Literature DB >> 18560089

Access and privacy rights using web security standards to increase patient empowerment.

Filipa Falcão-Reis1, Altamiro Costa-Pereira, Manuel E Correia.   

Abstract

Electronic Health Record (EHR) systems are becoming more and more sophisticated and include nowadays numerous applications, which are not only accessed by medical professionals, but also by accounting and administrative personnel. This could represent a problem concerning basic rights such as privacy and confidentiality. The principles, guidelines and recommendations compiled by the OECD protection of privacy and trans-border flow of personal data are described and considered within health information system development. Granting access to an EHR should be dependent upon the owner of the record; the patient: he must be entitled to define who is allowed to access his EHRs, besides the access control scheme each health organization may have implemented. In this way, it's not only up to health professionals to decide who have access to what, but the patient himself. Implementing such a policy is walking towards patient empowerment which society should encourage and governments should promote. The paper then introduces a technical solution based on web security standards. This would give patients the ability to monitor and control which entities have access to their personal EHRs, thus empowering them with the knowledge of how much of his medical history is known and by whom. It is necessary to create standard data access protocols, mechanisms and policies to protect the privacy rights and furthermore, to enable patients, to automatically track the movement (flow) of their personal data and information in the context of health information systems. This solution must be functional and, above all, user-friendly and the interface should take in consideration some heuristics of usability in order to provide the user with the best tools. The current official standards on confidentiality and privacy in health care, currently being developed within the EU, are explained, in order to achieve a consensual idea of the guidelines that all member states should follow to transfer such principles into national laws. A perspective is given on the state of the art concerning web security standards, which can be used to easily engineer health information systems complying with the patient empowering goals. In conclusion health systems with the characteristics thus described are technically feasible and should be generally implemented and deployed.

Entities:  

Mesh:

Year:  2008        PMID: 18560089

Source DB:  PubMed          Journal:  Stud Health Technol Inform        ISSN: 0926-9630


  2 in total

1.  Orchestrating differential data access for translational research: a pilot implementation.

Authors:  Marco Brandizi; Olga Melnichuk; Raffael Bild; Florian Kohlmayer; Benedicto Rodriguez-Castro; Helmut Spengler; Klaus A Kuhn; Wolfgang Kuchinke; Christian Ohmann; Timo Mustonen; Mikael Linden; Tommi Nyrönen; Ilkka Lappalainen; Alvis Brazma; Ugis Sarkans
Journal:  BMC Med Inform Decis Mak       Date:  2017-03-23       Impact factor: 2.796

2.  Modeling the adoption of personal health record (PHR) among individual: the effect of health-care technology self-efficacy and gender concern.

Authors:  Bireswar Dutta; Mei-Hui Peng; Shu-Lung Sun
Journal:  Libyan J Med       Date:  2018-12       Impact factor: 1.657

  2 in total

北京卡尤迪生物科技股份有限公司 © 2022-2023.