Access and privacy rights using web security standards to increase patient empowerment
- PMID: 18560089
Access and privacy rights using web security standards to increase patient empowerment
Abstract
Electronic Health Record (EHR) systems are becoming more and more sophisticated and include nowadays numerous applications, which are not only accessed by medical professionals, but also by accounting and administrative personnel. This could represent a problem concerning basic rights such as privacy and confidentiality. The principles, guidelines and recommendations compiled by the OECD protection of privacy and trans-border flow of personal data are described and considered within health information system development. Granting access to an EHR should be dependent upon the owner of the record; the patient: he must be entitled to define who is allowed to access his EHRs, besides the access control scheme each health organization may have implemented. In this way, it's not only up to health professionals to decide who have access to what, but the patient himself. Implementing such a policy is walking towards patient empowerment which society should encourage and governments should promote. The paper then introduces a technical solution based on web security standards. This would give patients the ability to monitor and control which entities have access to their personal EHRs, thus empowering them with the knowledge of how much of his medical history is known and by whom. It is necessary to create standard data access protocols, mechanisms and policies to protect the privacy rights and furthermore, to enable patients, to automatically track the movement (flow) of their personal data and information in the context of health information systems. This solution must be functional and, above all, user-friendly and the interface should take in consideration some heuristics of usability in order to provide the user with the best tools. The current official standards on confidentiality and privacy in health care, currently being developed within the EU, are explained, in order to achieve a consensual idea of the guidelines that all member states should follow to transfer such principles into national laws. A perspective is given on the state of the art concerning web security standards, which can be used to easily engineer health information systems complying with the patient empowering goals. In conclusion health systems with the characteristics thus described are technically feasible and should be generally implemented and deployed.
Similar articles
-
Complying with the Health Insurance Portability and Accountability Act. Privacy standards.AAOHN J. 2001 Nov;49(11):501-7. AAOHN J. 2001. PMID: 11760704
-
Standards for confidentiality, privacy, access, and data security.Top Health Inf Manage. 1996 May;16(4):44-8. Top Health Inf Manage. 1996. PMID: 10157660
-
Functions of an electronic health record.Int J Comput Dent. 2002 Apr-Jul;5(2-3):125-32. Int J Comput Dent. 2002. PMID: 12680044 English, German.
-
American Academy of Pediatrics. Pediatric Practice Action Group and Task Force on Medical Informatics. Privacy protection and health information: patient rights and pediatrician responsibilities.Pediatrics. 1999 Oct;104(4 Pt 1):973-7. Pediatrics. 1999. PMID: 10506245 Review.
-
Securing electronic health records without impeding the flow of information.Int J Med Inform. 2007 May-Jun;76(5-6):471-9. doi: 10.1016/j.ijmedinf.2006.09.015. Epub 2007 Jan 3. Int J Med Inform. 2007. PMID: 17204451 Review.
Cited by
-
Orchestrating differential data access for translational research: a pilot implementation.BMC Med Inform Decis Mak. 2017 Mar 23;17(1):30. doi: 10.1186/s12911-017-0424-6. BMC Med Inform Decis Mak. 2017. PMID: 28330491 Free PMC article.
-
Modeling the adoption of personal health record (PHR) among individual: the effect of health-care technology self-efficacy and gender concern.Libyan J Med. 2018 Dec;13(1):1500349. doi: 10.1080/19932820.2018.1500349. Libyan J Med. 2018. PMID: 30037314 Free PMC article.
MeSH terms
LinkOut - more resources
Full Text Sources