How to manage secure direct access of European patients to their computerized medical record and personal medical record.

Citation:

Quantin C, Allaert FA, Fassa M, Riandey B, Avillach P, Cohen O. How to manage secure direct access of European patients to their computerized medical record and personal medical record. Stud Health Technol Inform 2007;127:246-55.

Date Published:

2007

Abstract:

The multiplication of the requests of the patients for a direct access to their Medical Record (MR), the development of Personal Medical Record (PMR) supervised by the patients themselves, the increasing development of the patients' electronic medical records (EMRs) and the world wide internet utilization will lead to envisage an access by using technical automatic and scientific way. It will require the addition of different conditions: a unique patient identifier which could base on a familial component in order to get access to the right record anywhere in Europe, very strict identity checks using cryptographic techniques such as those for the electronic signature, which will ensure the authentication of the requests sender and the integrity of the file but also the protection of the confidentiality and the access follow up. The electronic medical record must also be electronically signed by the practitioner in order to get evidence that he has given his agreement and taken the liability for that. This electronic signature also avoids any kind of post-transmission falsification. This will become extremely important, especially in France where patients will have the possibility to mask information that, they do not want to appear in their personal medical record. Currently, the idea of every citizen having electronic signatures available appears positively Utopian. But this is yet the case in eGovernment, eHealth and eShopping, world-wide. The same was thought about smart cards before they became generally available and useful when banks issued them.