Enhancing Privacy Controls for Patients via a Selective Authentic Electronic Health Record Exchange Service: Qualitative Study of Perspectives by Medical Professionals and Patients

被引:14
作者
Alaqra, Ala Sarah [1 ]
Fischer-Hubner, Simone [1 ]
Framner, Erik [2 ]
机构
[1] Karlstad Univ, Dept Comp Sci, Privacy & Secur Res Grp, Univ Gatan 2, S-65188 Karlstad, Sweden
[2] Karlstad Univ, Dept Informat Syst, Karlstad, Sweden
关键词
privacy; patient data privacy; electronic health record; user control; data protection; data security; eHealth; human computer interaction; INFORMATION; SECURITY; EHEALTH;
D O I
10.2196/10954
中图分类号
R19 [保健组织与事业(卫生事业管理)];
学科分类号
摘要
Background: Patients' privacy is regarded as essential for the patient-doctor relationship. One example of a privacy-enhancing technology for user-controlled data minimization on content level is a redactable signature. It enables users to redact personal information from signed documents while preserving the validity of the signature, and thus the authenticity of the document. In this study, we present end users' evaluations of a Cloud-based selective authentic electronic health record (EHR) exchange service (SAE-service) in an electronic health use case. In the use case scenario, patients were given control to redact specified information fields in their EHR, which were signed by their doctors with a redactable signature and transferred to them into a Cloud platform. They can then selectively disclose the remaining information in the EHR, which still bears the valid digital signature, to third parties of their choice. Objective: This study aimed to explore the perceptions, attitudes, and mental models concerning the SAE-service of 2 user roles: signers (medical professionals) and redactors (patients with different technical knowledge) in Germany and Sweden. Another objective was to elicit usability requirements for this service based on the analysis of our investigation. Methods: We chose empirical qualitative methods to address our research objective. Designs of mock-ups for the service were used as part of our user-centered design approach in our studies with test participants from Germany and Sweden. A total of 13 individual walk-throughs or interviews were conducted with medical staff to investigate the EHR signers' perspectives. Moreover, 5 group walk-throughs in focus groups sessions with (N=32) prospective patients with different technical knowledge to investigate redactor's perspective of EHR data redaction control were used. Results: We found that our study participants had correct mental models with regard to the redaction process. Users with some technical models lacked trust in the validity of the doctor's signature on the redacted documents. Main results to be considered are the requirements concerning the accountability of the patients' redactions and the design of redaction templates for guidance and control. Conclusions: For the SAE-service to be means for enhancing patient control and privacy, the diverse usability and trust factors of different user groups should be considered.
引用
收藏
页数:23
相关论文
共 37 条
  • [1] Putting the Focus Back on the Patient: How Privacy Concerns Affect Personal Health Information Sharing Intentions
    Abdelhamid, Mohamed
    Gaia, Joana
    Sanders, G. Lawrence
    [J]. JOURNAL OF MEDICAL INTERNET RESEARCH, 2017, 19 (09)
  • [2] Alaqra A, 2016, HAISA, P220
  • [3] [Anonymous], 2005, CHI 05 EXTENDED ABST, DOI DOI 10.1145/1056808.1057073
  • [4] Benenson Zinaida, 2014, Human Aspects of Information Security, Privacy, and Trust. Second International Conference, HAS 2014, Held as Part of HCI International 2014. Proceedings: LNCS 8533, P375, DOI 10.1007/978-3-319-07620-1_33
  • [5] Outsourcing Medical Data Analyses: Can Technology Overcome Legal, Privacy, and Confidentiality Issues?
    Brumen, Bostjan
    Hericko, Marjan
    Sevcnikar, Andrej
    Zavrsnik, Jernej
    Hoelbl, Marko
    [J]. JOURNAL OF MEDICAL INTERNET RESEARCH, 2013, 15 (12)
  • [6] Patients want granular privacy control over health information in electronic medical records
    Caine, Kelly
    Hanania, Rima
    [J]. JOURNAL OF THE AMERICAN MEDICAL INFORMATICS ASSOCIATION, 2013, 20 (01) : 7 - 15
  • [7] Are Personal Health Records Safe? A Review of Free Web-Accessible Personal Health Record Privacy Policies
    Carrion Senor, Inmaculada
    Luis Fernandez-Aleman, Jose
    Toval, Ambrosio
    [J]. JOURNAL OF MEDICAL INTERNET RESEARCH, 2012, 14 (04) : e114
  • [8] Cavoukian A., 2009, Privacy by design. Take the challenge. Information and privacy commissioner of Ontario
  • [9] A cross-national analysis of eHealth in the European Union: Some policy and research directions
    Currie, Wendy L.
    Seddon, Jonathan J. M.
    [J]. INFORMATION & MANAGEMENT, 2014, 51 (06) : 783 - 797
  • [10] Derler D, 2015, LNCS, P3, DOI DOI 10.1007/978-3-319-30840-11