Securing interoperability between chip card based medical information systems and health networks

Blobel, Bernd and Pharow, Peter and Spiegel, Volker and Engel, Kjeld and Engelbrecht, Rolf (2001) Securing interoperability between chip card based medical information systems and health networks. International Journal of Medical Informatics 64 (2-3), pp. 401-415.

Full text not available from this repository.

Abstract

Health information systems supporting shared care are going to be distributed and interoperable. Dealing with sensitive personal medical information, such information systems have to provide appropriate security services, allowing only authorised users restricted access rights to the patients’ data according to the ‘need to know’ principle. Especially in healthcare, chip card based information systems occur in the shape of patient data cards providing informational self determination and mobility of the users as well as quality, integrity, accountability, and availability of the data stored on the card, thus improving the shared care of patients. The DIABCARD1 project aims at the implementation and evaluation of a chip card based medical information system (CCMIS) for facilitating communication and co-operation between health professionals in different organisations or departments caring the same patient with diabetes as an example. In co-operation with the EC-funded TrustHealth2 project, communication and application security services needed are provided like strong authentication as well as the derived services such as authorisation, access control, accountability, confidentiality, etc. The solution is based on Health Professional Cards and Trusted Third Party services. In addition to the secure handling of the patient's chip card and data in DIABCARD workstations, the secure communication between these workstations and related departmental systems has been implemented. Based on the results of this feasibility study, an enhanced security services specification for the DIABCARD example of a CCMIS is provided which will be implemented in the framework of a health network being established in the German federal state Bavaria. Beside the preferred solution of a combination of Patient Identification Card and Patient Data Card, lower level alternatives using card-verifiable certificates are explained in some details. Finally, a few legal issues, future trends like the XML standard set and their implications for the solution presented as well as for distributed health information systems in general are shortly discussed.

Item Type:Article
Institutions: Medicine > Zentren des Universitätsklinikums Regensburg > eHealth Competence Center
Identification Number:
ValueType
10.1016/S1386-5056(01)00193-9DOI
Keywords:Health information systems; Smart cards; Security; DIABCARD
Subjects:600 Technology > 610 Medical sciences Medicine
Status:Published
Refereed:Yes, this version has been refereed
Created at the University of Regensburg:Unknown
Owner:Petra Gürster
Deposited On:14 Oct 2008 15:41
Last Modified:05 Aug 2009 15:46
Item ID:4180
Owner Only: item control page