Skip to main content
Top
Published in: BMC Medical Informatics and Decision Making 1/2023

Open Access 01-12-2023 | Research

Integrated personal health record (PHR) security: requirements and mechanisms

Authors: Azamossadat Hosseini, Hassan Emami, Yousef Sadat, Somayeh Paydar

Published in: BMC Medical Informatics and Decision Making | Issue 1/2023

Login to get access

Abstract

Background

Personal Health Records (PHRs) are designed to fulfill the goals of electronic health (eHealth) and empower the individual in the process of self-care. Integrated PHR can improve the quality of care, strengthen the patient-healthcare provider relationship, and reduce healthcare costs. Still, the process of PHR acceptance and use has been slow and mainly hindered by people’s concerns about the security of their personal health information. Thus, the present study aimed to identify the Integrated PHR security requirements and mechanisms.

Methods

In this applied study, PHR security requirements were identified with a literature review of (library sources, research articles, scientific documents, and reliable websites). The identified requirements were classified, and a questionnaire was developed accordingly. Thirty experts completed the questionnaire in a two-round Delphi technique, and the data were analyzed by descriptive statistics.

Results

The PHR security requirements were identified and classified into seven dimensions confidentiality, availability, integrity, authentication, authorization, non-repudiation, and right of access, each dimension having certain mechanisms. On average, the experts reached an agreement about the mechanisms of confidentiality (94.67%), availability (96.67%), integrity (93.33%), authentication (100%), authorization (97.78%), non-repudiation (100%), and right of access (90%).

Conclusion

Integrated PHR security is a requirement for its acceptance and use. To design a useful and reliable integrated PHR, system designers, health policymakers, and healthcare organizations must identify and apply security requirements to guarantee the privacy and confidentiality of data.
Appendix
Available only for authorised users
Literature
4.
6.
go back to reference Paydar S, Emami H, Asadi F, Moghaddasi H, Hosseini A. Functions and outcomes of personal health records for patients with chronic diseases: a systematic review. Perspect Health Inf Manag 2021, 18(Spring). Paydar S, Emami H, Asadi F, Moghaddasi H, Hosseini A. Functions and outcomes of personal health records for patients with chronic diseases: a systematic review. Perspect Health Inf Manag 2021, 18(Spring).
9.
go back to reference Harahap NC, Handayani PW, Hidayanto AN. The Challenges in Integrated Personal Health Record Adoption in Indonesia: A Qualitative Analysis of Regulatory Perspectives. In: 2021 International Conference on Informatics, Multimedia, Cyber and Information System (ICIMCIS: 2021: IEEE; 2021: 169–174. https://doi.org/10.1109/ICIMCIS53775.2021.9699353. Harahap NC, Handayani PW, Hidayanto AN. The Challenges in Integrated Personal Health Record Adoption in Indonesia: A Qualitative Analysis of Regulatory Perspectives. In: 2021 International Conference on Informatics, Multimedia, Cyber and Information System (ICIMCIS: 2021: IEEE; 2021: 169–174. https://​doi.​org/​10.​1109/​ICIMCIS53775.​2021.​9699353.
10.
go back to reference Alkhatlan H. Evaluation of young adults’ Preferences, needs, and the understandability of the Personal Health Record Data contents. University of Pittsburgh; 2010. Alkhatlan H. Evaluation of young adults’ Preferences, needs, and the understandability of the Personal Health Record Data contents. University of Pittsburgh; 2010.
12.
go back to reference AHIMA e-HIM Personal Health Record Work Group. Defining the personal health record. Journal of AHIMA 2005, 76(6):24-25.2005. AHIMA e-HIM Personal Health Record Work Group. Defining the personal health record. Journal of AHIMA 2005, 76(6):24-25.2005.
23.
go back to reference Daglish D, Archer N. Electronic personal health record systems: a brief review of privacy, security, and architectural issues. In: Privacy, Security, Trust and the Management of e-Business, 2009 CONGRESS’09 World Congress on: 2009: IEEE; 2009: 110–120. https://doi.org/10.1109/CONGRESS.2009.1. Daglish D, Archer N. Electronic personal health record systems: a brief review of privacy, security, and architectural issues. In: Privacy, Security, Trust and the Management of e-Business, 2009 CONGRESS’09 World Congress on: 2009: IEEE; 2009: 110–120. https://​doi.​org/​10.​1109/​CONGRESS.​2009.​1.
27.
go back to reference US Department of Health Human Services. Literature review and environmental scan: evaluation of personal health records pilots for fee-forservice Medicare enrollees from South Carolina. 2010, 17:2012. US Department of Health Human Services. Literature review and environmental scan: evaluation of personal health records pilots for fee-forservice Medicare enrollees from South Carolina. 2010, 17:2012.
29.
30.
go back to reference Rodolfo IMS. Design strategy for Integrated Personal Health Records: improving the user experience of Digital Healthcare and Wellbeing. Universidade NOVA de Lisboa (Portugal); 2017. Rodolfo IMS. Design strategy for Integrated Personal Health Records: improving the user experience of Digital Healthcare and Wellbeing. Universidade NOVA de Lisboa (Portugal); 2017.
31.
go back to reference Alyami MA. Toward patient-centered personal health records systems to promote evidence-based decision-making and information sharing. Towson University; 2018. Alyami MA. Toward patient-centered personal health records systems to promote evidence-based decision-making and information sharing. Towson University; 2018.
34.
36.
go back to reference Padol PR, More HK, Mandre NV, Shimpi PN. Personal health records in cloud computing. Int Res J Eng Technol. 2018;5(2):1666–73. Padol PR, More HK, Mandre NV, Shimpi PN. Personal health records in cloud computing. Int Res J Eng Technol. 2018;5(2):1666–73.
38.
go back to reference Wang C-K. Security and privacy of personal health record, electronic medical record and health information. Probl Perspect Manage. 2015;13(4):19–26. Wang C-K. Security and privacy of personal health record, electronic medical record and health information. Probl Perspect Manage. 2015;13(4):19–26.
40.
go back to reference Kiourtis A, Mavrogiorgou A, Mavrogiorgos K, Kyriazis D, Graziani A, Symvoulidis C, et al. Electronic Health Records at People’s Hands across Europe: the InteropEHRate Protocols. In: pHealth 2022. IOS Press; 2022. pp. 145–50. https://doi.org/10.3233/SHTI220973. Kiourtis A, Mavrogiorgou A, Mavrogiorgos K, Kyriazis D, Graziani A, Symvoulidis C, et al. Electronic Health Records at People’s Hands across Europe: the InteropEHRate Protocols. In: pHealth 2022. IOS Press; 2022. pp. 145–50. https://​doi.​org/​10.​3233/​SHTI220973.
41.
go back to reference Hansen A. Guidelines on Minimum/Non-Exhaustive patient Summary dataset for Electronic Exchange in Accordance with the Cross-Border Directive 2011/24. In.: European Commission; 2013. Hansen A. Guidelines on Minimum/Non-Exhaustive patient Summary dataset for Electronic Exchange in Accordance with the Cross-Border Directive 2011/24. In.: European Commission; 2013.
44.
go back to reference Coatrieux G. Contribution au contrôle d’intégrité des images médicales. Université de Rennes 1; 2011. Coatrieux G. Contribution au contrôle d’intégrité des images médicales. Université de Rennes 1; 2011.
49.
go back to reference Dubbink D. Personal health records in dutch hospitals: is hte hype already over? University of Twente; 2013. Dubbink D. Personal health records in dutch hospitals: is hte hype already over? University of Twente; 2013.
50.
go back to reference Keikavousi MR, Asadi F, Paydar S, Khounraz F. Development of Inflammatory Bowel Diseases Registry Software. Middle East J Dig Dis 2021, 13(2):145. https://doi.org/0.34172/mejdd.2021.218. Keikavousi MR, Asadi F, Paydar S, Khounraz F. Development of Inflammatory Bowel Diseases Registry Software. Middle East J Dig Dis 2021, 13(2):145. https://​doi.​org/​0.​34172/​mejdd.​2021.​218.​
51.
go back to reference Mishra P. User interface design: for existing system monitoring application. 2013. Mishra P. User interface design: for existing system monitoring application. 2013.
53.
go back to reference Dimitropoulos LL. Privacy and security solutions for interoperable health information exchange. Impact analysis. RTI International: 2007. Dimitropoulos LL. Privacy and security solutions for interoperable health information exchange. Impact analysis. RTI International: 2007.
Metadata
Title
Integrated personal health record (PHR) security: requirements and mechanisms
Authors
Azamossadat Hosseini
Hassan Emami
Yousef Sadat
Somayeh Paydar
Publication date
01-12-2023
Publisher
BioMed Central
Published in
BMC Medical Informatics and Decision Making / Issue 1/2023
Electronic ISSN: 1472-6947
DOI
https://doi.org/10.1186/s12911-023-02225-0

Other articles of this Issue 1/2023

BMC Medical Informatics and Decision Making 1/2023 Go to the issue