A patient-identity security mechanism for electronic medical records during transit and at rest.
نویسندگان
چکیده
This paper proposes a patient-identity security mechanism, including an identity cipher/decipher and a user-authentication protocol, to ensure the confidentiality and authentication of patients' electronic medical records (EMRs) during transit and at rest. To support the confidentiality of an EMR, the identity cipher/decipher uses a data-hiding function and three logical-based functions to encrypt/decrypt a patient's identifying data and medical details in an EMR. The ciphertext of the patient's identifying data is patient-EMR related, whereas that of medical details is healthcare agent-EMR related. To support the authentication of an EMR, the user-authentication protocol based on a public key infrastructure uses certificates and dynamic cookies for verification/identification. The identity cipher has been simulated using C programming language running on a 1500 MHz Pentium PC with 512 MB of RAM. The experimental results show that healthcare agents can install large amounts of patients' encrypted EMRs in healthcare databases efficiently. In addition, separately storing the keys in a user's token and an EMR database for decryption increases the safety of patients' EMRs. For each user-authentication trail, the use of certificates and dynamic cookies for verification/identification ensures that only authorized users can obtain access to the EMR, and anyone involved cannot make false claims on the transmission made.
منابع مشابه
A Patient-Identity Security Mechanism For Electronic Medical Records (EMRs) During Transit and At Rest
Primary Objective: This paper proposes a patient-identity security mechanism, including an identity cipher/decipher and a user authentication protocol, to ensure the confidentiality and authentication of patients’ EMRs during transit and at rest. Research Design and Methods: To support the confidentiality of an EMR, the identity cipher/decipher uses a data-hiding function and three logical-base...
متن کاملInformation Security Requirements for Implementing Electronic Health Records in Iran
Background and Goal: ICT development in recent years has created excellent developments in human social and economic life. One of the most important opportunities to use information technology is in the medical field, that the result would be electronic health record (EHR).The purpose of this research is to investigate the effects information securi...
متن کاملIn vivo dose verification using using an amorphous silicon flat panel-type imager (a-Si EPIDs)
Introduction: Electronic portal imaging devices (EPIDs) could be used to dose verification of radiotherapy treatment plans. In vivo dose verification is performed to reduce differences found between dose delivered to the patient and the prescribed dose. The aim of this study was to perform a fast and efficient technique for the verification of delivered dose to the patient usin...
متن کاملInformation Security Requirements for Implementing Electronic Health Records in Iran
Background and Goal: ICT development in recent years has created excellent developments in human social and economic life. One of the most important opportunities to use information technology is in the medical field, that the result would be electronic health record (EHR).The purpose of this research is to investigate the effects information securi...
متن کاملبررسی و مقایسه میزان آمادگی بیمارستانهای آموزشی جهت استقرار مدارک پزشکی الکترونیکی در دانشگاه علوم پزشکی ارومیه
Background and Aim: Development of information and communication technology has led to enormous changes in different areas. Electronic medical records system is valuable to access patient data in hospitals. This study aimed to investigate and compare the educational hospitals of Uemia University of Medical Sciences in case of technical, organizational and legal to establish the system. Material...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- Medical informatics and the Internet in medicine
دوره 30 3 شماره
صفحات -
تاریخ انتشار 2005