Author(s) | Collection number | Pages | Download abstract | Download full text |
---|---|---|---|---|
Havrysh B. M., Tymchenko O. V., Кустра Н. О. | № 1 (66) | 68-79 |
The development of electronic forms of storage, processing and transmission of medical data has influenced not only the improvement of the quality of medical care for patients, but also the development of new methods of obtaining knowledge from medical databases by unauthorized persons. To prevent the disclosure of confidential data, medical information systems must be constantly tested for security in all system structures. Technical security measures should be complemented by physical, personal and organizational security measures. The methods described in the work are the main methods of medical data anonymization, on the basis of which other anonymization methods have been developed, such as: l-diversification, (X, Y)-connectivity, (X, Y)-privacy, LKC-privacy closure, bounded trust, and personalized privacy. Thanks to anonymization methods in medical databases, the effectiveness of attacks on patient data can be minimized.
The patient’s medical record is a key element during his treatment, as it contains all the information about the state of health, tests performed, stays in the hospital and procedures performed over the years. A few years ago, medical documentation was mostly in paper form. Currently, it is slowly being replaced by electronic forms. One fact has not changed over the years – most often it is the patient who is responsible for transporting him to another medical institution. Therefore, in emergency cases during treatment in a new institution, the level of knowledge about this patient is zero. This problem is solved by the introduction of the electronic medical record EMR (English Electronic Medical Record - EMR). EMR is a virtual document that consists of all medical records in digital form belonging to one patient. Thanks to this solution, patient information can be created, stored and used in many different medical facilities and made available to the patient in a single document in a web application.
The introduction of an electronic system of medical documentation brings advantages, but also creates new problems. The advantages are improving the quality of medical care for patients, more efficient and much more effective management (the electronic prescription system allows controlling unwanted interactions between drugs prescribed and taken at the same time), supporting the decisions of doctors and reducing medical errors by up to 55%, remote treatment, which is good in big cities, intercity, intercontinental. The most serious consequence of the transfer of resources from hospital databases to the network is problems with control and protection of information contained in medical documents. The integrity of digital objects is also an issue in the case of multi-module EHR systems.
Keywords: anonymization, pseudo-identifier, attack, system protection, security.
doi: 10.32403/1998-6912-2023-1-66-68-79