for consent Strict Health insurance company Private Excellent - Excellent Minimal risk Drafted Policies for consent Strict Private organizations Private Excellent - Excellent Minimal risk Minimal Consent Easy
Inventions 2021,6, 45 22 of 30 Table 10. Privacy issues stated in the Indian healthcare system (continued). Type of Healthcare Privacy Issues Stated in the Indian Healthcare System. Type Infrastructure Privacy Policies Data Breaching Hacking Accountability Cultural Interventions Cost Super specialty hospital Public Excellent Well defined and followed Less probability Less probability Yes No Average Medical institutes/colleges Public Adequate Well defined and followed Adequate probability Adequate probability Yes No Low District and taluka hospitals Public Poor Well defined but not followed High probability High probability No Yes considerably low/no cost Primary healthcare centers Public Considerably poor Well defined but not followed High probability High probability No Yes considerably low/no cost Village hospitals Public Considerably poor Not defined High probability High probability No Yes No cost Super and multispecialty hospitals Private Excellent Well defined and followed Less probability Less probability Yes No Very high Tier II and III city hospitals Private Excellent Well defined and followed Less probability Less probability Yes No High/considerably high Private clinics Private Excellent Well defined and followed Less probability Less probability Yes No High Non-profit organizations Private Excellent Well defined and followed Less probability Less probability Yes No Low Pharmaceutical industry Private Excellent Well defined and followed Less probability Less probability Yes No NA Health insurance company Private Excellent Well defined and followed Less probability Less probability Yes No NA Private organizations Private Excellent Well defined and followed Less probability Less probability Yes No NA 7. Open Issues and Further Discussions With the emerging healthcare sector from a revolutionary perspective, India is growing in healthcare analytics rapidly [ 95 – 98 ]. Healthcare 3.0 was patient-centric from a diseasecentric approach. However, healthcare 4.0 uses various technologies like IoT, Blockchain, Machine learning, and AI to identify and predict disease, analyze historical health data, and other intelligent healthcare applications. Such newer technologies require extensive data and fastest accessing resources, which ultimately need equivalent security techniques to protect them [ 99 ]. In India, the security and privacy of healthcare data are always complex and challenging tasks. The reasons are already discussed in the previous sections. Based on the detailed overview of the Indian healthcare system and its privacy issues, there are some open issues and further discussions elaborated in this section. Privacy issues in healthcare-specific to India are due to prevalent complacency, culture, politics, budget limitations, huge population, and infrastructure. Due to these factors, data security takes a backseat allowing for easy access to confidential information. The prevalent culture also affects healthcare disclosure in India. In many cultures, the disclosure of sensitive personal healthcare data is looked down upon. This leads to discrepancies in the healthcare data recorded and a decrease in the level of treatment meted out. Research and statistics of treatment given then do not match the records due to inaccurate reporting of data. India is a country of large democracy and large populations; maintaining standard infrastructure is another issue of implementing privacy models. The cost required to implement a privacy model is substantial and requires funding from the government and individuals. To ensure the privacy model is a success, it involves specialists in privacy and the field of healthcare. Budget constraints may lead to an ineffective model being implemented, which will not be secure and safe from attacks.
Inventions 2021,6, 45 23 of 30 7.1. Key Performance Indicators in the Context of Privacy in the Indian Healthcare System Key Performance Indicators (henceforth termed as a KPI) are very important as they measure privacy concerns that need to be addressed first. According to the research done in [ 100 , 101 ], the following KPI is related to privacy issues; however, they are applicable for social media photos and video sharing in the existing research. Since privacy issues exist everywhere, in every field, KPI is applicable in the Indian healthcare context as well. The list of KPIs and their details are given below: •Forced Trust vs. Control: A forced trust is a trust in which an individual has no choice but to trust any healthcare system. On the other hand, control is a systematic view of obtaining trust and assuring each individual that their sensitive personal data will not be shared with the third party without any consent. In the Indian healthcare context, the ratio of forced trust to control is high. People tend to have less trust in any healthcare system because of constitutional limitations. This is one of the significant KPIs in the context of Indian Healthcare privacy. •Content Viewed by Whom: Though there is limited access to any EHR and only authenticated people can view or access the sensitive data, there is still the possibility that unauthorized entities may access health records. Weak passwords, inappropriate security policies, conflict in access controls, and sharing passwords to untrusted persons are the possible reasons sensitive data may be misused. In India, the healthcare system is not very structured and centralized. Local hospitals keep their records on local servers, which are highly vulnerable to various attacks. Data breaching primarily happens in tier 2 and tier 3 cities and village hospitals. •Tacit Knowledge: Even if the healthcare system ensures maximum protection against data breaches for healthcare data, the metadata or tacit information may reveal more information than basic health information. Using reverse engineering techniques or social media analysis, it is easy to gain personal information. In India, there are many cases reported against criminals who seek sensitive information through social media accounts. Unfortunately, there is no control over the protection against such information. •Laws and Regulation: Limited regulation and law in the constitution are essential KPI in the Indian healthcare field. As per the latest data of 2019, Indian healthcare generates 1021 gigabytes of data per year. Managing such a massive amount of data by protecting sensitive content must prioritize the Indian government. •Use of new Data Protection Technologies: The newer technologies like blockchain, two-factor authentication, machine learning, AI, and attribute-based anonymization is only implemented in high-end industries or healthcare organizations. Small sector health organizations, village, or tier 3 hospitals do not have funds to support the protection of such data, and hence newer technologies cannot be used. •Researcher’s Satisfaction: Since there is a massive generation of healthcare data, it is an excellent opportunity to analyze the data for research purposes. Healthcare analytics is the emerging field of computing and is rising exponentially in India. More restricted and policy-imposed data are not suitable for analytics purposes, and data quality gets degraded. •Industry-academia collaboration exists for privacy preservation mechanisms : There is a huge gap between industry and academia in India. Despite having good researchers in the privacy field, their work is not reaching the industry. It is also noted that all these KPI are not treated with the same priority. In order to priorities KPIs, the different stakeholders are taken into consideration. This paper’s contribution is to summarize the ratings given by stakeholders directly or indirectly involved in managing or accessing healthcare data. The following stakeholders are chosen:
Inventions 2021,6, 45 24 of 30 •Doctors and Healthcare Professionals/practitioners (DH) : Five doctors are selected from all tier cities and villages who manage patient records through the digital and paper-based modes. •Hospital administrative staff (HA): Five administrative staff are taken from various hospitals from all tier cities and villages, maintaining patient records for future communication. •Researchers and Scientist (RS): Five Researchers from healthcare data analytics and data privacy are selected to work in a new development in healthcare data science and data privacy. •Academicians in the computer science field (AC): Five Academicians in the Computer Science field are selected to either teach data analytics courses or security courses in their curriculum. The rating obtained from a 1 to 5 Likert scale where one represents strongly agree and 5 represents strongly disagree. Table 11 gives the consolidated ratings about KPIs defined over privacy issues in the Indian healthcare context. It can be seen that almost all the stakeholders are in favor of considering privacy issues. Table 11. Ratings of KPIs defined over privacy issues by healthcare stakeholders. KPI Doctors and Healthcare Professionals/Practitioners Hospital Administrative Staff Researchers and Scientist Academicians in the Computer Science Field Mean Samples DH1 DH2 DH3 DH4 DH5 HA1 HA2 HA3 HA4 HA5 RS1 RS2 RS3 RS4 RS5 AC1 AC2 AC3 AC4 AC5 Forced Trust Vs. Control 1 2 2 3 3 2 2 2 2 4 1 1 1 2 1 2 2 1 1 2 1.85 Content Viewed by Whom 3 3 4 2 1 3 2 4 1 2 1 1 1 1 1 2 1 3 1 2 1.95 Tacit Knowledge 3 3 3 4 2 2 2 2 3 1 1 1 1 3 2 2 3 2 3 1 2.2 Laws and Regulation 1 1 2 1 2 1 2 1 1 1 1 1 1 1 2 1 3 1 1 3 1.4 Use of new Data Protection Technologies 3 3 3 3 1 3 2 2 3 4 2 2 2 1 1 1 1 1 1 1 2 Researcher’s Satisfaction 4 4 4 4 2 5 5 4 4 4 2 2 2 3 1 1 1 1 1 2 2.8 Industry-academia collaboration exists for privacy preservation mechanisms 3 3 3 3 3 3 3 3 3 3 2 2 2 1 1 1 2 1 2 2 2.3 7.2. Future of Data Privacy in India The government of India took significant steps to address the privacy issues and protect sensitive data from unauthorized access. According to the recent news, the government proposed a law to govern data security in all emerging sectors like healthcare, finance and banking, education, and retail that would give individuals complete ownership of their data. Individuals can access, share, and deny the records associated with them. The Personal Data Protection Bill (PDP) draft was proposed in 2019, which is similar to GDPR [ 102 ]. The committee suggested the following key points and developed a privacy framework: •The law must be flexible and must be adhered to changing technologies. •Law must be applied to public and private sector entities. •Entities controlling the data should be accountable for any data processing. •Consent must be structured and genuine. •Processing and analysis of data must be minimal. • Enforcement of the data protection framework should be carried out by a highpowered statutory authority. Indian published health data are very diverse and collected from different heterogeneous sources, moving towards the healthcare sector and the proposed bill. There are
Inventions 2021,6, 45 25 of 30 no regulations over the authorship of the health data, due to which any third party can gain access to the sensitive data and misuse the data. The reidentification attack is the most common attack of health data wherein, with the help of a group of some identifiable entities (called quasi-identifiers), individuals’ identities can be easily determined. The proposed law mentioned in the above section has guidelines and technological aspects of preserving healthcare data privacy. The proposed research will be the outcome of the privacy framework developed by the Indian government in the PDP bill. The primary constituents of the PDP bill are drawn in Figure 10. Figure 10. Personal Data Protection bill entities adopted from [101]. Figure 10 presents the essential elements of the data protection bill adopted in India. The data owner is called a data principle in GDPR; they are also called a data custodian. The data fiduciary can be any company, organization, group of people, or individual who determine the purpose of the data use and dissemination. They can be a data holder in the context of GDPR. A data processor is a third-party entity that is involved in the processing of data. In some situations, the data fiduciary and data processor roles can be the same, and the whole depends upon a particular situation. The Data Protection Authority of India (DPAI) is the statutory body that can define rules and regulations about data protection. 7.3. Data Utility-Privacy Trade-Off in Personal Data Protection Bill Recalling Section 1of the paper, there is a thin border between data utility and privacy. Privacy is subjective and cannot be fully addressed; data breaches can occur not only due to data publishing but also data pre-processing, data sharing, as well as due to inappropriate policies. Privacy also varies from nation to nation. The newly created PDP bill is enhanced by maintaining the proper balance of data utility and privacy. Recall that Indian healthcare data generated from heterogeneous sources are very unstructured. The user (termed as role) also restricts the access to a particular level of data according to the bill. To provide a different and enhanced level of protection, the data fiduciary can implement data anonymization, randomization, and similar data hiding techniques to ensure that data are protected from various privacy attacks such as background knowledge, linkage,