Security of the distributed electronic patient record: a case-based approach to identifying policy issues

Security of the distributed electronic patient record: a case-based approach to identifying policy issues
复制标题

分布式电子病历的安全性:基于案例的方法来识别政策问题

DOI:
10.1016/s1386-5056(00)00110-6
复制
发表时间:
2000
期刊:
Int. J. Medical Informatics
影响因子:
--
通讯作者:
James G. Anderson
James G. Anderson
中科院分区:
--
文献类型:
--
作者:
James G. Anderson

文献摘要

被引文献

相似文献

管理式医疗和综合交付系统的发展创造了一种新的商品、健康信息及其所需的技术。德勤和 Touche 的调查表明,美国一半以上的医院正在实施电子病历 (EPR) 系统。国家研究委员会已确定,业界在信息技术 (IT) 上的支出高达 150 亿美元,这一数字每年以 20% 的速度增长。收集、电子存储和使用信息的重要性是无可争议的。消费者需要这些信息才能做出明智的选择;由医生提供适当的优质临床护理;并通过健康计划来评估结果、控制成本和监控质量。然而,大量患者个人数据的收集、存储和通信存在一个重大困境。如何在提供新的医疗服务形式所需的数据的同时保护患者的个人隐私?最近有关医疗隐私立法、软件监管和远程医疗的争论表明,这一困境不会轻易解决。这个问题是系统性的,是由于整个健康行业的信息的常规使用和流动而产生的。医疗保健信息主要在授权用户之间传输。这些信息不仅用于患者护理和财务报销,这些信息的二次用户还包括医疗、护理和相关健康教育、研究、社会服务、公共卫生、监管、诉讼和商业目的,例如新医疗技术的开发和营销。对隐私和保密性的主要威胁来自提供患者护理的机构以及出于次要目的而访问患者数据的机构内部。
The growth of managed care and integrated delivery systems has created a new commodity, health information and the technology that it requires. Surveys by Deloitte and Touche indicate that over half of the hospitals in the US are in the process of implementing electronic patient record (EPR) systems. The National Research Council has established that industry spends as much as $15 billion on information technology (IT), an amount that is expanding by 20% per year. The importance of collecting, electronically storing, and using the information is undisputed. This information is needed by consumers to make informed choices; by physicians to provide appropriate quality clinical care; and by health plans to assess outcomes, control costs and monitor quality. The collection, storage and communication of a large variety of personal patient data, however, present a major dilemma. How can we provide the data required by the new forms of health care delivery and at the same time protect the personal privacy of patients? Recent debates concerning medical privacy legislation, software regulation, and telemedicine suggest that this dilemma will not be easily resolved. The problem is systemic and arises out of the routine use and flow of information throughout the health industry. Health care information is primarily transferred among authorized users. Not only is the information used for patient care and financial reimbursement, secondary users of the information include medical, nursing, and allied health education, research, social services, public health, regulation, litigation, and commercial purposes such as the development of new medical technology and marketing. The main threats to privacy and confidentiality arise from within the institutions that provide patient care as well as institutions that have access to patient data for secondary purposes.