Suppr超能文献

基于云的电子健康记录系统的安全性和隐私性要求分析

Analysis of the security and privacy requirements of cloud-based electronic health records systems.

作者信息

Rodrigues Joel J P C, de la Torre Isabel, Fernández Gonzalo, López-Coronado Miguel

机构信息

Instituto de Telecomunicações, University of Beira Interior, Covilha, Portugal.

出版信息

J Med Internet Res. 2013 Aug 21;15(8):e186. doi: 10.2196/jmir.2494.

Abstract

BACKGROUND

The Cloud Computing paradigm offers eHealth systems the opportunity to enhance the features and functionality that they offer. However, moving patients' medical information to the Cloud implies several risks in terms of the security and privacy of sensitive health records. In this paper, the risks of hosting Electronic Health Records (EHRs) on the servers of third-party Cloud service providers are reviewed. To protect the confidentiality of patient information and facilitate the process, some suggestions for health care providers are made. Moreover, security issues that Cloud service providers should address in their platforms are considered.

OBJECTIVE

To show that, before moving patient health records to the Cloud, security and privacy concerns must be considered by both health care providers and Cloud service providers. Security requirements of a generic Cloud service provider are analyzed.

METHODS

To study the latest in Cloud-based computing solutions, bibliographic material was obtained mainly from Medline sources. Furthermore, direct contact was made with several Cloud service providers.

RESULTS

Some of the security issues that should be considered by both Cloud service providers and their health care customers are role-based access, network security mechanisms, data encryption, digital signatures, and access monitoring. Furthermore, to guarantee the safety of the information and comply with privacy policies, the Cloud service provider must be compliant with various certifications and third-party requirements, such as SAS70 Type II, PCI DSS Level 1, ISO 27001, and the US Federal Information Security Management Act (FISMA).

CONCLUSIONS

Storing sensitive information such as EHRs in the Cloud means that precautions must be taken to ensure the safety and confidentiality of the data. A relationship built on trust with the Cloud service provider is essential to ensure a transparent process. Cloud service providers must make certain that all security mechanisms are in place to avoid unauthorized access and data breaches. Patients must be kept informed about how their data are being managed.

摘要

背景

云计算范式为电子健康系统提供了增强其提供的功能和特性的机会。然而,将患者的医疗信息迁移到云端意味着在敏感健康记录的安全性和隐私性方面存在若干风险。本文回顾了在第三方云服务提供商的服务器上托管电子健康记录(EHRs)的风险。为保护患者信息的保密性并推动该过程,为医疗保健提供者提出了一些建议。此外,还考虑了云服务提供商应在其平台中解决的安全问题。

目的

表明在将患者健康记录迁移到云端之前,医疗保健提供者和云服务提供商都必须考虑安全和隐私问题。分析了通用云服务提供商的安全要求。

方法

为研究基于云的最新计算解决方案,主要从Medline来源获取文献资料。此外,还与几家云服务提供商进行了直接联系。

结果

云服务提供商及其医疗保健客户都应考虑的一些安全问题包括基于角色的访问、网络安全机制、数据加密、数字签名和访问监控。此外,为确保信息安全并符合隐私政策,云服务提供商必须符合各种认证和第三方要求,如SAS70 Type II、PCI DSS Level 1、ISO 27001以及美国联邦信息安全管理法案(FISMA)。

结论

将诸如电子健康记录之类的敏感信息存储在云端意味着必须采取预防措施以确保数据的安全性和保密性。与云服务提供商建立基于信任的关系对于确保过程透明至关重要。云服务提供商必须确保所有安全机制都已到位,以避免未经授权的访问和数据泄露。必须让患者了解其数据的管理方式。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/65f1/3757992/6607994e774a/jmir_v15i8e186_fig1.jpg

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验