Suppr超能文献

开放电子健康记录与通用数据保护条例:原则与要求评估

OpenEHR and General Data Protection Regulation: Evaluation of Principles and Requirements.

作者信息

Gonçalves-Ferreira Duarte, Sousa Mariana, Bacelar-Silva Gustavo M, Frade Samuel, Antunes Luís Filipe, Beale Thomas, Cruz-Correia Ricardo

机构信息

Center for Health Technology and Services Research, Porto, Portugal.

Healthy Systems, Porto, Portugal.

出版信息

JMIR Med Inform. 2019 Mar 25;7(1):e9845. doi: 10.2196/medinform.9845.

Abstract

BACKGROUND

Concerns about privacy and personal data protection resulted in reforms of the existing legislation in the European Union (EU). The General Data Protection Regulation (GDPR) aims to reform the existing directive on the topic of personal data protection of EU citizens with a strong emphasis on more control of the citizens over their data and in the establishment of rules for the processing of personal data. OpenEHR is a standard that embodies many principles of interoperable and secure software for electronic health records (EHRs) and has been advocated as the best approach for the development of hospital information systems.

OBJECTIVE

This study aimed to understand to what extent the openEHR standard can help in the compliance of EHR systems to the GDPR requirements.

METHODS

A list of requirements for an EHR to support GDPR compliance and also a list of the openEHR design principles were made. The requirements were categorized and compared with the principles by experts on openEHR and GDPR.

RESULTS

A total of 50 GDPR requirements and 8 openEHR design principles were identified. The openEHR principles conformed to 30% (15/50) of GDPR requirements. All the openEHR principles were aligned with GDPR requirements.

CONCLUSIONS

This study showed that the openEHR principles conform well to GDPR, underlining the common wisdom that truly realizing security and privacy requires it to be built in from the start. By using an openEHR-based EHR, the institutions are closer to becoming compliant with GDPR while safeguarding the medical data.

摘要

背景

对隐私和个人数据保护的担忧促使欧盟(EU)对现有立法进行改革。《通用数据保护条例》(GDPR)旨在改革关于欧盟公民个人数据保护主题的现有指令,特别强调公民对其数据有更多控制权,并建立个人数据处理规则。OpenEHR是一种体现电子健康记录(EHR)可互操作和安全软件诸多原则的标准,被倡导为开发医院信息系统的最佳方法。

目的

本研究旨在了解OpenEHR标准在多大程度上有助于EHR系统符合GDPR要求。

方法

列出EHR支持GDPR合规性的要求清单以及OpenEHR设计原则清单。由OpenEHR和GDPR专家对这些要求进行分类并与原则进行比较。

结果

共确定了50项GDPR要求和8项OpenEHR设计原则。OpenEHR原则符合30%(15/50)的GDPR要求。所有OpenEHR原则均与GDPR要求一致。

结论

本研究表明,OpenEHR原则与GDPR高度契合,这凸显了一个共识,即真正实现安全和隐私需要从一开始就将其融入其中。通过使用基于OpenEHR的EHR,各机构在保护医疗数据的同时更接近符合GDPR要求。

相似文献

7
General Data Protection Regulation in Health Clinics.健康诊所的一般数据保护条例。
J Med Syst. 2020 Jan 10;44(2):53. doi: 10.1007/s10916-020-1521-0.

引用本文的文献

本文引用的文献

8

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验