• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

有效共享健康记录并维护隐私:一种实用模式。

Effective sharing of health records, maintaining privacy: a practical schema.

作者信息

Neame Roderick

机构信息

University of Queensland St Lucia Campus, Brisbane QLD Australia.

出版信息

Online J Public Health Inform. 2013 Jul 1;5(2):217. doi: 10.5210/ojphi.v5i2.4344. Print 2013.

DOI:10.5210/ojphi.v5i2.4344
PMID:23923101
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC3733761/
Abstract

A principal goal of computerisation of medical records is to join up care services for patients, so that their records can follow them wherever they go and thereby reduce delays, duplications, risks and errors, and costs. Healthcare records are increasingly being stored electronically, which has created the necessary conditions for them to be readily sharable. However simply driving the implementation of electronic medical records is not sufficient, as recent developments have demonstrated (1): there remain significant obstacles. The three main obstacles relate to (a) record accessibility (knowing where event records are and being able to access them), (b) maintaining privacy (ensuring that only those authorised by the patient can access and extract meaning from the records) and (c) assuring the functionality of the shared information (ensuring that the records can be shared non-proprietorially across platforms without loss of meaning, and that their authenticity and trustworthiness are demonstrable). These constitute a set of issues that need new thinking, since existing systems are struggling to deliver them. The solution to this puzzle lies in three main parts. Clearly there is only one environment suited to such widespread sharing, which is the World Wide Web, so this is the communications basis. Part one requires that a sharable synoptic record is created for each care event and stored in standard web-format and in readily accessible locations, on 'the web' or in 'the cloud'. To maintain privacy these publicly-accessible records must be suitably protected either stripped of identifiers (names, addresses, dates, places etc.) and/or encrypted: either way the record must be tagged with a tag that means nothing to anyone, but serves to identify and authenticate a specific record when retrieved. For ease of retrieval patients must hold an index of care events, records and web locations (plus any associated information for each such as encryption keys, context etc.). For added security, as well as for trustworthiness, a method of verifying authenticity, integrity and authorship is required, which can be provided using a public key infrastructure (PKI) for cryptography (2). The second part of the solution is to give control over record access and sharing to the patient (or their identified representative), enabling them to authorise access by providing the index and access keys to their records. This can be done using a token (fe.g. smart card) or a secure online index which holds these details: this serves to relieve the formal record keeper of responsibility for external access control and privacy (internal access control and privacy can remain an institutional responsibility). The third part of the solution is to process the content of the stored records such that there is a 'plain English' copy, as well as an electronic copy which is coded and marked up using XML tags for each data element to signify 'type' (e.g. administrative, financial, operational, clinical etc.) and sub-types (e.g. diagnosis, medication, procedure, investigation result etc.). This ensures that the recipient can always read the data using a basic browser, but can readily manipulate and re-arrange the data for display and storage if they have a more sophisticated installation.

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/16ac/3733761/ef082d088d4c/ojphi-05-e217-g001.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/16ac/3733761/ef082d088d4c/ojphi-05-e217-g001.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/16ac/3733761/ef082d088d4c/ojphi-05-e217-g001.jpg
摘要

医疗记录计算机化的一个主要目标是整合患者的护理服务,以便他们的记录能够随患者前往任何地方,从而减少延误、重复、风险、错误和成本。医疗记录越来越多地以电子方式存储,这为它们易于共享创造了必要条件。然而,正如最近的发展所表明的那样(1),仅仅推动电子病历的实施是不够的:仍然存在重大障碍。三个主要障碍涉及(a)记录的可访问性(知道事件记录在哪里并能够访问它们),(b)维护隐私(确保只有患者授权的人才能访问记录并从中提取信息),以及(c)确保共享信息的功能(确保记录能够在不同平台间以非专有的方式共享而不丢失信息,并且其真实性和可信度是可证明的)。这些构成了一系列需要新思维的问题,因为现有系统难以实现这些目标。这个难题的解决方案主要包括三个部分。显然,只有一个环境适合如此广泛的共享,那就是万维网,所以这是通信基础。第一部分要求为每个护理事件创建一个可共享的概要记录,并以标准的网络格式存储在易于访问的位置,如“网络”或“云”中。为了维护隐私,这些可公开访问的记录必须得到适当保护,要么去除标识符(姓名、地址、日期、地点等),要么进行加密:无论哪种方式,记录都必须用一个对任何人都毫无意义的标签进行标记,但在检索时用于识别和认证特定记录。为了便于检索,患者必须持有护理事件、记录和网络位置的索引(以及每个索引的任何相关信息,如加密密钥、上下文等)。为了增强安全性以及可信度,需要一种验证真实性、完整性和作者身份的方法,可以使用公钥基础设施(PKI)进行加密(2)来提供。解决方案的第二部分是将记录访问和共享的控制权交给患者(或其指定代表),使他们能够通过提供记录索引和访问密钥来授权访问。这可以使用令牌(如智能卡)或保存这些详细信息的安全在线索引来完成:这有助于免除正式记录保管人对外部访问控制和隐私的责任(内部访问控制和隐私仍可由机构负责)。解决方案的第三部分是处理存储记录的内容,以便有一个“通俗易懂的英语”副本,以及一个电子副本,该副本使用XML标签对每个数据元素进行编码和标记,以表示“类型”(如行政、财务、运营、临床等)和子类型(如诊断、药物治疗、手术、检查结果等)。这确保了接收者始终可以使用基本浏览器读取数据,但如果他们有更复杂的设备,就可以轻松地操作和重新排列数据以进行显示和存储。

相似文献

1
Effective sharing of health records, maintaining privacy: a practical schema.有效共享健康记录并维护隐私:一种实用模式。
Online J Public Health Inform. 2013 Jul 1;5(2):217. doi: 10.5210/ojphi.v5i2.4344. Print 2013.
2
Outstanding scientist of the year 2006: Rogel Patawaran, BS.2006年度杰出科学家:罗格尔·帕塔瓦兰,理学学士。
J Long Term Eff Med Implants. 2006;16(1):1-7. doi: 10.1615/jlongtermeffmedimplants.v16.i1.10.
3
A Blockchain Framework for Patient-Centered Health Records and Exchange (HealthChain): Evaluation and Proof-of-Concept Study.一种用于以患者为中心的健康记录与交换的区块链框架(HealthChain):评估与概念验证研究
J Med Internet Res. 2019 Aug 31;21(8):e13592. doi: 10.2196/13592.
4
Privacy preserving probabilistic record linkage (P3RL): a novel method for linking existing health-related data and maintaining participant confidentiality.隐私保护概率性记录链接(P3RL):一种链接现有健康相关数据并维护参与者隐私的新方法。
BMC Med Res Methodol. 2015 May 30;15:46. doi: 10.1186/s12874-015-0038-6.
5
A blockchain-based framework for electronic medical records sharing with fine-grained access control.基于区块链的电子病历共享细粒度访问控制框架。
PLoS One. 2020 Oct 6;15(10):e0239946. doi: 10.1371/journal.pone.0239946. eCollection 2020.
6
Distributed clinical data sharing via dynamic access-control policy transformation.通过动态访问控制策略转换实现分布式临床数据共享。
Int J Med Inform. 2016 May;89:25-31. doi: 10.1016/j.ijmedinf.2016.02.002. Epub 2016 Feb 12.
7
δ-dependency for privacy-preserving XML data publishing.用于隐私保护的XML数据发布的δ-依赖性。
J Biomed Inform. 2014 Aug;50:77-94. doi: 10.1016/j.jbi.2014.01.013. Epub 2014 Feb 8.
8
A method for cohort selection of cardiovascular disease records from an electronic health record system.一种从电子健康记录系统中选择心血管疾病记录队列的方法。
Int J Med Inform. 2017 Jun;102:138-149. doi: 10.1016/j.ijmedinf.2017.03.015. Epub 2017 Mar 30.
9
Intelligent Security and Privacy of Electronic Health Records Using Biometric Images.使用生物特征图像的电子健康记录的智能安全与隐私保护
Curr Med Imaging Rev. 2019;15(4):386-394. doi: 10.2174/1573405615666181228121535.
10
Obfuscatable multi-recipient re-encryption for secure privacy-preserving personal health record services.用于安全隐私保护个人健康记录服务的可混淆多接收者重新加密
Technol Health Care. 2015;23 Suppl 1:S139-45. doi: 10.3233/thc-150946.

引用本文的文献

1
Digital microbiology.数字微生物学。
Clin Microbiol Infect. 2020 Oct;26(10):1324-1331. doi: 10.1016/j.cmi.2020.06.023. Epub 2020 Jun 27.
2
Implementation of a shared medication list: physicians' views on availability, accuracy and confidentiality.共享用药清单的实施:医生对可用性、准确性和保密性的看法。
Int J Clin Pharm. 2014 Oct;36(5):933-42. doi: 10.1007/s11096-014-0012-0. Epub 2014 Sep 6.

本文引用的文献

1
What it will take to achieve the as-yet-unfulfilled promises of health information technology.实现健康信息技术尚未兑现的承诺所需的条件。
Health Aff (Millwood). 2013 Jan;32(1):63-8. doi: 10.1377/hlthaff.2012.0693.
2
Privacy and health information: health cards offer a workable solution.
Inform Prim Care. 2008;16(4):263-70. doi: 10.14236/jhi.v16i4.702.
3
Personally controlled online health data--the next big thing in medical care?个人可控的在线健康数据——医疗保健领域的下一个重大突破?
N Engl J Med. 2008 Apr 17;358(16):1653-6. doi: 10.1056/NEJMp0801736.
4
Applying new thinking from the linked and emerging fields of digital identity and privacy to information governance in health informatics.
Inform Prim Care. 2003;11(4):223-8. doi: 10.14236/jhi.v11i4.571.
5
Patient perspectives of medical confidentiality: a review of the literature.患者对医疗保密的看法:文献综述
J Gen Intern Med. 2003 Aug;18(8):659-69. doi: 10.1046/j.1525-1497.2003.20823.x.
6
Sharing patient care records over the World Wide Web.通过万维网共享患者护理记录。
Int J Med Inform. 2001 May;61(2-3):189-205. doi: 10.1016/s1386-5056(01)00141-1.
7
Adverse events in British hospitals: preliminary retrospective record review.英国医院的不良事件:初步回顾性记录审查
BMJ. 2001 Mar 3;322(7285):517-9. doi: 10.1136/bmj.322.7285.517.
8
Public standards and patients' control: how to keep electronic medical records accessible but private.公共标准与患者控制:如何确保电子病历可访问但私密。
BMJ. 2001 Feb 3;322(7281):283-7. doi: 10.1136/bmj.322.7281.283.