Suppr超能文献

利用网络安全标准保障访问和隐私权,增强患者自主权。

Access and privacy rights using web security standards to increase patient empowerment.

作者信息

Falcão-Reis Filipa, Costa-Pereira Altamiro, Correia Manuel E

机构信息

Computer Science Department, Faculty of Science, University of Porto, Portugal.

出版信息

Stud Health Technol Inform. 2008;137:275-85.

Abstract

Electronic Health Record (EHR) systems are becoming more and more sophisticated and include nowadays numerous applications, which are not only accessed by medical professionals, but also by accounting and administrative personnel. This could represent a problem concerning basic rights such as privacy and confidentiality. The principles, guidelines and recommendations compiled by the OECD protection of privacy and trans-border flow of personal data are described and considered within health information system development. Granting access to an EHR should be dependent upon the owner of the record; the patient: he must be entitled to define who is allowed to access his EHRs, besides the access control scheme each health organization may have implemented. In this way, it's not only up to health professionals to decide who have access to what, but the patient himself. Implementing such a policy is walking towards patient empowerment which society should encourage and governments should promote. The paper then introduces a technical solution based on web security standards. This would give patients the ability to monitor and control which entities have access to their personal EHRs, thus empowering them with the knowledge of how much of his medical history is known and by whom. It is necessary to create standard data access protocols, mechanisms and policies to protect the privacy rights and furthermore, to enable patients, to automatically track the movement (flow) of their personal data and information in the context of health information systems. This solution must be functional and, above all, user-friendly and the interface should take in consideration some heuristics of usability in order to provide the user with the best tools. The current official standards on confidentiality and privacy in health care, currently being developed within the EU, are explained, in order to achieve a consensual idea of the guidelines that all member states should follow to transfer such principles into national laws. A perspective is given on the state of the art concerning web security standards, which can be used to easily engineer health information systems complying with the patient empowering goals. In conclusion health systems with the characteristics thus described are technically feasible and should be generally implemented and deployed.

摘要

电子健康记录(EHR)系统正变得越来越复杂,如今包含众多应用程序,不仅医疗专业人员可以访问,会计和行政人员也可以访问。这可能会引发诸如隐私和保密等基本权利方面的问题。经合组织关于隐私保护和个人数据跨境流动的原则、准则和建议在健康信息系统开发中得到了描述和考量。授予对电子健康记录的访问权限应取决于记录所有者,即患者:除了每个健康组织可能实施的访问控制方案外,患者必须有权定义谁被允许访问他的电子健康记录。这样一来,决定谁可以访问什么的不仅仅是医疗专业人员,患者本人也有决定权。实施这样的政策是朝着患者赋权的方向发展,社会应该鼓励,政府应该推动。本文随后介绍了一种基于网络安全标准的技术解决方案。这将使患者能够监控和控制哪些实体可以访问他们的个人电子健康记录,从而让他们了解自己的病史有多少被知晓以及被谁知晓。有必要创建标准的数据访问协议、机制和政策来保护隐私权,此外,要使患者能够在健康信息系统的背景下自动跟踪其个人数据和信息的流动。这个解决方案必须具备功能性,最重要的是要用户友好,界面应该考虑一些可用性启发式方法,以便为用户提供最佳工具。对目前正在欧盟内部制定的医疗保健领域保密和隐私的现行官方标准进行了解释,以便就所有成员国应遵循的将此类原则转化为国家法律的准则达成共识。文中给出了关于网络安全标准的技术现状的观点,这些标准可用于轻松设计符合患者赋权目标的健康信息系统。总之,具有上述特征的健康系统在技术上是可行的,应该普遍实施和部署。

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验