Search PubMed⌕ Search

Biomedical subjects

Peter Pharow

Publications and source records attributed to Peter Pharow.

At least 19 recordsLinked to original sources

A model driven approach for the German health telematics architectural framework and security infrastructure.

Shared care concepts such as managed care and continuity of care are based on extended communication and cooperation between different health professionals or between them and the patient respectively. Health information systems and their components, which are very different in their structure, behavior, data and their semantics as well as regarding implementation details used in different environments for different purposes, have to provide intelligent interoperability. Therefore, flexibility, portability, and future orientation must be guaranteed using the newest development of model driven architecture. The ongoing work for the German health telematics platform based on an architectural framework and a security infrastructure is described in some detail. This concept of future proof health information networks with virtual electronic health records as core application starts with multifunctional electronic health cards. It fits into developments currently performed by many other developed countries.

Computer Security↗

EHR standards--A comparative study.

For ensuring quality and efficiency of patient's care, the care paradigm moves from organization-centered over process-controlled towards personal care. Such health system paradigm change leads to new paradigms for analyzing, designing, implementing and deploying supporting health information systems including EHR systems as core application in a distributed eHealth environment. The paper defines the architectural paradigm for future-proof EHR systems. It compares advanced EHR architectures referencing them at the Generic Component Model. The paper introduces the evolving paradigm of autonomous computing for self-organizing health information systems.

Database Management Systems↗

Personal health--the future care paradigm.

Demographic, economic and social conditions developed countries are faced with require a paradigm change for delivering high quality and efficient health services. In that context healthcare systems have to turn towards individualized of patient's care, also called personal care. Interoperability requirements for ubiquitous personalized health services reach beyond current concepts of health information integration among professional stakeholders and related Electronic Patient Records ("e-Health"): Future personal health platforms have particularly to maintain semantic interoperability among systems using different modalities and technologies, different knowledge representation and domain experts' languages as well as different coding schemes and terminologies to include home, personal and mobile systems. The paper introduces the evolving paradigm related to personal health information systems.

Computer Communication Networks↗

Formal policies for flexible EHR security.

State of the Art methodologies for establishing requirements and solutions to securing applications are based on narrative descriptions about the use of available system, sometimes also dedicated to system components. Even nowadays new developments to ruling application security services by the use of predicate logic suffer from being administered manually. Therefore, security and privacy requirements cannot be properly met resulting in restrictions and fears for allowing the use of sensitive data and functions. Because of the sensitivity of personal health information and especially of genetic data with its wider implications beyond the original subject of care, weaknesses in guaranteeing fine-grained security and privacy rules lead to less acceptance or even the avoidance of essential information transfer and use. To overcome the problem, security and privacy have to become properties of the architectural components of the respective health information system. Embedding security into the systems architecture allows for negotiating and enforcing any security and privacy services related to principals, their roles, their relationships, further contextual information as well as other regulations summarized in formally modeled policies. The paper introduces the evolving paradigm of the model-driven architecture, first time also comprehensively deployed for security and privacy services in bio-genetic and health information systems.

Authorship↗

BioHealth--the need for security and identity management standards in eHealth.

The experience gained in these last years and the several lesson learned have clearly shown that eHealth is more than just a simple change from paper records to electronic records. It necessitates a change of paradigms, on the one hand and the use of new technologies and introduction of new procedures on the other. Interoperability becomes a crucial issue. Security and confidentiality are vital for the acceptance of the new approaches and for the support of eHealth. Shared care and across-border interactions require a reliable and stable normative framework based on the application of standardized solutions, which are often not yet sufficiently known, diffused and implemented. Feeling this gap, a group of international experts in the medical area proposed to the EC the BioHealth project whose main aim is to create awareness about standardization in eHealth and to facilitate its practical implementation. The project will address all the stakeholders concerning their respective domain. It will evaluate the socio-economic and cultural aspects concerning eHealth with particular reference to the growing introduction of emerging technologies such as health cards, biometrics, RFID (radio-frequency identification) and NFC (Near field communication) tags. By providing information and expert advice on standardization and best practices it will raise the acceptance on standardization. Furthermore, the project will deeply approach the ethical and accessibility issues connected to identity management in eHealth, which -together with privacy- represent probably the most significant obstacles for the wide diffusion of eHealth procedures.

Biometry↗

Specific interoperability problems of security infrastructure services.

Communication and co-operation in healthcare and welfare require a well-defined set of security services based on a standards-based interoperable security infrastructure and provided by a Trusted Third Party. Generally, the services describe status and relation of communicating principals, corresponding keys and attributes, and the access rights to both applications and data. Legal, social, behavioral and ethical requirements demand securely stored patient information and well-established access tools and tokens. Electronic signatures as means for securing integrity of messages and files, certified time stamps and time signatures are important for accessing and storing data in Electronic Health Record Systems. The key for all these services is a secure and reliable procedure for authentication (identification and verification). While mentioning technical problems (e.g. lifetime of the storage devices, migration of retrieval and presentation software), this paper aims at identifying harmonization and interoperability requirements of securing data items, files, messages, sets of archived items or documents, and life-long Electronic Health Records based on a secure certificate-based identification. It's commonly known that just relying on existing and emerging security standards does not necessarily guarantee interoperability of different security infrastructure approaches. So certificate separation can be a key to modern interoperable security infrastructure services.

Authorship↗

Standards for enabling health informatics interoperability.

Most of industry countries are turning their healthcare system towards integrated care paradigms for improving quality, efficiency, and safety of patients' care. Integrated care has to be supported by extended communication and cooperation between the involved healthcare establishments' information systems. The required interoperability level goes beyond technical interoperability and simple data exchange as it has been started in the early world of electronic data exchange (EDI). For realising semantic interoperability, series of standards must be specified, implemented and enforced. The paper classifies standards for health information systems needed for enabling practical semantic interoperability.

Germany↗

Benefits and weaknesses of health cards used in health information systems.

The acceptance-based success of modern health information systems and health networks highly depends on the respective involvement of all relevant partners into the communication and co-operation processes characterising the medical and administrative workflow. Personal information stored in a networking environment guarantee for fast access fulfilling advanced shared care requirements whereas security token like smart cards stand for identification purposes, data protection, privacy protection, access rights, and limited person-based information storage, e.g., for emergency procedures. Linking these means of information provision allows for making use of the benefits of the different technologies without ignoring their existing weaknesses. The presented paper intends to summarise the respective categories of benefits and weaknesses allowing the reader to implement cards in health information systems as well as with the related aspects of awareness, confidence, and acceptance. Concluding this analysis, the preferred way to deal with the challenges of modern healthcare and welfare requirements shall be a well-balanced combination of cards and networks.

Diffusion of Innovation↗

Modelling privilege management and access control.

OBJECTIVES: For establishing trustworthiness in advanced architectures for future-proof health information systems being open, flexible, scaleable, portable, and semantically interoperable, security and privacy services needed must be designed as an inherent part of the architecture. Such architecture has to meet the paradigms of distribution, component orientation, formal modelling, separation of logical and technological aspects, etc. METHODS: In model-driven architectures components providing security and privacy services have to be specified using the same methodology of formal models with meta-languages as expression means, as deployed in computational, technical, or medical domains. The resulting approach must be based on the ISO Reference Model-Open Distributed Processing. RESULTS: Currently, standards developing organisation are defining emerging tasks and standards for semantic interoperability and trustworthy collaboration for advanced health information systems. Communication security issues have been specified and implemented, while application security challenges such as privilege management and access control are still under development. Therefore, a series of formal models have been developed by the authors covering, e.g. domains, service delegation, claims control, policies, roles, authorisations, and access control. The required models are introduced and interpreted in a generic way. The crucial concept of security policy and its relationship to the other concepts has been considered in detail. CONCLUSION: Based on formal models, security services can be integrated into advanced systems architectures enabling semantic interoperability in the context of trustworthiness of communication and co-operation.

Access to Information↗

Electronic signatures for long-lasting storage purposes in electronic archives.

Communication and co-operation in healthcare and welfare require a certain set of trusted third party (TTP) services describing both status and relation of communicating principals as well as their corresponding keys and attributes. Additional TTP services are needed to provide trustworthy information about dynamic issues of communication and co-operation such as time and location of processes, workflow relations, and system behaviour. Legal and ethical requirements demand securely stored patient information and well-defined access rights. Among others, electronic signatures based on asymmetric cryptography are important means for securing the integrity of a message or file as well as for accountability purposes including non-repudiation of both origin and receipt. Electronic signatures along with certified time stamps or time signatures are especially important for electronic archives in general, electronic health records (EHR) in particular, and especially for typical purposes of long-lasting storage. Apart from technical storage problems (e.g. lifetime of the storage devices, interoperability of retrieval and presentation software), this paper identifies mechanisms of e.g. re-signing and re-stamping of data items, files, messages, sets of archived items or documents, archive structures, and even whole archives.

Computer Security↗

A model-driven approach for the german health telematics architectural framework and the related security infrastructure.

Shared care concepts such as managed care and continuity of care are based on extended communication and co-operation either between different health professionals, or between them and the patient. Health information systems and their components, which are very different in their structure, their behaviour, the respective data, and their semantics as well as regarding implementation details used in different environments for different purposes, have to provide intelligent interoperability. Therefore, flexibility, portability, and future-orientation must be guaranteed using the newest development of model driven architecture. The ongoing work for the German health telematics platform based on an architectural framework and a security infrastructure is described in some detail. This concept of future-proof health information networks with virtual Electronic Health Records as core application starts with multifunctional Electronic Health Cards. It fits into developments currently performed by many other developed countries in Europe and beyond.

Communication↗

Security infrastructure requirements for electronic health cards communication.

Communication and co-operation processes in the healthcare and welfare domain require a security infrastructure based on services describing status and relation of communicating principals as well as corresponding keys and attributes. Additional services provide trustworthy information on dynamic issues of communication and co-operation such as time and location of processes, workflow relations, integrity of archives and record systems, and system behaviour. To provide this communication and co-operation in a shared care environment, smart cards are widely used. Serving as storage media and portable application systems, patient data cards enable patient-controlled exchange and use of personal health data bound to specific purposes such as prescription and disease management. Additionally, patient status data such as the emergency data set or immunization may be stored in, and communicated by, patient data cards. Another deployment field of smart cards is their token functionality within a security framework, supporting basic security services such as identification, authentication, integrity, confidentiality, or accountability using cryptographic algorithms. In that context, keys, certificates, and card holder's attributes might be stored in the card as well. As an example, the German activity of introducing patient health cards and health professional cards is presented. Specification and enrolment aspects are on-going processes.

Communication↗

Security Services for the HemaCAM Project.

Within the HemaCAM project which deals with automated differential white blood cell count by image processing, a security infrastructure has been integrated. The security services for this demonstrator have been derived from the German health network ONCONET that enables a trustworthy framework for both health professionals and patients as well as supports clinical studies. For the solution, services assuring both communication security and application security have to be provided. This task has been realised by the use of the security token Health Professional Card and an appropriate Trusted Third Party infrastructure.

Communication↗

MDA-based EHR application security services.

Component-oriented, distributed, virtual EHR systems have to meet enhanced security and privacy requirements. In the context of advanced architectural paradigms such as component-orientation, model-driven, and knowledge-based, standardised security services needed have to be specified and implemented in an integrated way following the same paradigm. This concerns the deployment of formal models, meta-languages, reference models such as the ISO RM-ODP, and development as well as implementation tools. International projects' results presented proceed on that streamline.

Computer Communication Networks↗

Implementing MDA-based distributed, interoperable, flexible, scalable, portable, and secure EHR systems.

Electronic Health Record (EHR) systems provide the kernel application of health information systems and health networks which should be independent of complexity, localisation constraints, platforms, protocols, etc. Based on shared care information systems' requirements for high level interoperability, a generic component architecture has been introduced. For implementing, running and maintaining acceptable and useable health information systems components, all views of the ISO Reference Model-Open Distributed Processing have to be considered. Following the Model Driven Architecture paradigm, a reference model as well as concept-representing domain models both independent of platforms must be specified, which are combined and harmonised as well as automatically transferred into platform-specific models using appropriate tools.

Computer Communication Networks↗

Security infrastructure services for electronic archives and electronic health records.

Communication and co-operation in the domain of healthcare and welfare require a well-defined set of security services based on a Public Key Infrastructure and provided by a Trusted Third Party (TTP). These services describe both status and relation of communicating principals, corresponding keys and attributes, and the access rights to applications and data. Additional services are needed to provide trustworthy information about dynamic issues of communication and co-operation such as time and location of processes, workflow relations, and system behaviour. Legal, social, behavioural and ethical requirements demand securely stored patient information and well-established access tools and tokens. Electronic (and more specifically digital) signatures--as important means for securing the integrity of a message or file--along with certified time stamps or time signatures are especially important for purposes of data storage in electronic archives and electronic health records (EHR). While just mentioning technical storage problems (e.g. lifetime of the storage devices, interoperability of retrieval and presentation software), this paper identifies mechanisms of securing data items, files, messages, sets of archived items or documents, electronic archive structures, and life-long electronic health records. Other workshop contributions will demonstrate related aspects of policies, patient privacy, and privilege management.

Access to Information↗

Electronic signatures for long-lasting storage purposes in electronic archives.

Communication and co-operation in healthcare and welfare requires certain Trusted Third Party (TTP) services describing both status and relation of communicating principals as well as their corresponding keys and attributes. Additional TTP services are needed to provide trustworthy information about dynamic issues of communication and co-operation such as time and location of processes, workflow relations, and system behaviour. Electronic signatures based on asymmetric cryptography are important means for securing the integrity of a message or file as well as for accountability purposes including non-repudication of both origin and receipt. These electronic signatures along with certified time stamps are especially important for electronic health records (EHR), electronic archives in general, and other typical purposes of a long-lasting storage. Apart from technical storage problems (e.g. lifetime of the storage devices), this paper needs to look for mechanisms of e.g. re-signing of messages, archive details, or whole archives.

Access to Information↗