Computational Health Informatics Program, Boston Children's Hospital, Department of Pediatrics, Harvard Medical School, Boston, Massachusetts, USA.
Department of Pediatrics, Harvard Medical School, Boston, Massachusetts, USA.
J Am Med Inform Assoc. 2021 Mar 1;28(3):640-645. doi: 10.1093/jamia/ocaa227.
Under the 21st Century Cures Act and the Office of the National Coordinator for Health Information Technology (ONC) rule implementing its interoperability provisions, a patient's rights to easily request and obtain digital access to portions of their medical records are now supported by both technology and policy. Data, once directed by a patient to leave a Health Insurance Portability and Accountability Act-covered health entity and enter a consumer app, will usually fall under Federal Trade Commission oversight. Because the statutory authority of the ONC does not extend to health data protection, there is not yet regulation to specifically address privacy protections for consumer apps. A technologically feasible workflow that could be widely adopted and permissible under ONC's rule, involves using the SMART on FHIR OAuth authorization routine to present standardized information about app behavior. This approach would not bias the patient in a way that triggers penalties under information blocking provisions of the rule.
根据《21 世纪治愈法案》和实施其互操作性条款的国家卫生信息技术协调办公室 (ONC) 规则,患者现在可以通过技术和政策轻松请求和获取其部分医疗记录的数字访问权限。一旦患者指示数据离开受《健康保险携带和责任法案》覆盖的健康实体并进入消费者应用程序,这些数据通常将受到联邦贸易委员会的监督。由于 ONC 的法定权限不扩展到健康数据保护,因此尚未有法规专门针对消费者应用程序的隐私保护问题。ONC 规则下可广泛采用且符合规定的一种技术上可行的工作流程涉及使用 SMART on FHIR OAuth 授权例程来呈现有关应用程序行为的标准化信息。这种方法不会以触发规则信息阻止条款下的处罚的方式使患者产生偏见。