Mobile Electronic Medical Records James T. Monastra Virginia Wesleyan College August 6, 2007
The Remote Medicine Maze
Entering the Maze
The Concept Patient’s medical records are maintained on a secure portable device. Patient’s medical records are maintained on a secure portable device. Information is immediately available to Emergency Technicians. Information is immediately available to Emergency Technicians. Information is available to doctors and hospital staff. Information is available to doctors and hospital staff. Serves as the entry point to remote medical systems. Serves as the entry point to remote medical systems.
State-of-the-Art Authentication Password / Username Password / Username Smart Cards Smart Cards Particular Biometrics Particular Biometrics Storage Paper Filing System Paper Filing System
Password / Username Authenticates user by “something you know” Authenticates user by “something you know” Most common authentication method Most common authentication method Joint responsibility Joint responsibility Memorization Memorization Confidentiality Confidentiality Security Security
Smart Cards Authenticates user by “something you have” Authenticates user by “something you have” Capable of two-factor authentication Capable of two-factor authentication “Pocket-sized cards with embedded integrated circuits” “Pocket-sized cards with embedded integrated circuits” User-friendly User-friendly Password concerns Password concerns
Biometric Authentication by “who you are” Authentication by “who you are” “identification based on physiological or behavioral characteristics” “identification based on physiological or behavioral characteristics” Cannot forget, lose, or give away a part of you (except for injury) Cannot forget, lose, or give away a part of you (except for injury)
Commonly used Biometrics Hand Geometry Hand Geometry Retina Scanner Retina Scanner Speaker Recognition Speaker Recognition Fingerprint Scanner Fingerprint Scanner
Storage (Paper-filing System) Widely accepted Widely accepted Significant disadvantages Significant disadvantages i. Unavailability ii. Illegibility iii. Inability to be accessed remotely
Biometric authentication Biometric authentication Mobile Electronic Device Mobile Electronic Device Stealth MXP Stealth MXP Solution
Stealth MXP Memory Experts International Memory Experts International Portable secure storage Portable secure storage Biometric & Password Authentication Biometric & Password Authentication Encryption Encryption
Requirements Privacy (HIPAA) Privacy (HIPAA) Security (HIPAA) Security (HIPAA) Portability Portability Availability Availability Reliability Reliability User Acceptance User Acceptance
Privacy and Security Advanced Encryption Standard (AES) HMAC-based One Time Password (HOTP) Rivest, Shamir, Adleman (RSA) Biometric and Password capabilities Federal Information Processing Standard
Portability and Availability USB Flash Drive 24/7 Patient Access ACCESS Console and Client software Multi-patient (Family)
Reliability and User Acceptance Strong Security Easily Mobile Cost concerns Incentives
HOSPITAL RECORDS Information Partitioning PERSONAL RECORDS EMERGENCY DATA Personal Contact Information Medical Conditions (Illness, Allergies) Medications Physician’s Contact Information Personal Contact Information Family Contact Information Medical Conditions (Illness, Allergies) Medications Complete Medical History Physician’s Contact Information Insurance Contact Information Personal Contact Information Family Contact Information Medical Conditions (Illness, Allergies) Medications Complete Medical History Physician’s Contact Information Insurance Contact Information Records and Specialty Contact Information
HOSPITAL RECORDS Information Availability PERSONAL RECORDS EMERGENCY DATA Available to All No ID NO Password Available to Selected Personnel Requires ID Requires Password Available to Selected Personnel Available to Medical and Hospital Personnel Requires ID Requires Password
An Example
Any Questions??