Yang Yanjiang, Han Xiaoxi, Bao Feng, Deng Robert H
Institute for Infocomm Research, Singapore 119613.
IEEE Trans Inf Technol Biomed. 2004 Mar;8(1):47-58. doi: 10.1109/titb.2004.824731.
Within the overall context of protection of health care information, privacy of prescription data needs special treatment. First, the involvement of diverse parties, especially nonmedical parties in the process of drug prescription complicates the protection of prescription data. Second, both patients and doctors have privacy stakes in prescription, and their privacy should be equally protected. Third, the following facts determine that prescription should not be processed in a truly anonymous manner: certain involved parties conduct useful research on the basis of aggregation of prescription data that are linkable with respect to either the patients or the doctors; prescription data has to be identifiable in some extreme circumstances, e.g., under the court order for inspection and assign liability. In this paper, we propose an e-prescription system to address issues pertaining to the privacy protection in the process of drug prescription. In our system, patients' smart cards play an important role. For one thing, the smart cards are implemented to be portable repositories carrying up-to-date personal medical records and insurance information, providing doctors instant data access crucial to the process of diagnosis and prescription. For the other, with the secret signing key being stored inside, the smart card enables the patient to sign electronically the prescription pad, declaring his acceptance of the prescription. To make the system more realistic, we identify the needs for a patient to delegate his signing capability to other people so as to protect the privacy of information housed on his card. A strong proxy signature scheme achieving technologically mutual agreements on the delegation is proposed to implement the delegation functionality.
在医疗保健信息保护的整体背景下,处方数据的隐私需要特殊对待。首先,在药物处方过程中涉及的各方,尤其是非医疗方,使得处方数据的保护变得复杂。其次,患者和医生在处方方面都有隐私权益,他们的隐私应得到同等保护。第三,以下事实决定了处方不应以真正匿名的方式处理:某些相关方基于可与患者或医生关联的处方数据汇总进行有用的研究;在某些极端情况下,例如根据法院的检查令和责任认定令,处方数据必须是可识别的。在本文中,我们提出了一种电子处方系统,以解决药物处方过程中的隐私保护问题。在我们的系统中,患者的智能卡起着重要作用。一方面,智能卡被实现为携带最新个人病历和保险信息的便携式存储库,为医生提供诊断和处方过程中至关重要的即时数据访问。另一方面,由于秘密签名密钥存储在内部,智能卡使患者能够对处方笺进行电子签名,声明其接受该处方。为了使系统更具现实性,我们确定了患者将其签名能力委托给其他人以保护其卡上所存信息隐私的需求。提出了一种在技术上就委托达成相互协议的强代理签名方案来实现委托功能。