| Literature DB >> 22917868 |
Inmaculada Carrión Señor1, José Luis Fernández-Alemán, Ambrosio Toval.
Abstract
BACKGROUND: Several obstacles prevent the adoption and use of personal health record (PHR) systems, including users' concerns regarding the privacy and security of their personal health information.Entities:
Mesh:
Year: 2012 PMID: 22917868 PMCID: PMC3510685 DOI: 10.2196/jmir.1904
Source DB: PubMed Journal: J Med Internet Res ISSN: 1438-8871 Impact factor: 5.428
Description of the assessed personal health record (PHR) system characteristics.
| Category | Description | |
|
| ||
| Privacy policy location | Considers whether user can easily access the privacy policy | |
| Management and notification of privacy policy changes | Describes whether users are notified of changes in the privacy policy, and the means for doing so | |
| Access management | Focuses on who shares the information, with whom it is shared, and types of permissions | |
|
| ||
| Data management | Considers who manages the information, what information is managed, and where this information comes from | |
| Data accessed without user’s permission | Describes what data are shared without the user’s explicit consent for secondary use of the data (eg, for marketing, policy) | |
| Access audit | Informs whether the user can trace with whom his or her information has been shared | |
| Access criteria | Establishes whether the user is authorized to access the particular resource and what actions she or he is permitted to take with respect to that resource in accordance with certain access criteria | |
| Authentication | Describes the method used to prevent identity theft | |
| Without cookies | Indicates whether the system uses cookies | |
| Safeguards | Presents what security measures are deployed by the PHR system | |
|
| ||
| Standards or regulations | Describes whether the PHR system meets any standards or regulations | |
Figure 1Preferred Reporting Items for Systematic Reviews and Meta-analyses (PRISMA) flow diagram. IC1–3 = inclusion criteria 1 to 3, PHR = Personal Health Record.
Evaluation of personal health record (PHR) system characteristics and proportion of PHR systems (n = 24) satisfying each characteristic.
| Characteristic | Depends on | n | % | |
|
| ||||
| Accessible | 23 | 96 | ||
|
| ||||
| Change notification | Accessible | 14 | 61 | |
| Change notification on website | Change notification | 12 | 86 | |
| Change notification directly | Change notification | 3 | 21 | |
|
| ||||
| User grants access | 17 | 71 | ||
| User grants access to health care professionals | User grants access | 10 | 59 | |
| User grants access to people with other roles | User grants access | 3 | 18 | |
| Kinds of permissions | 5 | 21 | ||
| Access in case of emergency | User grants access | 6 | 35 | |
|
| ||||
| User adds, modifies, removes, and updates information | 20 | 83 | ||
| Health care professionals update or add information | 5 | 21 | ||
| Family members’ data | User adds, modifies, removes and updates information | 3 | 15 | |
| Connection with other PHRs | User adds, modifies, removes and updates information | 4 | 20 | |
| Monitoring devices | 2 | 8 | ||
|
| ||||
| Not accessed or information related to the user’s accesses | 6 | 25 | ||
|
| ||||
| Who has accessed it | 9 | 38 | ||
| With what aim | Who has accessed it | 2 | 22 | |
|
| ||||
| Roles | 13 | 54 | ||
| Groups | 0 | 0 | ||
| Location | 1 | 4 | ||
| Time | 2 | 8 | ||
| Transaction type | 0 | 0 | ||
|
| ||||
| Yes | 9 | 38 | ||
|
| ||||
| Something known | 23 | 96 | ||
| Something the user has | 1 | 4 | ||
| Biometric factors | 0 | 0 | ||
|
| ||||
| Physical security measures | 15 | 63 | ||
| Limited access | 5 | 21 | ||
| Electronic security measures | 16 | 67 | ||
| Encrypted data | 12 | 50 | ||
| Backup system | 4 | 17 | ||
| Defined data security plan | 1 | 4 | ||
| Staff training | 1 | 4 | ||
| Privacy seal | 4 | 17 | ||
|
| ||||
| HIPAAa considered | 10 | 42 | ||
| HIPAA | HIPAA considered | 6 | 60 | |
| HONcodeb | 7 | 29 | ||
a Health Insurance Portability and Accountability Act.
b Health on the Net Foundation Code of Conduct.
The personal health record (PHR) systems and their assigned scoresa.
| PHR and reference | Security score | Privacy score | Total score |
| Microsoft HealthVault [ | 14 | 7 | 23 |
| Google Health [ | 10 | 7 | 18 |
| NoMoreClipBoard [ | 8 | 6 | 16 |
| HealthyCircles [ | 11 | 4 | 15 |
| myHealthFolders [ | 10 | 5 | 15 |
| RememberItNow! [ | 7 | 8 | 15 |
| MiVIA [ | 8 | 4 | 14 |
| Telemedical [ | 8 | 4 | 13 |
| MedicAlert [ | 7 | 5 | 12 |
| Juniper Health [ | 8 | 4 | 12 |
| MediCompass [ | 6 | 3 | 12 |
| myMediConnect [ | 8 | 3 | 12 |
| Health Butler [ | 7 | 3 | 11 |
| ZebraHealth [ | 8 | 1 | 11 |
| My Doclopedia PHR [ | 5 | 5 | 11 |
| Dr. I-Net [ | 7 | 3 | 11 |
| Keas [ | 5 | 4 | 9 |
| MedsFile.com [ | 6 | 3 | 9 |
| PatientsLikeMe [ | 2 | 6 | 9 |
| My HealtheVet [ | 6 | 1 | 9 |
| dLife [ | 3 | 3 | 7 |
| MyChart [ | 4 | 1 | 7 |
| EMRy Stick [ | 5 | 2 | 7 |
| iHealthRecord [ | 4 | 1 | 5 |
a Maximum possible scores: 14 (security score), 8 (privacy score), 24 (total score).
Kappa coefficients for level of agreement in cross-checks of privacy policy assessment.
| Personal health record system | Kappa coefficient | Agreement level |
| Dr. I-Net | 0.42 | Low |
| EMRy Stick | 0.77 | High |
| HealthButler | 0.79 | High |
| HealthyCircles | 0.82 | Almost perfect |
| Juniper Health | 0.77 | High |
| Microsoft HealthVault | 1 | Perfect |
| My DoclopediaPHR | 0.9 | Almost perfect |
| myHealthFolders | 0.81 | Almost perfect |
| myMediConnect | 0.55 | Medium |
| NoMoreClipBoard | 0.62 | High |
| RememberItNow! | 0.71 | High |
| Telemedical | 0.38 | Low |