DocumentCode
1897087
Title
Towards a practical healthcare information security model for healthcare institutions
Author
Dwivedi, Ashish ; Bali, Rajeev K. ; Belsis, Meletis A. ; Naguib, Raouf N G ; Every, Peter ; Nassar, Nahy S.
fYear
2003
fDate
24-26 April 2003
Firstpage
114
Lastpage
117
Abstract
In recent years, a number of countries have introduced plans for national electronic patient record (EPR) systems. This paper argues that, in the near future, both patients and healthcare stakeholders will be able to access medical records from WWW-based EPR systems. We contend that the primary impediment to the successful implementation and widespread uptake of the EPR concept is the fact that current healthcare information security (HIS) applications are not sufficiently robust. This paper identifies two main Information Security technologies: 1) Public key infrastructure (PKI) and 2) Biometrics that hold a lot of promise in a healthcare context. The key contribution of this paper is to propose a novel multi-layered HIS framework based on a combination of PKI, Smartcard and Biometrics technologies. We argue that this new HIS framework could assist healthcare institutions to provide a truly secure infrastructure for the electronic transmission of clinical data in the future. This paper also makes a case for the creation of a new nodal HIS body because existing information security bodies like the Forum of Incident Response and Security Teams are for general-purpose organizations and not specifically suited for the healthcare sector.
Keywords
Internet; biometrics (access control); data privacy; medical information systems; patient care; public key cryptography; telemedicine; WWW-based electronic patient record systems; biometrics; clinical data; electronic patient record concept; electronic transmission; general-purpose organizations; healthcare information security apptications; healthcare institutions; healthcare stakeholders; information security bodies; information security technologies; multi-layered healthcare information security framework; national electronic patient record systems; practical healthcare information security model; public key infrastructure; successful implementation; truly secure infrastructure; widespread uptake; Biometrics; Electronic medical prescriptions; Impedance; Information security; Knowledge engineering; Mathematical model; Medical services; Paramagnetic resonance; Public key; Robustness;
fLanguage
English
Publisher
ieee
Conference_Titel
Information Technology Applications in Biomedicine, 2003. 4th International IEEE EMBS Special Topic Conference on
Print_ISBN
0-7803-7667-6
Type
conf
DOI
10.1109/ITAB.2003.1222486
Filename
1222486
Link To Document