JOURNAL HOME CME HOME THIS MONTH PAST ISSUES ETOC COLLECTIONS
AUTHORS REVIEWERS EDITORIAL BOARD FEEDBACK RSS HELP
A&A International Anesthesia Research Society
 QUICK SEARCH:   [advanced]


     


This Article
Right arrow Full Text (PDF)
Right arrow Alert me when this article is cited
Right arrow Alert me if a correction is posted
Services
Right arrow Email this article to a colleague
Right arrow Similar articles in this journal
Right arrow Similar articles in ISI Web of Science
Right arrow Similar articles in PubMed
Right arrow Alert me to new issues of the journal
Right arrow Download to citation manager
Citing Articles
Right arrow Citing Articles via HighWire
Right arrow Citing Articles via Google Scholar
Google Scholar
Right arrow Articles by van Oostrom, J. H.
Right arrow Search for Related Content
PubMed
Right arrow PubMed Citation
Right arrow Articles by van Oostrom, J. H.

Anesth Analg 2005;101:1888
© 2005 International Anesthesia Research Society
doi: 10.1213/01.ANE.0000180265.58307.52


LETTER TO THE EDITOR

Web-Based Data Collection: Security Is Only as Good as the Weakest Link

J. H. van Oostrom, PhD

Department of Anesthesiology, University of Florida, Gainesville, FL, hans{at}anest.ufl.edu

To the Editor:

I read the paper by Avidan et al. (1) with great interest because the World Wide Web is a great communication tool and it is only logical that studies involving multicenter data collection would utilize it. When comparing a web-based method to a single computer data collection method (a database, for example), the biggest difference is the remote data entry and, thus, the communication aspect to the centralized server. Many choices can be made for this communication to occur, but the most convenient and cost-efficient method is to use the Internet as the authors have done. They rightfully point out that, because of this, security is the most critical issue. However, the generally accepted concept that "security is only as good as the weakest link" (2) is not applied to their methods. The authors acknowledge that they send their clinical data via insecure (unencrypted) email to their protected (firewalled) database server. This is similar to locking all the doors to your house but leaving the bathroom window open. The risk of intercepting data from email messages is not minimal. Emails typically flow through several servers (just look at the full headers of any email for "Received:" entries) and the system administrators for each of those systems have access to the emails. In addition, if there is a problem with email delivery (even if it is temporary), bounce messages are sent, and those typically are copied to system administrators. It is relatively easy for hackers to monitor unencrypted data streams. I agree that there is a small chance that a hacker would accidentally find the data stream, but it would be relatively easy to target this setup and to get a lot of data out of it.

In the United States, privacy and security of patient health information has been regulated by the Health Insurance Portability and Accountability Act (HIPAA) of 1996, Public Law 104–191. Under this law a setup as presented in this paper would be unacceptable.

Electronic, web-based data collection systems can be set up in compliance with HIPAA. Data must be encrypted as it flows through the system. Typically that means a secure SSL-based connection from the web browser on the client to the web server (https connections) and a secure encrypted connection between the web server and the database server. Firewall techniques can be employed as well because the database server only needs to accept connections from the web server. Only by ensuring that data are always encrypted and by maintaining and patching the computers the data reside on can we be reasonably sure that patient health information is private and secure.

References

  1. Avidan A, Weissman C, Sprung CL. An internet web site as a data collection platform for multicenter research. Anesth Analg 2005;100:506–11.[Abstract/Free Full Text]
  2. Arce I. The weakest link revisited [information security]. IEEE Security & Privacy Magazine 2003;1:72–6.



This article has been cited by other articles:


Home page
Anesth. Analg.Home page
B. M. Ilfeld, V. J. Loland, J. C. Gerancher, A. N. Wadhwa, E. M. Renehan, D. I. Sessler, J. J. Shuster, D. W. Theriaque, R. C. Maldonado, E. R. Mariano, et al.
The Effects of Varying Local Anesthetic Concentration and Volume on Continuous Popliteal Sciatic Nerve Blocks: A Dual-Center, Randomized, Controlled Study
Anesth. Analg., August 1, 2008; 107(2): 701 - 707.
[Abstract] [Full Text] [PDF]


This Article
Right arrow Full Text (PDF)
Right arrow Alert me when this article is cited
Right arrow Alert me if a correction is posted
Services
Right arrow Email this article to a colleague
Right arrow Similar articles in this journal
Right arrow Similar articles in ISI Web of Science
Right arrow Similar articles in PubMed
Right arrow Alert me to new issues of the journal
Right arrow Download to citation manager
Citing Articles
Right arrow Citing Articles via HighWire
Right arrow Citing Articles via Google Scholar
Google Scholar
Right arrow Articles by van Oostrom, J. H.
Right arrow Search for Related Content
PubMed
Right arrow PubMed Citation
Right arrow Articles by van Oostrom, J. H.


Lippincott, Williams & Wilkins Anesthesia & Analgesia® is published for the International Anesthesia Research Society® by Lippincott Williams & Wilkins with the assistance of Stanford University Libraries' HighWire Press®. Copyright 2006 by the International Anesthesia Research Society. Online ISSN: 1526-7598   Print ISSN: 0003-2999 HighWire Press