Managing the security of computerized records.
Explore the source record for details and available documents.
SEARCH · PubMed Health
Explore indexed PubMed citations for clinical trials, systematic reviews and public health research. Read source abstracts and follow each citation to its original PubMed record.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Explore the source record for details and available documents.
This paper reports on the results obtained by the pilot operation of Trusted Third Parties (TTP) for secure telemedical applications over the WWW. The work reported on herein was carried out within the context of EUROMED-ETS, a R&D project funded by the INFOSEC office of Directorate General XIII of the European Union. The paper discusses the platform used, the security needs of the specific application, the TTP solution provided, the steps taken in order to implement the solution at a pilot scale and the results of the pilot operation; it is compiled using material included in the project deliverables.
Handheld personal digital assistants (PDAs) have undergone continuous and substantial improvements in hardware and graphics capabilities, making them a compelling platform for novel developments in teleradiology. The latest PDAs have processor speeds of up to 400 MHz and storage capacities of up to 80 Gbytes with memory expansion methods. A Digital Imaging and Communications in Medicine (DICOM)-compliant, vendor-independent handheld image access system was developed in which a PDA server acts as the gateway between a picture archiving and communication system (PACS) and PDAs. The system is compatible with most currently available PDA models. It is capable of both wired and wireless transfer of images and includes custom PDA software and World Wide Web interfaces that implement a variety of basic image manipulation functions. Implementation of this system, which is currently undergoing debugging and beta testing, required optimization of the user interface to efficiently display images on smaller PDA screens. The PDA server manages user work lists and implements compression and security features to accelerate transfer speeds, protect patient information, and regulate access. Although some limitations remain, PDA-based teleradiology has the potential to increase the efficiency of the radiologic work flow, increasing productivity and improving communication with referring physicians and patients.
Securing health information is an application domain which can learn more from other environments like airlines and banking than from military formalism or academic freedom. The techniques of the 80s using clear separation between public and private areas have to be upgraded. Propositions are made. Costs are evaluated.
We describe the Security Plan for the 'MyAngelWeb' service. The different actors involved in the service are subject to different security procedures. The core of the security system is implemented at the host site by means of a DBMS and standard Information Technology tools. Hardware requirements for sustainable security are needed at the web-site construction sites. They are not needed at the emergency physician's site. At the emergency physician's site, a two-way authentication system (password and test phrase method) is implemented.
The TIHI (Trusted Interoperation of Healthcare Information) project addresses a security issue that arises when some information is being shared among collaborating enterprises, although not all enterprise information is sharable. It assumes that protection exists to prevent intrusion by adversaries through secure transmission and firewalls. The TIHI system design provides a gateway, owned by the enterprise security officer, to mediate queries and responses. The latter are typically transmitted via the Internet. The enterprise policy is determined by rules provided to the mediator. We show examples of typical rules. The problem and our solution, although developed in a healthcare context, is equally valid among collaborating enterprises.
MOTIVATION: Telemedical services for ophthalmology are developed within the OPHTEL project, which has been funded by the European Union and by the Bavarian government in the Bavaria-online initiative. METHODS: Seven private ophthalmologists, one university eye clinic, one clinical Diabetes center and an informatics research institute are connected within a teleconsultation network. Asynchronous (based on Internet E-Mail) and synchronous (based on ISDN-mediated videoconferencing tools) types of teleconsultations are realized. RESULTS: 86 teleconsultations (62 asynchronous, 23 synchronous) took place within the first 10 months. Complex and rare eye diseases as well as interdisciplinary questions (ophthalmology--diabetology) are the main area of medical communication interest. Legal and security problems are discussed. CONCLUSIONS: Telemedical services must be understood as a complete process of medical care on the basis of modern communication technologies, which influences also the management of this process.
We are developing the Patient Clinical Information System (PatCIS) project at Columbia-Presbyterian Medical Center to provide patients with access to health information, including their own medical records (permitting them to contribute selected aspects to the record), educational materials and automated decision support. The architecture of the system allows for multiple, independent components which make use of central services for managing security and usage logging functions. The design accommodates a variety of data entry, data display and decision support tools and provides facilities for tracking system usage and questionnaires. The user interface minimizes hypertext-related disorientation and cognitive overload; our success in this regard is the subject of on-going evaluation.
The rapid development of the Internet and the increasing interest in Internet-based solutions has promoted the idea of creating Internet-based health information applications. This will force a change in the role of IC cards in healthcare card systems from a data carrier to an access key medium. At the Medical Informatics Department of Kyoto University Hospital we are developing a smart card patient information project where patient databases are accessed via the Internet. Strong end-to-end data encryption is performed via Secure Socket Layers, transparent to transmit patient information. The smart card is playing the crucial role of access key to the database: user authentication is performed internally without ever revealing the actual key. For easy acceptance by healthcare professionals, the user interface is integrated as a plug-in for two familiar Web browsers, Netscape Navigator and MS Internet Explorer.
Within the working programme of CEN/TC251 (Health Informatics), a standard for Security Categorisation and Protection for Healthcare Information Systems has been developed. This document was formally adopted in 1997 by CEN as pre-standard CEN ENV 12924. A demonstration and implementation effort, which was to be effected in principle at one location, was planned and executed as part of the MEDSEC project. The standard CEN ENV 12924 contains a security categorisation model for information systems in Healthcare, distinguishing six categories, plus some refinements. For each category it specifies the required protection measures. The project task consisted of demonstrating and implementing the standard (as far as possible within a limited period) in a real life situation, and providing feedback on these results to the CEN organisation. To this end, the categorisation scheme, as specified in the standard, was applied to a large part of the information (sub)-systems in the Leiden University Medical Centre. A set of ten sub-systems was then selected for a more detailed investigation. The actual protection status for each sub-system was evaluated on the basis of the recommended protection profiles specified in the standard. For each of the relevant recommendations in the standard, its status was recorded, and remarks were added on its relevance, feasibility, etc. These detailed data have been gathered in separate reports for each sub-system. These reports evidently are confidential, in view of protection of the hospital's information security. A similar, though more limited exercise has been done at Magdeburg University Hospital (UHM), in order to be able to allow for possible differences in local situations. A thorough comparison of results for different hospitals was beyond the scope of the project, however. From the overall picture we have tried to draw conclusions on the quality, completeness and applicability of the standard, as well as on the actual level of protection of the systems. As a by-product of the investigation, for all systems out of the small group, implementation plans have been specified to bring the protection in the various (sub)-systems on a higher level, where necessary. Subsequently, these plans have been realised to a large extent. To facilitate the bookkeeping of the results, we have used the SIDERO model, resulting from the SEISMED project. This model has been enhanced, for this purpose, with the recommendations from this standard. A brief description of this database model has been included in Appendix B. As an overall conclusion, we may state that the standard has proven to be a very useful instrument, providing a good basis for a security review of the types of Healthcare information systems which are encountered in a hospital environment. Some suggestions have been presented, for amending recommendations that were found too unpractical or too heavy in the circumstances considered. Also, we suggest to add one category to the set of six which is being used now. Furthermore, the use of a 'bookkeeping tool' (like e.g. SIDERO) is strongly recommended.
For the connection of several partners to a Dicom-e-mail based teleradiology network concepts were developed to allow the integration of different teleradiology applications. The organisational and technical needs for such an integration were analysed. More than 60 institutions including 23 hospitals in the Rhein-Neckar-Region, Germany were connected. The needed functionality was grouped in six teleradiology applications (emergency consultation, tele-guided examinations, expert consultations, cooperative work, scientific cooperations and homework with on call services) and their technical and organisational needs according to availability, speed of transfer, workflow definitions and data security needs was analysed. For the local integration of teleradiology services the setup and workflow is presented for a standalone teleradiology workstation and a server based teleradiology gateway. The line type needed for different groups of applications and users is defined. The security concept and fallback strategies are laid out, potential security problems and sources of errors are discussed. The specialties for the emergency teleradiology application are presented. The DICOM-e-mail protocol is a flexible and powerful protocol that can be used for a variety of teleradiology applications. It can meet the conditions for emergency applications but is limited if synchronous applications like teleconferences are needed.
IT support for home health care is an expanding area within health care IT development. Home health care differs from other in- or outpatient care delivery forms in a number of ways, and thus, the introduction of home health care applications must be based on a rigorous analysis of necessary requirements to secure safe and reliable health care. This article reports early experiences from the development of a home health care application based on emerging JAVA technologies. A prototype application for the follow-up of diabetes patients is presented and discussed in relation to a list of general requirements on home health care applications.
Internal and world-wide communication, access to medical databases, and information services are essential demands in the science of medicine not only for research, but also for improving patient care. A network connection between the medical network of the Erlangen University Hospital and other international networks was examined as a concept within the scope of a Erlangen Hospital Communication System (EKKS) project and tested with an actual installation.
This paper presents mu grid, a light weight middleware for grid applications, and focuses mainly on security issues--more specifically on the access control to resources--that are critical for the gridification of many medical applications. For this purpose, we use Sygn as a distributed, certificate based, and flexible access control mechanism, which has been fully integrated in mu grid. We discuss the advantages of the solution compared to classical grid approaches and the limitations of the final architecture.
This application report describes the technologies and strategies used by MedStage, an open infrastructure for secure telemedical internet applications. The infrastructure includes several technical and application frameworks including a public key infrastructure for providing professional security solutions, like certificate-based authentication, secure transport protocol, strong data encryption and digital signature. The key components are an universal healthcare data repository based on the work of CEN TC 251 with extensions for the storage of multimedia data, an exchangeable authorization management, an exchangeable patient index service based on CORBAmed PIDS and a set of XML-based import and export modules. Additionally there are prototype applications for home-monitoring, telereporting and personal health passport.
This paper describes initial experience with the Web-based Patient Clinical Information System (PatCIS). The system was designed to serve as a framework for the integration of applications that help patients access their electronic medical record, add data to their record, review on-line health information, and apply their own clinical data (automatically) to guideline programs that offer health advice. The architecture supports security functions and records user activities, relieving application developers from concerns about safe information practices and the evaluation process. PatCIS is being used to study the social and cognitive impact of allowing patients to have access to their health records via the Web. To date, PatCIS has grown to include 15 clinical functions and 4 dynamic links to literature (called infobuttons). Eleven patients have been enrolled since April, 1999; five have been active users. Experience shows that the PatCIS architecture supports application integration while providing adequate security and evaluation functions. Initial caution with the patient enrollment process has limited recruitment and, consequently, usage. However, experience thus far suggests that PatCIS has good usability and utility. No adverse events, including undesirable impact on doctor-patient interactions, have been reported. There do not appear to be any technical impediments to scaling up the enrollment to continue to observe patient usage.
The Ministry of Health and Welfare of Japan announced 'Healthcare Information Strategy 21' in 1994. This report shows that the Healthcare Information System is the key to improving the quality and efficiency of healthcare. One of the elements for realizing the new Healthcare Information System is the Electronic Medical Record (EMR). Following the publication of this report, work began with the aim of discovering a way to recognize the EMR as formal documentation and four national projects of research and development have been started. The themes of these projects are: 'Interoperability of EMR', 'Standardization of EMR', 'Modeling of the Clinical Process' and 'Security for EMR'. The Japanese Association of the Healthcare Information Systems Industry (JAHIS) is in charge of 'Security for EMR'. There are many discussions in relation to the security for EMR. However, many of these discussions relate to information technology, while there are few discussions regarding definitions of security. Therefore, there are many different theories about security itself, which will be an obstacle to standardization. To design the security system for EMR, JAHIS has defined 'Security for EMR' as the first step. The present study was conducted with medical informatics and security specialists. It has designed 'Requirement Definitions', 'Goals of Security', 'Estimation of threats to security', 'Necessity conditions' and a 'Security Model'. This paper covers these definitions and our security design concept.
The authors describe the development of a real-time tracking, notification, and Web-based enrollment system designed specifically to facilitate emergency department research. The system was developed in a cooperative arrangement between an emergency medicine researcher and a medical information software company. The system design and utilization are described as well as the security measures to ensure compliance with Health Insurance Portability and Accountability Act (HIPAA) regulations and database security.