| Literature DB >> 30907730 |
Duarte Gonçalves-Ferreira1,2, Mariana Sousa1,2, Gustavo M Bacelar-Silva1, Samuel Frade1, Luís Filipe Antunes2, Thomas Beale3, Ricardo Cruz-Correia1.
Abstract
BACKGROUND: Concerns about privacy and personal data protection resulted in reforms of the existing legislation in the European Union (EU). The General Data Protection Regulation (GDPR) aims to reform the existing directive on the topic of personal data protection of EU citizens with a strong emphasis on more control of the citizens over their data and in the establishment of rules for the processing of personal data. OpenEHR is a standard that embodies many principles of interoperable and secure software for electronic health records (EHRs) and has been advocated as the best approach for the development of hospital information systems.Entities:
Keywords: GDPR; data protection; electronic health record; health information interoperability; openEHR
Year: 2019 PMID: 30907730 PMCID: PMC6452286 DOI: 10.2196/medinform.9845
Source DB: PubMed Journal: JMIR Med Inform
List of the 17 General Data Protection Regulation (GDPR) requirements that are met by openEHR principles.
| GDPR requirements | openEHR principles | |||||||
| 2-level modeling | Separation of EHR and demographic information | Service model | Version control—versioning | Version control—digital signature | Access control—access control list | Access control—configurations | Audit trailing | |
| Method storage limitation | —a | Xb | — | — | — | — | — | — |
| Integrity and confidentiality | — | — | — | X | X | X | X | X |
| Accountability | — | — | — | — | — | — | — | X |
| Record of processing | — | — | — | — | — | — | — | X |
| Availability of records of processing | — | — | — | — | — | — | — | X |
| Verification of the identity of the data subjects | — | X | — | — | — | — | — | — |
| Data subject access | — | — | — | — | — | X | X | — |
| Data subject direct access | — | — | X | — | — | X | X | — |
| Confirmation of data processing | — | — | — | X | — | — | — | X |
| Portability of personal data | X | — | — | — | — | — | — | — |
| Portability of personal data between controllers | X | — | — | — | — | — | — | — |
| Interoperability of systems and formats | X | — | X | — | — | — | — | — |
| Cross-border data transfers | X | — | — | — | — | — | — | — |
| Privacy by design | — | X | — | — | — | — | — | — |
| Privacy by default | — | X | — | — | X | X | X | — |
aRepresents no match.
bX represents a match in the table.