Norwegian Centre for Integrated Care and Telemedicine, University Hospital of North Norway, Tromsø, Norway.
BMC Med Inform Decis Mak. 2013 Aug 9;13:85. doi: 10.1186/1472-6947-13-85.
Privacy and information security are important for all healthcare services, including home-based services. We have designed and implemented a prototype technology platform for providing home-based healthcare services. It supports a personal electronic health diary and enables secure and reliable communication and interaction with peers and healthcare personnel. The platform runs on a small computer with a dedicated remote control. It is connected to the patient's TV and to a broadband Internet. The platform has been tested with home-based rehabilitation and education programs for chronic obstructive pulmonary disease and diabetes. As part of our work, a risk assessment of privacy and security aspects has been performed, to reveal actual risks and to ensure adequate information security in this technical platform.
Risk assessment was performed in an iterative manner during the development process. Thus, security solutions have been incorporated into the design from an early stage instead of being included as an add-on to a nearly completed system. We have adapted existing risk management methods to our own environment, thus creating our own method. Our method conforms to ISO's standard for information security risk management.
A total of approximately 50 threats and possible unwanted incidents were identified and analysed. Among the threats to the four information security aspects: confidentiality, integrity, availability, and quality; confidentiality threats were identified as most serious, with one threat given an unacceptable level of High risk. This is because health-related personal information is regarded as sensitive. Availability threats were analysed as low risk, as the aim of the home programmes is to provide education and rehabilitation services; not for use in acute situations or for continuous health monitoring.
Most of the identified threats are applicable for healthcare services intended for patients or citizens in their own homes. Confidentiality risks in home are different from in a more controlled environment such as a hospital; and electronic equipment located in private homes and communicating via Internet, is more exposed to unauthorised access. By implementing the proposed measures, it has been possible to design a home-based service which ensures the necessary level of information security and privacy.
隐私和信息安全对于所有医疗保健服务都很重要,包括家庭医疗服务。我们设计并实现了一个原型技术平台,用于提供家庭医疗服务。它支持个人电子健康日记,并能够与同行和医疗保健人员进行安全可靠的通信和交互。该平台在一台带有专用遥控器的小型计算机上运行。它连接到患者的电视和宽带互联网。该平台已在慢性阻塞性肺疾病和糖尿病的家庭康复和教育计划中进行了测试。作为我们工作的一部分,对隐私和安全方面的风险进行了评估,以揭示实际风险,并确保在这个技术平台中有足够的信息安全。
风险评估是在开发过程中迭代进行的。因此,安全解决方案从早期阶段就被纳入设计中,而不是作为一个几乎完成的系统的附加组件。我们已经将现有的风险管理方法适用于我们自己的环境,从而创建了自己的方法。我们的方法符合 ISO 信息安全风险管理标准。
总共确定并分析了大约 50 个威胁和可能的意外事件。在四个信息安全方面的威胁中:保密性、完整性、可用性和质量;保密性威胁被认为是最严重的,有一个威胁被评为不可接受的高风险。这是因为与健康相关的个人信息被视为敏感信息。可用性威胁被分析为低风险,因为家庭计划的目的是提供教育和康复服务;而不是用于急性情况或连续健康监测。
大多数确定的威胁都适用于旨在为患者或公民在自己家中提供的医疗保健服务。家庭中的保密性风险与医院等更受控制的环境中的风险不同;并且位于私人住宅中的电子设备通过互联网进行通信,更容易受到未经授权的访问。通过实施拟议的措施,我们可以设计一种家庭医疗服务,确保必要的信息安全和隐私级别。