Previously submitted to: Journal of Medical Internet Research (no longer under consideration since Feb 02, 2022)
Date Submitted: Aug 19, 2021
Open Peer Review Period: Aug 19, 2021 - Aug 30, 2021
(closed for review but you can still tweet)
NOTE: This is an unreviewed Preprint
Warning: This is a unreviewed preprint (What is a preprint?). Readers are warned that the document has not been peer-reviewed by expert/patient reviewers or an academic editor, may contain misleading claims, and is likely to undergo changes before final publication, if accepted, or may have been rejected/withdrawn (a note "no longer under consideration" will appear above).
Peer review me: Readers with interest and expertise are encouraged to sign up as peer-reviewer, if the paper is within an open peer-review period (in this case, a "Peer Review Me" button to sign up as reviewer is displayed above). All preprints currently open for review are listed here. Outside of the formal open peer-review period we encourage you to tweet about the preprint.
Citation: Please cite this preprint only for review purposes or for grant applications and CVs (if you are the author).
Final version: If our system detects a final peer-reviewed "version of record" (VoR) published in any journal, a link to that VoR will appear below. Readers are then encourage to cite the VoR instead of this preprint.
Settings: If you are the author, you can login and change the preprint display settings, but the preprint URL/DOI is supposed to be stable and citable, so it should not be removed once posted.
Submit: To post your own preprint, simply submit to any JMIR journal, and choose the appropriate settings to expose your submitted version as preprint.
Warning: This is an author submission that is not peer-reviewed or edited. Preprints - unless they show as "accepted" - should not be relied on to guide clinical practice or health-related behavior and should not be reported in news media as established information.
Representation of Personal and Person-Generated Data with HL7 FHIR and HAPI Endpoint Security with TSD: Proof-of-Concept Study
ABSTRACT
Background:
Interoperability is a challenge in healthcare information systems because of heterogeneity in semantic and technical levels of data. It creates a problem in exchanging data from different sources. Person-Generated Health Data (PGHD) is health-related data created, recorded, or collected by individuals or family members, or caregivers. PGHD can be captured passively and continuously to create a more accurate and comprehensive picture of the individual. PGHD is a category of Personal Health Records (PHR) that helps people to store and manage their health records. The rapid growth of PHRs and standards to exchange PHRs in a secure way have improved different aspects of health practices and personal care.
Objective:
This is a two-fold study. First, this study aims to investigate Health Level 7’s (HL7) new standard, Fast Healthcare Interoperable Resources (FHIR), as a standard format to explain information model (personal, physiological, and behavioral data from heterogeneous sources, such as activity sensor, questionnaire, and interview) and clinical terminologies together. Second, we explore the protocol’s advantages in some detail and critically analyze endpoint security of the HL7 application programming interface (HAPI).
Methods:
To address the interoperability problem, we combine FHIR and internationally acclaimed medical terminologies and use JavaScript object notion (JSON) to represent and exchange PGHD. We develop a secure digital infrastructure with TSD (services for sensitive data) as Infrastructure as a Service (IaaS), where we deploy the HAPI FHIR server as a docker image. We integrate the concepts such as authentication, authorization, and identity brokering to protect HAPI REST interfaces. PGHD inside TSD are protected following the Norwegian Data Protection Policies (NORMEN) and General Data Protection Regulation (GDPR). We use personal, physiological, and behavioral data involved in health monitoring and store them in the TSD database using the HAPI FHIR server. Storage and retrieval of PGHD from TSD are HL7 compliant.
Results:
First, we discuss storing PGHD in TSD and retrieving it from TSD following HL7 protocol using the HAPI FHIR server in JSON format, combining the information model and medical terminologies. Second, it describes how to secure HAPI REST APIs with the TSD platform.
Conclusions:
FHIR resources can establish a coherent view of PGHD collected from heterogeneous sources by enabling flexible data exchange between stakeholders and service providers. Besides, the study reveals that TSD is a secure platform for the management of PGHD. Clinical Trial: NA
Citation
Request queued. Please wait while the file is being generated. It may take some time.
Copyright
© The authors. All rights reserved. This is a privileged document currently under peer-review/community review (or an accepted/rejected manuscript). Authors have provided JMIR Publications with an exclusive license to publish this preprint on it's website for review and ahead-of-print citation purposes only. While the final peer-reviewed paper may be licensed under a cc-by license on publication, at this stage authors and publisher expressively prohibit redistribution of this draft paper other than for review purposes.