数字医疗服务评估框架:医疗技术中的信息安全和数据保护——初步经验

Jari Jääskelä, Jari Haverinen, Rauli Kaksonen, J. Reponen, Kimmo Halunen, T. Tokola, J. Röning
{"title":"数字医疗服务评估框架:医疗技术中的信息安全和数据保护——初步经验","authors":"Jari Jääskelä, Jari Haverinen, Rauli Kaksonen, J. Reponen, Kimmo Halunen, T. Tokola, J. Röning","doi":"10.23996/fjhw.111776","DOIUrl":null,"url":null,"abstract":"It is well-known that security issues in medical devices, services and applications have potentially catastrophic consequences. To avoid compromising patient data or information systems, it is essential that healthcare services and products meet the relevant information security and data protection requirements. For these reasons, the Digi-HTA assessment includes information security and data protection assessment domains. The outcome of the Digi-HTA process is a recommendation that decision-makers can use during the procurement process. We present results and experiences from the first assessments made in the Digi-HTA process.\nWe have assessed six products so far and multiple assessments are in progress. The results indicate that healthcare product manufacturers have found the process useful, and usually, the manufacturers have had to improve the security of their product during the Digi-HTA process to get a favourable recommendation for their product. The assessment processes have taken longer than expected due to shortcomings and ambiguities in the provided self-assessment forms, and due to feedback cycles and meetings prompted by assessment findings. Of the six assessed products, four received a green light in information security and data protection, whereas two have received a yellow light due to issues that were not fixed during the process. In addition to shortcomings in adhering to best practices, we have also found exploitable security issues.","PeriodicalId":424295,"journal":{"name":"Finnish Journal of eHealth and eWelfare","volume":"345 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-04-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"Digi-HTA, assessment framework for digital healthcare services: information security and data protection in health technology – initial experiences\",\"authors\":\"Jari Jääskelä, Jari Haverinen, Rauli Kaksonen, J. Reponen, Kimmo Halunen, T. Tokola, J. Röning\",\"doi\":\"10.23996/fjhw.111776\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"It is well-known that security issues in medical devices, services and applications have potentially catastrophic consequences. To avoid compromising patient data or information systems, it is essential that healthcare services and products meet the relevant information security and data protection requirements. For these reasons, the Digi-HTA assessment includes information security and data protection assessment domains. The outcome of the Digi-HTA process is a recommendation that decision-makers can use during the procurement process. We present results and experiences from the first assessments made in the Digi-HTA process.\\nWe have assessed six products so far and multiple assessments are in progress. The results indicate that healthcare product manufacturers have found the process useful, and usually, the manufacturers have had to improve the security of their product during the Digi-HTA process to get a favourable recommendation for their product. The assessment processes have taken longer than expected due to shortcomings and ambiguities in the provided self-assessment forms, and due to feedback cycles and meetings prompted by assessment findings. Of the six assessed products, four received a green light in information security and data protection, whereas two have received a yellow light due to issues that were not fixed during the process. In addition to shortcomings in adhering to best practices, we have also found exploitable security issues.\",\"PeriodicalId\":424295,\"journal\":{\"name\":\"Finnish Journal of eHealth and eWelfare\",\"volume\":\"345 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-04-14\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Finnish Journal of eHealth and eWelfare\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.23996/fjhw.111776\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Finnish Journal of eHealth and eWelfare","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.23996/fjhw.111776","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

摘要

众所周知,医疗设备、服务和应用程序中的安全问题具有潜在的灾难性后果。为了避免危及患者数据或信息系统,医疗保健服务和产品必须满足相关的信息安全和数据保护要求。因此,Digi-HTA评估包括信息安全和数据保护评估领域。Digi-HTA过程的结果是决策者可以在采购过程中使用的建议。我们介绍了在Digi-HTA过程中进行的第一次评估的结果和经验。到目前为止,我们已经评估了六种产品,并正在进行多项评估。结果表明,医疗保健产品制造商发现该过程很有用,通常,制造商必须在Digi-HTA过程中提高其产品的安全性,以获得对其产品的有利推荐。由于所提供的自我评估表格有缺点和含糊不清,以及由于评估结果所引起的反馈周期和会议,评估过程所花费的时间比预期的要长。在6个被评估的产品中,有4个产品在信息安全和数据保护方面获得了绿灯,而2个产品由于在此过程中没有解决问题而获得了黄灯。除了遵循最佳实践的缺点之外,我们还发现了可利用的安全问题。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Digi-HTA, assessment framework for digital healthcare services: information security and data protection in health technology – initial experiences
It is well-known that security issues in medical devices, services and applications have potentially catastrophic consequences. To avoid compromising patient data or information systems, it is essential that healthcare services and products meet the relevant information security and data protection requirements. For these reasons, the Digi-HTA assessment includes information security and data protection assessment domains. The outcome of the Digi-HTA process is a recommendation that decision-makers can use during the procurement process. We present results and experiences from the first assessments made in the Digi-HTA process. We have assessed six products so far and multiple assessments are in progress. The results indicate that healthcare product manufacturers have found the process useful, and usually, the manufacturers have had to improve the security of their product during the Digi-HTA process to get a favourable recommendation for their product. The assessment processes have taken longer than expected due to shortcomings and ambiguities in the provided self-assessment forms, and due to feedback cycles and meetings prompted by assessment findings. Of the six assessed products, four received a green light in information security and data protection, whereas two have received a yellow light due to issues that were not fixed during the process. In addition to shortcomings in adhering to best practices, we have also found exploitable security issues.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信