PubMed Health⌕ Search

Biomedical subjects

Pekka Ruotsalainen

Publications and source records attributed to Pekka Ruotsalainen.

8 recordsLinked to original sources

A notary archive model for secure preservation and distribution of electrically signed patient documents.

The healthcare industry is moving from paper-based documentation into the digital era. Electronic health records (EHR) are playing a major role in this development. Electronic health records will not only to be shared among a growing number of healthcare providers but they have also to be archived over long periods of time. The required life cycle depends of national regulations, but typically the preservation time of patient data varies between 20 and 100 years. Availability, integrity, confidentiality and non-repudiation of stored data over these lengthy preservation periods needs to be fully proven, both to preclude loss and also ensure the ability to read and understand content is maintained. This document describes a co-operative trusted notary archive (TNA) which receives granular health data from different EHR-systems, stores data together with associated meta-information for long periods and distributes granular EHR-data objects. TNA communicates with EHR-systems and external users via archive request and distribution messages. TNA can store objects in XML-format and prove the non-repudiation and integrity of stored data with the help of event records, Time-stamps and archive e-signatures.

Access to Information↗

Sharable EHR systems in Finland.

In Finland, the shared record is a virtual electronic health record (EHR). It consists of health data generated, maintained and preserved by different health care service providers. Two different kinds of technologies for integrating regional EHR-systems are applied, but mainly by using a common middleware. Services provided by this middleware are EHR location services using a link repository and combining EHR-viewing services with security management services including consent management and identification services for health professionals. The Regional Health Information Organization (UUMA) approach is based on a stepwise implementation of integrated regional healthcare services to create a virtually borderless healthcare organization--a patient centered virtual workspace. In the virtual workspace multi-professional teams and patients collaborate and share information regardless of time and place. Presently the regional health information network (RHIN) is comprised of three integrated services between primary, secondary and tertiary care within the county of Uusimaa. The regional healthcare modules consist of an (1) eReferral network, (2) integrated EHR service between health care professionals and (3) PACS system. The eReferral between primary and secondary care not only speeds up the transfer, but also offers an option for communication in the form of eConsultation between general practitioners and hospital specialists. By sharing information and knowledge remote eConsultations create a new working environment for integrated delivery of eServices between the health care providers. Over 100,000 eReferral messages (40 %) were transferred between health care providers. Interactive eConsultations enable supervised care leading to the reduction of outpatient visits and more timely appointments. One third (10/31) of the municipal health centers are connected to the clinics in the Helsinki University Central Hospital by the eReferral system. The link directory service extends the dimensions of networking between organizations by combining legacy systems within regional primary and secondary care. The link directory is an interface to diverse patient information systems, like HUSpacs, containing links pointing to the actual patient data located in remote information systems. The original data including images can be viewed with a web browser, but data can be accessed only with the patient's informed consent. Currently the reference data base includes 9.5 million links from 1.4 million patients with over 2.000 daily users. We aim to create a new working environment for professionals by incorporation of innovative information and communication technology, new organization of work and re-engineering of workflows. In the near-future, the citizen will have an active role participating in decisions on his care, carrying out guided self-care and taking steps of pro-active prevention.

Computer Communication Networks↗

eHealth in Europe: towards higher goals.

Significant events are unfolding in the field of eHealth in Europe. eHealth has been a strategic priority of the European Commission in both the eEurope 2002 and 2005 Action Plans. But how are developments on the national level progressing? The authors contrast the status-quo of eHealth in the EU-15 with the latest trends and key action priorities in the EU-25 after the Union's latest enlargement in May 2004. The initiatives and actions of the European Commission are presented vis-à-vis those of national Member States, particularly in terms of strategic priorities and implementation actions. The review is accompanied by an analysis of expert feedback on eHealth drivers and barriers.

Computer Security↗

Implementing interoperable secure health information systems.

Ensuring the privacy and confidentiality of individuals has made security an indispensable component of health information systems. Delivery of healthcare services beyond the enterprise level to the regional, national or cross-border area places new challenges for security implementation. We review the current status and uptake of security measures in healthcare settings across European countries and examine in more detail some of the leading eHealth applications. Drawing on the findings of this analysis, we propose a generic model for streamlining the security implementation process on any level -local, regional, national or cross-border. Finally, we address the future prospects and requirements for advancing secure delivery of healthcare services across European borders.

Computer Security↗

A cross-platform model for secure Electronic Health Record communication.

During the past decade, there have been many regional, national and European projects focused on the development of platforms for secure access and sharing of distributed patient information. A platform is needed because present local or enterprise-wide information systems are typically not intended for cross-organisational secure access of patient data. Most of the present secure platforms are local or regional. Commonly used platform types in the health care environment vary from secure point-to-point communication systems to internet-based portals. This paper defines an enhanced cross-security platform which makes it possible for different kinds of local, regional, and national health information systems to communicate in a secure way. The proposed evolutionary way interconnects regional or national security domains with the help of a cross-platform zone. A more revolutionary model based on peer-to-peer Grid like networks and dynamic security credentials is also discussed. The proposed evolutionary model uses cross-domain security and interoperability services to ensure secure communication and interoperability between different security domains. The platform supports both communication defined beforehand and adhoc dynamic access to distributed electronic health records (EHRs). The internet is proposed as the "glue" between different regional or national security domains.

Access to Information↗

Security requirements in EHR systems and archives.

EHR system is a system for recording, retrieving, and manipulating information in electronic health care records. Archive is an organisation that intends to preserve health records for access and use for an identified group of consumers. There exist many combinations of EHR-systems and archives. EHR-system can be a single on-line system with integrated archiving functions or archive and EHR-system are co-operative or federated systems. This paper describes both common security requirements for EHR-systems and archives and security requirement specific for archives. Requirements are derived from ethical and legal principles. From principles a set of security requirements are derived. Safeguards for implementing security are discussed. In practise EHR-system and archive share many security services. This document is proposing that inside a security domain both the archive and EHR-system have a common security policy. In addition to this the archiving organisation needs a documented policy for information preserving and a policy for access and distribution of information between other archives.

Access to Information↗

European security framework for healthcare.

eHealth and telemedicine services are promising business areas in Europe. It is clear that eHealth products and services will be sold and ordered from a distance and over national borderlines in the future. However, there are many barriers to overcome. For both national and pan-European eHealth and telemedicine applications a common security framework is needed. These frameworks set security requirements needed for cross-border eHealth services. The next step is to build a security infrastructure which is independent of technical platforms. Most of the European eHealth platforms are regional or territorial. Some countries are looking for a Public Key Infrastructure, but no large scale solutions do exist in healthcare. There is no clear candidate solution for European-wide interoperable eHealth platform. Gross-platform integration seems to be the most practical integration method at a European level in the short run. The use of Internet as a European integration platform is a promising solution in the long run.

Computer Security↗