• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

通过半形式化建模确定健康 ICT 应用程序的隐私政策缺陷。

Determining the privacy policy deficiencies of health ICT applications through semi-formal modelling.

机构信息

Southern Cross University, Lismore, Australia.

出版信息

Int J Med Inform. 2011 Feb;80(2):e32-8. doi: 10.1016/j.ijmedinf.2010.10.006. Epub 2010 Nov 13.

DOI:10.1016/j.ijmedinf.2010.10.006
PMID:21075675
Abstract

To ensure that patient confidentiality is securely maintained, health ICT applications that contain sensitive personal information demand comprehensive privacy policies. Determining the adequacy of these policies to meet legal conformity together with clinical users and patient expectation is demanding in practice. Organisations and agencies looking to analyse their Privacy and Security policies can benefit from guidance provided by outside entities such as the Privacy Office of their State or Government together with law firms and ICT specialists. The advice given is not uniform and often open to different interpretations. Of greater concern is the possibility of overlooking any important aspects that later result in a data breach. Based on three case studies, this paper considers whether a more formal approach to privacy analysis could be taken that would help identify the full coverage of a Privacy Impact Analysis and determine the deficiencies with an organisation's current policies and approach. A diagrammatic model showing the relationships between Confidentiality, Privacy, Trust, Security and Safety is introduced. First the validity of this model is determined by mapping it against the real-world case studies taken from three healthcare services that depend on ICT. Then, by using software engineering methods, a formal mapping of the relationships is undertaken to identify a full set of policies needed to satisfy the model. How effective this approach may prove as a generic method for deriving a comprehensive set of policies in health ICT applications is finally discussed.

摘要

为了确保患者的保密性得到妥善维护,包含敏感个人信息的卫生信息和通信技术应用程序需要全面的隐私政策。在实践中,确定这些政策是否足以满足法律合规性以及临床用户和患者的期望是一项具有挑战性的任务。希望分析其隐私和安全政策的组织和机构可以从外部实体(如州或政府的隐私办公室)、律师事务所和信息通信技术专家那里获得指导。所提供的建议并不统一,并且经常存在不同的解释。更令人担忧的是,可能会忽略任何重要方面,而这些方面后来会导致数据泄露。本文基于三个案例研究,探讨是否可以采取更正式的隐私分析方法,以帮助确定隐私影响分析的全面覆盖范围,并确定组织当前政策和方法的不足之处。引入了一个显示保密性、隐私、信任、安全和安全之间关系的图表模型。首先,通过将其映射到依赖于信息和通信技术的三个医疗保健服务的实际案例研究来确定该模型的有效性。然后,通过使用软件工程方法,对关系进行正式映射,以确定满足模型所需的完整政策集。最后讨论了这种方法作为在卫生信息和通信技术应用程序中推导出全面的政策集的通用方法可能具有的有效性。

相似文献

1
Determining the privacy policy deficiencies of health ICT applications through semi-formal modelling.通过半形式化建模确定健康 ICT 应用程序的隐私政策缺陷。
Int J Med Inform. 2011 Feb;80(2):e32-8. doi: 10.1016/j.ijmedinf.2010.10.006. Epub 2010 Nov 13.
2
Formal policies for flexible EHR security.灵活电子健康记录安全的正式政策。
Stud Health Technol Inform. 2006;121:307-16.
3
American Society of Clinical Oncology policy statement update: genetic testing for cancer susceptibility.美国临床肿瘤学会政策声明更新:癌症易感性基因检测
J Clin Oncol. 2003 Jun 15;21(12):2397-406. doi: 10.1200/JCO.2003.03.189. Epub 2003 Apr 11.
4
Privacy and security in Pennsylvania: ensuring privacy and security of health information exchange in Pennsylvania.宾夕法尼亚州的隐私与安全:确保宾夕法尼亚州健康信息交换的隐私与安全。
J Healthc Inf Manag. 2009 Spring;23(2):38-44.
5
HIPAA--a real world perspective.《健康保险流通与责任法案》——现实视角
Radiol Manage. 2001 Mar-Apr;23(2):29-37; quiz 38-40.
6
A standardised graphic method for describing data privacy frameworks in primary care research using a flexible zone model.一种使用灵活区域模型描述初级保健研究中数据隐私框架的标准化图形方法。
Int J Med Inform. 2014 Dec;83(12):941-57. doi: 10.1016/j.ijmedinf.2014.08.009. Epub 2014 Sep 3.
7
Privacy and security in teleradiology.远程放射学中的隐私和安全。
Eur J Radiol. 2010 Jan;73(1):31-5. doi: 10.1016/j.ejrad.2009.10.018. Epub 2009 Nov 13.
8
Health information privacy: without confidentiality.健康信息隐私:缺乏保密性。
Int J Biomed Comput. 1994 Feb;35 Suppl:97-104.
9
Access and privacy rights using web security standards to increase patient empowerment.利用网络安全标准保障访问和隐私权,增强患者自主权。
Stud Health Technol Inform. 2008;137:275-85.
10
Data privacy considerations in Intensive Care Grids.重症监护网格中的数据隐私考量
Stud Health Technol Inform. 2008;138:178-87.

引用本文的文献

1
Sociotechnical challenges and progress in using social media for health.使用社交媒体促进健康方面的社会技术挑战与进展。
J Med Internet Res. 2013 Oct 22;15(10):e226. doi: 10.2196/jmir.2792.
2
Bringing the artificial pancreas home: telemedicine aspects.将人工胰腺带回家:远程医疗方面
J Diabetes Sci Technol. 2011 Nov 1;5(6):1381-6. doi: 10.1177/193229681100500609.