Secure Exchange of Information in Electronic Health Records Alejandro Flores University of Wollongong
Total Page:16
File Type:pdf, Size:1020Kb
University of Wollongong Research Online University of Wollongong Thesis Collection University of Wollongong Thesis Collections 2010 Secure exchange of information in electronic health records Alejandro Flores University of Wollongong Recommended Citation Flores, Alejandro, Secure exchange of information in electronic health records, Doctor of Philosophy thesis, School of Information Systems & Technology, University of Wollongong, 2010. http://ro.uow.edu.au/theses/3308 Research Online is the open access institutional repository for the University of Wollongong. For further information contact Manager Repository Services: [email protected]. Secure Exchange of Information in Electronic Health Records A thesis submitted in partial fulfilment of the requirements for the awards of the degree Doctor of Philosophy from UNIVERSITY OF WOLLONGONG By Alejandro Flores School of Information Systems & Technology 2010 Dedicated to Paulina ii Declaration This is to certify that the work reported in this thesis was done by the author, unless specified otherwise, and that no part of it has been submitted in a thesis to any other university or similar institution. Alejandro Flores December, 2010 iii iv Abstract Information technology is expected to become an essential tool in providing reliable information for supporting the delivery of health care services. Nevertheless, incorporating such technologies to support the provision of healthcare raises concerns over the protection of patient‟s information. The technological, social and legal implications regarding the access and release of medical data have to be considered carefully during the implementation of interconnected health information systems. Secure and effective data exchange along with the protection of patient‟s confidentiality are two issues that electronic health records need to address to make them reliable and secure in a shared care environment. In this thesis, the author explores these issues by analysing several topics regarding electronic health records, communication, exchange of information and security. The result of this analysis provides an understanding of the framework required to support the exchange of EHRs in a shared care environment. The core of this contribution consists in the description of an approach which uses attribute-based encryption to protect the confidentiality of v patients‟ information during the exchange of electronic health records among healthcare providers. Attribute-based encryption allows the reinforcing of access policies and reduces the risk of unauthorized access to sensitive information. A prototype version of a communication interface based on the proposed solution has been implemented and tested to evaluate its viability. The prototype has shown that attribute-based encryption provides an answer to restrictions presented by traditional approaches and facilitate the reinforcing of existing security policies over the transmitted data. vi Acknowledgements My sincere gratitude goes to everyone that has supported me through this long process. To both my supervisors, Dr. Khin Than Win and Prof. Willy Susilo. I would like to thank you for their guidance, patience and support through these years. They never stop believing and supporting me in those difficult moments. I am honoured to have been their student. To the National Commission for Scientific research and technology (CONICYT), Government of Chile, I would like to give my thanks for providing me with a scholarship to support my permanence in the doctoral program at the University of Wollongong. To the University of Talca, Chile, I give my gratitude for your support. To my family and friends back in Chile and here in Australia, thank you for your understanding, friendship and support during this period. vii To Paulina, my beloved wife. Without your love and support I do not think I would be in the position I am at this moment. This has been a long walk that is finally coming to an end. Tomorrow we start our new path, but with you by my side I know that the wherever that path lead us, I am sure it will be filled with joy and hopes. Thank you for being there all the time. Alejandro Flores viii Publications Flores, A., & Win, K. (2007, August 20-24). Analyzing the Key Variables in the Adoption Process of HL7. Proceedings of the 12th World Congress on Health (Medical) Informatics (Medinfo 2007), Brisbane, Australia, pp 444- 448. Flores, A., Win, K. T., & Susilo, W. (2010). Secure exchange of Electronic Health Records. In I. Apostolakis, M. A. Chryssanthou & D. I. Varlamis (Eds.), Certification and Security in Health-Related Web Applications: Concepts and Solutions, IGI Global: Hershey PA. Flores, A., Win, K., & Susilo, W. (2010). Biometrics for Electronic Health Records. Journal of Medical Systems, Volume 34, Issue 5. Available online at http://dx.doi.org/10.1007/s10916-009-9313-6. Flores, A., Win, K., & Susilo, W. (2009, November 22-24). Securing Electronic Health Records: An Overview. Proceedings of the Asia Pacific Association for Medical Informatics (APAMI), Hiroshima, Japan, pp 17-24. ix Flores, A., Win, K., & Susilo, W. Functionalities of Free and Open Electronic Health Records System. The International Journal of Technology Assessment in Health, Volume 26, Issue 04. Available online at http://journals.cambridge.org/action/displayAbstract?fromPage=online&aid=7 917209. x Contents 1 INTRODUCTION ............................................................................................... 1 1.1 Background ....................................................................................................................... 4 1.2 Purpose and Significance of the Study ............................................................................... 7 1.3 Statement of the Problem ............................................................................................... 10 1.4 Research Question .......................................................................................................... 12 1.5 Research Approach ......................................................................................................... 13 1.6 Research Scope ............................................................................................................... 14 1.7 Organisation of the Thesis ............................................................................................... 15 2 LITERATURE REVIEW .................................................................................. 17 2.1 Health Systems ................................................................................................................ 18 2.1.1 Health Information Systems .................................................................................... 19 xi 2.1.2 Patient’s Health Records ......................................................................................... 21 2.1.3 Electronic Health Records ....................................................................................... 22 2.1.4 Purpose, Dimension and Functionalities of EHRs ..................................................... 25 2.1.5 Architectural Approaches of Electronic Health Record ............................................. 27 2.2 Security and Privacy of Patient’s EHRs ............................................................................. 29 2.3 Social, Ethical and Legal Perspective of Protecting Patient’s Privacy ............................... 32 2.3.1 Privacy Protection from a International Perspective ................................................ 35 2.3.2 Australian Legislation for Privacy Protection ............................................................ 36 2.3.3 Australian States Privacy Legislation for Health Information .................................... 39 2.4 Security and Privacy in a Shared Care Environment......................................................... 41 2.4.1 Interoperability of EHRs .......................................................................................... 43 2.4.2 Standardization and Interoperability in the Health Care Sector ................................ 45 2.4.3 International Standardization Initiatives .................................................................. 48 2.4.3.1 American National Standard Institute ............................................................ 48 2.4.3.2 The International Standard Organization ........................................................ 48 2.4.3.3 The European Committee for Standards......................................................... 50 2.4.4 Commonly Used Information Standars in Medicine ................................................. 51 2.4.4.1 Common Object Request Broker Architecture ................................................ 51 2.4.4.2 Digital Imaging and Communication in Medicine ............................................ 51 2.4.4.3 Unified Medical Language System .................................................................. 52 2.4.4.4 Health Level 7 Messaging Standard ................................................................ 52 2.4.4.4.1 HL7 Version 2 ............................................................................................ 54 2.4.4.4.1.1 HL7 Version 2.x Messages................................................................... 54 2.4.4.4.1.2 HL7 version 2.x Message Rulers .......................................................... 56 2.4.4.4.1.3 HL7 version 2 XML Encoding Syntax .................................................... 57 2.4.4.4.1.4