Ruotsalainen Pekka, Blobel Bernd, Nykänen Pirkko, Seppälä Antto, Sorvari Hannu
National Institute for Health and Welfare, Finland.
Stud Health Technol Inform. 2011;169:497-501.
Trustfulness (i.e. health and wellness information is processed ethically, and privacy is guaranteed) is one of the cornerstones for future Personal Health Systems, ubiquitous healthcare and pervasive health. Trust in today's healthcare is organizational, static and predefined. Pervasive health takes place in an open and untrusted information space where person's lifelong health and wellness information together with contextual data are dynamically collected and used by many stakeholders. This generates new threats that do not exist in today's eHealth systems. Our analysis shows that the way security and trust are implemented in today's healthcare cannot guarantee information autonomy and trustfulness in pervasive health. Based on a framework model of pervasive health and risks analysis of ubiquitous information space, we have formulated principles which enable trusted information sharing in pervasive health. Principles imply that the data subject should have the right to dynamically verify trust and to control the use of her health information, as well as the right to set situation based context-aware personal policies. Data collectors and processors have responsibilities including transparency of information processing, and openness of interests, policies and environmental features. Our principles create a base for successful management of privacy and information autonomy in pervasive health. They also imply that it is necessary to create new data models for personal health information and new architectures which support situation depending trust and privacy management.
可信赖性(即健康与保健信息以符合道德的方式进行处理,并保证隐私)是未来个人健康系统、普及医疗和泛在健康的基石之一。当今医疗保健中的信任是组织层面的、静态的且预先定义的。泛在健康发生在一个开放且不可信的信息空间中,在这个空间里,个人的终身健康与保健信息以及上下文数据由众多利益相关者动态收集和使用。这产生了当今电子健康系统中不存在的新威胁。我们的分析表明,当今医疗保健中实施安全和信任的方式无法保证泛在健康中的信息自主性和可信赖性。基于泛在健康的框架模型和对泛在信息空间的风险分析,我们制定了能够在泛在健康中实现可信信息共享的原则。这些原则意味着数据主体应有权动态验证信任并控制其健康信息的使用,以及有权基于情境设置情境感知个人政策。数据收集者和处理者有责任,包括信息处理的透明度以及利益、政策和环境特征的开放性。我们的原则为成功管理泛在健康中的隐私和信息自主性奠定了基础。它们还意味着有必要创建用于个人健康信息的新数据模型以及支持依赖情境的信任和隐私管理的新架构。