Katt Basel, Trojer Thomas, Breu Ruth, Schabetsberger Thomas, Wozak Florian
Research Group Quality Engineering, University of Innsbruck, Austria.
Stud Health Technol Inform. 2010;155:85-91.
In the last few years, Electronic Health Record (EHR) systems have received a great attention in the literature, as well as in the industry. They are expected to lead to health care savings, increase health care quality and reduce medical errors. This interest has been accompanied by the development of different standards and frameworks to meet EHR challenges. One of the most important initiatives that was developed to solve problems of EHR is IHE (Integrating the Healthcare Enterprise), which adapts the distributed approach to store and manage healthcare data. IHE aims at standardizing the way healthcare systems exchange information in distributed environments. For this purpose it defines several so called Integration Profiles that specify the interactions and the interfaces (Transactions) between various healthcare systems (Actors) or entities. Security was considered also in few profiles that tackled the main security requirements, mainly authentication and audit trails. The security profiles of IHE currently suffer two drawbacks. First, they apply end point security methodology, which has been proven recently to be insufficient and cumbersome in distributed and heterogeneous environment. Second, the current security profiles for more complex security requirements are oversimplified, vague and do not consider architectural design. This recently changed to some extend e.g., with the introduction of newly published white papers regarding privacy [5] and access control [9]. In order to solve the first problem we utilize results of previous studies conducted in the area of security-aware IHE-based systems and the state-of-the-art Security-as-a-Service approach as a convenient methodology to group domain-wide security needs and overcome the end point security shortcomings.
在过去几年中,电子健康记录(EHR)系统在文献以及行业中都受到了极大关注。人们期望它们能节省医疗保健成本、提高医疗保健质量并减少医疗差错。这种关注伴随着为应对EHR挑战而开发的不同标准和框架。为解决EHR问题而开发的最重要举措之一是IHE(整合医疗企业),它采用分布式方法来存储和管理医疗数据。IHE旨在规范医疗系统在分布式环境中交换信息的方式。为此,它定义了几个所谓的集成概要文件,这些文件指定了各种医疗系统(参与者)或实体之间的交互和接口(事务)。在少数处理主要安全要求(主要是身份验证和审计跟踪)的概要文件中也考虑了安全性。IHE的安全概要文件目前存在两个缺点。首先,它们应用端点安全方法,最近已证明这种方法在分布式和异构环境中是不足且繁琐的。其次,针对更复杂安全要求的当前安全概要文件过于简化、模糊且未考虑架构设计。最近这种情况在一定程度上有所改变,例如,随着关于隐私[5]和访问控制[9]的新发布白皮书的引入。为了解决第一个问题,我们利用在基于IHE的安全感知系统领域进行的先前研究结果以及最新的安全即服务方法,作为一种方便的方法来汇总全领域的安全需求并克服端点安全缺点。