Sousa Mariana, Ferreira Duarte, Santos-Pereira Cátia, Bacelar Gustavo, Frade Samuel, Pestana Olívia, Cruz-Correia Ricardo
CINTESIS, Porto, Portugal.
HealthySystems, Portugal.
Stud Health Technol Inform. 2018;247:91-95.
The concerns about privacy and personal data protection resulted in reforms of the existing legislation in European Union (EU). The General Data Protection Regulation (GDPR) aims to reform the existing measures on the topic of personal data protection of the European Union citizens, with a strong input on the rights and freedoms of people and in the establishment of rules for the processing of personal data. OpenEHR is a standard that embodies many principles of interoperable and secure software for electronic health records. This work aims to understand to what extent the openEHR standard can be considered a solution for the requirements needed by GDPR. A list of requirements for a Hospital Information Systems (HIS) compliant with GDPR and an identification of openEHR specifications was made. The requirements were categorized and compared with the specifications. The requirements identified for the systems were matched with the openEHR specifications, which result in 16 requirements matched with openEHR. All the specifications identified matched at least one requirement. OpenEHR is a solution for the development of HIS that reinforce privacy and personal data protection, ensuring that they are contemplated in the system development. The institutions can secure that their Eletronic Health Record are compliant with GDPR while safeguarding the medical data quality and, as a result, the healthcare delivery.
对隐私和个人数据保护的担忧促使欧盟对现有立法进行改革。《通用数据保护条例》(GDPR)旨在改革欧盟公民个人数据保护主题的现有措施,大力关注人们的权利和自由,并制定个人数据处理规则。OpenEHR是一种体现电子健康记录互操作性和安全软件诸多原则的标准。这项工作旨在了解OpenEHR标准在多大程度上可被视为满足GDPR所需要求的解决方案。列出了符合GDPR的医院信息系统(HIS)的要求清单,并确定了OpenEHR规范。对这些要求进行了分类,并与规范进行了比较。为系统确定的要求与OpenEHR规范相匹配,结果有16项要求与OpenEHR相匹配。所有确定的规范至少符合一项要求。OpenEHR是开发HIS的一种解决方案,可加强隐私和个人数据保护,确保在系统开发中考虑到这些因素。各机构可以确保其电子健康记录符合GDPR,同时保障医疗数据质量,从而保障医疗服务的提供。