Security and personalized ehealth systems

Similar documents
Personalized ehealth systems Standardization work at ETSI

Invitation to the workshop on. Personalization and user profile standardization

The ICT for Health Perspective

Europe (DAE) for Telehealth

mhealth & integrated care

Portable Devices, Sensors and Networks: Wireless Personalized ehealth Services

Example of Focus Group Discussion Guide (Caregiver)

D.9.1 Web Portal Creation and Launch

WHITE PAPER. HIPAA Breaches Continue to Rise: Avoid Becoming a Casualty

Summary. Strategy at EU Level: Digital Agenda for Europe (DAE) What; Why; How ehealth and Digital Agenda. What s next. Key actions

s, Texts and Social Media: What Physicians Need to Know

ehealth and DSM, Digital Single Market

Regulating Telemedicine: the

This study is brought to you courtesy of.

Empowering Citizens through phealth

Road Map for CAT4 Suite. CAT4 Road Map. Road Map for CAT4 Suite

mhealth (Mobile Health)

INFORMATION GOVERNANCE. Caldicott Approval Procedure

Working with Health IT Systems is available under a Creative Commons Attribution-NonCommercial- ShareAlike 3.0 Unported license.

Business Architecture in Healthcare

Privacy Policy Effective Date: October 4, 2017

Introduction to mhealth

ECHO HMIS FREQUENTLY ASKED QUESTIONS BASED OFF OF WEBINAR AND NEW ROI

THE SOCIO-ECONOMIC IMPACT OF MOBILE HEALTH MALAYSIA & THAILAND

Standards Development

Seminar Medical Informatics 2015

Digital Healthcare. Yordan Iliev Director R&D Healthcare. Regional Cybersecurity Forum, November 2016, Grand Hotel Sofia, Bulgaria

State of US Telemedicine Industry

The MovingLife Project

Doctor with a tablet in the hands and office background suedhang_gettyimages.com

Transforming Healthcare with mhealth Solutions.

APF!submission!!draft!Mandatory!data!breach!notification! in!the!ehealth!record!system!guide.!

Enabling tomorrow s Healthcare

The HUMANE roadmaps towards future human-machine networks Oxford, UK 21 March 2017

BRIDGEWATER SURGERIES. Privacy Notice

Issues and Considerations for Healthcare Consumers Using Mobile Applications

A Way to Personalize In-Home Healthcare and Assisted Living

Balancing the pressures of a healthcare SQL Server DBA

BASELINE GENERAL PRACTICE SECURITY CHECKLIST Guide

ehaction Joint Action to Support the ehealth Network

Acurian on. The Role of Technology in Patient Recruitment

Future-Proof Security & Privacy in IoT

ehealth in Europe: at the convergence of technology, medicine, law and society

School of Health and Social Studies

This guide is for informational purposes only. Please do not treat it as a substitute of a professional legal

Horizon Health Care, Inc.

A pill box with biometric access control and web connection (work in progress)

Older African Americans perspectives on mhealth approaches for HIV management

Mobile Data for Public and Personal Health

Setting the Scene: The National ehealth Context and Big Data Big Data and AI for Achieving UHC: An International Consultation on Ethics

Writing for the Web for Health Care

Comparing Approaches to Measuring the Adoption and Usability of Electronic Health Records: Lessons Learned from Canada, Denmark and Finland

HIPAA Faux Pas. Lauren Gluck Physician s Computer Company User s Conference 2016

Early Learning SF User Guide for Families

Frequently asked questions on video-surveillance: prior checking

EuroRec Functional Statements Repository. EHR-QTN Workshop Vilnius, January 26, 2011 Dr. Jos Devlies, Belgium

Chances & Challenges of ehealth

Healthcare to go. WAC, Katarzyna, BULTS, Richard. Abstract

A Web Application to Visualize Trends in Diabetes across the United States

Analysis of the Central District Clinic

Electronic Communication of Personal Health Information

The New Healthcare Economy is rising up

Handbook of ehealth evaluation INTRODUCTION 1

ISO/IEC JTC 1 N Replaces: JTC 1 N ISO/IEC JTC 1 Information Technology

Fill Out the Form to Name an Authorized Delegate

Provider Communication. July Version: 1.0

Report of the Working Group on mhealth Assessment Guidelines February 2016 March 2017

Prescription. Information Services. Gateway: 01/NHSBSA/RxS/06/2018

EY s data privacy service offering

Managing Trust in e-health with Federated Identity Management

2016 Member Needs Survey Results

ehealth EIF ehealth European Interoperability Framework European Commission ISA Work Programme

SRA A Strategic Research Agenda for Future Network Technologies

How the European Commission is supporting innovation in mobile health technologies Nordic Mobile Healthcare Technology Congress 2015

Data Backup and Contingency Planning Procedure

Healthcare Security Success Story

The Monsenso Advantage Partner Programme

HIPAA Privacy and Security. Rochelle Steimel, HIPAA Privacy Official Judy Smith, Staff Development January 2012

What is the Northern Ireland ehealth and Care strategy?

Putting consumers at the center of healthcare

IT Security in a Meaningful Use Era C&SO HIMSS Meeting

National ehealth and esocial strategy 2020 in Finland

Two types of market (3.3B cellphones WW) City center / USA and European (10%) Rural and urban (90%)

ORDINARY. Connected Health and Wellness Project. Context Creative RGD Web Accessibility Conference

HIPAA Privacy & Security Training. Privacy and Security of Protected Health Information

Building a Privacy Management Program

The Journey to Mobility. Session NI5, March 5, 2018 Victoria L. Tiase, MSN, RN-BC Director of Research Science, NewYork-Presbyterian Hospital

DEFINE THE QUERY AS ONE OF THE DATABASE OBJECTS A Query is database object that retrieves specific information from a database.

CMS and ehealth. Robert Tagalicod Director, Office of ehealth Standards and Services (OESS)

ehealth action in the EU

Results, 2 nd Quarter Data Security. HIMSS Analytics ehealth TRENDBAROMETER Q2/2017

Kostas Giokas MONITORING OF COMPLIANCE ON AN INDIVIDUAL TREATMENT THROUGH MOBILE INNOVATIONS

Person-centred ehealth

Planning for disaster recovery in a health care setting

Innovation in Horizon 2020: From ehealth Policy Strategy to funding instrument

Use Of Mobile Communication Devices Within Healthcare Premises Policy

ehealth Innovations Partnership Program (ehipp)

Carina Dantas Cáritas Coimbra. Willeke van Staalduinen AFEdemy

Borderless ehealth in support of healthy citizens in Europe

Iguana Web 2.0 Self-Service Portal

Transcription:

Security and personalized ehealth systems 4th ETSI Security Workshop 13-14 January 2009 - ETSI, Sophia Antipolis, France Francoise Petersen APICA/ETSI Human Factors, ehealth Francoise.Petersen@apica.com ETSI 2008. All rights reserved ETSI ehealth and Human Factors - Personalization of ehealth systems

What is an ehealth system? World Class Standards ehealth systems include tools for health authorities and professionals as well as personalized health systems for patients (including formal and informal carers) including the process of curative or preventative care, contributing thereby to the person's well-being. ETSI ehealth and Human Factors - Personalization of ehealth systems 2

ehealth system users can be very diverse Including such widely differing categories such as people with disabilities and very old or young people ETSI ehealth and Human Factors - Personalization of ehealth systems 3

Situations where ehealth services need to be delivered can be equally diverse Not just in locations within the healthcare system Not just at home Not just at work But wherever the client may be - at home or abroad ETSI ehealth and Human Factors - Personalization of ehealth systems 4

Other challenges The client of an e-health system may: not be particularly computer literate have a physical and/or mental impairment World Class Standards mental impairment may compromise understanding of security implications Many of today s e-health systems: handle sensitive data that requires protective measures a major privacy challenge are tailored to a professional user are difficult for a client to understand are combined with other (e-health) systems may require special setup procedures ETSI ehealth and Human Factors - Personalization of ehealth systems 5

What can be personalized? World Class Standards Standardizing personalization and the user experience of e-health systems related to: the degree of user control user perception related parameters e.g. audio volume, use of colour user input methods e.g. tactile, voice, keyboard/mouse, switches, eye-tracking Fine-grained control of the sharing of sensitive information Standardizing the meaning and scale of personalization parameters: terms for medical concepts that can be understood by non-medical people (e.g. by both clients and carers) the handling of particularly sensitive data ETSI ehealth and Human Factors - Personalization of ehealth systems 6

Information sharing and privacy As users become more aware of privacy issues, there is an increasing need for user acceptance of personalized services a demand for solutions allowing them to be in control of their profile content. If profile content is made available to the wrong people, then users will lose confidence. Too restricted access to profile content should be avoided, as it may reduce the usability and the number of available services. Roles including: client carers formal and informal relatives ETSI Human Factors - Personalization and user profiles 7

Privacy settings should change if others are present! HIV level increased contact your doctor immediately! ETSI ehealth and Human Factors - Personalization of ehealth systems 8

The benefits of personalization Re-use of personalization parameters across e-health systems Users can themselves tailor each system to their preferences Less user confusion, less risk of improper user handling, fewer errors In summary: Easier adoption of e-health systems More control of security/privacy issues ETSI ehealth and Human Factors - Personalization of ehealth systems 9

ETSI work on personalization and user profiles EG 202 325 published 2005 Concept and guidelines World Class Standards New Specialist Task Force ETSI Human Factors STF342 ETSI Standard (ES) on standardized personalization objects ETSI Technical Specification (TS) on architectural framework New Specialist Task Force ETSI Human Factors and ehealth STF352 ETSI Standard (ES) on standardized personalization objects in the ehealth domain Co-financed by the EC/EFTA in response to the EC s ICT Standardisation Work Programme ETSI ehealth and Human Factors - Personalization of ehealth systems 10

personal information World Class Standards What is in a User Profile? preferences and depending on time, activity, role, location context information pointers to extracts from the user s ehealth Record rules automatically activate a situation dependent profile that allows the ehealth services to be adapted to suit the current situation specific security related obligations and preferences related to the above ETSI ehealth and Human Factors - Personalization of ehealth systems 11

Privacy issues depending on where profile data is located EHR ETSI ehealth and Human Factors - Personalization of ehealth systems 12

Access to Electronic Health Record General access safeguards apart from the patient himself only those healthcare professionals/ authorized personnel of healthcare institutions who presently are involved in the patient s treatment may have access (ref.) Special access safeguards by involvement of the patient If feasible and if possible the patient should be given the chance to prevent access to his EHR data if he so chooses. (ref.) Relevant also for the ehealth profile? Ref. see Working Document on the processing of personal data relating to health" in electronic health records (EHR) ETSI ehealth and Human Factors - Personalization of ehealth systems 13

Sensors Sensors can be related to the person What sensors are practical e.g. anything worn might not be worn Sensors can be related to the environment What sensors are acceptable e.g. video and privacy Example: PIR based system to monitor activity in a home Video is usually considered to be more invasive Who can (not) access the data? ETSI ehealth and Human Factors - Personalization of ehealth systems 14

Scenario: Bert goes to the Bookies Bert and his care issues 75 year old male living alone Route to bookies includes an underpass where dim light disorientates him Concerned that the route is unsafe Concerned that because he has COPD (Chronic Obstructive Pulmonary Disease) and that he can t run from trouble in the underpass Smoker, and has been for 60 years Those who care about Bert Jim, friend, living next door Alice, daughter, living an hour away Bert s doctor Bert s social worker ETSI ehealth and Human Factors - Personalization of ehealth systems 15

Bert World Class Standards Privacy and profile related issues Navigation aid might help Bert to feel confident to go to Bookies Self management strategy for giving up smoking and taking COPD drugs Jim, Bert s friend Did Bert make it to the Bookies? Bert s social worker Did Bert make it to the Bookies? Bert s doctor Has Bert given up smoking? Is he taking his medication? Alice, Bert s daughter Has Bert given up smoking, if not he will be ineligible for medical care! ETSI ehealth and Human Factors - Personalization of ehealth systems 16

Who we are World Class Standards ETSI ehealth and Human Factors - Personalization of ehealth systems 17

Thank you! Information and communication World Class Standards Web: http://portal.etsi.org/stfs/stf_homepages/stf352/stf352.asp Email: Francoise.Petersen@etsi.org Do you want to: receive the newsletters from our STF (about once a month, or when relevant)? discuss personalization and user profiles with a wider group? If so welcome to use our mail list STF352_CONSULTATION@LIST.ETSI.ORG Subscribe at: http://list.etsi.org/stf352_consultation.html ETSI ehealth and Human Factors - Personalization of ehealth systems 18