在紧急情况下对患者控制的个人健康记录的隐私意识访问

M. N. Huda, S. Yamada, N. Sonehara
{"title":"在紧急情况下对患者控制的个人健康记录的隐私意识访问","authors":"M. N. Huda, S. Yamada, N. Sonehara","doi":"10.4108/ICST.PERVASIVEHEALTH2009.6008","DOIUrl":null,"url":null,"abstract":"Patient-controlled Personal Health Record (PHR) systems may facilitate a patient not only to share her health records with healthcare professionals but also to control her health privacy, in a convenient and easy way. Governed by privacy protection laws, explicit consent/permission of the respective patient is a prerequisite for sharing personal health records. However, in emergency situations, when the patient becomes unable to give consent on her PHRs, healthcare professionals of emergency care units may need to access her health history for better and safer care. In this paper, we have introduced a novel privacy-aware protocol for handling access to patient-controlled PHR by healthcare professionals in emergency situations. The protocol is for the Privacy-aware Patient-controlled Personal Health Record (P3HR) system. It uses strong authentication using health IC cards, authorizes healthcare professionals and embeds emergency access report into the patients health IC card by which we achieve non-repudiation. Use of a dynamic access token in the authorization process protects replay attack. Intuitive privacy analysis shows that the proposed solution can preserve patients privacy from unauthorized parties while granting traceable access to personal health records by authorized healthcare professionals in emergency situations.","PeriodicalId":199517,"journal":{"name":"2009 3rd International Conference on Pervasive Computing Technologies for Healthcare","volume":"os-21 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2009-04-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"20","resultStr":"{\"title\":\"Privacy-aware access to Patient-controlled Personal Health Records in emergency situations\",\"authors\":\"M. N. Huda, S. Yamada, N. Sonehara\",\"doi\":\"10.4108/ICST.PERVASIVEHEALTH2009.6008\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Patient-controlled Personal Health Record (PHR) systems may facilitate a patient not only to share her health records with healthcare professionals but also to control her health privacy, in a convenient and easy way. Governed by privacy protection laws, explicit consent/permission of the respective patient is a prerequisite for sharing personal health records. However, in emergency situations, when the patient becomes unable to give consent on her PHRs, healthcare professionals of emergency care units may need to access her health history for better and safer care. In this paper, we have introduced a novel privacy-aware protocol for handling access to patient-controlled PHR by healthcare professionals in emergency situations. The protocol is for the Privacy-aware Patient-controlled Personal Health Record (P3HR) system. It uses strong authentication using health IC cards, authorizes healthcare professionals and embeds emergency access report into the patients health IC card by which we achieve non-repudiation. Use of a dynamic access token in the authorization process protects replay attack. Intuitive privacy analysis shows that the proposed solution can preserve patients privacy from unauthorized parties while granting traceable access to personal health records by authorized healthcare professionals in emergency situations.\",\"PeriodicalId\":199517,\"journal\":{\"name\":\"2009 3rd International Conference on Pervasive Computing Technologies for Healthcare\",\"volume\":\"os-21 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2009-04-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"20\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2009 3rd International Conference on Pervasive Computing Technologies for Healthcare\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.4108/ICST.PERVASIVEHEALTH2009.6008\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2009 3rd International Conference on Pervasive Computing Technologies for Healthcare","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.4108/ICST.PERVASIVEHEALTH2009.6008","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 20

摘要

患者控制的个人健康记录(PHR)系统不仅可以方便患者与医疗保健专业人员共享其健康记录,还可以以方便和简单的方式控制其健康隐私。根据隐私保护法的规定,患者的明确同意/许可是共享个人健康记录的先决条件。然而,在紧急情况下,当患者无法就其PHRs表示同意时,急诊单位的医疗保健专业人员可能需要查看其健康史,以获得更好和更安全的护理。在本文中,我们介绍了一种新的隐私意识协议,用于处理紧急情况下医疗保健专业人员对患者控制的PHR的访问。该协议适用于具有隐私意识的患者控制的个人健康记录(P3HR)系统。它使用健康IC卡进行强认证,授权医疗保健专业人员,并在患者健康IC卡中嵌入紧急访问报告,实现不可抵赖性。在授权过程中使用动态访问令牌可以保护重放攻击。直观的隐私分析表明,所提议的解决方案可以保护患者的隐私不受未经授权的各方侵犯,同时允许授权的医疗保健专业人员在紧急情况下可追踪地访问个人健康记录。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Privacy-aware access to Patient-controlled Personal Health Records in emergency situations
Patient-controlled Personal Health Record (PHR) systems may facilitate a patient not only to share her health records with healthcare professionals but also to control her health privacy, in a convenient and easy way. Governed by privacy protection laws, explicit consent/permission of the respective patient is a prerequisite for sharing personal health records. However, in emergency situations, when the patient becomes unable to give consent on her PHRs, healthcare professionals of emergency care units may need to access her health history for better and safer care. In this paper, we have introduced a novel privacy-aware protocol for handling access to patient-controlled PHR by healthcare professionals in emergency situations. The protocol is for the Privacy-aware Patient-controlled Personal Health Record (P3HR) system. It uses strong authentication using health IC cards, authorizes healthcare professionals and embeds emergency access report into the patients health IC card by which we achieve non-repudiation. Use of a dynamic access token in the authorization process protects replay attack. Intuitive privacy analysis shows that the proposed solution can preserve patients privacy from unauthorized parties while granting traceable access to personal health records by authorized healthcare professionals in emergency situations.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Semantic coordination of Ambient Intelligent medical devices - A case study A context-aware component for identifying risks associated to elders' activities of daily living An integrated multi-sensing framework for pervasive healthcare monitoring Technologies to monitor cognitive decline a preliminary case study Keeping everyone happy: Multiple stakeholder requirements for home care technology
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1