The proposed introduction of a nationwide NHS network has led to concern about security. Doctors and other clinical professionals are worried that making personal health information more widely available may endanger patient confidentiality [ACH95]. The problem is not limited to the NHS; it also concerns clinicians in prisons, immigration services, forensic laboratories and private healthcare. However the NHS network has forced the issues to the fore.

It has been generally agreed that the security of electronic patient records must meet or exceed the standard that should be applied to paper records, yet the absence of clarity on the proper goals of protection has led to confusion. The British Medical Association therefore asked the author to consider the risks, and to prepare a security policy for clinical information systems.

Ross Anderson
Fri Jan 12 10:49:45 GMT 1996