Riva A, Mandl K D, Oh D H, Nigrin D J, Butte A, Szolovits P, Kohane I S
Children's Hospital Informatics Program, Division of Endocrinology, Children's Hospital, 300 Longwood Avenue, Boston, MA 02115, USA.
Int J Med Inform. 2001 Jun;62(1):27-40. doi: 10.1016/s1386-5056(00)00136-2.
In this paper, we propose a secure, distributed and scaleable infrastructure for a lifelong personal medical record system. We leverage on existing and widely available technologies, like the Web and public-key cryptography, to define an architecture that allows patients to exercise full control over their medical data. This is done without compromising patients' privacy and the ability of other interested parties (e.g. physicians, health-care institutions, public-health researchers) to access the data when appropriately authorized. The system organizes the information as a tree of encrypted plain-text XML files, in order to ensure platform independence and durability, and uses a role-based authorization scheme to assign access privileges. In addition to the basic architecture, we describe tools to populate the patient's record with data from hospital databases and the first testbed applications we are deploying.
在本文中,我们为终身个人医疗记录系统提出了一种安全、分布式且可扩展的基础设施。我们利用现有的且广泛可用的技术,如网络和公钥加密技术,来定义一种架构,使患者能够对自己的医疗数据行使完全控制权。这样做不会损害患者的隐私,也不会影响其他相关方(如医生、医疗机构、公共卫生研究人员)在获得适当授权时访问数据的能力。该系统将信息组织成加密的纯文本XML文件树,以确保平台独立性和耐久性,并使用基于角色的授权方案来分配访问权限。除了基本架构外,我们还描述了用于用医院数据库中的数据填充患者记录的工具以及我们正在部署的首个测试平台应用程序。