Blobel B
Medical Informatics Department, Faculty of Medicine, Institute of Biometrics and Medical Informatics, Otto-von-Guericke University Magdeburg, Germany.
Int J Med Inform. 2000 Nov;60(2):169-75. doi: 10.1016/s1386-5056(00)00117-9.
Responding to the challenge for efficient and high quality health care, the shared care paradigm must be established in health. In that context, information systems such as electronic patient records (EPR) have to meet this paradigm supporting communication and interoperation between the health care establishments (HCE) and health professionals (HP) involved. Due to the sensitivity of personal medical information, this co-operation must be provided in a trustworthy way. To enable different views of HCE and HP ranging from management, doctors, nurses up to systems administrators and IT professionals, a set of models for analysis, design and implementation of secure distributed EPR has been developed and introduced. The approach is based on the popular UML methodology and the component paradigm for open, interoperable systems. Easy to use tool kits deal with both application security services and communication security services but also with the security infrastructure needed. Regarding the requirements for distributed multi-user EPRs, modelling and implementation of policy agreements, authorisation and access control are especially considered. Current developments for a security infrastructure in health care based on cryptographic algorithms as health professional cards (HPC), security services employing digital signatures, and health-related TTP services are discussed. CEN and ISO initiatives for health informatics standards in the context of secure and communicable EPR are especially mentioned.
为应对高效和高质量医疗保健的挑战,必须在医疗领域建立共享护理模式。在这种情况下,诸如电子病历(EPR)之类的信息系统必须符合这种模式,以支持相关医疗保健机构(HCE)和医疗专业人员(HP)之间的通信与互操作。由于个人医疗信息的敏感性,这种合作必须以可信赖的方式进行。为了满足从管理层、医生、护士到系统管理员和IT专业人员等不同HCE和HP的视角需求,已经开发并引入了一套用于分析、设计和实现安全分布式电子病历的模型。该方法基于流行的UML方法和用于开放、可互操作系统的组件范式。易于使用的工具包不仅处理应用程序安全服务和通信安全服务,还处理所需的安全基础设施。针对分布式多用户电子病历的要求,特别考虑了策略协议、授权和访问控制的建模与实现。讨论了基于加密算法(如健康专业人员卡(HPC))的医疗保健安全基础设施的当前发展、采用数字签名的安全服务以及与健康相关的TTP服务。特别提到了CEN和ISO在安全且可通信的电子病历背景下的健康信息学标准倡议。