  • 學位論文


Design and Implementation of Electronic Medical Record Sharing System with Privacy Protection

指導教授 : 黃國軒


目前大多數的醫療院所是將病歷以電腦化的方式輸入,紙本方式輸出存放,因此就以現況來說,大多還是依賴紙本的方式儲存和保管。紙本病歷有諸多的不便,紙本病歷可能因環境潮濕而損毀,保存不易。另外,若歷史資料龐大攜帶上也不易。相較之下,電子病歷即有著不易損毀保存容易、攜帶方便等優點,此外也因為病歷為電子化的模式,在醫院間的交流與分享就顯得方便許多。 然而隱私性在電子病歷中成為了一個重要的議題。根據美國的健康保險流通與責任法案(HIPAA)中的定義,電子病歷中較為私密的部分是需要被保護的,因此在進行電子病歷交換或共享時,必須具有保護病人隱私的機制。隱私保護機制可以分為匿名、化名、無連結性和非觀察性這四種。在過去的相關研究利用一些數學轉換式或對照表的方式,來將電子病歷具有病人隱私性的部分隱藏來達到隱私,但這些方法對於無連結性與非觀察性較無法達到。因此,在本論文中則對於此加以改進,加強病人與病歷間的無連結性。 雲端運算以他的計算能力快、儲存空間大為著名。本論文藉由雲端技術可以整合醫院的電子病歷系統,利用上傳電子病歷為統一格式,便利於電子病歷交換與共享,此外也能提供資源較小的醫院診所儲存電子病歷的空間,而省去另外建置的硬體空間的花費。另外為了加強電子病歷的安全性,本論文亦利用智慧卡來加密電子病歷文件,以達到保護電子病歷安全。


電子病歷 交換 分享 隱私性 雲端運算 智慧卡


Most hospitals and clinics now record the medical records computerized, and output the paper-based medical records to store. For now on, most hospitals and clinics store their medical records which are paper-based. There are some disadvantages of using paper-based medical records. For example, the paper-based medical records may be damaged cause of the muggy day. It is not convenient to carry the paper-based medical records if the file is huge. By contrast, the electronic medical records can be well-preserved and convenient to carry. Besides, it is easy to share and exchange between the hospitals and clinics by using electronic medical records. Privacy is a very important issue when storing electronic medical records. According to the definition set out in the Health Insurance Portability and Accountability Act (HIPPA), the confidential section of the electronic medical record needs to be protected. Thus, a mechanism to protect the patient’s privacy is needed during exchange and sharing of electronic medical records. The privacy protection mechanism can be categorized into four types, namely anonymity, pseudonymity, unlinkability, and unobservability. In previous researches in this area, mathematical conversions and cross reference tables have been utilized to conceal the confidential part of the electronic medical records to achieve privacy protection. However, it is harder to use these methods with respect to the unlinkability and unobservability mechanisms. Thus, this thesis tries to improve on this aspect, and improves the unlinkability mechanism between the patient and the electronic medical record. Cloud computing is known for its fast computation capability and provides large storage space. Through cloud computing, the electronic medical record system in a hospital can be integrated, to facilitate the exchange and sharing of electronic medical records by updating them to be the unified forms, and to provide smaller hospitals or clinics that have fewer resources with adequate electronic medical record storage space. Besides, in order to enhancing the safety of electronic medical records, we utilize the smart card to encrypt them to achieve protecting this goal.


[3] R. Zhang and L. Liu, “Security Models and Requirements for Healthcare Application Clouds,” In Proceedings of the IEEE 3rd International Conference on Cloud Computing, pp. 268-275, July 2010.
[8] A. Pfitzmann and M. Hansen, “Anonymity, Unlinkability, Unobservability, Pseudonymity, and Identity Management – A Consolidated Proposal for Terminology,” available at http://dud.inf.tu-dresden.de/Anon_Terminology.shtml
[10] L.-C. Huang, H.-C. Chu, C.-Y. Lien, C.-H. Hsiao and T. Kao “Privacy Preservation and Information Security Protection for Patients' Portable Electronic Health Records,” International Journal of Computers in Biology and Medicine, Vol.39, pp. 743-750, Sep. 2009.
[13] B. Alhaqbani and C. Fidge, “Privacy-Preserving Electronic Health Record Linkage Using Pseudonym Identifiers,” In Proceedings of e-health Networking, Applications and Services, pp. 108-117, July 2008.
[14] M.van der Haak, A.C Wolff, R. Brandner, P. Drings, M. Wannenmacher and Th. Wetter, “Data Security and Protection in Cross-institutional Electronic Patient Records,” International Journal of Medical Informatics, Vo1.70, pp.117-130, July 2003.


