Department Epidemiology of Health Care and Community Health, Institute for Community Medicine, University Medicine Greifswald, Greifswald, Germany.
Institute of Medical Informatics, Statistics and Epidemiology (IMISE), Leipzig University, Leipzig, Germany.
Methods Inf Med. 2022 Dec;61(S 02):e134-e148. doi: 10.1055/a-1950-2791. Epub 2022 Sep 23.
The TMF (Technology, Methods, and Infrastructure for Networked Medical Research) Data Protection Guide (TMF-DP) makes path-breaking recommendations on the subject of data protection in research projects. It includes comprehensive requirements for applications such as patient lists, pseudonymization services, and consent management services. Nevertheless, it lacks a structured, categorized list of requirements for simplified application in research projects and systematic evaluation. The 3LGM2IHE ("Three-layer Graphbased meta model - Integrating the Healthcare Enterprise [IHE] " ) project is funded by the German Research Foundation (DFG). 3LGM2IHE aims to define modeling paradigms and implement modeling tools for planning health care information systems. In addition, one of the goals is to create and publish 3LGM information system architecture design patterns (short "design patterns") for the community as design models in terms of a framework. A structured list of data protection-related requirements based on the TMF-DP is a precondition to integrate functions (3LGM Domain Layer) and building blocks (3LGM Logical Tool Layer) in 3LGM design patterns.
In order to structure the continuous text of the TMF-DP, requirement types were defined in a first step. In a second step, dependencies and delineations of the definitions were identified. In a third step, the requirements from the TMF-DP were systematically extracted. Based on the identified lists of requirements, a fourth step included the comparison of the identified requirements with exemplary open source tools as provided by the "Independent Trusted Third Party of the University Medicine Greifswald" (TTP tools).
As a result, four lists of requirements were created, which contain requirements for the "patient list", the "pseudonymization service", and the "consent management", as well as cross-component requirements from the TMF-DP chapter 6 in a structured form. Further to requirements (1), possible variants (2) of implementations (to fulfill a single requirement) and recommendations (3) were identified. A comparison of the requirements lists with the functional scopes of the open source tools E-PIX (record linkage), gPAS (pseudonym management), and gICS (consent management) has shown that these fulfill more than 80% of the requirements.
A structured set of data protection-related requirements facilitates a systematic evaluation of implementations with respect to the fulfillment of the TMF-DP guidelines. These re-usable lists provide a decision aid for the selection of suitable tools for new research projects. As a result, these lists form the basis for the development of data protection-related 3LGM design patterns as part of the 3LGM2IHE project.
TMF(网络医学研究的技术、方法和基础架构)数据保护指南(TMF-DP)在研究项目的数据保护主题上提出了开创性的建议。它包括对患者名单、假名服务和同意管理服务等应用的全面要求。然而,它缺乏结构化、分类的要求列表,无法简化应用于研究项目和系统评估。3LGM2IHE(“基于三层图的元模型 - 整合医疗企业 [IHE]”)项目由德国研究基金会(DFG)资助。3LGM2IHE 的目的是为医疗保健信息系统规划定义建模范例和实现建模工具。此外,目标之一是为社区创建和发布 3LGM 信息系统架构设计模式(简称“设计模式”)作为框架方面的设计模型。基于 TMF-DP 的结构化数据保护相关要求列表是在 3LGM 设计模式中集成功能(3LGM 领域层)和构建块(3LGM 逻辑工具层)的前提条件。
为了对 TMF-DP 的连续文本进行结构化,首先定义了需求类型。在第二步中,确定了定义的依赖关系和划分。在第三步中,系统地从 TMF-DP 中提取了要求。基于确定的需求列表,第四步包括将确定的需求与“格赖夫斯瓦尔德大学独立可信第三方”(TTP 工具)提供的示例开源工具进行比较。
结果创建了四个需求列表,其中包含以结构化形式包含“患者名单”、“假名服务”和“同意管理”以及 TMF-DP 第 6 章跨组件要求的需求。进一步的要求 (1),实现 (满足单个要求) 的可能变体 (2) 和建议 (3) 已被确定。将需求列表与开源工具 E-PIX(记录链接)、gPAS(假名管理)和 gICS(同意管理)的功能范围进行比较表明,这些工具满足了 80%以上的要求。
一组结构化的数据保护相关要求有助于系统地评估实现 TMF-DP 指南的情况。这些可重复使用的列表为选择新研究项目中合适工具提供了决策辅助。因此,这些列表构成了 3LGM2IHE 项目中开发数据保护相关 3LGM 设计模式的基础。