Suppr超能文献

迈向欧洲健康数据空间:基于电子健康记录的精准医学研究的 IMPaCT-Data 安全基础设施。

Toward the European Health Data Space: The IMPaCT-Data secure infrastructure for EHR-based precision medicine research.

机构信息

Computational Health Informatics Group, Institute of Biomedicine of Seville, IBiS/Virgen del Rocio University Hospital/CSIC/University of Seville, Avenue Manuel Siurot S/N, Seville, 41013, Spain.

IFS-CSIC, Albasanz 26, Madrid, 28036, Spain.

出版信息

J Biomed Inform. 2024 Aug;156:104670. doi: 10.1016/j.jbi.2024.104670. Epub 2024 Jun 14.

Abstract

BACKGROUND

Art. 50 of the proposal for a Regulation on the European Health Data Space (EHDS) states that "health data access bodies shall provide access to electronic health data only through a secure processing environment, with technical and organizational measures and security and interoperability requirements".

OBJECTIVE

To identify specific security measures that nodes participating in health data spaces shall implement based on the results of the IMPaCT-Data project, whose goal is to facilitate the exchange of electronic health records (EHR) between public entities based in Spain and the secondary use of this information for precision medicine research in compliance with the General Data Protection Regulation (GDPR).

DATA AND METHODS

This article presents an analysis of 24 out of a list of 72 security measures identified in the Spanish National Security Scheme (ENS) and adopted by members of the federated data infrastructure developed during the IMPaCT-Data project.

RESULTS

The IMPaCT-Data case helps clarify roles and responsibilities of entities willing to participate in the EHDS by reconciling technical system notions with the legal terminology. Most relevant security measures for Data Space Gatekeepers, Enablers and Prosumers are identified and explained.

CONCLUSION

The EHDS can only be viable as long as the fiduciary duty of care of public health authorities is preserved; this implies that the secondary use of personal data shall contribute to the public interest and/or to protect the vital interests of the data subjects. This condition can only be met if all nodes participating in a health data space adopt the appropriate organizational and technical security measures necessary to fulfill their role.

摘要

背景

《关于建立欧洲健康数据空间的提案》第 50 条规定,“健康数据访问机构只能通过安全处理环境提供电子健康数据,同时需要采取技术和组织措施以及安全和互操作性要求”。

目的

根据旨在促进西班牙公共实体之间电子健康记录(EHR)交换并根据《通用数据保护条例》(GDPR)允许对这些信息进行精准医学研究的二次利用的 IMPaCT-Data 项目的结果,确定参与健康数据空间的节点应实施的具体安全措施。

数据和方法

本文分析了 24 项从西班牙国家安全计划(ENS)中确定的 72 项安全措施列表中选取的措施,并采用了在 IMPaCT-Data 项目中开发的联邦数据基础设施成员所采用的措施。

结果

IMPACT-Data 案例通过将技术系统概念与法律术语相协调,有助于澄清愿意参与 EHDS 的实体的角色和责任。确定并解释了数据空间守门员、推动者和消费者最相关的安全措施。

结论

只要公共卫生当局的谨慎护理信托责任得到维护,EHDS 才具有可行性;这意味着个人数据的二次利用应有助于公共利益和/或保护数据主体的重大利益。只有当参与健康数据空间的所有节点都采取适当的组织和技术安全措施来履行其职责,才能满足这一条件。

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验