com and phone

Digitization of the healthcare system - Data security issues

Digitization of the healthcare system - Data security issues

The Federal Data Protection Officer presses the alarm button: He sees deficiencies in the data security of the planned electronic patient record. The digitization of the healthcare system is generally a huge construction site - with many unresolved problems.
By Peter Welchering

The digitization of the healthcare system has many construction sites (imago / Norbert Neetz)

“The fact that I and my colleagues from the federal states are addressing you during the ongoing legislative process shows how serious we consider the situation to be. Throughout the process of drafting the law, I have repeatedly and urgently urged compliance with the data protection requirements that have been known and agreed for many years. The result is all the more unsatisfactory in some important points. "
On Wednesday, the Federal Commissioner for Data Protection and Freedom of Information, Ulrich Kelber, justified his appearance at the federal press conference. There he announced measures against the statutory health insurance companies should they introduce the electronic patient file on January 1, 2021, as the Bundestag has decided.
Because, according to Kelber, that would violate the European General Data Protection Regulation. So there are concerns about electronic files.

What effects do the warnings of the Federal Data Protection Commissioner have on the legislative process?

That was a somewhat desperate warning shot. The electronic patient record was the external reason. But actually it's about something else. For 15 years there have been attempts to digitize the healthcare system in Germany - and for the last 15 years we have been hearing about bankruptcies, bad luck and mishaps. The tragedy surrounding the electronic health card alone speaks for itself. We are now facing two very decisive developments: firstly, to centrally manage the data of more than 60 million insured persons and, secondly, to set up a communication infrastructure for the entire healthcare system that enables considerable progress in medical care, but which can be massively misused. The electronic patient record shows, for example, that we are not able to

How is Kelber's warning to be assessed in general?

This is a failure on the technical and political level. This became very clear in the discussion after the federal press conference with Ulrich Kelber on the problems of electronic patient files. It has also become clear that we now have to decide: How do we continue with the patient file? Simply a restart, as ultimately happened with the health card, is not included here. That is why the course that is now being set for the electronic patient record (EPR) is eminently important, above all from a technical point of view. The EPR has set the precedent for the digitization of the healthcare system. That is what makes the discussion about them so relevant.

We are looking for a digitization strategy for the healthcare sector: What are the practical problems?

"Since health data are particularly sensitive, I insist that the health insurance companies only allow access to the health data of the electronic patient file from outside the secure telematics infrastructure after using a highly secure authentication method according to the state of the art", is how the Federal Data Protection Commissioner Ulrich Kelber justified his request for better protection when accessing the data in the electronic patient record via smartphones or tablets.
The previously envisaged procedures for access are highly insecure. In addition, policyholders initially have no option at all, and later only partially, to determine exactly which data the various specialists, general practitioners, pharmacists or individual therapists are allowed to see in their digital patient files.
For example, an insured person does not want his dentist to see his psychiatrist's reports. However, he cannot control access rights until 2022. And even after January 1, 2022, only insured persons should be able to do this from a smartphone or tablet, but not from their PC or laptop at home. Ulrich Kelber on this:
“In concrete terms, this means that insured persons who cannot or do not want to use a so-called front-end will not have sufficient control over their data in the long term. Instead, they are forced to choose between extremes. Either any body authorized by them, doctors, clinics can view all the information contained in the electronic patient file or none at all. "

How do the statutory health insurances assess this?

The health insurance companies want to enable such differentiated access. But they are slowed down. Barbara Thiel, State Commissioner for Data Protection in Lower Saxony, explained it like this:
"In discussions with the AOK Lower Saxony, we were working with the federal association on being able to offer a fine-grained access concept as early as January 1, 2021. That would of course be the solution. However, according to Gematik, it will probably not be possible to implement this in the secure environment of the telematics infrastructure in good time. "

What do the problems with the digital patient record mean for the general digitization of the healthcare system?

Above all, it is about a secure and data protection-compliant digitization of the healthcare system. The electronic patient record has to prove that this is possible. This is also pointed out by Stefan Brink, State Commissioner for Data Protection and Freedom of Information in Baden-Württemberg.
“As data protectors, we also see the digitization of the healthcare system as an eminent opportunity. We use them very intensively in the countries. The remote treatment ban has fallen. In Baden-Württemberg we have offers such as docdirekt, i.e. video consultation hours, e-prescriptions and the like. Data protection and digitization also go hand in hand in the healthcare sector. But you just have to make sure that this is coordinated and does not collide with one another as a result. Hence our appeal. "

What are the most important digitization construction sites in the healthcare sector?

The digital supply law with the lack of protection of patient data when it is passed on to research institutions and the completely inadequate regulation of health apps, the nullification of data protection in the implant register establishment law and the lack of control in the event of breakdowns in the telematics infrastructure of the health care system. We recently had a week-long failure for many practices because Gematik was unable to cope with a problem with the certificates that was actually not that serious. So we are faced with two problem areas: with legislation that either does not take sufficient account of data protection and data security issues or even literally overrules them. Secondly, with very practical problems in implementation,

What is the undermining of data protection in the Implant Register Establishment Act, which has been in force since January 2020?

The experts at the Gesellschaft für Informatik criticize the fact that a patient who has an implant inserted - a pacemaker, for example - has to submit all of his patient data to the registry. He has no right to object to data processing. And that means he cannot specify the conditions under which he wants to release his data. In addition, the patient data is only pseudonymized, not anonymized. In this way, however, it is easy to calculate the identity of an individual patient. In addition, it is still unclear where patient data is pseudonymized and where clear data is used. Even who has access to this data is not adequately regulated.

What does this mean for the digital supply law, in which patients cannot object to the fact that health insurances forward their data to the central associations?

On the one hand, the accounting data in the research data center can be stored unencrypted according to the legal situation. In this case too, the data itself is merely pseudonymized, not anonymized. It is also unregulated which research institutions are allowed to access this personal accounting data and how this data should then be protected.

Who is interested in this patient data?

First of all, organized crime. Peter Bauer from McAfee and his team did some research: the trade in patient data has now become just as important as the industrial espionage market segment.

Then companies are interested in this patient data, which precisely calculates a person's life expectancy. The aim is to save expensive therapies for the seriously ill. To do this, the data specialists at these companies use algorithms that calculate exactly when a person dies. Those who do not have long enough to live should only be cared for until death, but no longer receive medical therapy.
And ultimately, pharmaceutical companies are interested in this patient data because it allows them to better control the success of their sales representatives. With back-calculated data it can be determined whether a certain doctor has prescribed a certain drug significantly more often after visiting a pharmaceutical representative. In this case, the assignment to a doctor is made using the retroactive patient names.


Subscribe to get more videos :