Digi-HTA, assessment framework for digital healthcare services: information security and data protection in health technology – initial experiences

Authors

  • Jari Jääskelä Biomimetics and Intelligent Systems Group, University of Oulu, Oulu
  • Jari Haverinen Finnish Coordinating Center for Health Technology Assessment (FinCCHTA), Oulu and FinnTelemedicum, Research Unit of Medical Imaging, Physics and Technology, Faculty of Medicine, University of Oulu, Oulu
  • Rauli Kaksonen Biomimetics and Intelligent Systems Group, University of Oulu, Oulu
  • Jarmo Reponen FinnTelemedicum, Research Unit of Medical Imaging, Physics and Technology, Faculty of Medicine, University of Oulu, Oulu and Medical Research Center Oulu, Oulu University Hospital and University of Oulu, University of Oulu, Oulu
  • Kimmo Halunen Biomimetics and Intelligent Systems Group, University of Oulu, Oulu
  • Teemu Tokola Biomimetics and Intelligent Systems Group, University of Oulu, Oulu
  • Juha Röning Biomimetics and Intelligent Systems Group, University of Oulu, Oulu

Keywords:

health technology assessment, cyber security, telemedicine [http://www.yso.fi/onto/yso/p20333]

Abstract

It is well-known that security issues in medical devices, services and applications have potentially catastrophic consequences. To avoid compromising patient data or information systems, it is essential that healthcare services and products meet the relevant information security and data protection requirements. For these reasons, the Digi-HTA assessment includes information security and data protection assessment domains. The outcome of the Digi-HTA process is a recommendation that decision-makers can use during the procurement process. We present results and experiences from the first assessments made in the Digi-HTA process.

We have assessed six products so far and multiple assessments are in progress. The results indicate that healthcare product manufacturers have found the process useful, and usually, the manufacturers have had to improve the security of their product during the Digi-HTA process to get a favourable recommendation for their product. The assessment processes have taken longer than expected due to shortcomings and ambiguities in the provided self-assessment forms, and due to feedback cycles and meetings prompted by assessment findings. Of the six assessed products, four received a green light in information security and data protection, whereas two have received a yellow light due to issues that were not fixed during the process. In addition to shortcomings in adhering to best practices, we have also found exploitable security issues.

Downloads

Download data is not yet available.
Section
Scientific articles

Published

2022-04-14

How to Cite

Jääskelä, J., Haverinen, J., Kaksonen, R., Reponen, J., Halunen, K., Tokola, T., & Röning, J. (2022). Digi-HTA, assessment framework for digital healthcare services: information security and data protection in health technology – initial experiences. Finnish Journal of EHealth and EWelfare, 14(1), 19–30. https://doi.org/10.23996/fjhw.111776