PubMed Health⌕ Search

Biomedical subjects

Bernd Blobel

Publications and source records attributed to Bernd Blobel.

At least 19 recordsLinked to original sources

Comparing approaches for advanced e-health security infrastructures.

OBJECTIVES: The healthcare systems of all developed countries face the challenge for improving quality, efficiency and safety of patients' care. For meeting this challenge, health is moving from being organisation-centred to process-based care. This process will continue in the future turning health towards person-centred architectures. This system transformation is combined with extended and advanced communication and collaboration supported and enabled by appropriate information and communication technologies (ICT), also called e-health. The resulting solutions have to be trustworthy. METHODS: There is a set of security services needed for realising trustworthy e-health solutions. Those security services must be comprehensively integrated in the e-health application. Furthermore, a set of infrastructure services has to be specified and implemented. For keeping the solutions future-proof, they have to comply with architectural principles and paradigms. RESULTS: After shortly introducing meanwhile internationally acknowledged architectural paradigms for applications, means and infrastructures providing security services, existing, or specified advanced solutions are described and compared. In that context, the Electronic Health Record as e-health core application has been especially considered. Based on published work as well as on explored solutions, the security services needed are summarised and evaluated. The pros and cons of investigated examples are collected and interpreted. In that context, especially the German health telematics framework architecture and security infrastructure and the corresponding implementable solutions on the one hand and the USA Veterans Health Administration approach to security have been carefully considered. CONCLUSION: Processes and systems are determined by policies, which define and distinguish constraints for communication and collaboration. Therefore, formally modelling policies and performing policy bridging are the main challenges to be met. As result of investigations, recommendations have been derived for establishing the trustworthiness required for any e-health solution at different level from regional to national, European, and even global scale, which are included in the conference summary.

Computer Security↗

A model driven approach for the German health telematics architectural framework and security infrastructure.

Shared care concepts such as managed care and continuity of care are based on extended communication and cooperation between different health professionals or between them and the patient respectively. Health information systems and their components, which are very different in their structure, behavior, data and their semantics as well as regarding implementation details used in different environments for different purposes, have to provide intelligent interoperability. Therefore, flexibility, portability, and future orientation must be guaranteed using the newest development of model driven architecture. The ongoing work for the German health telematics platform based on an architectural framework and a security infrastructure is described in some detail. This concept of future proof health information networks with virtual electronic health records as core application starts with multifunctional electronic health cards. It fits into developments currently performed by many other developed countries.

Computer Security↗

EHR standards--A comparative study.

For ensuring quality and efficiency of patient's care, the care paradigm moves from organization-centered over process-controlled towards personal care. Such health system paradigm change leads to new paradigms for analyzing, designing, implementing and deploying supporting health information systems including EHR systems as core application in a distributed eHealth environment. The paper defines the architectural paradigm for future-proof EHR systems. It compares advanced EHR architectures referencing them at the Generic Component Model. The paper introduces the evolving paradigm of autonomous computing for self-organizing health information systems.

Database Management Systems↗

Personal health--the future care paradigm.

Demographic, economic and social conditions developed countries are faced with require a paradigm change for delivering high quality and efficient health services. In that context healthcare systems have to turn towards individualized of patient's care, also called personal care. Interoperability requirements for ubiquitous personalized health services reach beyond current concepts of health information integration among professional stakeholders and related Electronic Patient Records ("e-Health"): Future personal health platforms have particularly to maintain semantic interoperability among systems using different modalities and technologies, different knowledge representation and domain experts' languages as well as different coding schemes and terminologies to include home, personal and mobile systems. The paper introduces the evolving paradigm related to personal health information systems.

Computer Communication Networks↗

Formal policies for flexible EHR security.

State of the Art methodologies for establishing requirements and solutions to securing applications are based on narrative descriptions about the use of available system, sometimes also dedicated to system components. Even nowadays new developments to ruling application security services by the use of predicate logic suffer from being administered manually. Therefore, security and privacy requirements cannot be properly met resulting in restrictions and fears for allowing the use of sensitive data and functions. Because of the sensitivity of personal health information and especially of genetic data with its wider implications beyond the original subject of care, weaknesses in guaranteeing fine-grained security and privacy rules lead to less acceptance or even the avoidance of essential information transfer and use. To overcome the problem, security and privacy have to become properties of the architectural components of the respective health information system. Embedding security into the systems architecture allows for negotiating and enforcing any security and privacy services related to principals, their roles, their relationships, further contextual information as well as other regulations summarized in formally modeled policies. The paper introduces the evolving paradigm of the model-driven architecture, first time also comprehensively deployed for security and privacy services in bio-genetic and health information systems.

Authorship↗

BioHealth--the need for security and identity management standards in eHealth.

The experience gained in these last years and the several lesson learned have clearly shown that eHealth is more than just a simple change from paper records to electronic records. It necessitates a change of paradigms, on the one hand and the use of new technologies and introduction of new procedures on the other. Interoperability becomes a crucial issue. Security and confidentiality are vital for the acceptance of the new approaches and for the support of eHealth. Shared care and across-border interactions require a reliable and stable normative framework based on the application of standardized solutions, which are often not yet sufficiently known, diffused and implemented. Feeling this gap, a group of international experts in the medical area proposed to the EC the BioHealth project whose main aim is to create awareness about standardization in eHealth and to facilitate its practical implementation. The project will address all the stakeholders concerning their respective domain. It will evaluate the socio-economic and cultural aspects concerning eHealth with particular reference to the growing introduction of emerging technologies such as health cards, biometrics, RFID (radio-frequency identification) and NFC (Near field communication) tags. By providing information and expert advice on standardization and best practices it will raise the acceptance on standardization. Furthermore, the project will deeply approach the ethical and accessibility issues connected to identity management in eHealth, which -together with privacy- represent probably the most significant obstacles for the wide diffusion of eHealth procedures.

Biometry↗

Formal design of electronic public health records.

EHR systems have evolved from management of medical and patient records to the management of comprehensive health records including information about any observed health states e.g., social, economic and environmental conditions; and process such as public health surveillance, health promotion, prevention, education, etc. The paper discusses the analysis and design of Electronic Public Health Records (EPHR) according to the advanced state of knowledge in methodologies, models, techniques and tools for the specification of EPHR systems. A formal component-based architectural approach, based on internationally agreed terminologies, healthcare standards and software engineering de facto standards is presented.

Germany↗

Specific interoperability problems of security infrastructure services.

Communication and co-operation in healthcare and welfare require a well-defined set of security services based on a standards-based interoperable security infrastructure and provided by a Trusted Third Party. Generally, the services describe status and relation of communicating principals, corresponding keys and attributes, and the access rights to both applications and data. Legal, social, behavioral and ethical requirements demand securely stored patient information and well-established access tools and tokens. Electronic signatures as means for securing integrity of messages and files, certified time stamps and time signatures are important for accessing and storing data in Electronic Health Record Systems. The key for all these services is a secure and reliable procedure for authentication (identification and verification). While mentioning technical problems (e.g. lifetime of the storage devices, migration of retrieval and presentation software), this paper aims at identifying harmonization and interoperability requirements of securing data items, files, messages, sets of archived items or documents, and life-long Electronic Health Records based on a secure certificate-based identification. It's commonly known that just relying on existing and emerging security standards does not necessarily guarantee interoperability of different security infrastructure approaches. So certificate separation can be a key to modern interoperable security infrastructure services.

Authorship↗

Standards for enabling health informatics interoperability.

Most of industry countries are turning their healthcare system towards integrated care paradigms for improving quality, efficiency, and safety of patients' care. Integrated care has to be supported by extended communication and cooperation between the involved healthcare establishments' information systems. The required interoperability level goes beyond technical interoperability and simple data exchange as it has been started in the early world of electronic data exchange (EDI). For realising semantic interoperability, series of standards must be specified, implemented and enforced. The paper classifies standards for health information systems needed for enabling practical semantic interoperability.

Germany↗

Benefits and weaknesses of health cards used in health information systems.

The acceptance-based success of modern health information systems and health networks highly depends on the respective involvement of all relevant partners into the communication and co-operation processes characterising the medical and administrative workflow. Personal information stored in a networking environment guarantee for fast access fulfilling advanced shared care requirements whereas security token like smart cards stand for identification purposes, data protection, privacy protection, access rights, and limited person-based information storage, e.g., for emergency procedures. Linking these means of information provision allows for making use of the benefits of the different technologies without ignoring their existing weaknesses. The presented paper intends to summarise the respective categories of benefits and weaknesses allowing the reader to implement cards in health information systems as well as with the related aspects of awareness, confidence, and acceptance. Concluding this analysis, the preferred way to deal with the challenges of modern healthcare and welfare requirements shall be a well-balanced combination of cards and networks.

Diffusion of Innovation↗

Modelling privilege management and access control.

OBJECTIVES: For establishing trustworthiness in advanced architectures for future-proof health information systems being open, flexible, scaleable, portable, and semantically interoperable, security and privacy services needed must be designed as an inherent part of the architecture. Such architecture has to meet the paradigms of distribution, component orientation, formal modelling, separation of logical and technological aspects, etc. METHODS: In model-driven architectures components providing security and privacy services have to be specified using the same methodology of formal models with meta-languages as expression means, as deployed in computational, technical, or medical domains. The resulting approach must be based on the ISO Reference Model-Open Distributed Processing. RESULTS: Currently, standards developing organisation are defining emerging tasks and standards for semantic interoperability and trustworthy collaboration for advanced health information systems. Communication security issues have been specified and implemented, while application security challenges such as privilege management and access control are still under development. Therefore, a series of formal models have been developed by the authors covering, e.g. domains, service delegation, claims control, policies, roles, authorisations, and access control. The required models are introduced and interpreted in a generic way. The crucial concept of security policy and its relationship to the other concepts has been considered in detail. CONCLUSION: Based on formal models, security services can be integrated into advanced systems architectures enabling semantic interoperability in the context of trustworthiness of communication and co-operation.

Access to Information↗

Advanced and secure architectural EHR approaches.

OBJECTIVES: Electronic Health Records (EHRs) provided as a lifelong patient record advance towards core applications of distributed and co-operating health information systems and health networks. For meeting the challenge of scalable, flexible, portable, secure EHR systems, the underlying EHR architecture must be based on the component paradigm and model driven, separating platform-independent and platform-specific models. METHODS: Allowing manageable models, real systems must be decomposed and simplified. The resulting modelling approach has to follow the ISO Reference Model - Open Distributing Processing (RM-ODP). The ISO RM-ODP describes any system component from different perspectives. Platform-independent perspectives contain the enterprise view (business process, policies, scenarios, use cases), the information view (classes and associations) and the computational view (composition and decomposition), whereas platform-specific perspectives concern the engineering view (physical distribution and realisation) and the technology view (implementation details from protocols up to education and training) on system components. Those views have to be established for components reflecting aspects of all domains involved in healthcare environments including administrative, legal, medical, technical, etc. Thus, security-related component models reflecting all view mentioned have to be established for enabling both application and communication security services as integral part of the system's architecture. Beside decomposition and simplification of system regarding the different viewpoint on their components, different levels of systems' granularity can be defined hiding internals or focusing on properties of basic components to form a more complex structure. The resulting models describe both structure and behaviour of component-based systems. RESULTS: The described approach has been deployed in different projects defining EHR systems and their underlying architectural principles. In that context, the Australian GEHR project, the openEHR initiative, the revision of CEN ENV 13606 "Electronic Health Record communication", all based on Archetypes, but also the HL7 version 3 activities are discussed in some detail. The latter include the HL7 RIM, the HL7 Development Framework, the HL7's clinical document architecture (CDA) as well as the set of models from use cases, activity diagrams, sequence diagrams up to Domain Information Models (DMIMs) and their building blocks Common Message Element Types (CMET) Constraining Models to their underlying concepts. CONCLUSION: The future-proof EHR architecture as open, user-centric, user-friendly, flexible, scalable, portable core application in health information systems and health networks has to follow advanced architectural paradigms.

Computer Security↗

Electronic signatures for long-lasting storage purposes in electronic archives.

Communication and co-operation in healthcare and welfare require a certain set of trusted third party (TTP) services describing both status and relation of communicating principals as well as their corresponding keys and attributes. Additional TTP services are needed to provide trustworthy information about dynamic issues of communication and co-operation such as time and location of processes, workflow relations, and system behaviour. Legal and ethical requirements demand securely stored patient information and well-defined access rights. Among others, electronic signatures based on asymmetric cryptography are important means for securing the integrity of a message or file as well as for accountability purposes including non-repudiation of both origin and receipt. Electronic signatures along with certified time stamps or time signatures are especially important for electronic archives in general, electronic health records (EHR) in particular, and especially for typical purposes of long-lasting storage. Apart from technical storage problems (e.g. lifetime of the storage devices, interoperability of retrieval and presentation software), this paper identifies mechanisms of e.g. re-signing and re-stamping of data items, files, messages, sets of archived items or documents, archive structures, and even whole archives.

Computer Security↗

A model-driven approach for the german health telematics architectural framework and the related security infrastructure.

Shared care concepts such as managed care and continuity of care are based on extended communication and co-operation either between different health professionals, or between them and the patient. Health information systems and their components, which are very different in their structure, their behaviour, the respective data, and their semantics as well as regarding implementation details used in different environments for different purposes, have to provide intelligent interoperability. Therefore, flexibility, portability, and future-orientation must be guaranteed using the newest development of model driven architecture. The ongoing work for the German health telematics platform based on an architectural framework and a security infrastructure is described in some detail. This concept of future-proof health information networks with virtual Electronic Health Records as core application starts with multifunctional Electronic Health Cards. It fits into developments currently performed by many other developed countries in Europe and beyond.

Communication↗

Security infrastructure requirements for electronic health cards communication.

Communication and co-operation processes in the healthcare and welfare domain require a security infrastructure based on services describing status and relation of communicating principals as well as corresponding keys and attributes. Additional services provide trustworthy information on dynamic issues of communication and co-operation such as time and location of processes, workflow relations, integrity of archives and record systems, and system behaviour. To provide this communication and co-operation in a shared care environment, smart cards are widely used. Serving as storage media and portable application systems, patient data cards enable patient-controlled exchange and use of personal health data bound to specific purposes such as prescription and disease management. Additionally, patient status data such as the emergency data set or immunization may be stored in, and communicated by, patient data cards. Another deployment field of smart cards is their token functionality within a security framework, supporting basic security services such as identification, authentication, integrity, confidentiality, or accountability using cryptographic algorithms. In that context, keys, certificates, and card holder's attributes might be stored in the card as well. As an example, the German activity of introducing patient health cards and health professional cards is presented. Specification and enrolment aspects are on-going processes.

Communication↗

Security Services for the HemaCAM Project.

Within the HemaCAM project which deals with automated differential white blood cell count by image processing, a security infrastructure has been integrated. The security services for this demonstrator have been derived from the German health network ONCONET that enables a trustworthy framework for both health professionals and patients as well as supports clinical studies. For the solution, services assuring both communication security and application security have to be provided. This task has been realised by the use of the security token Health Professional Card and an appropriate Trusted Third Party infrastructure.

Communication↗

Does HL7 Go towards an Architecture Standard?

Starting as a rather simple message standard to be used within hospitals, the scope of HL7 has been extended to covering all domains and institutions in health. The most important development of the HL7 standard set was its development towards a model-based message specification methodology and the further movement towards a unified development process: HL7 Version 3. The focus was design for interoperability, which is also the driving aspect of architectural standards such as OMG's CORBA or the CEN EN 13606 Electronic Health Record Communication. The paper gives an overview about the HL7 standard set, comparing it with the principles of advanced information systems architecture.

Computer Communication Networks↗