PubMed Health⌕ Search

SEARCH · PubMed Health

Results for “secured computing”

Explore indexed PubMed citations for clinical trials, systematic reviews and public health research. Read source abstracts and follow each citation to its original PubMed record.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 1,225 records · Page 68Linked to original sources

secureBLAST.

secureBLAST supplements NCBI wwwblast with features necessary to control in an easy manageable way usage of BLAST data sets and their update. The concept we implemented allows to offer on a single BLAST server several data sets with individually configurable access rights. Security is provided by user authentication and encryption of the http traffic via SSL. By using secureBLAST, the administration of users and databases can be done via a web interface. Therefore, secureBLAST is valuable for institutions that have to restrict access to their datasets or just want to administer BLAST servers via a web interface.

Computer Security↗

Metadata-driven ad hoc query of patient data: meeting the needs of clinical studies.

Clinical study data management systems (CSDMSs) have many similarities to clinical patient record systems (CPRSs) in their focus on recording clinical parameters. Requirements for ad hoc query interfaces for both systems would therefore appear to be highly similar. However, a clinical study is concerned primarily with collective responses of groups of subjects to standardized therapeutic interventions for the same underlying clinical condition. The parameters that are recorded in CSDMSs tend to be more diverse than those required for patient management in non-research settings, because of the greater emphasis on questionnaires for which responses to each question are recorded separately. The differences between CSDMSs and CPRSs are reflected in the metadata that support the respective systems' operation, and need to be reflected in the query interfaces. The authors describe major revisions of their previously described CSDMS ad hoc query interface to meet CSDMS needs more fully, as well as its porting to a Web-based platform.

Computer Security↗

A framework for an institutional high level security policy for the processing of medical data and their transmission through the Internet.

BACKGROUND: The Internet provides many advantages when used for interaction and data sharing among health care providers, patients, and researchers. However, the advantages provided by the Internet come with a significantly greater element of risk to the confidentiality, integrity, and availability of information. It is therefore essential that Health Care Establishments processing and exchanging medical data use an appropriate security policy. OBJECTIVE: To develop a High Level Security Policy for the processing of medical data and their transmission through the Internet, which is a set of high-level statements intended to guide Health Care Establishment personnel who process and manage sensitive health care information. METHODS: We developed the policy based on a detailed study of the existing framework in the EU countries, USA, and Canada, and on consultations with users in the context of the Intranet Health Clinic project. More specifically, this paper has taken into account the major directives, technical reports, law, and recommendations that are related to the protection of individuals with regard to the processing of personal data, and the protection of privacy and medical data on the Internet. RESULTS: We present a High Level Security Policy for Health Care Establishments, which includes a set of 7 principles and 45 guidelines detailed in this paper. The proposed principles and guidelines have been made as generic and open to specific implementations as possible, to provide for maximum flexibility and adaptability to local environments. The High Level Security Policy establishes the basic security requirements that must be addressed to use the Internet to safely transmit patient and other sensitive health care information. CONCLUSIONS: The High Level Security Policy is primarily intended for large Health Care Establishments in Europe, USA, and Canada. It is clear however that the general framework presented here can only serve as reference material for developing an appropriate High Level Security Policy in a specific implementation environment. When implemented in specific environments, these principles and guidelines must also be complemented by measures, which are more specific. Even when a High Level Security Policy already exists in an institution, it is advisable that the management of the Health Care Establishment periodically revisits it to see whether it should be modified or augmented.

Access to Information↗

Privilege management and access control in Shared Care IS and EHR.

Realising the shared care concept based on distributed health information systems, we have to meet the challenge for advanced security and privacy based on a Public Key Infrastructure (PKI) Beside strong authentication, authorisation of principals and access control using role concepts and security object classification schemes are essential application security services. The paper presents the actual drafts of ISO and CEN standards dealing with privilege management and access control.

Access to Information↗

Security policy development for Healthcare Information Systems.

In this paper the issue of security policy development for health information systems is addressed. Security policy development involves the definition of the policy content, the analysis of the social, organisational, and technical contexts, as well as the organisation of the policy development process. We present the structure of security policies, analyse the characteristics of the HIS context, and analyse the different categories of methodologies, which can be used towards this end.

Computer Security↗

The Health Insurance Portability & Accountability Act and the practice of dentistry in the United States: system security.

This article reviews the issues related to the Health Insurance Portability & Accountability Act (HIPAA) security rule that apply to dental practice. The security rule specifically addresses individually identifiable health information that is transmitted or maintained in electronic media. System security must be applied to the entire technical infrastructure for the practice environment as well as to the work culture on a daily basis and must be thought of as an enterprise asset. Security refers to all of the policies, procedures, tools, and techniques used to assure that privacy and confidentiality are adequately addressed in a healthcare system. HIPAA requires all covered entities that transmit or maintain electronic health information perform, and document, a risk assessment for security and develop a security plan to address major areas of concern. A self-assessment tool is provided in this article.

Computer Security↗

Cryptographic mechanisms for health care IT-systems.

Present health care information and communication system sufficiently respect neither the interests of the professional users (physicians, nurses, etc.) nor those of the usees (patients) concerning informational self-determination, integrity, and non-repudiation. The EU-AIM-SEISMED project has attacked this challenge. There is consensus that legal regulations and organisational measures around health care IT-systems have to be revisited and harmonised. However, the increasing processing capacities of IT-systems demand that the legitimate security interests of users and usees are enforced in advance--not only after the fact. This cannot be achieved against -----stems but only by the help of IT-systems. Since cryptographic mechanisms are an essential tool to this end SEISMED provides guidelines and technical recommendations on cryptographic mechanisms.

Classification↗

Legal issues concerning electronic health information: privacy, quality, and liability.

Personally identifiable health information about individuals and general medical information is increasingly available in electronic form in health databases and through online networks. The proliferation of electronic data within the modern health information infrastructure presents significant benefits for medical providers and patients, including enhanced patient autonomy, improved clinical treatment, advances in health research and public health surveillance, and modern security techniques. However, it also presents new legal challenges in 3 interconnected areas: privacy of identifiable health information, reliability and quality of health data, and tortbased liability. Protecting health information privacy (by giving individuals control over health data without severely restricting warranted communal uses) directly improves the quality and reliability of health data (by encouraging individual uses of health services and communal uses of data), which diminishes tort-based liabilities (by reducing instances of medical malpractice or privacy invasions through improvements in the delivery of health care services resulting in part from better quality and reliability of clinical and research data). Following an analysis of the interconnectivity of these 3 areas and discussing existing and proposed health information privacy laws, recommendations for legal reform concerning health information privacy are presented. These include (1) recognizing identifiable health information as highly sensitive, (2) providing privacy safeguards based on fair information practices, (3) empowering patients with information and rights to consent to disclosure (4) limiting disclosures of health data absent consent, (5) incorporating industry-wide security protections, (6) establishing a national data protection authority, and (7) providing a national minimal level of privacy protections.

Computer Communication Networks↗

ASP archiving solution of regional HUSpacs.

The application service provider (ASP) model is not novel, but widely used in several non-health care-related business areas. In this article, ASP is described as a potential solution for long-term and back-up archiving of the picture archiving and communication system (PACS) of the Hospital District of Helsinki and Uusimaa (HUS). HUSpacs is a regional PACS for 21 HUS hospitals serving altogether 1.4 million citizens. The ultimate goal of this study was to define the specifications for the ASP archiving service and to compare different commercial options for archiving solutions (costs derived by unofficial requests for proposal): in-house PACS components, the regional ASP concept and the hospital-based ASP concept. In conclusion, the large scale of the HUS installation enables a cost-effective regional ASP archiving, resulting in a four to five times more economical solution than hospital-based ASP.

Computer Security↗

Security implementation issues in Japan.

A survey was conducted in the year 1994 among medical school hospitals in Japan to know whether there are some written rules or regulations about the use of medical information, and whether they are well matched both to secure patient's privacy and to promote the adequate use of the information. A questionnaire was mailed to 80 medical school hospitals in Japan and 65 of them responded. Besides copies of rules, questioners were also requested for detailed investigation. Twenty nine hospitals responded to our request. The security implementation issues in Japan will be discussed using data thus obtained.

Computer Security↗

A JAVA-based DICOM server with integration of clinical findings and DICOM-conform data encryption.

The transfer of large amounts of medical data within heterogeneous hard and software infrastructures and the exploitation of distributed resources require a fast, secure, and platform-independent data exchange. To avoid costly vendor-specific solutions, a DICOM server was implemented in JAVA. Data access was enabled via internet browser technology. Relevant patient and image acquisition information was extracted from the DICOM images and stored into a relational database. Patient information such as radiological findings were transferred from the Radiological Information System into the database. Image data were accessed either by a fast preview tool or using a JAVA-based DICOM viewer. Since data security mechanisms are not yet part of the DICOM standard, a DICOM-conform encryption of sensitive patient data was implemented. The method allowed a dynamic selection of the data to be encrypted. Integrating this module into the image server enabled the fast and secure transfer of image data across insecure networks as well as long-term storage on CD-Recordables.

CD-ROM↗

4.4 Electronic management systems.

The international development and deployment of an electronic modularized dental curriculum is central to the development of an electronic engine to be used for the effective management of dental education. This will ensure continuity in high quality of care across all boundaries, through the continuous updating of its content and linkages to contemporary resources and databases. An electronic engine to be used for the effective management of dental education in a comprehensive dental school/hospital setting is at the core of an international 'virtual' dental education institution. The issue of policy development necessary to ensure consistency, quality and management for an electronic engine is at the very centre of: a) systems management and system databases; b) records of students, patients and personnel; and c) financial records.

Computer Security↗

Design of a national retail data monitor for public health surveillance.

The National Retail Data Monitor receives data daily from 10,000 stores, including pharmacies, that sell health care products. These stores belong to national chains that process sales data centrally and utilize Universal Product Codes and scanners to collect sales information at the cash register. The high degree of retail sales data automation enables the monitor to collect information from thousands of store locations in near to real time for use in public health surveillance. The monitor provides user interfaces that display summary sales data on timelines and maps. Algorithms monitor the data automatically on a daily basis to detect unusual patterns of sales. The project provides the resulting data and analyses, free of charge, to health departments nationwide. Future plans include continued enrollment and support of health departments, developing methods to make the service financially self-supporting, and further refinement of the data collection system to reduce the time latency of data receipt and analysis.

Algorithms↗