Baker D B, Masys D R
Commercial Health Care Group, Science Applications International Corporation, El Segundo, CA 90245, USA.
Int J Med Inform. 1999 May;54(2):97-104. doi: 10.1016/s1386-5056(98)00088-4.
The Internet holds both promise and peril for the communications of person-identifiable health information. Because of technical features designed to promote accessibility and interoperability rather than security, Internet addressing conventions and transport protocols are vulnerable to compromise by malicious persons and programs. In addition, most commonly used personal computer (PC) operating systems currently lack the hardware-based system software protection and process isolation that are essential for ensuring the integrity of trusted applications. Security approaches designed for electronic commerce, that trade known security weaknesses for limited financial liability, are not sufficient for personal health data, where the personal damage caused by unintentional disclosure may be far more serious. To overcome these obstacles, we are developing and evaluating an Internet-based communications system called PCASSO (Patient-centered access to secure systems online) that applies state of the art security to health information. PCASSO includes role-based access control, multi-level security, strong device and user authentication, session-specific encryption and audit trails. Unlike Internet-based electronic commerce 'solutions,' PCASSO secures data end-to-end: in the server; in the data repository; across the network; and on the client. PCASSO is designed to give patients as well as providers access to personal health records via the Internet.
互联网对于可识别个人身份的健康信息通信而言,既带来了希望,也存在风险。由于旨在促进可访问性和互操作性而非安全性的技术特性,互联网寻址惯例和传输协议容易受到恶意人员和程序的破坏。此外,目前大多数常用的个人计算机(PC)操作系统缺乏基于硬件的系统软件保护和进程隔离,而这对于确保可信应用程序的完整性至关重要。为电子商务设计的安全方法,是以已知的安全弱点换取有限的财务责任,这对于个人健康数据而言是不够的,因为无意泄露所造成的个人损害可能要严重得多。为克服这些障碍,我们正在开发和评估一种名为PCASSO(以患者为中心的在线安全系统访问)的基于互联网的通信系统,该系统将先进的安全技术应用于健康信息。PCASSO包括基于角色的访问控制、多级安全、强大的设备和用户认证、特定会话加密以及审计跟踪。与基于互联网的电子商务“解决方案”不同,PCASSO对数据进行端到端的保护:在服务器中;在数据存储库中;在网络中;以及在客户端上。PCASSO旨在让患者和医疗服务提供者都能通过互联网访问个人健康记录。