You are on page 1of 5

2008 International Conference on BioMedical Engineering and Informatics

Protection of Patient’s Privacy and Data Security in


E-Health Services
Yi Hong1, 2, Timothy B. Patrick2, Rick Gillis1
1
Medical College of Wisconsin and 2University of Wisconsin – Milwaukee
Milwaukee, WI
yhong@mcw.edu, tp5@uwm.edu, rgillis@mcw.edu

Abstract questions. Online appointment services in particular


are the most common e-Health services.
E-Health involves new forms of patient-physician Healthcare consumers have the right to expect that
interaction and poses new ethical challenges and their personal data will be kept confidential. Since
threats to patient privacy. This paper reviews Health online appointment services are the most common e-
On the Net Foundation Code of Conduct (HONcode) Health services, this study reviews HONcode
accredited e-Health websites that provide online accredited websites that provide online appointment
appointment services in the U.S.A for compliance services for compliance with basic principles of
with basic principles of security and privacy. We security and privacy.
found that 20 of 30 HON sites we reviewed are
secure sites but only 8 of 20 secure sites state that it
2. Background: the need for Consumer
is secure. Most HON sites require patients to submit
confidential data. 12 of 30 websites do not display Protections
privacy notice on the web appointment request page.
The reading level might be a problem for the patients Despite its advantages for healthcare consumers, e-
who have lower educational background to Health poses new challenges and threats to their
understand the privacy notice. Regulations and privacy. Many healthcare consumers are not aware
guidelines do not ensure that privacy protection and that their use of healthcare resources on the Internet
data security is done appropriately or well. More may be tracked. Consumers may also not be aware
attention to security methods and procedures is of the personal information gathered about them
needed to safeguard patients’ privacy rights. when visiting a website.[2] For example, consumers
may not be aware that their personal information may
be collected without acknowledgment by cookies, nor
1. Introduction how it may be used when it is collected by other
mechanisms such as online surveys and assessments.
E-Health is “…the application of Internet and other In this case, rating and accreditation standards or
related technologies in the healthcare industry to regulations such as the E-Health Code of Ethics,
improve the access, efficiency, effectiveness, and Health Insurance Portability and Accountability Act
quality of clinical and business processes utilized by (HIPAA), and the HONcode are critical to the
healthcare organizations, practitioners, patients, and success of e-Health services.
consumers in an effort to improve the health status of
patients.”[1] E-Health can provide healthcare E-Health Code of Ethics. To protect consumers’
consumers with opportunities to interact with their privacy and personal data, the e-Health Code of
healthcare systems online and can provide new forms Ethics requires e-Health websites to clearly disclose
of patient-physician interaction. potential user privacy risks and clearly indicate what
data are being collected when users visit the site, who
Various services may be provided by an e-Health is collecting the data, how the data will be used, and
site. It may provide healthcare consumers access to whether the site will share data (with whom and for
internet-based tools to monitor their health records, what purpose).[3]
view test results, refill prescriptions, schedule
appointments, communicate electronically with their HIPAA. While the e-Health Code of Ethics requires
personal care physician, and get online reference e-Health sites to adopt reasonable mechanisms to
services from health librarians to help answer their trace how personal data is processed to ensure the

978-0-7695-3118-2/08 $25.00 © 2008 IEEE 643


DOI 10.1109/BMEI.2008.331
security of patients’ personal data, HIPAA 3. Methods
regulations aim to inform and educate patients about
their privacy rights and establish standards for the We searched for HONcode accredited sites using the
privacy and security of health information. HON search engine [8] with the query “web
The HIPAA Privacy Rule protects all “individually appointment request” on November 16 2007. The
identifiable health information” in any form or search retrieved 170 HONcode accredited sites. We
media. This information is called “protected health reviewed the 30 USA websites that actually provided
information (PHI)”, and includes many common online appointment services. The 30 sites are listed
identifiers (e.g. name, address, birth date, Social in Table 1.
Security Number (SSN)).
We reviewed each of the 30 sites to determine:
The Privacy Rule requires covered entities to provide (1) Is it a secure site?
patients with a Notice of Privacy Practices. The (2) Does it include a statement regarding its status as
Notice must describe the ways in which the covered a secure site?
entity may use and disclose protected health (3) Does it request confidential data elements from
information. the user making an appointment?
(4) Does it include a privacy notice or statement of
According to HIPAA, a covered entity must maintain privacy policy?
reasonable and appropriate administrative, physical (5) What is the reading level of the privacy notice or
and technical safeguards to prevent intentional or statement of privacy policy?
unintentional use or disclosure of PHI in violation of
the Privacy Rule. [4] We considered a site to be secure if it used HTTPS,
The HONcode. The Health On the Net Foundation which is a “…combination of a normal HTTP
(HON) is another effort to protect consumers. HON interaction over an encrypted Secure Sockets Layer
was founded in 1995 to promote "…the effective and (SSL) or Transport Layer Security (TLS) transport
reliable use of the new technologies for telemedicine mechanism.” [9]
in healthcare around the world." The HONcode was
developed We used the SMOG Calculator [10] to assess the
educational level needed to fully understand the text
…to help standardize the reliability of of the privacy notice or statement of privacy policy.
medical and health information available on We coded SMOG grade <12 (high school level) as
the World-Wide Web. [5] low level (l), SMOG grade 12-16 (college level) as
medium level (m), SMOG grade >16 (university
Currently there are more than 120,000 health-related degree) as high level (h).
websites that are HONcode accredited. [6] The
HONcode principle regarding privacy and 4. Results
confidentiality states that
Table 1 shows the results of the review.
Your site must describe how you treat
confidential, private or semi-private 4.1. Is it a secure site?
information such as email addresses and the
content of emails received from or sent to Among the 30 HON sites, 20 sites are secure sites, 10
your visitors. You must inform your visitors are not.
whether their data will be recorded in your
own database, who can access this database 4.2. Does it include a statement regarding its
(others, only you, nobody), if this status as a secure site?
information is used for your own statistics
(anonymous or not), or if these statistics are Among the 20 secure sites, only 9 of them state that
used by third party or other companies. they are secure.
A statement or a privacy policy page 4.3. Does it request confidential data elements
regarding confidentiality of data must be
from the user making an appointment?
clearly displayed. [7]
Most of the HON sites require patients to submit
confidential data such as Social Security Number,

644
date of birth, medical record number, medical them require patients to provide birth date
information, insurance information, etc. Almost all of information.

Table 1 Review of the HONcode accredited websites for compliance with basic principles of
security and privacy
Criteria
Online Appointment Site 1 2 3 4 5

https://epatient.muhealth.org/UMCWeb/idxpol/pslogin.asp (Click “Visit as a Guest” to y y n y m


access to the secure Web appointment access form)
https://forms.mayoforms.org/forms/up/mc408606.cfm (Access to the secure site through: y n y y m
http://www.mayoclinic.org/patientinfo/appointments.html)
https://secure.childrensmemorial.org/kids_doc/apptForm.asp y n y y h
https://secure.mcw.edu/appt_form.htm y y y y l
https://secure01.cqservices.com/guthrie/FindAPhysician/Physicians/Default.asp?mode=ne y n y y h
w
https://transact.med.yale.edu/ynhhphysiciandata/apptrequestform.asp?inst=ynhh y n y y m
https://www.brighamandwomens.org/forms/RequestAppointment.aspx y y y y m
https://www.clevelandclinic.org/myappointment/form.asp y n y n na
https://www.dfci.harvard.edu/pat/becoming/request/Default.asp y n y y m
https://www.forsberg.com/sparrowsecure/preregister1.asp y n y n na
https://www.geisinger.org/patients/appts/appt_form.html y y y y m
https://www.jeffersonhospital.org/cgi-bin/jeffnowappt/apptfrmloc.cgi?tjuh++++0 y n y n na
https://www.marshfieldclinic.org/patients/pages/default.aspx?page=apptrequest y n y y m
https://www.meei.harvard.edu/db/appoint.php y n y y m
https://www.muschealth.com/patients_visitors/eservices/request_appointment/request_app y y y y m
ointment.htm
https://secure.opi.upmc.edu/webscheduling/Pat_demo.cfm?select_site=STERGIOS y n n y m
https://www.summitprimarycare.com/secureforms/register.asp y y y y m
https://www.sleh.com/sleh/SectionSecured/index.cfm?PageName=PRForm&PageMD=PH y y n y m
YSICIAN%20REFERRALS&FormMD=On
https://www.utphysicians.org/Appointment/forms/default.htm y y y n na
https://www.ucsfhealth.org/adult/patient_guide/request_primary_care.html y y y n na
http://nmhphysicians.photobooks.com/Appointment.asp?disclaimer=Continue n na y y h
http://www.dentalgentlecare.com/make_appointment.htm n na n n na
http://www.depediatrics.com/appointment.php n na n n na
http://www.englewoodortho.com/new_pt_form.htm n na y n na
http://www.evpeds.com/onlineappt.htm n na y y m
http://www.healthgrades.com/consumer/index.cfm?fuseaction=mod&modtype=prc&moda n na y n na
ct=view_appt&hgid=HGPY01C99FF3875647053&type=emailphone&tv=Report_EmailLi
nk&TV_LID=BTN_Apt
http://www.jhintl.net/forpatients/page.aspx?id=2338 n na n n na
http://www.mscenter.org/content/category/1/1/15/ n na y y h
http://www.ssdental.com/appointments/appointments_dw.asp n na n n na
http://www.vasectomy.com/Appointment.asp?DoctorId=1967 n na n n na
Legend
n = no; y = yes; na = not applicable; l = low; m = medium; h = high
Criteria:
1: Is it a secure site?
2: Does it include a statement regarding its status as a secure site?
3: Does it request confidential data elements from the user making an appointment?
4: Does it include a privacy notice or statement of privacy policy?
5: What is the reading level of the privacy notice or statement of privacy policy? (SMOG grade)

645
6 of them require Social Security Number along with Including a privacy notice or statement of privacy
birthday. The secure sites require more confidential policy on a site is very important. Even though a site
data than non-secure sites. adopts security procedures and displays a privacy
policy, users might still not trust it or may be misled
4.4. Does it include a privacy notice or unless there is a brief and understandable statement
statement of privacy policy? of security and privacy displayed on the site. In our
study, we regarded the websites that have “https”
12 of 30 websites do not display a privacy notice or within their URLs as secure sites since information
statement of privacy policy, or a link to such a exchanged with any address beginning with https is
statement, on the web appointment request page. encrypted using Secure Sockets Layer (SSL) before
transmission. However, very few lay users realize
4.5. What is the reading level of the privacy the difference between “http” and “https”. It is thus
necessary to show that the website is secure by either
notice or statement of privacy policy?
displaying a secured seal or a brief statement. This is
especially important for the users with lower
Among 18 websites that have a privacy notice or
educational background, particularly when the site
statement of privacy policy on their appointment
requires users to submit confidential data such as
page, 13 of them have a medium or college reading
SSN, date of birth, medical record number, medical
level, 4 of them have a high reading level, and only
information, or insurance information.
one has a low reading level.

5. Discussion 6. Conclusion

There is an obvious need for secure websites to Security, privacy, and confidentiality are major
ensure visitors' privacy and prevent personal health concerns in e-Health services. HIPAA regulations, e-
information. A considerable challenge arises from Health Code of Ethics, HON principles, and other
trying to balance the desire to make information guidelines do not ensure that privacy protection and
freely available to users of the Internet, while at the data security are done appropriately or well. There is
same time protecting people's privacy and a gap between ideal and reality. More attention to the
confidentiality. [11] spirit of existing measures and procedures is needed
to safeguard patients’ privacy rights.
People who use the Internet for health-related reasons
have the right to expect that personal data they To deal with the challenges to manage and ensure
provide will be kept confidential and also have the individual privacy, the following steps should be
right to be informed that personal data may be taken to maintain the e-Health site visitor's rights to
gathered, and to choose whether they will allow their privacy and the confidentiality of personal
personal data to be collected and whether they will information:
allow it to be used or shared.
6.1. Ensure personal data security with user ID and
However, Non-medical professionals involved in password or using SSL Certificate Encryption and
providing online medical services may be unaware of display the Secured Seal to let the user know that his
the unique standards they must adhere to when or her transactions are secure.
dealing with online healthcare consumers and may
need to be educated about the obligation not to 6.2. Provide a statement or a link to the privacy
exploit patients or clients and to respect issues of policy of the e-Health site on the home page or the
privacy and confidentiality. [12] Few healthcare site navigational bar that is easily accessible and
consumers have any idea what is done with their understandable to the user.
personal data and health information on the Internet.
Even though a health website claims it respects 6.3. Do not collect name, birthday, phone number, e-
patients’ privacy and takes steps to protect patients’ mail address, or any other personal information
personal data, a patients’ data may not be safe during unless voluntarily provided by the visitor after the
the transaction process. The study of HONcode visitor is informed about the potential use of such
accredited medical and health websites reveals the information.
gap between ideal and reality. In our sample, one
third of the HONcode accredited sites that provide 6.4. Do not collect SSN, personal medical
online appointment services are not secure. information (medical conditions, health-seeking

646
behaviors and questions, and use of or requests for [updated 2007 Jan 22; cited 2008 Jan 21]. Available from:
information about drugs, therapies, or medical http://www.hon.ch/HONcode
devices) and other sensitive personal information
without the express consent of the site visitor, and [6] The Health On the Net Foundation. HON statistics
information. [updated 2006 Sep 6; cited 2008 Jan 21].
only after explanation of the potential uses of such
Available from http://www.hon.ch/Global/stat.html.
information.
[7] The Health On the Net Foundation. Operational
7. References definition for principle 3 - Confidentiality. [updated 2007
Oct 8; cited 2008 Jan 21]. Available from
[1] J. Marconi, “E-Health: Navigating the Internet for http://www.hon.ch/HONcode/Guidelines/hc_p3.html.
Health Information Healthcare”, Advocacy White Paper.
Healthcare Information and Management Systems Society, [8] The Health On the Net Foundation. HONcode Hunt.
May, 2002, as cited in Broderick M, Smaltz DH. E-Health [cited 2008 Jan 21]. Available from
Defined. E-Health Special Interest Group, Healthcare http://www.hon.ch/HONcode/Hunt/.
Information and Management Systems Society, 2003 May
5. [updated 2003 May 5; cited 2008 Jan 21]. Available [9] Https. Wikimedia Foundation; c2006 [updated 2008 Jan
from 17; cited 2008 Jan 21]. Available from:
http://www.himss.org/content/files/ehealth_whitepaper.pdf http://en.wikipedia.org/wiki/Https.

[2] K.A. Dyer, “Ethical Challenges of Medicine and Health [10] SMOG (Simple Measure of Gobbledygook). Words
on the Internet: A Review”, Journal of Medical Internet Count; c2006 [cited 2008 Jan 21]. SMOG Calculator.
Research. Centre for Global eHealth Innovation, Toronto, Available from: http://www.wordscount.info/hw/smog.jsp.
2001: 3(2). e23
[11] M.A. Winker, A. Flanagin, B. Chi-lum, J. White, K.
[3] H. Rippen, A. Risk. “eHealth Code of Ethics”, Journal Andrews, Kennett RL, et al., “Guidelines for medical and
of Medical Internet Research. Centre for Global eHealth health information sites on the internet: principles
Innovation, Toronto, 2000:2(2). e9 governing AMA websites”, Journal of American Medical
Association, American Medical Association, Chicago,
[4] Public Health Data Standards Consortium [homepage 2000:283(12), pp. 1600-1606.
on the Internet]. The Consortium; c2006 [updated 2006 Oct
11; cited 2008 Jan 21]. Summary of the HIPAA Privacy [12] K.W. Goodman, R.A. Miller. Ethics and Health
Rule. Available from: Informatics: Users, Standards, and Outcomes. In: Shortliffe
http://www.hhs.gov/ocr/privacysummary.pdf EH, Perreault LE, editors. Medical Informatics: Computer
Applications in Health Care and Biomedicine. Springer-
[5] The Health On the Net Foundation. HON Code of Verlag, New York, 2000:Chap. 7.
Conduct (HONcode) for medical and health Web sites

647

You might also like