Related Experiment Video
Updated: Jul 30, 2025

Advanced Workflow for Taking High-Quality Increment Cores - New Techniques and Devices
Published on: March 10, 2023
Enhancing Data Protection via Auditable Informational Separation of Powers Between Workflow Engine Based Agents:
Felix Erdfelder1,2,3, Henning Begerau1,2, David Meyers1,2
1Staff Unit for Medical & Scientific Technology Development & Coordination (MWTek), Commercial Directorate; University Hospital Bonn, Germany.
A novel agent-based system ensures patient data privacy for research by separating identifying data (IDAT), pseudonyms (PSN), and medical data (MDAT). This approach meets German best practices for secure secondary data use.
Area of Science:
- Health Informatics
- Data Privacy Engineering
- Medical Research
Background:
- German best practice standards mandate strict data separation for secondary patient data use.
- Ensuring identifying data (IDAT), pseudonyms (PSN), and medical data (MDAT) are never simultaneously accessible is crucial.
- Existing systems may struggle to meet these stringent data protection requirements.
Purpose of the Study:
- To describe a software solution that adheres to German best practice standards for the secondary use of patient data.
- To implement a system ensuring informational separation of powers for data provisioning.
- To facilitate compliant and secure access to pseudonymized patient data for research.
Main Methods:
- A distributed agent architecture involving a clinical domain agent (CDA), trusted third party agent (TTA), and research domain agent (RDA).
- Utilizing an off-the-shelf workflow engine for distributed CDA and RDA operations.
- Integrating the gPAS framework within the TTA for pseudonym generation and persistence.
- Implementing agent interactions via secured REST-APIs.
Main Results:
- The system successfully implemented dynamic interaction between three software agents.
- Deployment across three university hospitals demonstrated a seamless rollout.
- The workflow engine facilitated auditability of data transfer and pseudonymization with minimal effort.
- The solution effectively met technical and organizational data protection requirements.
Conclusions:
- A distributed agent architecture, powered by workflow engine technology, is an efficient method for compliant patient data provisioning.
- The described solution successfully meets the rigorous requirements for secondary data use in Germany.
- This approach enhances data security and privacy while enabling valuable medical research.
Related Concept Videos
Legal Guidelines for Documentation
Ethical Standards I
The Code of Ethics provisions outline the nurse's duty to the patient, the healthcare team, the profession, and society. The Code's fundamental principles include advocacy,...
Guidelines and Strategies for Safe Computer Charting
Maintain Confidentiality and Security:
Zones of Protection
Protective zones are defined by closed dashed lines, containing one or more components. A key characteristic of these zones is the strategic placement of...
Censoring Survival Data
Distribution Reliability and Automation

