Cargando…

Privacy and information security risks in a technology platform for home-based chronic disease rehabilitation and education

BACKGROUND: Privacy and information security are important for all healthcare services, including home-based services. We have designed and implemented a prototype technology platform for providing home-based healthcare services. It supports a personal electronic health diary and enables secure and...

Descripción completa

Detalles Bibliográficos
Autores principales: Henriksen, Eva, Burkow, Tatjana M, Johnsen, Elin, Vognild, Lars K
Formato: Online Artículo Texto
Lenguaje:English
Publicado: BioMed Central 2013
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3751072/
https://www.ncbi.nlm.nih.gov/pubmed/23937965
http://dx.doi.org/10.1186/1472-6947-13-85
_version_ 1782281527350001664
author Henriksen, Eva
Burkow, Tatjana M
Johnsen, Elin
Vognild, Lars K
author_facet Henriksen, Eva
Burkow, Tatjana M
Johnsen, Elin
Vognild, Lars K
author_sort Henriksen, Eva
collection PubMed
description BACKGROUND: Privacy and information security are important for all healthcare services, including home-based services. We have designed and implemented a prototype technology platform for providing home-based healthcare services. It supports a personal electronic health diary and enables secure and reliable communication and interaction with peers and healthcare personnel. The platform runs on a small computer with a dedicated remote control. It is connected to the patient’s TV and to a broadband Internet. The platform has been tested with home-based rehabilitation and education programs for chronic obstructive pulmonary disease and diabetes. As part of our work, a risk assessment of privacy and security aspects has been performed, to reveal actual risks and to ensure adequate information security in this technical platform. METHODS: Risk assessment was performed in an iterative manner during the development process. Thus, security solutions have been incorporated into the design from an early stage instead of being included as an add-on to a nearly completed system. We have adapted existing risk management methods to our own environment, thus creating our own method. Our method conforms to ISO’s standard for information security risk management. RESULTS: A total of approximately 50 threats and possible unwanted incidents were identified and analysed. Among the threats to the four information security aspects: confidentiality, integrity, availability, and quality; confidentiality threats were identified as most serious, with one threat given an unacceptable level of High risk. This is because health-related personal information is regarded as sensitive. Availability threats were analysed as low risk, as the aim of the home programmes is to provide education and rehabilitation services; not for use in acute situations or for continuous health monitoring. CONCLUSIONS: Most of the identified threats are applicable for healthcare services intended for patients or citizens in their own homes. Confidentiality risks in home are different from in a more controlled environment such as a hospital; and electronic equipment located in private homes and communicating via Internet, is more exposed to unauthorised access. By implementing the proposed measures, it has been possible to design a home-based service which ensures the necessary level of information security and privacy.
format Online
Article
Text
id pubmed-3751072
institution National Center for Biotechnology Information
language English
publishDate 2013
publisher BioMed Central
record_format MEDLINE/PubMed
spelling pubmed-37510722013-08-24 Privacy and information security risks in a technology platform for home-based chronic disease rehabilitation and education Henriksen, Eva Burkow, Tatjana M Johnsen, Elin Vognild, Lars K BMC Med Inform Decis Mak Research Article BACKGROUND: Privacy and information security are important for all healthcare services, including home-based services. We have designed and implemented a prototype technology platform for providing home-based healthcare services. It supports a personal electronic health diary and enables secure and reliable communication and interaction with peers and healthcare personnel. The platform runs on a small computer with a dedicated remote control. It is connected to the patient’s TV and to a broadband Internet. The platform has been tested with home-based rehabilitation and education programs for chronic obstructive pulmonary disease and diabetes. As part of our work, a risk assessment of privacy and security aspects has been performed, to reveal actual risks and to ensure adequate information security in this technical platform. METHODS: Risk assessment was performed in an iterative manner during the development process. Thus, security solutions have been incorporated into the design from an early stage instead of being included as an add-on to a nearly completed system. We have adapted existing risk management methods to our own environment, thus creating our own method. Our method conforms to ISO’s standard for information security risk management. RESULTS: A total of approximately 50 threats and possible unwanted incidents were identified and analysed. Among the threats to the four information security aspects: confidentiality, integrity, availability, and quality; confidentiality threats were identified as most serious, with one threat given an unacceptable level of High risk. This is because health-related personal information is regarded as sensitive. Availability threats were analysed as low risk, as the aim of the home programmes is to provide education and rehabilitation services; not for use in acute situations or for continuous health monitoring. CONCLUSIONS: Most of the identified threats are applicable for healthcare services intended for patients or citizens in their own homes. Confidentiality risks in home are different from in a more controlled environment such as a hospital; and electronic equipment located in private homes and communicating via Internet, is more exposed to unauthorised access. By implementing the proposed measures, it has been possible to design a home-based service which ensures the necessary level of information security and privacy. BioMed Central 2013-08-09 /pmc/articles/PMC3751072/ /pubmed/23937965 http://dx.doi.org/10.1186/1472-6947-13-85 Text en Copyright © 2013 Henriksen et al.; licensee BioMed Central Ltd. http://creativecommons.org/licenses/by/2.0 This is an Open Access article distributed under the terms of the Creative Commons Attribution License (http://creativecommons.org/licenses/by/2.0), which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.
spellingShingle Research Article
Henriksen, Eva
Burkow, Tatjana M
Johnsen, Elin
Vognild, Lars K
Privacy and information security risks in a technology platform for home-based chronic disease rehabilitation and education
title Privacy and information security risks in a technology platform for home-based chronic disease rehabilitation and education
title_full Privacy and information security risks in a technology platform for home-based chronic disease rehabilitation and education
title_fullStr Privacy and information security risks in a technology platform for home-based chronic disease rehabilitation and education
title_full_unstemmed Privacy and information security risks in a technology platform for home-based chronic disease rehabilitation and education
title_short Privacy and information security risks in a technology platform for home-based chronic disease rehabilitation and education
title_sort privacy and information security risks in a technology platform for home-based chronic disease rehabilitation and education
topic Research Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3751072/
https://www.ncbi.nlm.nih.gov/pubmed/23937965
http://dx.doi.org/10.1186/1472-6947-13-85
work_keys_str_mv AT henrikseneva privacyandinformationsecurityrisksinatechnologyplatformforhomebasedchronicdiseaserehabilitationandeducation
AT burkowtatjanam privacyandinformationsecurityrisksinatechnologyplatformforhomebasedchronicdiseaserehabilitationandeducation
AT johnsenelin privacyandinformationsecurityrisksinatechnologyplatformforhomebasedchronicdiseaserehabilitationandeducation
AT vognildlarsk privacyandinformationsecurityrisksinatechnologyplatformforhomebasedchronicdiseaserehabilitationandeducation