skip to main content
US FlagAn official website of the United States government
dot gov icon
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
https lock icon
Secure .gov websites use HTTPS
A lock ( lock ) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


Title: The need for guidance and consistency in adolescent privacy policies: a survey of CMIOs
Research examining whether and how adolescent patients should gain access to their electronic health records is gaining momentum. We conducted a survey to explore diversity in adolescent privacy policies and identify common approaches in health information technology management for adolescent patients. Through descriptive analyses of survey data, we found a wide range of institutional policies regarding adolescent patient privacy, and large variations in health IT executives’ baseline knowledge of access policies. A majority of respondents agreed that formal guidelines pertaining to adolescent health record privacy would be helpful. Respondents suggested that these guidelines can be developed through the synthesis of multiple perspectives, including those of pediatricians, adolescent specialists, privacy experts, parents, patient advocates, and other professional entities.  more » « less
Award ID(s):
1652302
PAR ID:
10084797
Author(s) / Creator(s):
; ; ; ;
Date Published:
Journal Name:
American Medical Informatics Association 2018 Annual Symposium
Format(s):
Medium: X
Sponsoring Org:
National Science Foundation
More Like this
  1. Adolescence is a time when patients are approaching autonomy, both developmentally and legally. Yet they are still minors and are likely to encounter contradictions between situations in which they are treated as children and ones in which they are treated as adults. Being able to access their medical information may enable adolescents to take on a participatory role in their health care. However, federal policy, state law, and community norms are not consistent regarding adolescent healthcare and privacy. For example, in some regions and under some circumstances, adolescents may have consent and privacy rights similar to those of adults, with the right to make some, or all, of their own sensitive medical decisions privately. In other cases, parental notification is the norm, or guidance is unclear or lacking. In the absence of national guidelines, medical centers encounter serious challenges when developing policies about adolescent access to medical records via patient portals. The American Academy of Pediatrics has made recommendations, but these are not binding. To explore diversity in adolescent privacy policies and identify common approaches, we are conducting a qualitative study with key informants from different types of medical organizations in different regions of the country. The main objective is to identify diversity in adolescent privacy features within the patient portal. Another objective is to enumerate the factors involved in making portal access decisions. A third objective is to identify the potential need for more formalized guidance and standards on privacy features within the patient portal 
    more » « less
  2. Patient health records(PHRs) are crucial and sensitive as they contain essential information and are frequently shared among healthcare entities. This information must remain correct, up to date, private and accessible only to the authorized entities. Moreover, access must also be assured during health emergency crises such as the recent outbreak, which represents the greatest test of the flexibility and the efficiency of PHR sharing among healthcare providers, which ended up an immense interruption to the healthcare industry. Moreover, the right to privacy is the most fundamental right for a patient. Hence, the patient health records in the healthcare sector have faced issues with privacy breaches, insider outside attacks, and unauthorized access to crucial patients’ records. As a result, it pushes more patients to demand more control, security, and a smoother experience when they want to access their health records. Furthermore, the lack of interoperability among the healthcare system and providers and the added weight of cyber-attacks on an already overwhelmed system have called for an immediate solution. In this work, we developed a secured blockchain framework that safeguards patients’ full control over their health data which can be stored in their private IPFS and later shared with an authorized provider. Furthermore, the system ensures privacy and security while handling patient data, which can only be shared with the patients. The proposed Security and privacy analysis show promising results in providing time savings, enhanced confidentiality, and less disruption in patient-provider interactions. 
    more » « less
  3. Patients often have their healthcare data stored in centralized systems, leading to challenges when reconciling or consolidating their data across providers due to centralized databases that store patient identities. The challenges disrupt the flow of patient care where time is sensitive for both patients and providers. Decentralized technologies have enabled a new identity model–Self-Sovereign Identity (SSI)–that grants individuals the right to freely control, access, and share their own data. This work proposes a system that achieves SSI in a semi-permissioned blockchain network using an open protocol as the certificate of authority and several guidelines for securely handling transactions in the network. Open protocols like Keccak can grant access to a permission-based network such as Hyperledger Fabric. The network architecture ensures data security and privacy through mechanisms of multi-signature transactions and guidelines for storing transactions locally, making this architecture ideal for privacy-centered use cases, such as healthcare data-sharing applications. The ultimate goal is to give patients full control over their identity and other data derived from their identity within a semi-permissioned network. 
    more » « less
  4. Abstract ObjectiveOnline patient portals become important during disruptions to in-person health care, like when cases of coronavirus disease 2019 (COVID-19) and other respiratory viruses rise, yet underlying structural inequalities associated with race, socio-economic status, and other socio-demographic characteristics may affect their use. We analyzed a population-based survey to identify disparities within the United States in access to online portals during the early period of COVID-19 in 2020. Materials and MethodsThe National Cancer Institute fielded the 2020 Health and Information National Trends Survey from February to June 2020. We conducted multivariable analysis to identify socio-demographic characteristics of US patients who were offered and accessed online portals, and reasons for nonuse. ResultsLess than half of insured adult patients reported accessing an online portal in the prior 12 months, and this was less common among patients who are male, are Hispanic, have less than a college degree, have Medicaid insurance, have no regular provider, or have no internet. Reasons for nonuse include: wanting to speak directly to a provider, not having an online record, concerns about privacy, and discomfort with technology. DiscussionDespite the rapid expansion of digital health technologies due to COVID-19, we found persistent socio-demographic disparities in access to patient portals. Ensuring that digital health tools are secure, private, and trustworthy would address some patient concerns that are barriers to portal access. ConclusionExpanding the use of online portals requires explicitly addressing fundamental inequities to prevent exacerbating existing disparities, particularly during surges in cases of COVID-19 and other respiratory viruses that tax health care resources. 
    more » « less
  5. The healthcare sector is constantly improving patient health record systems. However, these systems face a significant challenge when confronted with patient health record (PHR) data due to its sensitivity. In addition, patient’s data is stored and spread generally across various healthcare facilities and among providers. This arrangement of distributed data becomes problematic whenever patients want to access their health records and then share them with their care provider, which yields a lack of interoperability among various healthcare systems. Moreover, most patient health record systems adopt a centralized management structure and deploy PHRs to the cloud, which raises privacy concerns when sharing patient information over a network. Therefore, it is vital to design a framework that considers patient privacy and data security when sharing sensitive information with healthcare facilities and providers. This paper proposes a blockchain framework for secured patient health records sharing that allows patients to have full access and control over their health records. With this novel approach, our framework applies the Ethereum blockchain smart contracts, the Inter-Planetary File System (IPFS) as an off-chain storage system, and the NuCypher protocol, which functions as key management and blockchain-based proxy re-encryption to create a secured on-demand patient health records sharing system effectively. Results show that the proposed framework is more secure than other schemes, and the PHRs will not be accessible to unauthorized providers or users. In addition, all encrypted data will only be accessible to and readable by verified entities set by the patient. 
    more » « less