PubMed Health⌕ Search

PubMed · 16752949

Instituting change.

Abstract

The source did not provide an abstract. Follow the original record for more information.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Hemai Parthasarathy. 2006-06-13. Instituting change.. https://doi.org/10.1371/journal.pbio.0040224

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related citations

Comprehensive management of the access to the electronic patient record: towards trans-institutional networks.

BACKGROUND: A system ensuring tight control access is used since 5 years at the University Geneva Hospitals (HUG) over a four campuses health care system with ambulatory care settings behaving like a small community care network. Access to identified clinical information is limited to care providers that have a therapeutic relationship with the patient and to those data needed for that relation. The same policy applies to administrative or scientific research accesses. This paper presents how the HUG met the challenging goal of protecting patient privacy within regulatory limits while keeping the system operational in terms of use and management. SOLUTION: The main characteristics of the system are: (a) an institution-wide policy for access rights to the computerized patient record; (b) an institutional management of the contracts of the collaborators; (c) access profiles based on application-independent, fine-grained access rights; (d) a decentralized attribution of profession-specific access profiles; (e) a complete, centralized log of all accesses to the clinical information system; and (f) a decentralized verification of the accesses. Many of these characteristics can be maintained when evolving towards a trans-institutional computerized patient record, but new constraints need to be taken into account.

Access to Information↗

Toward a national framework for the secondary use of health data: an American Medical Informatics Association White Paper.

Secondary use of health data applies personal health information (PHI) for uses outside of direct health care delivery. It includes such activities as analysis, research, quality and safety measurement, public health, payment, provider certification or accreditation, marketing, and other business applications, including strictly commercial activities. Secondary use of health data can enhance health care experiences for individuals, expand knowledge about disease and appropriate treatments, strengthen understanding about effectiveness and efficiency of health care systems, support public health and security goals, and aid businesses in meeting customers' needs. Yet, complex ethical, political, technical, and social issues surround the secondary use of health data. While not new, these issues play increasingly critical and complex roles given current public and private sector activities not only expanding health data volume, but also improving access to data. Lack of coherent policies and standard "good practices" for secondary use of health data impedes efforts to strengthen the U.S. health care system. The nation requires a framework for the secondary use of health data with a robust infrastructure of policies, standards, and best practices. Such a framework can guide and facilitate widespread collection, storage, aggregation, linkage, and transmission of health data. The framework will provide appropriate protections for legitimate secondary use.

Access to Information↗

Information governance in NHS's NPfIT: a case for policy specification.

PURPOSE: The National Health Service's (NHS's) National Programme for Information Technology (NPfIT) in the UK with its proposed nation-wide online health record service poses serious technical challenges, especially with regard to access control and patient confidentiality. The complexity of the confidentiality requirements and their constantly evolving nature (due to changes in law, guidelines and ethical consensus) make traditional technologies such as role-based access control (RBAC) unsuitable. Furthermore, a more formal approach is also needed for debating about and communicating on information governance, as natural-language descriptions of security policies are inherently ambiguous and incomplete. Our main goal is to convince the reader of the strong benefits of employing formal policy specification in nation-wide electronic health record (EHR) projects. APPROACH: Many difficulties could be alleviated by specifying the requirements in a formal authorisation policy language such as Cassandra. The language is unambiguous, declarative and machine-enforceable, and is based on distributed constrained Datalog. Cassandra is interpreted within a distributed Trust Management environment, where digital credentials are used for establishing mutual trust between strangers. RESULTS: To demonstrate how policy specification can be applied to NPfIT, we translate a fragment of natural-language NHS specification into formal Cassandra rules. In particular, we present policy rules pertaining to the management of Clinician Sealed Envelopes, the mechanism by which clinical patient data can be concealed in the nation-wide EHR service. Our case study exposes ambiguities and incompletenesses in the informal NHS documents. CONCLUSIONS: We strongly recommend the use of trust management and policy specification technology for the implementation of nation-wide EHR infrastructures. Formal policies can be used for automatically enforcing confidentiality requirements, but also for specification and communication purposes. Formalising the requirements also reveals ambiguities and missing details in the currently used informal specification documents.

Access to Information↗