Publication of the "Medical Information Security" Textbook — A "14th Five-Year Plan" Planning Teaching Material by the National Health Commission

Pubdate:2023-05-10

I. Main Introduction

    The development of medical science is inseparable from big data, informatization, and artificial intelligence. Currently, disease and health-related data and information have become key elements in the advancement of medical disciplines, especially playing a significant role in precision medicine, clinical diagnosis, and health management. On the other hand, with the widespread adoption of mobile internet technology and cloud computing, the leakage of healthcare data and the violation of medical records are continuously occurring, leading to an increasing emphasis on medical information security worldwide. Various laws, policies, and ethical standards have been introduced, posing greater challenges to the sharing of medical data and information. Against the backdrop of the rise of the fourth scientific paradigm and data-driven medical development, data sharing and data security have become one of the key elements in the advancement of medicine.

    To adapt to the rapid development of the era of medical informatics, the textbook "Medical Information Security," edited by Professor Shen Bairong, the Executive Dean of the Disease System Genetics Research Institute of West China Hospital of Sichuan University, has been recently published by People's Medical Publishing House.

    This book is a planned teaching material for the "14th Five-Year Plan" by the National Health Commission, a textbook for colleges and universities nationwide, and the first comprehensive textbook in China to introduce medical information security. It provides a comprehensive introduction to data protection methods and models, including privacy computing, and discusses and describes data security risks and solutions in different scenarios, as well as exploring the future development of the discipline of medical information security.

II. The book discusses the following topics:

  1. Background and Challenges of Medical Data Sharing and Medical Information Security

    With the rapid development of modern medical informatics, the sharing of medical big data and information has become an inevitable trend. However, its implementation requires meeting three conditions: consistency and universality of data content; consistency and computer readability of data structure; and the method and security of information sharing. Compared to information security in other fields, medical information security has particularities involving personal privacy, public interest, and national security. Against the backdrop of the continuous rise of ransomware and network security incidents in the medical industry, medical information security has become an urgent issue to be resolved.

    The book first introduces the content and significance of modern medical information security, the basic knowledge of medical information security and the basic concepts of cryptography, access control and protocols, software and operating system security, ethical review of medical information security, and relevant policies and regulations on data security, enabling readers to understand the current challenges and development directions of medical information security.

  1. Medical Information Privacy Risk Assessment and Privacy Protection Methods

    Modern medical informatics research requires the sharing and joint analysis of massive biomedical data. However, biomedical data types are numerous and contain a large amount of sensitive patient privacy information, making it necessary to focus on data privacy protection during data sharing and analysis.

    There are two important prerequisites for the privacy protection of biomedical data: one is to effectively assess the privacy leakage risks of biomedical data before sharing and use; the second is to provide sufficient privacy and security protection during the sharing and use process.

    Based on these two prerequisites, the book focuses on introducing several privacy computing technology routes and medical scenario cases, including multi-center research based on federated learning technology, data privacy protection with verifiable computing processes implemented by hardware-based trusted execution environments, multi-party secure computation and homomorphic encryption technology based on cryptography for protecting the computing process, and differential privacy technology for protecting the results of data.

  1. Discussion on Different Medical Information Security Scenarios and Measures

    Remote and cloud medical information security, individual medical and electronic health record information security, and hospital information system security are the main privacy and security issue scenarios in current medical informatization. With the combination of modern network technology, communication technology, multimedia technology, and medical care, the development of remote and cloud medicine is completely changing the existing medical model, making information security extremely important in this process. Individual medical and electronic health record information security is the most important information support in health medical big data, and the leakage of personal sensitive information can pose a serious security threat. At the same time, with the continuous deepening of medical informatization, hospital information systems have become an important support for the normal operation of medical services, and security issues in information systems can affect their efficiency and benefits.

    The book introduces relevant content on the information security of wearable devices, remote medical information, information security in cloud computing and blockchain, medical Internet of Things and medical consortium information security, individual medical and electronic health record information security, hospital information system security, and discusses effective measures to protect the integrity, confidentiality, and authenticity of medical information, thereby ensuring the security of medical information.

  1. Participatory Medicine and Information Security

    Participatory medicine is a new medical model under the background of an aging society and the prevalence of chronic diseases in the intelligent era. It will promote the transformation of medical service models from "doctor-centered" to "patient-centered," and the evolution from "clinical treatment model" to "health management model," which is also key to the transformation from "passive health" to "active health." Patient participation makes the collection and use of "cross-measurement, personalized, real-time dynamic personal health data" possible, but such personal big data also brings greater hidden dangers for identity identification and leakage of health information. Therefore, participatory medicine is a double-edged sword; while promoting the development of personalized medicine, it also poses challenges to medical information security and personal privacy protection.

    The book introduces information security in the participatory medical paradigm, multi-scale data in personal life, information security issues in the virtual society of the network, and information security in the management of human genetic resources under the integration of personal genetic data.

Conclusion

    Looking forward to the future development of medical information security, Professor Shen Bairong believes that the combination of algorithms can synthesize the advantages of algorithms and enhance the efficiency of privacy computing in cryptography; technically, the integration of hardware and software related to data information can be achieved; strategically, a variety of means need to work in concert to comprehensively enhance the protection of medical information security at the system level of the entire medical information security system. This is a systematic project that requires higher-level collaboration in society to achieve.

About the Editor-in-Chief

Professor Shen Bairong

    Dr. Shen Bairong, born in November 1964 in Rugao, Jiangsu, is a professor, doctoral supervisor, and holds a Doctor of Science degree. He is currently the Executive Dean of the Disease System Genetics Research Institute of West China Hospital of Sichuan University. He also serves as the Vice Chairman of the Chinese Bioinformatics Society (Preparation), a standing committee member of the Medical Informatics Branch of the Chinese Medical Association, the Chairman of the Sichuan Bioinformatics Society, the Director of the Medical Informatics Professional Committee of the Sichuan Medical Association, a part-time professor at the Systems Biology Institute in Seattle, USA, the founding chairman of the International Conference on Translational Bioinformatics and Systems Medicine (ICTBI/ICTI), and a review expert for major projects of the National Natural Science Foundation and the Ministry of Science and Technology. Dr. Shen studied under Academician Deng Jingfa, graduated with a Ph.D. from the Chemistry Department of Fudan University in June 1997, and has been engaged in interdisciplinary teaching and research in institutions such as Suzhou Medical College, Fudan University, Tampere University in Finland, Tongji University, Soochow University, and West China Hospital of Sichuan University for 32 years. He has presided over more than 10 major projects and NSF projects, trained more than 80 graduate students, and published more than 200 papers in various international disciplinary journals such as Bioinformatics, International Journal of Medical Informatics, Journal of Chemical Information and Modeling, Genome Biology, Journal of Translational Medicine, and Nucleic Acids Research. He has also edited and published 6 series of English works "Translational Informatics," and 3 Chinese works such as "Bioinformatics Analysis and Examples of Deep Sequencing Data."

About the Deputy Editors and Editorial Board Members

Deputy Editors:

  • Zhao Wei, Deputy Director of the National Center for Cardiovascular Diseases, Vice President of Fuwai Hospital, Chinese Academy of Medical Sciences

  • Cai Yongming, Dean of the School of Pharmaceutical Information Engineering (Director of the Information Center), Guangdong Pharmaceutical University

  • Zhang Zhaochen, Party Committee Secretary, School of Medical Information Engineering, Shandong First Medical University

  • Wen Chuanbiao, Party Committee Secretary, School of Intelligent Medicine, Chengdu University of Traditional Chinese Medicine

Some Editorial Board Members:

  • Wang Shuang, Professor, Founder of Nowaitech, Editorial Board Member and Secretary

  • Jin Tao, Professor, Big Data Research Center, Tsinghua University

  • Jia Jinying, Professor, Zunyi Medical University

  • Liu Gen, Professor, Department of Artificial Intelligence, Nanchang University

  • Wang Meng, Professor, Jining Medical College

  • Ye Mingquan, Professor, School of Medical Information, Wannan Medical College

  • Chen Qinqun, Professor, Information Center, Guangzhou University of Chinese Medicine

  • Zhang Yichen, Professor, Xinhua Hospital Affiliated to Shanghai Jiao Tong University School of Medicine