Operational Aspects (Encryption and Data Storage) in E-Prescription



Similar documents
How To Write An Eprescription In Dubai

EHR central system advantages and disadvantages, the case of Estonia. Estonian E-health Foundation Raul Mill

WEB SERVICES SECURITY

Electronic Prescription Service Implementation Strategy

Web Services and Service Oriented Architectures. Thomas Soddemann, RZG

Concept Series Paper on Electronic Prescribing

E-Health in The Netherlands

Running head: HEALTHCARE... ELECTRONIC PRESCRIBING 1

RECIP-E INTEGRATION SPECIFICATION DRAFT

Integration of Hotel Property Management Systems (HPMS) with Global Internet Reservation Systems

Digitization of Healthcare Information System (CSIOZ)

D . A reliable and secure online communication platform. Armin Wappenschmidt (secunet) More information:

Table of Contents. Page 1

EHR STRATEGY FINLAND. Kari Harno Helsinki University Central Hospital

RECIP-E INTEGRATION SPECIFICATION DRAFT

Instructions on TLS/SSL Certificates on Yealink Phones

Network Security Protocols

Tips and Tricks for Deploying BI Web Services Within Your Web Intelligence Environment Chris Greer EV Technologies

Electronic Prescription Service. Guidance for community pharmacy contractors on implementing Release 1

NCPDP Electronic Prescribing Standards

Αthina Triantafyllidi, Director IDIKA S.A

Entrust Managed Services PKI. Getting started with digital certificates and Entrust Managed Services PKI. Document issue: 1.0

MEDICFUSION / HERFERT. MEANINGFUL USE STAGE 1 and 2 ATTESTATION GUIDE 2015

mkryptor allows you to easily send secure s. This document will give you a technical overview of how. mkryptor is a software product from

Application Integration and Semantic Integration in Electronic Prescription Systems

FREQUENTLY ASKED QUESTIONS

Eligible Professionals please see the document: MEDITECH Prepares You for Stage 2 of Meaningful Use: Eligible Professionals.

Savitribai Phule Pune University

Norwegian e-health Infrastructure based on XML, ebxml and PKI

Advanced Authentication

Prescription Monitoring Program Information Exchange Service. Execution Context Version 1.0

AN ACT RELATING TO HEALTH COVERAGE; ENACTING SECTIONS OF THE HEALTH CARE PURCHASING ACT, THE PUBLIC ASSISTANCE ACT, THE NEW MEXICO

Privacy, Security, and Trust with Federated Identity Management

Overview of CSS SSL. SSL Cryptography Overview CHAPTER

Faculty Disclosure. Pharmacist Learning Objectives. Pharmacy e-hit: The Future of Pharmacy and Patient Care

TRANSFORMING HEALTH SYSTEM WITH IT Ain Aaviksoo, MD MPH. Deputy Secretary General for eservices & Innovation Ministry of Social Affairs of Estonia

10/1/2015. National Library of Medicine definition of medical informatics:

Electronic Prescribing and Eligibility System. pes. A system based on lessons learned in Europe

Health Information Technology: A Key Component of Health Reform

11/26/2012. Implementation of Florida s PDMP. Disclosure

Health Information Technology

Wakefield Council Secure and file transfer User guide for customers, partners and agencies

Why should I report issues directly through my pharmacy management system vendor and not Surescripts?

Participating in a Health Information Exchange (HIE) Many Faces of Community Health /27/11 Greg Linden

Securing your Online Data Transfer with SSL

E-Prescribing and the Medicare Prescription Drug Program. Maria A. Friedman, DBA Office of E-Health Standards and Services November 17, 2005

INSTRUCTIONS FOR USE: OA-RX

Health Information Exchange (HIE) in Minnesota

David A. Wang, MD Primary Care Sports Medicine Physician PRINT NAME: ADDRESS: DOB: AGE: SEX: SS# HOME: MOBILE PHONE: WORK: FAX:


MEDICAL ASSISTANCE BULLETIN

Introduction to Service Oriented Architectures (SOA)

Electronic Prescribing of Controlled Substances Technical Framework Panel. Mark Gingrich, RxHub LLC July 11, 2006

Security Issues In Cloud Computing and Countermeasures

SOLUTIONS FOR HEALTHCARE PROFESSIONALS AND GOVERNMENTS

How To Understand The Benefits Of Electronic Prescribing

Digital Certificates (Public Key Infrastructure) Reshma Afshar Indiana State University

BUSTER SYSTEM CLINICAL AND LOGISTIC MANAGEMENT OF DRUGS. Pharmacy Logistics. CONTACT

The basics of Health Information Technology

E-Signature. The Pharmacy Perspective

Connected from everywhere. Cryptelo completely protects your data. Data transmitted to the server. Data sharing (both files and directory structure)

E Mail Encryption End User Guide

e -Prescribing An Information Brief

Electronic Prescriptions for Controlled Substances (EPCS)

POINT OF CLARIFICATION

Authentication & Digital Signature

Using etoken for Securing s Using Outlook and Outlook Express

ENS4Care Questionnaire

Electronic Prescribing of Controlled Substances: Establishing a Secure, Auditable Chain of Trust

ICT in the National Health System

Policy on the Appropriate Use of Telemedicine Technologies in the Practice of Medicine

Frequently Asked Questions. Frequently Asked Questions SSLPost Page 1 of 31 support@sslpost.com

MAKING HEALTH INFORMATION ACCESSIBLE & SECURE. w w w. i m e d i c o r. c o m

Transcription:

Master of Science in Biomedical Engineering Exam Presentation Medical Informatics Operational Aspects (Encryption and Data Storage) in E-Prescription Thomas Gijs Roel Rynders 12/05/2014

Overview Introduction Data storage Encryption Recip-e Summary

Introduction Definition: Electronic prescribing, or e-prescribing is the computer-based electronic generation and transmission of a prescription, taking the place of paper and faxed prescriptions.

Introduction Medical doctor prescribes drugs Information about prescription is stored on a server Pharmacist can retrieve prescription and delivers the drug

Example from Estonia Estonian digital prescription system - how does it work? online video, accessed 5 May 2014, <https://www.youtube.com/watch?v=m9rtzm2kj78>

Introduction E-Prescribing and Medication Management webinar, Agency for Healthcare and Research Quality (AHRQ), March 31, 2009

Introduction Goal: Reduce medical errors and deaths Reduce the financial costs Eliminate prescription fraud

Data storage in E-Prescription Web service according W3C a software system designed to support interoperable machine-to-machine interaction over a network. It has an interface described in a machine-processable format (specifically WSDL). Other systems interact with the Web service in a manner prescribed by its description using SOAP messages, typically conveyed using HTTP with an XML serialization in conjunction with other Webrelated standards Php-based in browser

Data storage in E-Prescription XML-tags Submitter s Name Submitter ID Patients Name National Provider Identifier Tax Identification Number Drug Identification Number

Example <Prescription> <Patient> <Patient_name>John Taylor </Patient name> <Identification> 5765766677</Identification> <Medicine> <Medicine_name>Panadol</Medicine> <Disease>fewer</Disease> <Quantity>30</Quantity> <Dose>One tablet three times a day</dose> </Medicine> </Patient> </Prescription>

Data storage in E-Prescription Validation KMEHR Database from BCFI or RxNorm Independent of program that is used

Data storage in E-Prescription CDSS (clinical decision support system) Drug drug interactions can be noticed Same drugs from different manufacturers Data used in research

Data storage in E-Prescription Easy accessibility is needed Doctor not always in cabinet Ambulatory: PDA or laptop that can read e-id Possible with current 3G/4G coverage

Encryption in E-Prescription Confidential information use encryption to guarantee privacy 2 types of encryption: Symmetric Asymmetric Sending encrypted messages over network: typically symmetric + assymetric

Encryption in E-Prescription Symmetric Asymmetric

Encryption in E-Prescription Important considerations: Who should get decryption keys? (e.g. patient, pharmacist(s), prescriber, ) When encryption? (e.g. while electronic transfer, during intermediate storage, from creation untill reading by pharmacist) Who controls data privacy in an electronic transfer of prescriptions (ETP) system?

Encryption in E-Prescription Asymmetric key pair to all ETP professionals, directly encrypt for dispenser Key pairs to groups of ETP professionals, directly encrypt for group Asymmetric key pair to all ETP professionals, but only encryption when transfer to and from secure central storage Asymmetric key pairs to all patients, encrypt for the patient Symmetric key to patient, prescription in secure central storage

Encryption in E-Prescription Who controls data privacy in an electronic transfer of prescriptions (ETP) system? Patient control Patient controls own data privacy + flexibility (choice of pharmacy) e.g. Smartcard Barcode

Encryption in E-Prescription Who controls data privacy in an electronic transfer of prescriptions (ETP) system? Healthcare professional control e.g. Direct transfer encrypted data from prescriber to pharmacy/pharmacist(s) BUT: loss of flexibility

Encryption in E-Prescription Who controls data privacy in an electronic transfer of prescriptions (ETP) system? Sender Storage device administrator control e.g. Encryption Central Storage Device Decryption Encryption Decryption Receiver Can only be decrypted by key known by central storage device Sender Encryption Decryption Central Storage Device Encryption Decryption Receiver

Encryption in E-Prescription Example of an ETP system: Salford Model (UK) Security issues in the electronic transmission of prescriptions, D.P. Mundy and D. W. Chadwick, Med Inform Internet Med. 2003 Dec;28(4):253-77.

E-prescribing in Belgium: Recip-e

Data storage E-prescribing in Belgium: Temporary storage of prescription on recip-e server Decryption keys stored on ehealth platform Prescription format = XML KMEHR message Prescription software responsible for validation XSD validation Additional validation Recip-e

E-prescribing in Belgium: Additional validation Recip-e

Encryption E-prescribing in Belgium: End-to-end secured Recip-e Encryption before transmission and stored in encrypted form Symmetric encryption of prescription ( nonaddressed message ) Key linked to message NOT to actor (via ehealth) PKI infrastructure (via ehealth) for transport

Encryption E-prescribing in Belgium: Addressed encryption: public key of recipient received from ehealth service For transport Recip-e For storage (feedbacks/notifications) Non-addressed encryption: symmetric key provided by ehealth For storage (prescription)

Summary Electronic prescriptions are a secure way to create and transmit prescriptions Data stored in XML (validation possible) Communication through web services Encryption to ensure privacy During storage During transmission

Questions?