Initial Project Information: ISHTAR
Home European R&D List
Isar T IT Eductra
Updated: Nov 18, 97  

ISHTAR

Implementing Secure Healthcare Telematics Applications in Europe

[ Coordinator(s) ] [ Participants ] [ Project Objectives, ... ] [ Other Characteristics ]

Project Nr: HC 1028 Group: IV Project Duration: 36 months
Key words: Data Security
Category:Data Security in Health Telematics
Summary: The problem of ensuring that healthcare security requirements are addressed appropriately throughout the European Union is considerable and will take a substantial amount of time to take effect.
Healthcare security requirements are organisational, managerial, professional, legal and technical issues. The danger is that they are side-lined into the technical arena instead of being taken seriously at the level of education and awareness of healthcare professionals at the highest managerial level of HCEs.
The ISHTAR Project takes a major step in the awareness process and seeks to ensure that HCEs and 4FW Health Telematics Projects are kept in touch with the legal and safety issues arising from:
  • the widespread utilisation of Health Telematics in the context of direct patient care;
  • the legal implications of the EU Directive (95/46/EC) on the protection of individuals with regard to the processing of personal data and on the free movement of such data;
  • the implications of the forthcoming Council of Europe Recommendations on the protection of medical data.
Mission:Tight precautions to protect data in telematics-supported health services in Europe are the central concern of ISHTAR. The project will set up an expert group to advise and support the Commission and other personnel involved in security-sensitive health telematics projects. Existing guidelines on protection will be reinforced and products and services tested. The usefulness of telematics in handling the technicalities of data security will also be demonstrated. The project will launch publicity to heighten awareness of protection issues and also consider their legal and social implications.
URL: ted.see.plym.ac.uk/ishtar/

Coordinator(s)

  • Dr. Barry Barber
    NHS Executive Info. Manag. Center
    15, Frederick Road
    Edgbaston
    UK-B15 1JD Birmingham
    United Kingdom
    tel: 4 16 84 56 62 20
    fax: 44 16 84 56 67 70
    b.barber@imc.exec.nhs.uk
    url:

  • Ms. Alison Treacher
    ISHTAR
    Burton upon Trent
    DE13 8ZX
    United Kingdom
    tel: 44 1283 575 692
    fax: . 44 1283 575 692
    100606.2753@compuserve.com

Participants:

Name of InstitutionCity+Postal CodeCountryRegion
University of the Aegean Athens GR 11472 Greece GR254
HEIMDALL Limited Kingston upon Thames KT2 5EL GB UK532
Vrije Universiteit Brussel Brussels B-1050 Belgium BE1
Academisch Ziekenhuis Leiden Leiden 2300 RC Netherlands NL331
r3 Security Engineering AG Aathal CH-8607 CH
Universitartsklinikum Magdeburg Magdeburg D-39120 Germany DEE3

Project Objectives, Summary Description and Anticipated Results

The project’s main objective is to address the problems of health data protection and health information systems security within telematics applications in a horizontal way. This will be achieved by actioning programmes to raise the level of security awareness within healthcare establishments across Europe.

The work will be structured as follows:

  • Creating a group of experts on legal, medical and technical aspects of data protection in health care. This group will act as an advisory panel and "consultants" to both the Commission and to other health telematics projects facing security needs. This group will accumulate guidelines and training material from all relevant national, European and International security forums.
  • Providing means for implementing, validating and maintaining existing guidelines on health data protection and providing mechanisms and facilities to test relevant products and services with the support of expert assistance.
  • Enhancing existing security guidelines for health care by addressing the technical aspects of health data protection within the context of telematics applications and demonstrating their usefulness and practicality.
  • Increasing the awareness of both the public and health care personnel on issues related to health data protection by way of awareness seminars and world wide dissemination.
  • Identifying and analysing the legal and societal issues raised by telemedicine and networking in health care.

Other Characteristics of the Project:

Users involved
Security is an issue to be addressed by the whole organisation and users of telematics applications will be represented by the 10 verification centres involved in the project (estimate over 30,000). Key users and a major verification centre representative will also be a part of the project board.
Technologies and/or approach used
The project will use the most up-to-date information systems security guidance to impact on the technology applied to current information system architectures used in the European health environment.
Expected benefits for the citizen
The project will provide a greater awareness with the health care community of the significance and importance of security breaches - leading to patient damage, distress and possible death - if a breach occurs. This will highlight the importance of accuracy, integrity and availability in providing high quality health care services to patients.
Expected benefits for the users of the application
The successful implementation of security guidelines in health care establishments will mean that users can have confidence that the information systems they use has been satisfactorily reviewed from a security point of view and that they will not be open to legal action for negligence.
Expected benefits for the European Industries
The incorporation of effective security measures will give European health telematics systems a competitive edge in world markets where such security has not, until now, been adequately addressed. It will expand the market in Europe for security products.
Contribution to EU-policies
The EU Directive on the protection of individuals with regard to the processing of personal data and on the free movement of such data, especially the security requirements of Article 17, advocates the need to conduct risk analysis and appropriately secure information systems. The ISHTAR project will support and complement this Directive and its associated requirements. The requirements for the authentication of users, and the assurance of the integrity of the telematics systems and associated facilities is fundamental to the acceptance of EU policies on the utilisation of telematics to improve the cost effectiveness of European activities. In addition, facilities for ensuring the confidentiality of the information are vital in the sensitive area of patient care.

Validation Sites

Academisch Ziekenhuis Leiden Leiden Zuid-Holland NL
Université Catholique de Louvain Brussels Bruxelles Cap. BE
The Royal Hospitals NHS Trust London Greater London UK
AHEPA University Hospital of Thessaloniki Thessaloniki Kentriki Makedonia GR
Centre d'Evaluation et de Normalisation des Biotechnologies Dijon Bourgogne FR
Universitätsklinikum Magdeburg Magdeburg Magdeburg DE
Centre for Health Systems, Information and Communication Prague CZK
Hospital Egas Moniz Lisbon Lisboa e Vale do Tejo PT
RATE OY/Helsinki City Health and Data Protection Departments Espoo Uusimaa FI
Università di Brescia Brescia Lombardia IT

[ Top ] [ Coordinator(s) ] [ Participants ] [ Project Objectives, ... ] [ Other Characteristics ]

Isar T IT Eductra Next
Back to the Main Page
Copyright 1997 © EHTO All rights reserved
This server is the only official EHTO WWW knowledge repository.
Mail suggestions to: webmaster@ehto.org