Bourka A, Polemi N, Koutsouris D
Biomedical Engineering Laboratory, Department of Electrical and Computer Engineering, NTUA, 15773 Athens, Greece.
Stud Health Technol Inform. 2001;84(Pt 2):1242-6.
The scope of this paper is to present the current needs and trends in the field of healthcare systems security. The approach applied within the described review was based on three major steps. The first step was to define the point and ways of penetration and integration of security services in current healthcare related applications addressing technical, organisational and legal/regulatory issues. The second step was to specify and evaluate common security technologies applied in healthcare information systems pointing out gaps and efficient solutions, whereas the third was to draw conclusions for the present conditions and identify the future trends of healthcare information security. A number of EU RTD Projects were selected, categorised, analysed and comparatively evaluated in terms of security. The technical focus was on key security technologies, like Public Key Infrastructures (PKIs) based on Trusted Third Parties (TTPs) in conjunction with other state-of-the-art security components (programming tools, data representation formats, security standards and protocols, security policies and risk assessment techniques). The experience gained within this review will provide valuable input for future security applications in the healthcare sector, solving existing problems and addressing real user needs.
本文的范围是介绍医疗保健系统安全领域的当前需求和趋势。在所描述的综述中采用的方法基于三个主要步骤。第一步是定义安全服务在当前医疗相关应用中的渗透点和整合方式,解决技术、组织和法律/监管问题。第二步是指定和评估医疗信息系统中应用的常见安全技术,指出差距和有效的解决方案,而第三步是对当前状况得出结论,并确定医疗信息安全的未来趋势。选择了一些欧盟研发项目,从安全方面进行分类、分析和比较评估。技术重点是关键安全技术,如基于可信第三方(TTP)的公钥基础设施(PKI),以及其他先进的安全组件(编程工具、数据表示格式、安全标准和协议、安全策略和风险评估技术)。本次综述中获得的经验将为医疗保健领域未来的安全应用提供有价值的投入,解决现有问题并满足实际用户需求。