ASCLEPIOS

The vision of ASCLEPIOS was to maximize and fortify the trust of users on cloud-based healthcare services by developing mechanisms for protecting both corporate and personal sensitive data. ASCLEPIOS utilized several modern cryptographic approaches to build a cloud-based eHealth framework that protected users’ privacy and prevented both internal and external attacks. ASCLEPIOS offered to users the ability to verify the integrity of their medical devices prior to using them, whilst receiving certain guarantees about the trustworthiness of their cloud service provider. Furthermore, ASCLEPIOS offered a novel solution through which healthcare practitioners and medical researchers were able to calculate statistics on medical data in a privacy-preserving way. A list of activities aiming to raise security awareness within the healthcare industry were also foreseen to be organized by the project. The project’s results were showcased through three real-life, near production quality demonstrators provided by ASCLEPIOS healthcare partners, involving three leading European hospitals.

CUREX

CUREX addressed comprehensively the protection of the confidentiality and integrity of health data by producing a novel, flexible and scalable situational awareness-oriented platform. It allowed healthcare providers to assess the realistic cybersecurity and privacy risks they were exposed to and suggest mathematically optimal strategies for addressing these risks with safeguards tailored specifically for each business case and application. CUREX was GDPR compliant by design and aimed to develop one of the first blockchain platforms for risk assessment management under the GDPR. At its core, a decentralized architecture enhanced with a private blockchain infrastructure ensured the integrity of the risk assessment process and of all data transactions that occurred between the diverse range of stakeholders involved. Crucially, CUREX expanded beyond technical measures and placed emphasis also on improving cyber hygiene through training and raising awareness activities for a healthcare institution’s personnel. Its validation focused on the highly challenging condition of (cross-border) health data exchange, spanning patient cross-border mobility, remote healthcare, and data exchange for research.

FAITH

FAITH aimed to provide an Artificial Intelligence application that remotely identified depression markers, using Federated Learning, in people that had undergone cancer treatment to better model and predict disease/treatment trajectories. To protect privacy of the individual, but still gain insights that are beneficial to the broader population, FAITH applied the concept of federated machine learning, which makes it possible to build machine learning systems without direct access to personal treatment data that was used for training in machine learning. Devices private to the patient ran their own personalised AI models, via the project’s ‘AI Angel’ application, while a global AI model aggregated the individual model learnings (rather than the traditional approach of a central repository of holding all private patient data). FAITH’s ‘AI Angel’ remotely analysed depression markers, predicting negative trends in their disease trajectory, giving their healthcare providers advanced warnings to allow for timely intervention. These markers were treated under several distinct categories: Activity, Outlook, Sleep, and Appetite, in accordance with the 3M strategy for population health: Monitor–Measure–Manage. A key strength of FAITH was the involvement of eminent cancer hospitals and specialists in the consortium to provide relevant applicable cancer care related use cases that could effectively leverage a big data framework. FAITH had trial sites in Madrid, Waterford, and Lisbon, with real end users involved in assessing and validating the AI application to ensure its usefulness.

ONCORELIEF

Improvements in early detection and therapeutic treatment of cancer have resulted in the number of cancer survivors increasing globally, creating the need to improve not only treatment but also wellness and follow-up care. Cancer treatment often involves combined modalities such as surgery, chemotherapy, and radiotherapy. In the past decades, more effective and targeted therapeutic modalities and less destructive cancer treatments have been developed such as immunotherapy and drug targeted therapy. Even so, cancer and its treatment have important physical and psychosocial sequelae. ONCORELIEF was a 36-month action that leveraged the above 6 drivers in order to skillfully and methodologically overcome technical challenges, by introducing new approaches that allowed the utilization of big datasets in order to develop a user-centered AI System to facilitate the integration of QoL assessment instruments through the use of PROMs and PREMs in order to improve post-treatment health status, increase the wellbeing, and follow up care of cancer patients. This was achieved through an intuitive smart digital assistant (Guardian Angel), able to provide personalized support in post-treatment activities and tasks, suggest actions regarding the patients’ overall health-status, improved wellbeing and active health-care and ultimately maintain him/her engaged on a wellness journey that safeguarded his/her health over the foreseeable prolonged post-cancer treatment period. To achieve this, ONCORELIEF built on the combined knowhow of its interdisciplinary industry-driven consortium that brought together state-of-the-art technological skills, design thinking methodology and occupational psychology/health sciences.

ELIXIRION

ELIXIRION aims to revolutionize the healthcare landscape by establishing a comprehensive, interdisciplinary, and innovative training and research network that will serve as the foundation for the emerging Healthcare 4.0 (H4.0) paradigm. By leveraging cutting-edge 6G technologies, the project seeks to address a broad spectrum of healthcare service requirements, ranging from ultra-low latency for critical applications, such as remote surgeries and real-time health monitoring, to high-speed connectivity for data-intensive processes like advanced medical imaging and telemedicine. It also aims to ensure ubiquitous and secure access to healthcare resources, available anytime and anywhere, with a strong emphasis on respecting and protecting patient privacy.

Beyond improving service delivery, ELIXIRION is committed to fostering a democratized and efficient healthcare ecosystem that benefits all stakeholders. This involves creating a secure, sustainable, and open H4.0 market that facilitates access to innovative solutions and encourages collaboration among researchers, practitioners, and businesses. Through these efforts, the project not only seeks to enhance the quality of care and operational efficiency but also to establish healthcare environments that are adaptable, inclusive, and resilient in the face of future challenges.

By seamlessly integrating advancements in 6G technology with the principles of Healthcare 4.0, ELIXIRION aspires to redefine the boundaries of modern healthcare, paving the way for a future where healthcare is universally accessible, technologically advanced, and centered around the needs of patients and providers alike.

ENTRUST

Aligned with the guidelines of the Cybersecurity Act and the existing guidance on cybersecurity for medical devices, ENTRUST envisioned a Trust Management Architecture intended to dynamically and holistically manage the lifecycle of connected medical devices, strengthening trust and privacy in the entire medical ecosystem. Even from the proposal stage, ENTRUST had identified gaps and necessary revisions of the current guidance (e.g. absence of post-market conformity and certification, real-time surveillance and corrective mechanisms). Towards that ENTRUST leveraged a series of breakthrough solutions to enhance assurance without limiting the applicability of connected medical devices by enclosing to them cybersecurity features. The project introduced a novel remote attestation mechanism to ensure the device’s correct operation at runtime regardless of its computational power; it was efficient enough to run in also resource-constrained real-time systems such as the medical devices. This was accompanied by dynamic trust assessment models capable of identifying the Required Level of Trustworthiness (RTL) per device and function (service) that were then verified through a new breed of efficient, attestation mechanisms (deployed and executed during runtime). This also enabled us to be aligned with the existing standards on defining appropriate Protection profiles per device (especially considering the heterogeneous types of medical devices provided by different vendors with different requirements) including Targets of Validation Properties attested during runtime. The motivation behind ENTRUST was to ensure end-to-end trust management of medical devices including formally verified trust models, risk assessment process, secure lifecycle procedures, security policies, technical recommendations, and the first-ever real-time Conformity Certificates to safeguard connected medical devices.