透過您的圖書館登入
IP:3.15.147.53
  • 期刊

電子化醫療資訊系統的安全策略與隱私權保障

Security Policy and Privacy Protection of Electronic Medical Information System

摘要


網路發展經年,應用面向日漸繁複,相關技術也趨於多樣化,相對於醫療的應用,資訊技術的意義在於擴大醫療資訊的臨床輔助功能。數位化醫療所涵蓋的範圍,包括電子病歷、電子處方箋、醫療資訊系統等,各種相關系統的資料處理結構與格式的研究雖趨於成熟,但整合性不足,因此,本研究提出一個整合醫療資訊系統,使跨醫療院所之間的電子病歷交換可以安全的進行,並且透過密碼機制的設計,保障病患與醫師的隱私權,但也提供主管機關的查核追蹤機制。藉此,醫療資訊系統或可發展為全面性的功能,免除人工單據的傳遞,維持病患就醫資訊的安全性,因此可以降低、甚或免除後續護理、藥劑、技術人員等可能的人為失誤,不但可以改善醫療品質,同時也是醫務管理上不可或缺的基礎設施。本系統達到下列相關功能:強化健保IC卡的功能及其與整合式醫療資訊系統的相容性、建置功能完整的電子處方箋系統及其與醫療資訊系統的整合、保障病患與醫師的隱私權,並且從架構的設計上,根本解決病患就診紀錄儲存方式,提供代領藥物的機制設計以及維護醫師與病患的隱私權。

並列摘要


With the development of the Internet, the application orientations have become complicated as well as the relevant technologies have become diverse. Contrary to the application of medical treatments, the significance of information technology is to expand the clinical supports in medical information. Digital medical treatments cover the areas of electronic patient records, electronic prescriptions, and medical information system. Furthermore, studies on the data processing structures and the formats in various relevant systems have become mature, but the integration is still insufficient. For this reason, this project proposes an integrative medical information system to securely exchange electronic patient records among medical organizations, to guarantee the privacies of patients and doctors with the design of passwords, and to provide authorities with verification and tracking mechanisms. By doing so, the medical information system can be developed with comprehensive functions to dispense the transfer of manual documents and maintain the security of medical information so that the possible human errors, such as the follow-up nursing, medical preparation, and technical staff, can be reduced or even avoided. Not only can it improve the medical quality, but it can also become one of the inevitable fundamental facilities in medical management. This project aims to strengthen the functions of National Health Insurance IC card and the compatibility with the integrative medical information system, to establish a full-functional electronic prescription system and the integration with medical information system, and to guarantee the privacies of patients and doctors. From the architectural design, it further aims to solve the problem of storing patients' treatment records, provide the design of helping draw medicine mechanisms, and protect the privacies of doctors and patients.

參考文獻


Ateniese, G., Cutmola, R., Meideiros, B. de and Davis, D., “Medical Information Privacy Assurance: Cryptographic and System Aspects”, Third Conference on Security in Communication Networks, Amalfi, Italy, pp. 199-218, 2002.
Ball, E., Chadwick, D.W. and Mundy D., “Patient Privacy in Electronic Prescription Transfer”, IEEE Security & Privacy Magazine, Vol. 1, No. 2, pp. 77-80, 2003.
Chaum, D. and Heyst, E. van, “Group signatures”, In proceedings of Advances in Cryptology - Eurocrypt 1991, Vol. 547 of LNCS, Springer-Verlag, pp. 257-265, 1991.
Cao, F. and Cao, Z., “A secure identity-based proxy multi-signature scheme”, Information Sciences, Vol. 179, No. 3, pp. 292-302, 2009.
Chen, C.-L., Chen, Y.-Y. and Chen, Y.-H., “Group-based Authentication to Protect Digital Content for Business Applications”, International Journal of Innovative Computing, Information and Control, Vol. 5, No. 5, pp. 1243-1251, 2009.

延伸閱讀